Kettering Health Ransomware: 1.7M Affected, 200+ Lawsuits
Data Breach · Ohio Health System · Lawsuits Filed

Kettering Health's Ransomware Attack Exposed 1.7 Million People — and the Lawsuits Are Mostly About Delayed Care

Published August 13, 2026
Updated August 13, 2026

In May 2025 the Interlock ransomware group shut down Kettering Health, an Ohio system with 14 medical centers, forcing staff onto pen and paper for about three weeks. The federal breach portal now puts the number of people whose health information was exposed at 1,695,382 — and the litigation that followed is unusual, because most of it is about canceled appointments rather than stolen records.

Hospital corridor — lawsuits over the Kettering Health ransomware attack that exposed 1,695,382 people
Kettering Health took roughly 600 digital applications offline after the May 20, 2025 attack. The suits filed since allege the shutdown delayed or denied patient care.
Allegations Only · No Settlement Yet

This article describes pending civil complaints. The statements below are unproven allegations. Kettering Adventist HealthCare has not been found liable, no class has been certified, and there is nothing to claim at this time. This page is informational and is not legal advice.

What Is This About?

Kettering Health — the Ohio nonprofit system operating 14 medical centers and roughly 120 outpatient facilities across the Dayton region — is facing two waves of litigation over a ransomware attack it detected on May 20, 2025. One wave is a conventional data breach class action. The other, and the larger one, is a set of individual personal-injury suits alleging that the three-week technology outage delayed or denied patients' medical care. Kettering Health has not been found liable on any of it.

The attack itself is now fully quantified. Kettering Health's investigation concluded that an unauthorized party first reached its network on April 9, 2025 and kept that access until May 20 — a window of about six weeks before anything was detected. The Interlock ransomware group claimed responsibility, listed the health system on its dark web leak site, and published the files it said it had taken when no ransom was paid. In April 2026, eleven months after the attack, the federal breach portal entry was revised from a placeholder figure to 1,695,382 individuals.

Status Lawsuits Filed · Pending in Ohio State Court Montgomery County Court of Common Pleas · 44 suits consolidated under a master complaint; counsel reports 200+ filed overall
People Affected 1,695,382 Per the HHS Office for Civil Rights breach portal, revised around April 2026 from an initial placeholder of 501
Data Involved Names, Social Security numbers, driver's license and passport numbers, medical and diagnosis information, insurance and billing data, financial account numbers Categories varied by individual, per Kettering Health's notice of privacy incident
Can I Claim? No — nothing to claim yet No settlement, no fund, no claim form. Credit monitoring and identity restoration are being offered through Cyberscout, a TransUnion company

Three Weeks on Pen and Paper

The operational damage is what separates this incident from a routine records breach, and it is documented in Kettering Health's own public updates.

When the attack surfaced on the morning of May 20, 2025, the system took roughly 600 digital applications offline. Scheduled inpatient and outpatient procedures were canceled that day. Emergency departments went on diversion. Staff reverted to established downtime procedures, recording patient information on paper while phone lines and the call center were down. Kettering Health also warned within hours that callers were impersonating its staff and demanding credit card payments for medical bills, and said it would stop taking payments by phone entirely until further notice.

Restoration came in stages. The core of the Epic electronic health record was back on the morning of June 2, 2025, which let clinicians enter patient information directly again and begin working through the backlog of paper records. The MyChart patient portal returned in limited form on June 9. On June 10, Kettering Health announced that normal operations had resumed for surgery, imaging, retail pharmacy and physician office visits.

That timeline covers the systems. It does not cover the appointments. A hospital that cancels three weeks of scheduled procedures does not absorb the backlog in three weeks, and the gap between "systems restored" and "patients seen" is the space the personal-injury claims occupy.

What Interlock Claimed, and What Kettering Confirmed

Two very different numbers circulate about this breach, and they measure different things.

Interlock, a ransomware group that emerged in late 2024 and has repeatedly targeted healthcare organizations, claimed on its leak site that it took 941 gigabytes of data — 732,490 files across 20,418 folders. That is the attacker's own claim, published to pressure a victim into paying, and it has not been independently verified. Extortion groups have an obvious incentive to overstate what they hold. Based on folder and file names visible on the leak site, the material appeared to include payroll and employee files, scanned identity documents, pharmacy and blood bank records, financial and tax documents, and patient files.

