🏳️‍⚧️ trans rights are human rights 🏳️‍⚧️
Theme

Your Health Data Was Their Liability. They Paid $7.5 Million to Make the Problem Go Away

EvilCorporations.com • Case No. 2622-CC00320 | Thompson Coburn LLP Data Breach • Estimated Reading Time: 9 minutes

TL;DR

  • Thompson Coburn LLP, a major St. Louis law firm, was breached by a cybercriminal on May 28 and 29, 2024. The attacker accessed the private information of 377,211 people, the vast majority of whom were current or former patients of Presbyterian Health Services, a Thompson Coburn client.
  • The stolen data was among the most sensitive that exists: names, dates of birth, Social Security numbers, passport numbers, driver’s license information, health insurance details, prescription and treatment records, clinical data, and medical provider information.
  • Victims were not notified until November 2024, roughly six months after the breach. Nine class action lawsuits followed almost immediately.
  • Thompson Coburn agreed to a $7.5 million total settlement: a $6 million non-reversionary common fund plus up to $1.5 million in additional benefits covering documented losses, medical data monitoring, and attorney fees. The firm admitted no wrongdoing whatsoever.
  • Every class member who does not opt out releases all current and future claims against Thompson Coburn and every related party, including Presbyterian Health Services, whether or not they file a claim or receive a single dollar.

Keep reading to see the exact structure of what attorneys can collect versus what patients actually walk away with, and how the settlement legally shields Presbyterian Health Services from any further accountability for its own patients’ data.

The Non-Financial Ledger: What a Breach of Medical Privacy Actually Costs

Imagine receiving a letter in the mail, months after the fact, informing you that a law firm you have never hired, never met, and never agreed to do business with had been holding your most private medical records. And that someone broke in and took them.

That is what happened to 377,211 people, most of them patients of Presbyterian Health Services in New Mexico. They did not give Thompson Coburn their data directly. Their doctors did. Their insurance companies did. Their healthcare providers handed it over as part of legal work the firm was doing for Presbyterian. The patients had no say, no notice, and no idea their prescriptions, diagnoses, treatment histories, Social Security numbers, and insurance details were sitting on a law firm’s network in St. Louis.

Then one day in May 2024, a criminal walked through the digital door and took it all. And for six months, nobody told the patients.

That six-month silence is not a footnote. Medical identity theft is categorically different from financial identity theft. Someone using your credit card number can be stopped with a phone call. Someone using your Medicare beneficiary ID, your health insurance plan ID, or your medical record number to file fraudulent claims or obtain prescriptions can cause damage that takes years to untangle. You may not know it happened until you are denied care, billed for procedures you never had, or discovered in a criminal database as a drug seeker. The information stolen here is not the kind that expires.

The people harmed in this breach did not choose to be Thompson Coburn’s problem. They were patients. They trusted their doctors and their health system. That trust ran through Presbyterian Health Services to a law firm they never knew existed. And somewhere in that chain, a network was not protected well enough, a criminal found the gap, and 377,211 people are now permanently in the position of wondering what was done with the most intimate details of their lives.

The settlement gives them three years of medical data monitoring. Then it ends. The data does not expire in three years. The exposure does not expire in three years. The people do not get to stop being those 377,211 people in three years.


Legal Receipts: What the Settlement Document Actually Says

The following quotes are taken verbatim from the settlement agreement. They are the language the parties agreed to put in writing.

  • This language means Thompson Coburn pays $7.5 million to 377,211 breach victims while legally maintaining it did nothing wrong. The settlement explicitly bars anyone from using the agreement as evidence of fault in any future proceeding. The firm buys finality without accountability.
  • This is standard settlement boilerplate in the United States, but standard does not mean acceptable. It means the system is designed to allow exactly this outcome.
  • Every class member who does not actively opt out releases not only claims they know about today, but claims they do not yet know they have. If medical identity fraud surfaces in year four, after monitoring has expired, the release applies. The settlement explicitly invokes and waives the protections of California Civil Code Section 1542, which was designed to prevent exactly this kind of broad unknown-claims waiver.
  • The document acknowledges the inclusion of unknown claims was a deliberate negotiated element, not an accident: “the inclusion of ‘Unknown Claims’ in the definition of Released Claims was a key element of the Settlement Agreement.”
  • Presbyterian Health Services, the organization that handed patient data to Thompson Coburn and whose patients make up the vast majority of victims, is explicitly named as a released party. Patients who accept this settlement permanently give up any right to sue Presbyterian, even though Presbyterian was the data owner whose client relationship put patient records on Thompson Coburn’s network in the first place.
  • The release chain extends to essentially every person and entity connected to Thompson Coburn or Presbyterian in any capacity. The scope of immunity purchased by this single settlement is extraordinary.
“If a Settlement Class Member does not submit a Valid Claim, the Settlement Class Member will release his or her claims against Defendant and Released Parties without receiving a Cash Payment.”
  • Victims who miss the claims deadline, lack documentation, or simply do not learn about the settlement in time still permanently lose their legal rights. The release applies to every class member who does not affirmatively opt out, regardless of whether they receive anything at all.

