Data Breach · Lawsuit Filed

Kovo+ and St. Louis Behavioral Medicine Institute Sued Over Alleged Pear Ransomware Data Breach

Published October 2, 2026

Patients of St. Louis Behavioral Medicine Institute and other healthcare providers that use the medical billing company Kovo+ may be covered by two proposed class actions alleging Kovo+ and SLBMI failed to protect personal and health information that the Pear ransomware group claims it took. No class has been certified and there is nothing to file yet.

Padlock icon over lines of computer code
▼ Allegations Only · No Settlement Yet

This article describes a class action complaint. The statements below are unproven allegations. Kovo+ (USA), Inc. and St. Louis Behavioral Medicine Institute, Inc. have not been found liable, there is no certified class, and nothing to claim at this time. This page is informational and is not legal advice.

What Is This About?

Kovo+ (USA), Inc., an Eau Claire, Wisconsin company that handles medical billing and revenue cycle management for healthcare providers, was hit with two proposed class actions on October 1, 2026 in the U.S. District Court for the Western District of Wisconsin. Its client St. Louis Behavioral Medicine Institute, Inc. (SLBMI), a behavioral health practice serving the St. Louis area, is named as a defendant in both. The cases are Michalski v. Kovo+ (USA), Inc., Case No. 3:26-cv-00992, and Hodgson v. Kovo+ (USA), Inc., Case No. 3:26-cv-00993.

Both lawsuits were brought by Missouri residents who say they are patients, and the two complaints are nearly identical. They allege the two companies did not adequately protect patients’ personal and health information before a ransomware attack on Kovo+. One plaintiff also says she has received a noticeable increase in spam calls, texts and emails since the breach. Neither company has responded to either lawsuit, and none of the allegations has been tested in court.

Status Complaint Filed Two suits filed October 1, 2026 · W.D. Wis. · no class certified
Breach Confirmed? Not by Kovo+ or SLBMI Pear listed Kovo Healthtech on Sept. 5, 2026 · about 2.7 TB later advertised · no notice letters located
Who It Covers (Proposed) Everyone whose information was compromised in the breach Nationwide · not limited to SLBMI patients
Can I Claim? No — nothing to claim yet

What the Complaints Say Happened

According to the complaints, the Pear ransomware group claimed responsibility on or about September 5, 2026 for a cyberattack on Kovo+’s network and systems. The complaints cite a report by the threat-intelligence firm SOCRadar, which lists the target as Kovo Healthtech Corp, the company behind kovoplus.com.

The complaints say, on information and belief, that the attackers took personally identifiable information and protected health information. It bases that on the kind of work the defendants do rather than on a notice or disclosure from either company. It also says the defendants have not denied that the data was accessed, and that they did not quickly tell patients their information had been stolen.

What the Ransomware Group Claims

Threat-intelligence trackers SOCRadar, DeXpose and HookPhish each reported that Pear added Kovo Healthtech Corp to its dark web leak site on September 5, 2026. Pear is described in those reports as an extortion group that steals data and threatens to publish it unless a ransom is paid.

In late September, the dark web monitoring account DailyDarkWeb reported that about 2.7 terabytes of data said to come from Kovo Healthtech was being advertised on an underground forum. The sellers claim it includes personal and health information for millions of patients, along with financial records. None of those claims has been independently verified. Because Kovo+ handles billing for medical practices, clinics and hospitals, any patient data in the files would most likely belong to patients of its healthcare clients.

As of October 2, 2026, no breach notice letter, state attorney general filing or HHS breach report from Kovo+ or SLBMI had been located, and neither company had publicly confirmed the attack or said how many people were affected. The complaints themselves estimate only that the proposed class includes “thousands” of people.

Who Could Be Affected

The proposed class is nationwide: everyone whose personal information was compromised as a result of the breach. It is not limited to SLBMI patients. The complaints say Kovo+ provides billing services to healthcare providers and medical billing firms, and that its contracts with those clients are virtually identical across the country. That suggests patients of other Kovo+ clients could be involved, though no other clients are named.

The complaints do not list specific data fields. Medical billing records commonly include names, contact details, dates of birth, insurance information and treatment or billing codes. Whether any of that was actually taken has not been confirmed. The clearest way to know whether you are affected is a breach notice letter that names Kovo+ or your provider.

