Heart of America Medical Center Data Breach Lawsuit Investigation
Received a June 2025 breach notice from Heart of America Medical Center?
Dapeer Law, P.A. is investigating a potential class action against Heart of America Medical Center, a North Dakota based non-profit community hospital, on behalf of patients whose personal and health information may have been exposed in the June 2025 cyber incident.
Who may qualify
You may be eligible to participate in a class action if any of the following applies:
- You received a data breach notification letter from Heart of America Medical Center dated June 2025.
- Your letter offered enrollment in complimentary credit-monitoring services, with an enrollment window of roughly 90 days.
- You had personal or medical information held by Heart of America Medical Center in its capacity as a healthcare provider.
- No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
- Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.
Not sure if you qualify?
Send us your notice, we'll confirm your eligibility at no cost.
What happened
According to a notice Heart of America Medical Center filed with the Massachusetts Attorney General, the hospital detected suspicious activity on its network on or around June 12, 2025. Heart of America Medical Center reports that it launched an investigation with outside forensic specialists and determined on September 15, 2025 that an unauthorized third party had accessed its systems and removed certain files containing patient information.
Heart of America Medical Center reports that a third-party vendor completed its review of the affected files on May 12, 2026, that the hospital finished reviewing those findings on June 9, 2026, and that it received the final list of affected individuals on July 9, 2026. The hospital reported the incident to the Massachusetts Attorney General on August 5, 2026 and began mailing written notices to affected individuals. The filing indicates that the involved information includes medical information and Social Security numbers, and the hospital is offering complimentary credit-monitoring services with enrollment instructions provided in each individual letter. The gap between the June 2025 detection and the August 2026 notices, roughly 14 months, is one of the questions our investigation is examining.
The Embargo ransomware group publicly claimed responsibility for the incident and posted samples of what it described as data taken from the hospital. Because the exposed data reportedly includes Social Security numbers and medical information held by a hospital, affected individuals may face an elevated risk of identity theft, medical identity theft, and fraudulent use of health benefits. Medical information can carry heightened sensitivity and may be subject to protections under state law and federal health privacy rules.
What to do if you received a letter
Keep your notice letter
Do not discard it. Your letter contains the enrollment information for the credit-monitoring service and is important evidence if you decide to participate in a lawsuit.
Enroll in the free credit monitoring offered in your letter
Enroll in the complimentary credit-monitoring service offered in your letter before the stated deadline, which is reported to run about 90 days from the date of the notice. Accepting this benefit does not waive your right to pursue legal action.
Place a fraud alert or credit freeze
Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide.Because medical information was involved, also review the Explanation of Benefits statements from your health insurer for services you did not receive.
Speak with a data breach attorney
Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options, and advise whether you may be eligible to join a class action.
Submit your notice for a free review
Two minutes online. A licensed attorney reviews every submission.
Breach timeline
Compensation you may be entitled to
Out-of-pocket expenses
Credit freezes, identity restoration services, and other costs incurred responding to the breach.
Time spent monitoring
Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.
Identity theft & fraud losses
Unreimbursed funds stolen from accounts, unauthorized credit lines, or tax refund fraud tied to the breach.
Statutory damages
Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.
Injunctive relief
Court orders requiring Heart of America Medical Center to implement stronger data security practices going forward.
Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.
Common questions
I received a data breach letter from Heart of America Medical Center. What should I do? +
Keep your notice letter, enroll in the complimentary credit-monitoring service before the deadline stated in the letter, and review your credit reports, bank statements, and health insurance Explanation of Benefits statements for unfamiliar activity. Consider placing a fraud alert or security freeze on your credit files with all three major bureaus, stay alert for unsolicited requests for personal information, and contact a data breach attorney to understand your options.
Am I eligible to join a class action against Heart of America Medical Center? +
If you received a notice from Heart of America Medical Center about this incident, or your Social Security number or medical information was included in the files involved, you may be eligible. Factors that affect eligibility include your state of residence, the categories of your data exposed, and whether you experienced any economic or emotional harm.
How much money could I receive from a class action lawsuit? +
Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.
What personal information was exposed in the breach? +
The filing reports that the involved information includes medical information and Social Security numbers. Public reporting also refers to medical records and health insurance details. Your individual letter may list the specific categories of your information that were involved, so review it closely and keep it.
Did Heart of America Medical Center offer free credit monitoring? +
Yes. Heart of America Medical Center is offering complimentary credit-monitoring services to affected individuals, with enrollment instructions in each letter and a reported enrollment window of about 90 days. The provider and the length of coverage are not named in the public filing, so check your letter. Accepting this service does not waive your right to pursue legal action.
How many people were affected by the Heart of America Medical Center breach? +
The hospital reported the incident to the Massachusetts Attorney General as affecting 14 Massachusetts residents. The total number of individuals affected across all states has not been separately disclosed in the public filing. We will update this page as more becomes known.
Is there a deadline to take legal action? +
Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.
How do I get a copy of the official breach notice? +
Heart of America Medical Center's notice was filed with the Massachusetts Attorney General and can be downloaded from that office's data breach notification portal. Dapeer Law can also help you obtain a copy of the notice during a free consultation.
Sources & references
- Official breach notice filing · Massachusetts Attorney General, Data Breach Notification
- Company · Heart of America Medical Center (hamc.com)
- Credit bureau freezes · Equifax · Experian · TransUnion
- Free weekly credit reports · AnnualCreditReport.com
- Identity theft recovery guide · FTC IdentityTheft.gov
Don't let the deadline decide for you. Submit your claim today.
You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.