Fraud Management & Cybercrime
,
Healthcare
,
Incident & Breach Response
Co. Is Already Facing Several Lawsuits Based on Its Much Lower Victim Estimates

The number of known individuals affected by a February 2024 hacking incident at employee benefits administrator Verisource Services now stands at 4 million, a significant jump from initial estimates reported last summer.
See Also: New Attacks. Skyrocketing Costs. The True Cost of a Security Breach.
Hackers stole information pertaining to employees and dependents of clients that use the Texas company’s services, which include benefits enrollment, administrative and billing services and also human resources outsourcing.
The company initially disclosed in a May 4, 2024 breach report that the hack affected 1,382 people. An updated report filed Friday corrected the number to 4 million.
VSI did not immediately respond to Information Security Media Group’s request for additional details about the hacking incident, including the number of clients affected and why the number of affected individuals surged dramatically.
It is not unusual for organizations to file initial breach reports to regulators only to subsequently, and somewhat, dramatically increase the tally of affected individuals months later in an updated filing. Some HIPAA covered entities submit breach reports to HHS OCR with placeholder estimates of 500 or 501 individuals affected and end up filing updated reports indicating that millions were actually affected.
The company faces at least four proposed federal class action lawsuits filed against them in 2024, just weeks after the VSI first reported the breach. The revised breach disclosure could also bump up the number of lawsuits, with several other law firms announcing they too are investigating the breach for potential litigation.
The lawsuits filed so far claim VSI was negligent in failing to safeguard plaintiff and class members’ information. The lawsuits seek financial damages and injunctive relief requiring the company to strengthen its data security practices.
VSI in its updated breach notice said that on Feb. 28, 2024, the company became aware of unusual activity on its network environment.
An investigation that concluded on Aug. 12, 2024 “confirmed that certain personal information was involved. Based on that review, an initial set of notices were issued beginning on Aug. 20, 2024.”
VSI said it also notified its client companies and continued to work with them to collect the necessary information to notify additional individuals affected by this incident. “That process was completed on April 17, 2025. We then took steps to notify impacted individuals of the incident as quickly as possible,” VSI said.
Information affected varies among individuals, but may have included names, addresses, dates of birth, gender and Social Security numbers.
