▼
Allegations Only · No Settlement Yet
This article describes a class action complaint. The statements below are unproven
allegations. Devereux has not been found liable, has not yet responded to the complaint,
there is no certified class, and nothing to claim at this time. Claims made by the
ransomware group about what it obtained are the attacker's own assertions and have not
been verified. This page covers the data breach case only and is unrelated to any other
litigation involving Devereux. It is informational and is not legal advice.
A proposed class action accuses Devereux Advanced Behavioral Health of failing to secure the records of the children and adults it treats, after a ransomware group claimed to have stolen its data in late 2025. The complaint, Williams v. The Devereux Foundation d/b/a Devereux Advanced Behavioral Health (Case No. 2:26-cv-05354, U.S. District Court for the Eastern District of Pennsylvania, assigned to Judge Joshua D. Wolson), was filed on July 29, 2026 by a Pennsylvania parent suing on behalf of four minor children treated at a Devereux facility. Counsel are Bailey Glasser and Edelson Lechtzin.
What makes this case different from the ordinary healthcare breach filing is who is in the class. Devereux provides behavioral healthcare, special education and foster care services for people with autism, intellectual and developmental disabilities and mental health conditions, across roughly a dozen states. The records at issue are not just names and card numbers — according to the notice letters quoted in the complaint, they include diagnosis and treatment information and Social Security numbers, belonging in large part to children. Devereux has not yet responded, and the allegations are unproven.
Status
Complaint Filed · July 29, 2026
Williams v. The Devereux Foundation · U.S. District Court, Eastern District of Pennsylvania
The Incident
Suspicious network activity found November 9, 2025
A ransomware group posted a claim on November 28, 2025 · notice letters went out in December 2025
Data Reportedly Involved
Names, dates of birth, medical record and insurance numbers, diagnosis and treatment information, Social Security numbers, prescriptions and lab results
Categories vary by individual, per the notice letter quoted in the complaint
People Affected
No nationwide total published
One federal filing lists ~501 individuals; a Texas state report covers ~5,341 Texas residents alone · the complaint estimates "at a minimum several thousand"
Can I Claim?
No — nothing to claim yet
No settlement, no fund, no claim form, no deadline
The timeline in the complaint is short and has a gap in the middle of it.
Devereux identified suspicious activity on its network on November 9, 2025. On November 28, 2025, a ransomware group calling itself The Gentlemen posted publicly that it had taken Devereux data, started a countdown clock and threatened to leak the files if it was not paid within ten days. Devereux later put a "Notice of Data Event" on its website describing the categories of information involved more generally — name, demographic information, clinical information and financial information.
In December 2025, the named plaintiff received four notice letters from Devereux, one addressed to each of the four children. Those letters, quoted in the complaint, list a longer set of categories: name, address, date of birth and other contact and identifying information; medical record numbers and health insurance information; diagnosis and treatment information; and Social Security numbers, prescription information and lab results.
One thing to note about the complaint's own text. In an earlier paragraph it states that Devereux promised to notify people promptly and that "[t]o date, Devereux has not notified Plaintiff or Class Members of the breach." A later paragraph describes the four December 2025 letters the plaintiff actually received. Those two statements sit uneasily together, and we are flagging it rather than repeating either version as established fact. It may be a drafting artifact, or it may reflect a distinction the complaint does not spell out — for example between notifying individuals and making a public announcement.
The complaint also argues that Devereux has disclosed too little: it asks the court to require Devereux to say why the data was stored without adequate security, what the security deficiencies were, whether the data was encrypted, and how far the information has spread.
This is the single most important unknown, and it is worth being precise about what is and is not public.
The reason those numbers do not line up is almost certainly structural rather than contradictory. Devereux operates through separate state affiliates and centers, and breach notification obligations attach to each covered entity and to each state's residents. A single federal filing listing roughly 501 individuals and a Texas report covering roughly 5,341 Texas residents can both be accurate descriptions of different slices. What does not exist yet is an aggregate figure across all of Devereux's operations.
The practical takeaway for a reader: the Texas number alone already exceeds the single federal entry by an order of magnitude, so treat "501" as a floor for one entity, not a ceiling for the case. We will update this section if a consolidated total is published.
Most healthcare breach complaints spend their pages on credit card fraud and credit monitoring. This one spends real space on a different problem, and it is the strongest part of the filing.
A stolen adult identity usually surfaces within a billing cycle or two, because the adult is already using credit and watching statements. A stolen child's identity does not. Children generally have no credit file, so a thief can build an entire synthetic credit history against a child's Social Security number that nobody checks — and often nobody looks until the child applies for a student loan, a first credit card or an apartment years later. The complaint cites research putting roughly 915,000 U.S. children as identity fraud victims in a single year, at an average household cost of about $1,128 and 16 hours of remediation time, and describes cases where the fraud ran for more than a decade before discovery.
