🏳️‍⚧️ trans rights are human rights 🏳️‍⚧️
Theme

Compex Legal Services had a data breach of 57,000 people’s medical records and social security numbers

The Non-Financial Ledger

The people in this case didn’t hand their most private information to Compex by choice, if you can believe it which I hope you do. Compex is a middleman that retrieves medical records for law firms, which means the 57,000 affected people were mostly injured or sick individuals whose health histories were being pulled together for legal matters. Their names, birth dates, Social Security numbers, and medical files ended up in a single vendor’s systems, and then in the hands of an unauthorized intruder.

The stolen data set is the worst possible combination. A Social Security number paired with a date of birth and medical history is a permanent identity-theft toolkit; you cannot change your medical past the way you change a password. These people now carry a lifetime of watching their credit and their identity because a company they may never have heard of failed to keep intruders out.

They found out months after the fact. Compex discovered the breach around April 9, 2024, but the “Notice of Data Breach” letters did not go out until on or about August 30, 2024. For the length of that gap, tens of thousands of people had no idea their information was already loose.

Legal Receipts

The settlement document says the quiet part in writing. These are direct quotes from the agreement itself.

“Plaintiffs allege that, on or around April 9, 2024, Defendant discovered that the PII and PHI of approximately 57,000 individuals was accessed by an unauthorized threat actor… The potentially affected information included names, dates of birth, Social Security numbers, medical information and credit card information.”
  • This admits the scale: roughly 57,000 people affected, confirmed by the company’s own investigation.
  • It confirms the categories exposed include the permanent identifiers (Social Security numbers, dates of birth) and the sensitive medical files at the core of Compex’s business.
“This Agreement, whether or not consummated… shall not constitute, be construed as, or be admissible in evidence as any admission by Defendant of… any wrongdoing, fault, violation of law, or liability of any kind on the part of the Parties.”
  • Compex pays $872,500 and admits nothing. This is the standard corporate escape hatch: money changes hands, but no fault is recorded.
  • Because there is no admission, no regulator or future plaintiff can point to this deal as proof Compex was negligent.
“Defendant expressly disclaims any claim or allegation that its systems or environments were insufficiently secure at the time of the Cyber Incident or that it otherwise failed to take all reasonable steps to protect class members’ Private Information.”
  • Even while agreeing to make security “changes and improvements,” Compex refuses to concede its systems were ever inadequate.
  • The company gets to claim it was always doing everything right while simultaneously promising to do better, a contradiction it never has to reconcile in court.
“Each share of Cash Payment B is nominally valued at $100.00 (subject to pro-rata increase/decrease, based upon total Claim submission).”
  • The baseline compensation for a lifetime exposure of your Social Security number and medical history is $100, and the agreement itself calls it “nominal.”
  • That figure is not fixed. If more people file claims, each share shrinks, so higher participation means less money per victim.

Public Deception

The gap between how Compex frames its conduct and what the breach actually reveals runs straight through the settlement text.

  • Compex says it took “all reasonable steps” to protect Private Information, yet an unauthorized threat actor still accessed the data of roughly 57,000 people.
  • Compex agreed to undertake “specific, reasonable steps to further secure its systems,” while in the same paragraph denying its systems were ever insufficiently secure.
  • The company discovered the incident around April 9, 2024, but the public-facing notice letters did not go out until on or about August 30, 2024.
What You Were Told vs. The Reality What Was Claimed The Reality “Took all reasonable steps” to protect the data. Systems were never “insufficiently secure.” No wrongdoing, no liability of any kind. Hacker accessed data of ~57,000 people. Agreed to make security “changes and improvements.” Paid $872,500 to make it go away.

Profit-Maximization at All Costs: The Cost of Making It Disappear

The settlement lets the company resolve the fallout for a fraction of what it might have faced at trial, and every dollar has a ceiling attached.