Public Deception: The Gap Between the Story and the Record

The settlement document does not contain evidence of a public misinformation campaign. What it does document is a structural information gap: the people most harmed were the last to know, and what they were told, even in the settlement itself, requires careful reading to understand fully.

  • Victims were told notice letters were sent beginning in November 2024. The breach occurred on May 28 and 29, 2024. That is approximately six months between the incident and notification. The document does not explain why notification took six months.
  • The settlement is described with a headline value of $7,500,000. The reality is more complicated: up to $2,500,000 of that figure is earmarked for attorneys’ fees, up to $2,500 per class representative goes to service awards, and settlement administration costs including postage of $377,739 already paid come out of the common fund before a single claimant receives anything.
  • Medical data monitoring is presented as an automatic benefit for all class members. The reality is that it runs for three years and is provided through a vendor called CyEx under a separate agreement. After three years, it ends. The underlying exposure does not end.
  • The settlement is framed as resolving the action and providing relief. The document states in plain terms that Thompson Coburn denies all wrongdoing, no admission of fault is made, and the agreement cannot be used as evidence of liability in any future proceeding.
Visual: What Victims Were Told vs. The Settlement Reality WHAT WAS PRESENTED THE DOCUMENTED REALITY $7.5 million settlement for affected individuals Up to $2.5M goes to attorneys; admin costs extracted first Automatic medical monitoring for all class members Monitoring lasts 3 years only; stolen data has no expiration date The firm is being held accountable Thompson Coburn admits zero wrongdoing Presbyterian Health Services is a separate matter Presbyterian is explicitly released from all claims by this settlement Victims will be notified promptly Notice sent ~6 months after the breach; no explanation given

Societal Impact Mapping: Who Gets Hurt and How

Public Health

When medical records are breached, the harm is not hypothetical and it does not stay financial.

  • The stolen data included protected health information, prescription and treatment records, clinical information, medical provider information, health insurance plan details, Medicare beneficiary identifier numbers, and International Classification of Disease (ICD) codes. This is the full architecture of a person’s medical identity. Someone holding this data can file fraudulent insurance claims, obtain controlled substances, or alter medical records in ways that affect future care.
  • The CyEx Medical Shield Complete monitoring service offered through the settlement specifically includes Medicare beneficiary identifier monitoring and ICD code monitoring, which confirms the settlement parties themselves recognized medical identity fraud as a specific and real risk from this breach, not an abstract one.
  • Medical identity fraud can result in incorrect information being embedded in a victim’s health records. A victim may receive wrong diagnoses, be denied care, or face life-threatening medication errors rooted in a corrupted medical history they do not know has been tampered with.
  • The breach affected 377,211 individuals. The vast majority were patients of Presbyterian Health Services. These were not corporate clients or business partners who voluntarily engaged a law firm. They were people who went to a doctor.

Economic Inequality

The financial structure of the settlement transfers a disproportionate share of benefit to attorneys and a disproportionate share of burden to ordinary victims.

  • Class counsel will request up to $2,500,000 in total attorneys’ fees plus reimbursement of all costs. The common fund is $6,000,000. That means up to $2,250,000 of the common fund, plus an additional $250,000 from the separate additional benefits fund, could go to legal fees before the pro rata cash pool is calculated for ordinary claimants.
  • Settlement administration costs, including an initial postage payment of $377,739 already paid by Thompson Coburn, also come out of the common fund. These operational costs reduce the pool available to claimants before a single claim is reviewed.
  • Claimants seeking the maximum $5,000 documented loss payment face a strict evidence burden: receipts, documentation “not self-prepared,” proof that losses are “fairly traceable to the Data Incident.” People with fewer resources, less documentation, and less time to navigate a claims process are structurally disadvantaged in this framework.
  • Claimants who elect the pro rata cash share (Cash Payment B) receive an equal slice of whatever remains in the net settlement fund after all fees, awards, and admin costs are deducted. The actual per-person amount is unknown until all claims are submitted. Given that 377,211 people were affected, even a high claims participation rate would result in a small individual payout.
  • Eight named class representatives receive up to $2,500 each in service awards in addition to any cash payment and monitoring they receive as class members. This is disclosed and disclosed fairly, but it illustrates the layered financial hierarchy of class action settlements.