The Legal Claims and What the Case Asks For

Both lawsuits assert the same five claims:
The complaints allege the defendants did not meet FTC data security guidance, HIPAA’s Privacy and Security Rules, or industry frameworks such as the NIST Cybersecurity Framework. It says they failed to use multi-factor authentication and to train staff. Each asks the court to certify the class and to award damages, statutory damages where available, restitution and interest, and each demands a jury trial. Both plaintiffs are represented by Shamis & Gentile, P.A.; the Hodgson plaintiff is also represented by Kopelowitz Ostrow P.A., and the Michalski plaintiff by Milberg, PLLC.

What Patients Can Do Now

There is nothing to file in the lawsuit. People who were treated by SLBMI, or who think a provider that uses Kovo+ may have their information, can take steps that do not depend on the case:
Our guide to credit freezes versus fraud alerts explains which one fits your situation.

What Happens Next?

As of October 2, 2026, each docket showed only the complaint, summonses for both defendants and a disclosure statement. Neither defendant has been served or has responded. Because the two cases are in the same court against the same defendants over the same alleged breach, they are likely to be consolidated, and more suits may follow if Kovo+ or its clients send breach notices. This page will be updated if a breach notice is issued or the cases move forward.

Read the Complaint

The Hodgson v. Kovo+ (USA), Inc. complaint is embedded below. The Michalski complaint is nearly identical.

Your browser can’t display the embedded PDF. Open the complaint PDF in a new tab.


Hodgson v. Kovo+ (USA), Inc. — Class Action Complaint (PDF, October 1, 2026)

Questions

What is Kovo+?

Kovo+ (USA), Inc. is a healthcare technology and AI process automation company based in Eau Claire, Wisconsin. According to the complaints, it provides medical billing and revenue cycle management services to healthcare providers and medical billing firms. St. Louis Behavioral Medicine Institute is one of its clients.

Has Kovo+ confirmed a data breach?

Not publicly, as of October 2, 2026. Ransomware trackers reported that the Pear group listed Kovo Healthtech Corp on its leak site on September 5, 2026, and about 2.7 terabytes said to come from the company was later advertised on an underground forum. No breach notice letter or government breach filing from Kovo+ or St. Louis Behavioral Medicine Institute had been located.

What information may have been exposed in the Kovo+ breach?

The complaints do not list specific data fields. It says, on information and belief and based on the services the defendants provide, that the stolen files include personally identifiable information and protected health information. Neither company had confirmed what, if anything, was taken.

Am I affected if I was not a St. Louis Behavioral Medicine Institute patient?

Possibly. The complaints say Kovo+ works for healthcare providers and billing firms around the country, and the proposed class covers everyone whose information was compromised in the breach, not just SLBMI patients. The clearest sign would be a breach notice letter naming Kovo+ or your provider.

Is there a Kovo+ data breach settlement or claim form?

No. Two lawsuits were filed on October 1, 2026, no class has been certified, and there is no settlement, fund or claim form. Anyone who receives a breach notice about Kovo+ may want to keep it, because data breach settlements usually ask for the ID printed on the notice.

Sources

• Class Action Complaint — Hodgson v. Kovo+ (USA), Inc., U.S. District Court for the Western District of Wisconsin, Case No. 3:26-cv-00993 (filed October 1, 2026): Complaint (PDF)
• SOCRadar — Kovo Healthtech Corp listed as a Pear ransomware victim, September 5, 2026: SOCRadar report
• DeXpose and HookPhish ransomware trackers (September 5–6, 2026) and DailyDarkWeb (late September 2026) on the leak-site listing and the 2.7 TB data advertisement
• Class Action Complaint — Michalski v. Kovo+ (USA), Inc., U.S. District Court for the Western District of Wisconsin, Case No. 3:26-cv-00992 (filed October 1, 2026), via CourtListener: CourtListener Docket
• Docket for Hodgson v. Kovo+ (USA), Inc., No. 3:26-cv-00993 (W.D. Wis.), via CourtListener: CourtListener Docket
• Federal Trade Commission — identity theft reporting and recovery: IdentityTheft.gov

For more class actions keep scrolling below.
Status Two Complaints Filed
Case Title Michalski v. Kovo+ (USA), Inc. · Hodgson v. Kovo+ (USA), Inc.
Case Number 3:26-cv-00992 · 3:26-cv-00993
Court U.S. District Court, Western District of Wisconsin
Date Filed October 1, 2026
Defendants Kovo+ (USA), Inc. · St. Louis Behavioral Medicine Institute, Inc.

More Healthcare Data Breach Cases