Kettering Health's confirmed figure is the one that matters legally: 1,695,382 individuals whose protected health information was involved, as reported to the HHS Office for Civil Rights. A file count and a person count are not comparable — a single spreadsheet can hold tens of thousands of records, and one patient can appear across dozens of files.

On the substance of what was exposed, Kettering Health's completed file review identified name, contact information, date of birth, Social Security number, patient identification number, medical record number, medical, treatment and diagnosis information, health insurance information, driver's license or state ID number, financial account information and education records. Reporting on the breach portal entry also lists passport numbers and usernames with associated passwords. The categories varied by person; nobody should assume every field applied to them.

Why the Count Took Eleven Months

Kettering Health reported the breach to federal regulators on July 21, 2025 using the figure 501. That number is not an estimate of anything. Under the HIPAA Breach Notification Rule, a breach affecting 500 or more people must be reported to HHS within 60 days of discovery, and organizations that have not finished counting file the smallest qualifying placeholder to meet the deadline while the review continues. Reading "501 affected" on the federal portal in mid-2025 meant only that Kettering Health did not yet know.

The real number did not appear until around April 2026. Nearly a year of that gap was spent on document review — determining which patient records sat inside which stolen files, then matching them to current addresses for mailing. That work genuinely is slow, and it is slow at every large healthcare breach.

It also has a cost that is easy to overlook. For most of the eleven months the entry sat on the portal at 501, the public record understated the incident by more than three orders of magnitude, and the people in it could not know they were in it. That interval is central to the plaintiffs' framing: stolen data is most valuable to criminals early, and the class members' opportunity to freeze credit or watch for fraud ran while the count was still a placeholder.

Two Different Sets of Lawsuits

Coverage of this case tends to blur two separate tracks. They involve different plaintiffs, different injuries and different legal theories, and only one of them is a class action.

The data breach class action. In June 2025, weeks after the attack and long before the victim count was known, attorneys announced a proposed class action in the Montgomery County Court of Common Pleas on behalf of patients whose information was taken. The complaint alleges that Kettering Health was aware of the risk of a ransomware attack, failed to take reasonable steps to protect patient data, and did not meet regulatory guidance or industry-standard security practices. This is the track that would eventually produce a settlement and a claim form if it succeeds — and it is the reason the site's earlier Kettering Health data breach investigation page exists.

The delayed and denied care suits. These are individual personal-injury claims, not class claims, and they are the larger group. According to Wright & Schulte LLC, the Vandalia, Ohio firm representing many of the plaintiffs, 44 individual lawsuits were consolidated under a single master complaint in Montgomery County Common Pleas. Of those, the firm said 37 alleged delayed treatment and eight alleged outright denial of care. By early March 2026 the firm reported having filed suits on behalf of roughly 200 patients on care-related claims, and said more than 500 additional people had contacted it about stolen information.

The consolidated complaint asserts negligence, gross negligence, emotional distress and breach of contract. Plaintiffs' counsel has said publicly that the health system had no contingency plan for a ransomware attack and, in his words, "just stopped seeing patients, stopped taking phone calls, and they started turning everybody away." Patients in the litigation allege appointments rescheduled months out, prescription delays, and in some cases appointments never rescheduled at all — including, according to counsel, patients receiving cancer treatment and other critical care. Kettering Health has not been found liable, and no court has ruled on any of these allegations.

What "In Excess of $25,000" Actually Means

The consolidated complaint seeks damages in excess of $25,000, plus punitive damages, attorneys' fees and costs. That figure gets misread constantly, so it is worth being precise: it is a pleading formality, not a valuation.

Ohio Civ.R. 8(A) prohibits a plaintiff in a common pleas case from demanding a specific dollar amount. The rule requires the complaint to state only whether the amount sought exceeds $25,000 — the threshold that separates common pleas jurisdiction from the lower courts. Every complaint of this type in Ohio state court contains the same phrase, whether the case is worth $30,000 or $30 million. It tells you which courthouse the case belongs in and nothing else.

The plaintiffs are also seeking non-monetary relief: security improvements at Kettering Health intended to prevent a repeat. That is standard in breach litigation and, in practice, often survives into a settlement even when the cash component is modest.

Why the Care Claims Are the Harder Ones to Defend

From a defense perspective, the delayed-care suits are the more dangerous track, and the reason is structural rather than moral.

