Health Payment Systems Sued Over 12-Month Breach Delay
Data Breach · Healthcare Billing · Lawsuit Filed

Health Payment Systems Class Action Says Patients Waited a Year to Learn Their Data Was Exposed

Published August 12, 2026
Updated August 12, 2026

This case is about a breach at Health Payment Systems, the Milwaukee company behind the PayMedix medical billing platform, where an intruder sat in employee email accounts for four days in June 2025. The new class action says 9,380 people — some of whom had Social Security numbers and medical records exposed — were not told until about a year later.

Medical bills and paperwork — class action lawsuit over the Health Payment Systems data breach affecting 9,380 patients
Health Payment Systems processes medical bills and payments for providers and payors. The complaint alleges it left patient data unprotected and then delayed telling anyone.
Allegations Only · No Settlement Yet

This article describes a class action complaint. The statements below are unproven allegations. Health Payment Systems, Inc. has not been found liable, there is no certified class, and nothing to claim at this time. This page is informational and is not legal advice.

What Is This About?

Health Payment Systems, Inc. — a Milwaukee healthcare technology company that handles billing, payment processing and patient financing for providers and payors, and operates the PayMedix platform — is facing a proposed class action over a data breach that reached employee email accounts in June 2025. The complaint alleges the company failed to protect the patient information in those accounts and then took roughly a year to tell the people whose data was exposed. HPS has not been found liable, and the allegations remain unproven.

The case is captioned Baldwin v. Health Payment Systems, Inc., Case No. 2:26-cv-01342-LA. It was filed on August 5, 2026 in the U.S. District Court for the Eastern District of Wisconsin — the district where HPS is headquartered. The complaint brings claims for negligence and negligence per se, breach of implied contract, unjust enrichment, and declaratory judgment, on behalf of a proposed nationwide class.

Status Complaint Filed · August 5, 2026 Baldwin v. Health Payment Systems, Inc. · E.D. Wis. · No. 2:26-cv-01342-LA
People Affected 9,380 As reported by HPS to the HHS Office for Civil Rights on July 10, 2026
Data Involved Name, address, date of birth, member and subscriber IDs — plus Social Security number, medical information and health insurance information for some people Per the company's own notice of security event; categories varied by individual
Can I Claim? No — nothing to claim yet No settlement, no fund, no claim form. Complimentary credit monitoring is being offered to those notified

The Timeline Is the Story

Most data breach complaints have to work to establish that a company was careless. This one leads with a calendar, and the dates come from HPS itself.

According to the company's notice of security event, HPS became aware of suspicious activity involving certain employees' email accounts on or about June 27, 2025. It says it immediately secured the accounts and brought in third-party cybersecurity specialists, whose investigation determined that an unknown actor had access to certain emails from on or about June 24 to June 27, 2025 — a four-day window.

HPS then reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights on July 10, 2026, listing 9,380 individuals, and began mailing notification letters around the same time. That is roughly twelve and a half months after it discovered the intrusion.

The company's notice explains the gap this way: after the investigation concluded, it began "an in-depth process to identify the information that may have been contained in the impacted environment, identify the individuals whose information may have been impacted, and reviewed internal HPS records to identify address information for potentially impacted individuals," and says that process "was completed recently." Reviewing the contents of compromised mailboxes genuinely is slow work — email is unstructured, and figuring out which patient records sat in which message is a manual exercise that routinely takes months at healthcare companies.

Whether it justifies a year is the fight. HIPAA's breach notification rule requires covered entities to notify affected individuals "without unreasonable delay and in no case later than 60 days following discovery of the breach." The complaint's position is that the timeline blew through that window and left class members unable to protect themselves during the period when stolen data is most useful to criminals. HPS has not responded to the complaint on the public record, and no court has decided whether the delay was unreasonable.

What Was Exposed

The categories come from the company's own notice, and they varied by individual. For the broad group, the exposed fields were name, address, date of birth, ID, Subscription ID and Subscriber Person ID — the internal identifiers a billing platform uses to tie a person to their coverage and their bills.

For a narrower group, the notice says the information also included Social Security number, medical information and health insurance information. That combination is the one that matters. A Social Security number cannot be reissued the way a credit card can, and the Social Security Administration itself warns that getting a new number does not erase records held under the old one and can create fresh problems, including a thin credit file under the new number.

