UMass Memorial Medical Center of Worcester settles data breach civil suit

UMass Memorial Medical Center - University Campus

WORCESTER – A civil case stemming from a 2021 payroll data breach at UMass Memorial Medical Center was settled for $1.2 million this week.

About 3,178 workers, who were shorted because of a cyber break-in in December 2021 that forced the shutdown of the payroll system, will be paid in the settlement, according to federal court documents.

Workers filed a lawsuit in March 2022 against UMass Memorial and its payroll management systems Kronos Inc. and UKG Inc., criticizing the hospital’s “insufficient computer security policies and practices.”

Demanding $5 million in the suit, workers contended that they were not paid on time and were not paid the full amount of wages they were supposed to receive during and after the freeze, court documents show.

During the breach, UMass Memorial paid the workers using the amount of hours worked in the time before the shutdown, while ignoring the amount of hours worked during the shutdown, the plaintiffs contended.

UMass Memorial denied any wrongdoing at the time of the case filing, stating it had paid the workers “for improper payments” in the months following the pay freeze.

A representative for UMass Memorial said the hospital would not release a statement about the settlement.

In the settlement, each worker will be paid in proportion to what they lost in the data breach.

Meantime, between June 2020 and January 2021, UMass Memorial patients were targeted in a data breach in which 209,048 individuals' information was accessed by a hacker.

The information included names, subscriber ID numbers, benefits, election information, social security numbers and driver’s license numbers.

The hospital offered free credit monitoring and data protection services to those affected by the breach.

This had been the second time UMass Memorial patients were notified of a breach in recent years. In September 2020 UMass Memorial informed patients that a vendor that provides data services, Blackbaud, was hit by a data breach.

Law360: UMass Medical to pay $1.2 million to settle data breach claims

This article originally appeared on Telegram & Gazette: UMass Memorial Medical Center of Worcester settles data breach suit