Who Pays? Following the Cost

Thompson Coburn pays the settlement fund. But the cost does not stop there.

  • The 377,211 breach victims absorb the ongoing cost of exposure. The monitoring runs three years. The vulnerability, and the need for self-protection, continues indefinitely. Victims must invest their own time and effort in filing claims, gathering documentation, and watching for fraud, none of which is compensated under this settlement.
  • The net settlement fund available for pro rata cash payments is the $6,000,000 common fund minus settlement administration costs, minus service awards of up to $2,500 per class representative, minus up to $2,250,000 in attorneys’ fees and costs. The document does not specify how many class representatives there are beyond the eight named plaintiffs, but at $2,500 each that totals $20,000 maximum. The math means the pool available for claimant cash payments could be substantially less than $3.75 million, split among all valid claimants.
  • Presbyterian Health Services, whose patients make up the vast majority of victims and whose business relationship with Thompson Coburn caused patient data to be on the firm’s network, pays nothing under this settlement. It is a released party. Its patients bear the entire ongoing cost of exposure while Presbyterian exits the litigation entirely.
Visual: Cost-Shift Waterfall — From Settlement Fund to Who Actually Pays THOMPSON COBURN LLP Pays $7,500,000 total $6M COMMON FUND + $1.5M additional benefits cap CLASS COUNSEL FEES Up to $2,500,000 + costs from combined fund sources ADMIN + POSTAGE $377,739 already paid; remainder from common fund CLAIMANTS Pro rata share of net fund or up to $5K documented loss 377,211 BREACH VICTIMS Absorb ongoing identity fraud risk after 3-yr monitoring ends Incl. Presbyterian patients who paid nothing PRESBYTERIAN HEALTH SVCS Data owner; named as Released Party. Pays $0. Patients’ claims against it: extinguished Rate: legal fees Rate: admin Remainder to victims

The Settlement Isn’t Justice: Why $7.5 Million Is Structured to Protect the Firm

The settlement resolves claims for 377,211 people while delivering full legal immunity to Thompson Coburn and every entity connected to the breach, in exchange for a payment that averages roughly $19.88 per person before any fees are deducted.

  • The total settlement value is $7,500,000. Divided by 377,211 affected individuals, the raw per-person value before any deductions is approximately $19.88. After attorneys’ fees of up to $2,500,000, administration costs, and service awards, the per-claimant pro rata cash payment will be substantially lower than that, and only claimants who actually file valid claims receive it.
  • Thompson Coburn admits no liability. The settlement agreement states this explicitly and repeatedly. There is no finding of negligence, no public accountability, no regulatory action referenced in the document, and no mandated security improvements imposed by the settlement.
  • Presbyterian Health Services, the organization whose patients constitute the overwhelming majority of victims and whose data entrusted to Thompson Coburn was stolen, is released from all claims. Patients permanently lose any right to hold Presbyterian accountable, even though Presbyterian was the entity that gave their medical data to an outside law firm.
  • The release of unknown claims means victims who later discover harm they cannot yet identify, fraud that has not surfaced, medical records that have been corrupted, are barred from seeking relief. The document explicitly acknowledges this is intentional: “the inclusion of ‘Unknown Claims’ in the definition of Released Claims was a key element of the Settlement Agreement.”
  • The firm retains its right to walk away entirely if too many class members opt out. The opt-out threshold that triggers this right is contained in a separate confidential writing reviewed only in camera by the Court. The public does not know how many opt-outs Thompson Coburn will tolerate before terminating the deal.
  • If no cy pres recipient is needed, residual uncashed check funds go to the Missouri Bar Foundation. The legal profession’s own charitable foundation is the backstop beneficiary of unclaimed victim funds. Patients receive nothing from uncashed checks beyond their already-expired window to cash them.
377,211 people had their most sensitive medical and identity data stolen. The settlement resolves their claims for a gross average of less than $20 per person, with no admission of fault from anyone.

The “Cost of a Life” Metric


Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2154