Layer the behavioral health context on top of that. The records here allegedly include diagnosis and treatment information for children receiving autism, developmental disability and mental health services, and in some cases foster care placements. That is a category of information people are careful with for a lifetime, and unlike a compromised account number it cannot be reissued. The complaint's request for lifetime identity theft protection for class members, rather than the customary one or two years, is aimed squarely at that mismatch.
This is not the first behavioral health breach case OCA has tracked. The Aspire Health Alliance settlement gives a sense of where these cases can land — a Massachusetts behavioral health provider whose 2023 breach ended in a $400,000 fund with automatic pro rata checks plus medical-identity monitoring. We have also covered breaches at Cummins Behavioral Health Systems and Behavioral Health Resources in Washington.
The complaint pleads four counts, all on behalf of a single nationwide class:
• Negligence and negligence per se. The core count. It alleges Devereux owed a duty to safeguard the information it required patients to hand over, and breached it. The per se theory borrows two outside standards: Section 5 of the FTC Act, which the FTC treats as prohibiting unreasonable data security, and HIPAA's Security Rule, with the complaint listing specific provisions it says were violated — access controls, audit logging, risk management policies and workforce training among them.
• Breach of express contract. The theory is that Devereux's Notice of Privacy Practices became part of the agreement for services, and that its promises to protect information and to notify people promptly of a breach were terms Devereux failed to perform.
• Unjust enrichment. Pleaded on the basis that Devereux benefited from collecting and holding the data while allegedly not paying for adequate security.
• Injunctive and declaratory relief. This one is unusually specific. It asks the court to declare Devereux's current security inadequate and to order concrete measures: third-party penetration testing and audits, automated security monitoring, network segmentation so a single compromise cannot reach everything, purging data no longer needed, and regular staff training on breach detection and response.
On damages, the complaint seeks actual, nominal, consequential and punitive damages, compensation for time spent responding to the breach, free credit monitoring and identity theft insurance, and attorneys' fees. Jurisdiction is pleaded under CAFA, with more than $5 million in controversy. All of this is relief requested on unproven allegations; nothing has been awarded.
Worth knowing for context: HIPAA itself gives patients no private right to sue. That is why the complaint routes HIPAA through a state-law negligence per se theory rather than suing under it directly — a standard move in healthcare breach cases, and one defendants routinely challenge. Our explainer on how data breach class actions work covers that structure in more detail.
As pleaded, the class is all persons in the United States and its territories whose personally identifiable information or protected health information was compromised in the breach. Excluded are Devereux and its officers, directors, legal representatives, successors, subsidiaries and assigns, along with the judge and judicial staff on the case and their immediate families.
The complaint notes that class members can be identified from Devereux's own records, which is how notice would be sent if the case ever reaches that stage. It also reserves the right to amend the definition — expected here, given the unresolved question of how many people and which Devereux entities are actually in scope.
No class has been certified. Nationwide classes in data breach cases are frequently narrowed or split by state as litigation proceeds, and the case may not survive to certification at all.
Devereux has not filed a response, so none of this is its stated position. But the defenses in healthcare breach litigation are well established, and readers weighing the complaint should know what is coming.
The first is standing. Defendants routinely argue that class members who have not suffered actual misuse of their data have alleged only a risk of future harm, which after the Supreme Court's decision in TransUnion LLC v. Ramirez may not be enough to get into federal court. That fight tends to determine the shape of the class. Expect Devereux to press it, and expect the plaintiff to respond that data taken by a ransomware group in an attack the group publicly advertised is materially different from data that merely sat exposed.
Beyond that: that a criminal attack does not by itself establish negligence, and that the complaint pleads no specific security failure it can point to — a common weakness in breach complaints filed before discovery; that the Notice of Privacy Practices is a regulatory disclosure required by HIPAA rather than a contract with bargained-for terms; that HIPAA's lack of a private right of action should not be circumvented through negligence per se; and that unjust enrichment does not fit where an express contract is also pleaded.
No. This is a lawsuit at the complaint stage, not a settlement.
That means:
• There is no settlement fund.
• There is no claim form.
• There is no payout and no deadline to act.
• You do not need to register, sign up, or contact anyone to preserve your rights.
For money to reach anyone, the case would have to survive Devereux's expected motion to dismiss, win class certification, and then settle or prevail at trial. That takes years and often does not happen. Be cautious of any site claiming you can file a Devereux data breach claim today — no claim process exists.
None of this depends on the lawsuit, and none of it is legal advice — these are the standard steps after a breach involving Social Security numbers.
• Keep the notice letter. It documents that Devereux identified you as affected, which is what a settlement administrator would eventually match against. If there are letters for several children, keep all of them.
• Consider a credit freeze rather than just a fraud alert. Freezes are free at all three bureaus and block new accounts outright; alerts only prompt extra verification.