Data breach cases are hard for plaintiffs because the injury is usually contingent. Most class members cannot point to money actually stolen; they point to an elevated risk that someone will misuse their information later. Defendants attack that as speculative, and in federal court the argument runs through TransUnion LLC v. Ramirez and the question of whether a risk of future harm supports Article III standing. Many breach cases die there or settle for modest per-person amounts.

A delayed-care claim does not have that problem. The plaintiff identifies a specific appointment on a specific date that did not happen, and a specific medical consequence that followed. That is an ordinary personal-injury case with an ordinary injury, and it is worth vastly more per plaintiff than a breach claim. It is also why these suits were filed individually rather than as a class: the injuries are too different from one another to certify, since what happened to a patient whose chemotherapy slipped two weeks has little in common with what happened to a patient whose imaging was rescheduled.

The defense arguments are real, though. Causation is contested in every case of this kind — a hospital will argue that a two-week delay did not change a clinical outcome, and proving otherwise requires expert testimony patient by patient. There is also the threshold question of whether a claim arising from canceled care is an ordinary negligence claim or a medical claim under Ohio law, which carries a shorter limitations period and its own procedural requirements. How that gets characterized will shape the litigation more than the headline numbers do.

HIPAA Is Not the Claim

Readers reasonably expect a hospital breach case to be a HIPAA case. It cannot be.

HIPAA has no private right of action. An individual cannot sue a covered entity for violating it, and every court to consider the question has said so. Enforcement belongs to the HHS Office for Civil Rights, which can investigate and impose penalties, and to state attorneys general.

So the statute shows up a different way. Plaintiffs plead state-law claims — negligence, gross negligence, emotional distress, breach of contract — and use HIPAA's Security and Breach Notification Rules as evidence of the standard of care a healthcare organization owes. The federal rules define what reasonable data security looks like; the state-law claim is what actually carries the case.

Separately, because the breach was reported to OCR, the incident sits on the federal portal where the agency may open its own investigation. That track is independent of the lawsuits and can produce its own findings, penalties or corrective action plan on its own timeline.

Is There a Settlement Yet?

No. This is active litigation, not a settlement.

That means:

• There is no settlement fund.
• There is no claim form.
• There is no payout, and no deadline to act.
• No class has been certified.

If the data breach case later settles, a court-appointed administrator would mail notices and open a formal claims process with its own eligibility rules and deadlines, and this page and our data breach settlements tracker would be updated. Until then, any site inviting you to file a Kettering Health claim, or asking for a fee or bank details to secure a payout, is a scam — and this breach has already attracted phone scams, which Kettering Health warned about publicly within hours of the attack.

Who Could Be Affected?

Approximately 1,695,382 current and former Kettering Health patients, based on the figure reported to federal regulators. The health system serves the Dayton region of western Ohio, so the exposed population is concentrated there, though former patients who have since moved are included.

Employees may also be affected. The material Interlock published appeared, by file and folder name, to include payroll records, employee files and scanned identity documents alongside patient data. The federal count covers protected health information, which is a narrower category than everything that was taken.

The delayed-care suits are a much smaller and more specific group: patients whose appointments, procedures or prescriptions were canceled, postponed or never rescheduled during and after the outage, and who can tie a medical consequence to that gap. Being in the breach population does not by itself put someone in that group.

What Should You Do Now?

Nothing is required, but several steps are worth taking regardless of how the litigation turns out.

Keep your notice letter. If a settlement is ever reached, the mailed notice is normally how class members establish eligibility.
Enroll in the offered monitoring. Kettering Health says it is providing credit monitoring and identity restoration services through Cyberscout, a TransUnion company, to those it notified. Enrollment windows expire.
Consider a credit freeze at all three bureaus if your notice mentioned a Social Security number. A freeze is free and more protective than a fraud alert — see our comparison of credit freezes versus fraud alerts and our checklist for what to do when your SSN is exposed.
Read your explanation of benefits statements. Care you never received is the main warning sign of medical identity theft, and it will not appear on a credit report.
Change reused passwords. Usernames with associated passwords were among the exposed categories, so any account sharing those credentials is at risk.
Treat unexpected billing calls with suspicion. Kettering Health said it would not request payment by phone during the incident, and a caller who already knows your insurance details is not thereby legitimate.

This page is informational and is not legal advice.

What Happens Next?

The consolidated care claims proceed in Montgomery County Common Pleas, where the early fights will be over how those claims are characterized under Ohio law and whether individual causation can be established. Because they were filed individually rather than as a class, they resolve individually — there is no single ruling that ends them all, and no collective settlement that would reach patients who never filed.