Medical information carries a separate risk that consumers tend to underestimate. Health data supports medical identity theft — someone obtaining treatment, prescriptions or equipment in your name — which can corrupt your own medical record with another person's history, and which surfaces on an explanation of benefits statement rather than a credit report. That is why the practical advice for a healthcare breach differs from the advice after a retail one; we cover it in our guide to medical identity theft after a data breach.

A Small Breach, Legally Speaking

At 9,380 people, this is a small breach by healthcare standards — orders of magnitude below the incidents that dominate the HHS portal. That cuts in two directions, and it is worth being straight about both.

It makes the case harder to sustain economically. Data breach class actions are largely driven by class size, and a class this small produces a smaller potential recovery to fund the litigation. It also puts pressure on the jurisdictional threshold: the complaint invokes the Class Action Fairness Act, which requires more than $5 million in aggregate claims. Spread across 9,380 people, that works out to well over $500 each — a figure the plaintiff will have to support if HPS challenges it.

On the other side, the sensitivity of the data is higher than in a typical large consumer breach. This is not an email-and-password dump. For some class members it is a Social Security number sitting next to medical and insurance information — the combination that supports both financial and medical fraud, and the combination that healthcare-focused criminal markets pay the most for.

Why the Complaint Doesn't Sue Under HIPAA

Readers often expect a healthcare breach lawsuit to be a HIPAA lawsuit. It cannot be, and understanding why explains how the complaint is actually built.

HIPAA has no private right of action. An individual cannot sue a company for violating it. Enforcement belongs to the HHS Office for Civil Rights, which investigates and can impose penalties, and to state attorneys general. Every court to consider the question has reached the same conclusion.

So plaintiffs' lawyers use HIPAA a different way. This complaint pleads that HPS is a covered entity subject to the HIPAA Privacy and Security Rules and to HITECH, and that its alleged failures constitute negligence per se — the doctrine that violating a statute designed to protect a class of people is itself evidence of a breach of the duty of care. The same move is made with Section 5 of the FTC Act. The legal claims that actually carry the case are the common-law ones: negligence, breach of implied contract and unjust enrichment.

Courts are genuinely split on whether federal statutes without private rights of action can supply the standard of care this way. Some accept it; others hold that borrowing a statute that Congress chose not to make privately enforceable is an end run. It is one of the first things to watch when HPS responds.

What the Complaint Asks For

The complaint seeks damages, restitution and disgorgement, and attorneys' fees. Its more distinctive requests are the non-monetary ones: an order requiring HPS to adopt specific data security practices and submit to future audits, a declaration that HPS owes an ongoing legal duty to secure patient data and to give timely breach notice, and — notably — payment for at least ten years of credit monitoring.

That ten-year request is a direct answer to the delay allegation. Standard breach settlements typically provide one to three years of monitoring. The argument for a longer term is that stolen data does not expire: identity thieves routinely hold records for a year or more before using them, and information sold on criminal markets can circulate indefinitely. Whether a court would ever order that is another matter — these requests are opening positions, and none of it has been awarded.

Is There a Settlement Yet?

No. Baldwin v. Health Payment Systems, Inc. is a lawsuit filed on August 5, 2026, not a settlement.

That means:

• There is no settlement fund.
• There is no claim form.
• There is no payout, and no deadline to act.
• Nothing is required of class members at this stage.

The filing of a complaint is the beginning of a case, not the end. HPS has not been found liable simply because a lawsuit was filed. If the litigation later settles, a court-appointed administrator would send notices and open a formal claims process with its own eligibility rules and deadlines, and we would update this page and our data breach settlements hub. Be cautious of any site claiming you can file a Health Payment Systems claim today.

Who Could Be Affected?

The complaint proposes a nationwide class of all individuals in the United States whose private information was compromised in the breach, excluding HPS and its affiliates, officers and directors, counsel, and the judicial officers assigned to the case. Based on the HHS filing, that is approximately 9,380 people.

Because HPS works behind the scenes — it processes billing and payments on behalf of healthcare providers and payors — many affected people may not recognize the company's name at all. If you received a notice referencing Health Payment Systems or PayMedix, you are likely in the proposed class even if you have never knowingly done business with either. No class has been certified, and the definition could change.

What Should You Do Now?

Nothing is required, but several things are worth doing regardless of how the case turns out.