• Freeze your children's credit. This is the step most parents do not know exists. Each bureau will create and freeze a minor's file on request with proof of guardianship. Given how long child identity fraud goes undetected, it is the highest-value action available here.
• Read explanation-of-benefits statements. Medical identity theft shows up as care you never received, and it is easy to skim past.
• Use any credit monitoring Devereux offers. Enrolling does not waive your right to participate in a class action or any future settlement.
Devereux's response is the next milestone, and a motion to dismiss on standing is the most likely form it takes. If the case survives that, it moves into discovery — where what Devereux's security actually looked like on November 9, 2025, and how many people across how many entities were affected, finally become answerable — and then to class certification.
Two things to watch alongside the docket. First, whether a consolidated victim count is published; the current spread between the federal and Texas filings is the biggest open question on the page. Second, whether additional complaints are filed and consolidated. Multiple plaintiffs' firms announced investigations into this breach in late 2025, which frequently produces parallel suits that get folded together.
OpenClassActions.com will watch the docket and update this page on a ruling, a certification decision, a consolidated victim count, or a settlement with a claim form.
Searches for "Devereux lawsuit" surface unrelated cases from prior years involving allegations about conditions and conduct at Devereux facilities. Those are separate matters, with different plaintiffs, different claims and no relationship to this one. Nothing on this page refers to them, and the data breach complaint makes no allegations of that kind.
Is there a Devereux data breach settlement or claim form?
No. This is a newly filed class action complaint, not a settlement. There is no settlement fund, no claim form, no payout and no deadline to act. Devereux has not been found liable, no class has been certified, and there is nothing to claim at this time.
What information was exposed?
According to the notice letters quoted in the complaint, the information varies by individual but could include names, addresses, dates of birth and other contact and identifying information; medical record numbers and health insurance information; diagnosis and treatment information; and Social Security numbers, prescription information and lab results. A separate notice on Devereux's website described the categories more generally as name, demographic information, clinical information and financial information.
How many people were affected?
No nationwide total has been published. Devereux appears to have reported through several separate entities: one federal filing in January 2026 lists roughly 501 individuals, while a report to the Texas Attorney General covers about 5,341 Texas residents on its own. The complaint estimates the class at "a minimum several thousand." Because Devereux operates in about a dozen states, the national figure is likely higher than any single filing shows.
Who does the proposed class cover?
All persons in the United States and its territories whose personally identifiable information or protected health information was compromised in the breach. Because Devereux serves children and adults with autism, intellectual and developmental disabilities, mental health needs and foster care placements, a large share of the class are minors. No class has been certified, so the definition could change.
What should I do if I got a notice letter?
Keep the letter — it identifies you as someone Devereux notified, which matters if a settlement is ever reached. Standard steps after a breach involving Social Security numbers include placing a free credit freeze with the three bureaus and reviewing account statements and explanation-of-benefits notices for care you did not receive. Parents can request and freeze a child's credit report, which is worth doing because a child's stolen identity often goes undetected for years.
Can I sue Devereux under HIPAA?
Not directly. HIPAA gives no private right of action, which is why this complaint uses alleged HIPAA violations to support a state-law negligence per se claim instead of suing under HIPAA itself. Individuals can file a complaint with the HHS Office for Civil Rights, which enforces HIPAA, but that process does not produce compensation.
Is this related to the earlier Devereux abuse lawsuits?
No. Devereux has faced separate litigation in prior years over allegations of abuse at its facilities. That is a different set of cases with different plaintiffs, different claims and no connection to this one. This page covers only the 2026 data breach class action.
• Williams v. The Devereux Foundation d/b/a Devereux Advanced Behavioral Health — Class Action Complaint, No. 2:26-cv-05354 (E.D. Pa., filed July 29, 2026).
• Devereux Advanced Behavioral Health — Notice of Data Event
• CourtListener — Devereux Foundation federal docket search
• HHS Office for Civil Rights — Breach Portal (reported breaches of unsecured protected health information)
• Texas Attorney General — Data Security Breach Reports
• HHS — HIPAA Security Rule
• FTC — What to Know About Credit Freezes and Fraud Alerts
• FTC — Child Identity Theft
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
For more class actions keep scrolling below.
Status
Complaint Filed — Allegations Only
Case Title
Williams v. The Devereux Foundation d/b/a Devereux Advanced Behavioral Health
Case Number
2:26-cv-05354
Court
U.S. District Court, Eastern District of Pennsylvania
Judge
Hon. Joshua D. Wolson
Date Filed
July 29, 2026
Defendant
The Devereux Foundation (Villanova, Pennsylvania)
Incident
Suspicious network activity identified November 9, 2025; ransomware group claim posted November 28, 2025; notice letters December 2025
Claims
Negligence and negligence per se; breach of express contract; unjust enrichment; injunctive and declaratory relief