The data breach class action follows a different clock. Its next milestones are a response from Kettering Health, any motion practice over whether breach plaintiffs have alleged a cognizable injury, and eventually a motion for class certification. Each of those steps takes months, and the count revision to 1,695,382 arriving in 2026 may prompt amended pleadings or additional filings now that the actual scope is on the record.

Kettering Health, for its part, says it has reviewed its security policies and procedures, removed the attackers' tools and persistence mechanisms, and implemented network segmentation, enhanced monitoring and updated access controls. It has said it is unaware of any misuse of the exposed information. OpenClassActions.com will watch the Ohio dockets for rulings, certification activity, settlement talks or a future claim form, and will update this page when any of it lands.

Frequently Asked Questions

Why did the federal breach portal say 501 people for almost a year?

Because 501 is a placeholder. HIPAA requires a breach affecting 500 or more individuals to be reported to HHS within 60 days of discovery, and an organization that has not finished its file review files the smallest qualifying number to meet that deadline. It is a procedural entry, not an estimate. The revision to 1,695,382 came around April 2026, once the review was complete.

Is 941 GB the same as 1.7 million people?

No, and the two figures come from opposite sources. The 941 GB claim — along with 732,490 files across 20,418 folders — is Interlock's own posting on its leak site, published as extortion leverage and never independently verified. The 1,695,382 figure is Kettering Health's confirmed count of individuals, reported to federal regulators after its file review. Files and people do not map onto each other.

Did Kettering Health pay the ransom?

Kettering Health has declined to discuss the specifics of its response. What is publicly observable is that Interlock published the data it said it had taken, which is what these groups do when a victim does not pay.

I was a patient but my care was not delayed. Which case is mine?

The data breach class action, if anything, since it covers people whose information was exposed. The delayed-care suits are individual personal-injury claims requiring a specific canceled or postponed treatment and a medical consequence traceable to it. Neither track has anything to file at this stage.

Does the credit monitoring offer mean Kettering Health admitted fault?

No. Offering credit monitoring after a breach is standard practice and in many states effectively expected. It is not an admission of liability, and enrolling does not waive any legal rights. Declining it does not strengthen a future claim either.

How long until there is a settlement or a payout?

There is no way to answer that honestly, and anyone quoting a date is guessing. Healthcare breach class actions commonly run two to four years from filing to a claims process, and the individual care suits resolve on their own schedules. Nothing about this litigation has a deadline that requires you to act today.

Sources

Kettering Health, Notice of Privacy Incident — data categories, access window, credit monitoring and identity restoration offer.
Kettering Health, Cybersecurity Incident FAQ — restoration timeline, Interlock attribution, scam-call warnings, security measures.
U.S. Department of Health & Human Services, Office for Civil Rights, Breach Portal — reported July 21, 2025; entry revised to 1,695,382 individuals.
HHS, Breach Notification Rule, 45 C.F.R. §§ 164.400–414 — the 60-day reporting requirement behind the placeholder figure.
The HIPAA Journal, ongoing coverage of the Kettering Health ransomware attack — incident timeline, portal monitoring, litigation update.
Becker's Hospital Review, on the 44 consolidated lawsuits.
Dayton Daily News, on the growing number of suits — local reporting on the care-related claims.
Wright & Schulte LLC case announcement — plaintiffs' counsel's own account of the consolidation and claim breakdown.
American Bar Association Health Law Section, on the class action filing.
• Ohio Civ.R. 8(A) — the pleading rule behind the "in excess of $25,000" phrasing.


For more class actions keep scrolling below.
Status Lawsuits Filed — Pending
Defendant Kettering Adventist HealthCare (Kettering Health)
Court Montgomery County Court of Common Pleas, Ohio
Case Number Not publicly confirmed
Consolidation 44 individual suits consolidated under a master complaint; counsel reports 200+ filed overall
Claims Negligence; gross negligence; emotional distress; breach of contract
Relief Sought Damages in excess of $25,000 (Ohio Civ.R. 8(A) pleading threshold), punitive damages, attorneys' fees, and security improvements
Incident Dates Network access April 9 – May 20, 2025; attack detected May 20, 2025
People Notified 1,695,382 (HHS Office for Civil Rights breach portal)

More Healthcare Breach Cases & Guides