Data Breach · Lawsuit Filed

Comprehensive Care Services Sued Over Brain Cipher Ransomware Attack on Employee Data

Published October 1, 2026

Current and former employees of Comprehensive Care Services, Inc. (CCS), a Michigan perfusion services company, may be covered by a proposed class action alleging CCS failed to protect Social Security numbers and other personal data that the Brain Cipher ransomware group says it stole. No class has been certified and there is nothing to file yet.

Data breach graphic
▼ Allegations Only · No Settlement Yet

This article describes a class action complaint. The statements below are unproven allegations. Comprehensive Care Services, Inc. has not been found liable, there is no certified class, and nothing to claim at this time. This page is informational and is not legal advice.

What Is This About?

Comprehensive Care Services, Inc. (CCS), a Plymouth, Michigan company that supplies perfusion and autotransfusion services to hospitals, was sued in a proposed class action on September 21, 2026 in the U.S. District Court for the Eastern District of Michigan. The case, Palameta v. Comprehensive Care Services, Inc., Case No. 2:26-cv-13573, was brought by a former employee who alleges CCS did not adequately secure the personal information of its workers before a ransomware attack.

The complaint says the ransomware group Brain Cipher listed CCS on its leak site and claimed to have taken files that include employee personnel records. CCS has not responded to the lawsuit, and none of the allegations has been tested in court.

Status Complaint Filed Filed September 21, 2026 · E.D. Mich. · no class certified
Data Allegedly Exposed Social Security numbers, financial account details and other employee records Also names, addresses, dates of birth and professional licenses, per the complaint
Who It Covers (Proposed) Everyone in the U.S. whose information was compromised in the CCS breach
Can I Claim? No — nothing to claim yet

What the Complaint Says Happened

According to the complaint, a ransomware tracking site recorded on August 31, 2026 that CCS had been listed by Brain Cipher, a ransomware group that has been active since mid-2024. The group’s post allegedly carried the CCS name and logo and claimed more than 200 gigabytes of data, covering about 306,000 documents and files, roughly 160,000 of which involved employee personnel and other sensitive records.

The post also set a September 12, 2026 deadline to publish the data if no ransom was paid. The complaint says that date has passed and, on information and belief, the data has already been posted or soon will be. It also says CCS had not notified affected people or said anything publicly about a ransom demand as of September 21, 2026.

What Information Was Involved

The named plaintiff, a former CCS employee who now lives in Florida, says he had to give the company his name, address, Social Security number, date of birth, financial account information, contact details, emergency contacts, and medical and state licenses to be hired and paid. He believes that information was in the stolen files. CCS has not publicly confirmed which records were taken or how many people were affected.

The complaint is written mainly on behalf of current and former employees, though the proposed class is broader: everyone in the United States whose personal information was compromised in the breach, including anyone who received a notice.

The Legal Claims and What the Case Asks For

The lawsuit asserts negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy and a claim for a declaratory judgment. It alleges CCS failed to train staff on cybersecurity, failed to follow FTC guidance and industry frameworks such as the NIST Cybersecurity Framework, and delayed telling employees about the attack.

It asks for compensatory, punitive and statutory damages, restitution, and a court order requiring CCS to adopt adequate data security. The plaintiff is represented by Strauss Borrelli PLLC.

What CCS Employees Can Do Now

There is nothing to file in the lawsuit. Current and former employees who gave CCS a Social Security number can take steps that do not depend on the case: Our guide to what to do after a Social Security number is exposed covers each step in more detail.

What Happens Next?

As of October 1, 2026, the docket showed the complaint, a summons issued to CCS on September 22, and a routine notice about consenting to a magistrate judge. The case is assigned to U.S. District Judge Judith E. Levy and referred to Magistrate Judge Anthony P. Patti. CCS has not yet filed a response. If the company sends breach notices, more lawsuits may follow and could later be combined with this one.

Read the Complaint

The full Palameta v. Comprehensive Care Services, Inc. complaint is embedded below:

Your browser can’t display the embedded PDF. Open the complaint PDF in a new tab.


Palameta v. Comprehensive Care Services, Inc. — Class Action Complaint (PDF, September 21, 2026)

Questions

What is Comprehensive Care Services?

Comprehensive Care Services, Inc. (CCS) is a Plymouth, Michigan company that provides perfusion and autotransfusion services, the specialists and equipment that run heart-lung machines and blood-salvage systems during surgery, to hospitals and medical centers across North America.

What information was taken in the CCS data breach?

According to the complaint, the named plaintiff gave CCS his name, address, Social Security number, date of birth, financial account information, emergency contacts and medical and state licenses as a condition of employment, and he believes that information was in the stolen files. CCS had not publicly confirmed what was taken as of the filing.

Who is included in the proposed class?

The complaint proposes a nationwide class of everyone in the United States whose personal information was compromised in the CCS data breach, including anyone who received a breach notice. The court has not certified any class.

Is there a CCS data breach settlement or claim form?

No. The lawsuit was filed on September 21, 2026, no class has been certified and there is no settlement, fund or claim form. Anyone who receives a breach notice from CCS may want to keep it, because data breach settlements usually ask for the ID printed on the notice.

What can current and former CCS employees do now?

There is nothing to file in the lawsuit. Employees and former employees worried about exposure can place a free credit freeze with Equifax, Experian and TransUnion, review their credit reports and bank accounts, and report any misuse at the FTC’s IdentityTheft.gov.

Sources

• Class Action Complaint — Palameta v. Comprehensive Care Services, Inc., U.S. District Court for the Eastern District of Michigan, Case No. 2:26-cv-13573 (filed September 21, 2026): Complaint (PDF)
• Docket for Palameta v. Comprehensive Care Services, Inc., No. 2:26-cv-13573 (E.D. Mich.), via CourtListener: CourtListener Docket
• Federal Trade Commission — identity theft reporting and recovery: IdentityTheft.gov

For more class actions keep scrolling below.
Status Complaint Filed
Case Title Palameta v. Comprehensive Care Services, Inc.
Case Number 2:26-cv-13573
Court U.S. District Court, Eastern District of Michigan
Date Filed September 21, 2026
Judge Judith E. Levy
Court Docket CourtListener Docket

More Healthcare and Employee Data Breach Cases