  • Total settlement fund: $872,500. The agreement states Compex’s liability “shall not exceed” that amount, no matter what.
  • Before victims see a cent, the fund pays attorneys up to 33.33% of the fund in fees, plus up to $59,000 in administration costs, up to $2,500 per class representative in service awards, and taxes.
  • The baseline victim payment is a “nominal” $100 per share, capped and shrinkable based on how many people claim.
  • Documented-loss claims are capped at $5,000 and require receipts; a personal statement alone is not enough.
Where the $872,500 Fund Gets Carved Up (Maximums) Total Fund: $872,500 Presented as compensation for victims Attorney Fees up to 33.33% Admin Costs up to $59,000 Service Awards up to $2,500 each + Taxes What’s Left For Victims “Nominal” $100 per share

How Capitalism Exploits Delay: Time As A Corporate Weapon

The most telling gap in this case is the stretch between the moment Compex knew and the moment the affected people found out.

  • Compex discovered the unauthorized access on or around April 9, 2024, according to the plaintiffs’ allegations in the agreement.
  • The “Notice of Data Breach” letters were not sent until on or about August 30, 2024, a gap of roughly four to five months.
  • During that gap, tens of thousands of people whose Social Security numbers and medical files were exposed had no reason to freeze credit or watch for fraud.
Harm Onset vs. Notice: The Silent Months HARM TIMELINE NOTICE TIMELINE Apr 9, 2024 Breach discovered Aug 30, 2024 Victims notified ~4 to 5 months of silence

The Contractor Shield: Everyone’s Data In One Middleman

Compex is a vendor. Its entire business is holding other people’s most sensitive records so law firms do not have to, and that intermediary structure is what concentrated the risk.

  • Compex “provides medical record retrieval services for law firms,” which means the injured and sick people whose data it held were not its own customers; they were the clients of the firms that hired Compex.
  • Its “business operations require it to maintain individuals’ personally identifiable information (PII) and protected health information (PHI),” making it a single point of failure for roughly 57,000 people’s records.
  • The people harmed had no direct relationship with Compex and likely no idea it held their files until the breach notice arrived months later.
How The Data Flowed To A Single Point Of Failure ~57,000 injured people (victims) Law Firms Compex (record vendor) Threat Actor records unauthorized access

Societal Impact Mapping

Public Health

The exposed information sits at the intersection of health privacy and identity security, and both are compromised for good.

  • Medical information for roughly 57,000 people, the exact records Compex exists to handle, was among the categories accessed by the unauthorized threat actor.
  • Protected health information cannot be reset or reissued the way a password can, so the exposure is permanent for those affected.
  • Because the affected people were medical-record subjects tied to legal matters, their most sensitive health details were bundled with identity data in one place.

Economic Inequality

The financial burden of protecting against fraud lands on the individuals, while the compensation offered is deliberately small.

  • The baseline payout is a “nominal” $100 per share, described that way in the settlement itself, for the exposure of Social Security numbers and medical files.
  • Documented-loss reimbursement up to $5,000 requires credit card statements, bank statements, or receipts; victims without paperwork get nothing beyond the flat payment.
  • The per-person payment shrinks on a pro-rata basis if more people file claims, meaning broader victim participation lowers each individual recovery.

The Settlement Isn’t Justice

A capped fund, a nominal payout, and a full denial of wrongdoing add up to a resolution that protects the company more than the people it exposed.

  • Compex’s liability is capped: the agreement states it “shall not exceed” $872,500 regardless of the actual harm to 57,000 people.
  • The deal contains no admission of wrongdoing, so it creates no legal record that Compex’s security failed.
  • Victims split what remains only after attorneys (up to 33.33%), a $59,000 admin cap, service awards, and taxes are removed from the fund first.
  • If more than 20 people opt out, Compex can terminate the entire settlement, discouraging anyone from pursuing their own separate claim.
  • The baseline recovery is a self-described “nominal” $100, an amount the agreement admits can shrink further.

“Each share of Cash Payment B is nominally valued at $100.00 (subject to pro-rata increase/decrease, based upon total Claim submission).”