Keep the notice. If a settlement is ever reached, the mailed notice is typically how class members establish eligibility.
Enroll in the offered monitoring. HPS says it is providing complimentary credit monitoring and identity theft protection to those it notified. It costs nothing and enrollment offers usually expire.
Consider a credit freeze at all three bureaus if your notice mentioned a Social Security number. A freeze is free and more protective than a fraud alert — see our comparison of credit freezes versus fraud alerts, and our checklist for what to do when your SSN is exposed.
Read your explanation of benefits statements. Care you did not receive is the main warning sign of medical identity theft, and it will not show up on a credit report.
Treat unexpected billing calls and emails with suspicion. Phishing follows breaches, and a caller who already knows your insurance details is not thereby legitimate.

This page is informational and is not legal advice.

What Happens Next?

HPS now has a deadline to respond to the complaint, and in data breach cases the first move is usually a motion to dismiss aimed at standing. The recurring argument is that class members who cannot point to actual misuse of their information have alleged only a risk of future harm, which under TransUnion LLC v. Ramirez may not be enough for Article III standing in federal court. Plaintiffs counter with mitigation costs, lost time and the specific sensitivity of the data.

Two features of this case make that fight more interesting than usual. The notification delay gives the plaintiff a concrete, non-speculative theory — that people were denied the chance to act during the window when it mattered most. And the presence of Social Security numbers alongside medical information tends to help plaintiffs at the standing stage, since courts have treated that combination as materially riskier than exposure of contact details alone.

Because HPS reported the breach to the HHS Office for Civil Rights, the incident also appears on the federal breach portal, where OCR may open its own investigation independent of this lawsuit. That is a separate track from the litigation and can produce its own findings or corrective action plan. If the case survives dismissal, the parties would move into discovery and the plaintiff would eventually seek class certification. Each step takes months, and the case could be amended, narrowed, consolidated with any later-filed complaints, or resolved along the way. OpenClassActions.com will watch the docket for a ruling on any motion to dismiss, certification activity, settlement talks or a future claim form.

Frequently Asked Questions

I've never heard of Health Payment Systems. Why do they have my data?

HPS is a business-to-business company. It provides billing, payment processing and patient financing to healthcare providers and payors, and runs the PayMedix platform, so your information reaches it through your provider or your health plan rather than through any direct relationship with you. This is common in healthcare breaches — the company holding the data is often one you have never heard of.

Does the credit monitoring offer mean HPS admitted fault?

No. Offering complimentary credit monitoring after a breach is standard practice and, in many states, effectively expected. It is not an admission of liability, and accepting it does not waive any legal rights you may have. Declining it does not strengthen a future claim either.

Is a four-day intrusion less serious than a longer one?

Not necessarily. What matters is what was reachable during the window, not its length. Employee mailboxes at a medical billing company can hold years of accumulated patient records in attachments and message bodies, so a short intrusion into the right accounts can expose as much as a long one elsewhere.

Can I still be part of the case if I did not receive a notice?

The proposed class is defined by whose information was compromised, not by who received a letter. But HPS built its notification list from its own records, so if you believe you were affected and got nothing, the practical step is to keep documentation of your relationship with the provider involved. There is no case to join at this stage regardless — no class has been certified.

Should I do anything now?

Nothing is required. Enroll in the offered monitoring, keep your notice, consider a credit freeze if a Social Security number was involved, and watch your explanation of benefits statements. There is no form to submit, no deadline, and no one legitimate asking you for money or account details today.

Sources

• Class Action Complaint, Baldwin v. Health Payment Systems, Inc., No. 2:26-cv-01342-LA (E.D. Wis. filed Aug. 5, 2026).
• Health Payment Systems, Inc., Notice of Security Event (published on the company's website).
U.S. Department of Health & Human Services, Office for Civil Rights, Breach Portal — incident reported July 10, 2026, 9,380 individuals.
HHS, Breach Notification Rule, 45 C.F.R. §§ 164.400–414.
Social Security Administration, "Identity Theft and Your Social Security Number".
HIPAA Journal reporting on the Health Payment Systems breach.


For more class actions keep scrolling below.
Status Complaint Filed — Proposed Class Action
Case Title Baldwin v. Health Payment Systems, Inc.
Case Number 2:26-cv-01342-LA
Court U.S. District Court, Eastern District of Wisconsin
Date Filed August 5, 2026
Claims Negligence and negligence per se; breach of implied contract; unjust enrichment; declaratory judgment
People Notified 9,380 (reported to HHS Office for Civil Rights July 10, 2026)

More Healthcare & Data Breach Cases