The Virta Health lawsuit is a proposed class action filed in April 2026 in the U.S. District Court for the District of Colorado after a March 2026 data breach exposed personal and medical information belonging to roughly 14,636 patients of Virta Health Corp. and Virta Medical PC.1HIPAA Journal. GrayRobinson, C2N Diagnostics, Virta Health Data Breach2Westlaw. Koenemann v. Virta Health Corp. The suit alleges the company failed to protect patient data from a ransomware attack claimed by the Lapsus$ cybercriminal group.
Who Filed the Lawsuit and What It Claims
Former Virta patient Julie Koenemann filed the case, Koenemann v. Virta Health Corp., No. 26-cv-1469, on April 7, 2026. She is represented by Milberg PLLC.2Westlaw. Koenemann v. Virta Health Corp.
The complaint alleges Virta did not maintain security practices consistent with Federal Trade Commission guidelines and industry standards, and it brings claims including negligence and unjust enrichment. It also alleges that patient data ended up exposed to the dark web.3Law360. Colo. Co. Failed to Prevent Patient Data Leak, Suit Says
As of mid-2026, the case is in its early stages. No motions, class certification decisions, or settlement discussions have been reported.
What Information Was Exposed
Virta identified the intrusion on March 24, 2026, two days after unauthorized access ended. The company has described the compromised data repository as separate from its main production platform.4Virta Health. Notice of Data Event5Mason LLP. Virta Medical Data Breach Class Action
According to Virta’s public notice, the exposed information included:4Virta Health. Notice of Data Event
- Names, dates of birth, Social Security numbers, and Individual Tax Identification Numbers.
- Medical diagnoses, conditions, treatment details, dates of service, physician and facility information, and medical record numbers.
- Health insurance information and other unique health identifiers.
Who Was Behind the Attack
The Lapsus$ threat group publicly claimed the attack. Cybersecurity reporting places the announcement on March 27, 2026, when the group said it had added Virta Health as a target after releasing data allegedly stolen from AstraZeneca. Lapsus$ suggested a publication of Virta’s data could follow “within days” and claimed the dataset could be larger than the AstraZeneca one.6SOCRadar. AstraZeneca Data Breach: What to Know
There is an unresolved timeline question. Virta’s official notice to the California Attorney General limits unauthorized access to March 19 through March 22, 2026, but a third-party source has suggested initial access may date back to April 2023. That discrepancy has not been publicly resolved.4Virta Health. Notice of Data Event
What Affected Patients Can Do
Virta mailed notification letters to affected individuals on June 17, 2026.7ClaimDepot. Virta Health 2026 Data Breach The company is offering 12 months of complimentary single-bureau credit monitoring, credit report, and credit score services through CyberScout. Enrollment must be completed within 90 days of June 17, 2026, using a unique code included in the notification letter.8Federman & Sherwood. Virta Health Corp. and Virta Medical P.C. Data Breach Investigated by Federman & Sherwood
Virta also recommended that affected individuals place fraud alerts or credit freezes with the three major credit bureaus, monitor their credit reports at AnnualCreditReport.com, and review medical records and insurance statements for unfamiliar services.4Virta Health. Notice of Data Event
Other Law Firm Investigations
Two additional firms have publicly announced investigations tied to the breach, though neither had filed a formal complaint as of June 2026.
Cole & Van Note posted an investigation update on June 15, 2026, saying it would pursue legal action on behalf of affected individuals. The firm identified potential grounds including negligence, breach of contract, violations of the Fair Credit Reporting Act, and several California-specific statutes covering medical information confidentiality, consumer protection, and unfair competition.9Fierce Healthcare. Virta Health Data Breach Investigation
Federman & Sherwood is investigating whether Virta implemented reasonable cybersecurity safeguards and whether the breach could have been prevented.8Federman & Sherwood. Virta Health Corp. and Virta Medical P.C. Data Breach Investigated by Federman & Sherwood
Virta’s Response
Virta reported the incident to the California Attorney General and the U.S. Department of Health and Human Services beginning May 23, 2026, and posted a public notice on its website on May 22, 2026, later updated on June 12, 2026.7ClaimDepot. Virta Health 2026 Data Breach4Virta Health. Notice of Data Event The company stated it secured the affected environment, engaged external cybersecurity experts, and notified law enforcement.5Mason LLP. Virta Medical Data Breach Class Action