The “Cost of a Life” Metric

$100 The “nominal” baseline payment offered per person for the permanent exposure of a Social Security number, date of birth, and medical history, an amount the settlement itself warns can shrink if more victims file claims.

This Is The System Working As Intended

Every feature that looks like a bug here is actually a designed outcome that shields the company from meaningful consequences.

  • The hard liability cap of $872,500 means Compex knows its maximum exposure in advance, regardless of how much identity theft the 57,000 people ultimately suffer.
  • The explicit no-wrongdoing clause ensures the breach leaves no admission on record, protecting Compex from being cited as negligent later.
  • The 20-person opt-out termination trigger lets Compex collapse the whole deal if too many victims try to pursue their own claims, functionally penalizing individual action.
  • The “nominal” $100 payment and its shrink-on-participation design mean the more people who show up to claim, the less each one recovers.

What A Legitimate Fix Looks Like

This case exposes a core failure: a data-holding middleman can concentrate the sensitive records of tens of thousands, lose them, wait months to say so, and cap its own accountability. The following is editorial analysis, not a finding of the source document.

Regulatory Track

  • Data-breach notification rules should require vendors like Compex to notify affected individuals within a tight, fixed window, closing the roughly four-to-five-month gap seen here.
  • Third-party record vendors that hold PII and PHI for others should face mandatory independent security audits, given that Compex disclaimed any security failure while still agreeing to make “improvements.”
  • Regulators should require breach settlements involving health data to disclose the ratio of victim compensation to total fund, so “nominal” payouts are visible up front.

Legislative Track

  • Lawmakers should establish statutory minimum per-person compensation for breaches of Social Security numbers and medical data, so recovery is not a self-shrinking “nominal $100.”
  • Legislation should bar settlement clauses that let a defendant terminate an entire class deal based on a low opt-out threshold, a mechanism that discourages individual claims.
  • Statutes should require that liability for breaches of PHI cannot be pre-capped below the demonstrable cost of lifetime credit and identity monitoring for those affected.

Corporate Governance Track

  • A vendor whose entire business is holding others’ medical records should be required to maintain board-level security oversight and documented incident-response timelines.
  • Executive accountability should be tied to breach-notification speed, given the months-long delay between discovery and notice in this case.
  • Companies acting as data intermediaries should be required to disclose to the individuals whose records they hold that their information is being stored by a third party.

What Now?

Direct your attention to Compex Legal Services, Inc. of Torrance, California, and the agencies that oversee health-data and consumer protection.

  • Watchlist: the Federal Trade Commission, which handles consumer data-security enforcement, and the U.S. Department of Health and Human Services Office for Civil Rights, which oversees protected health information.
  • Watchlist: the California Attorney General, since this settlement is governed by California law and the class includes California residents with statutory claims.
  • If you received a Compex “Notice of Data Breach” letter, file your claim before the deadline and gather receipts to pursue the documented-loss payment up to $5,000, not just the nominal $100.
  • Support and connect with the Privacy Rights Clearinghouse, the nonprofit named in the settlement to receive residual funds, to learn how to protect your identity after a breach.
  • Freeze your credit, monitor your medical accounts, and organize locally with others who received the same notice to share information and push for stronger breach-notice laws.

The source document for this investigation is attached below.

Explore by category

01

Antitrust

Monopolies and anti-competition tactics used to crush rivals.

View Cases →
02

Product Safety Violations

When companies sell dangerous goods, consumers pay the price.

View Cases →
03

Environmental Violations

Pollution, ecological collapse, and unchecked greed.

View Cases →
04

Labor Exploitation

Wage theft, worker abuse, and unsafe conditions.

View Cases →
05

Data Breaches & Privacy

Misuse and mishandling of personal information.

View Cases →
06

Financial Fraud & Corruption

Lies, scams, and executive impunity that distort markets.

View Cases →
07

Intellectual Property

IP theft that punishes originality and rewards copying.

View Cases →
08

Misleading Marketing

False claims that waste money and bury critical safety info.

View Cases →
Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2070