The Ransom Was the Cheap Part

In March 2023, LockBit demanded $10 million from MCNA Dental. Management refused, the attackers published 700 GB of stolen data two days later, and everyone moved on. That refusal tends to get framed as courage in breach retrospectives. It wasn’t. It was a capital allocation decision made without anyone pricing the alternatives, and the invoice is now public. Call it $16 million to $23 million once the reconstructable costs are stacked against the settlement’s documented ceiling, before counting an ongoing security bill the company now pays anyway.

The receipts are scattered across a federal docket and a stack of settlement documents, which is probably why nobody has tried to put them together. Reconstructed from the docket, they’re a case study in what an unpurchased security program actually costs.

Who’s holding the bag

Managed Care of North America administers dental benefits for Medicaid, CHIP, and Medicare programs across multiple states and Puerto Rico, serving roughly 4 million members directly, though its data footprint would prove far wider. It’s private, which means no 10-K to check, but private with an asterisk. UnitedHealth Group has owned MCNA Health Care Holdings since November 2020, so when the loss landed, it landed on a subsidiary of the largest healthcare company in America. That helps explain how this case ground through nearly three years of litigation instead of settling early.

Revenue estimates run from roughly $224 million a year under Growjo’s employee-based modeling to figures an order of magnitude higher from other aggregators. The aggregators can’t both be right, but an Iowa HHS filing offers a usable anchor. MCNA Insurance Company reported about $68.3 million in premium revenue from the Iowa Dental Wellness Plan alone, one state program, which pushes a multi-state operation plausibly into the high hundreds of millions. Every point in that band makes the incident cost material.

The intrusion timeline

  • Late February 2023. Attackers enter MCNA’s network, sometime between February 22 and February 26 depending on which filing you read.
  • March 6. Detection, after roughly eight to twelve days of undetected dwell time.
  • March 7. LockBit claims the attack and demands $10 million.
  • April 7. The ransom refused, LockBit publishes all 700 GB of stolen data for anyone to download, per BleepingComputer.

The haul contained records on 8,923,662 individuals, according to HIPAA Journal’s review of the breach report, making it the largest healthcare breach reported in 2023 at the time. Names, Social Security numbers, driver’s licenses, Medicaid and Medicare IDs, and dental treatment histories including x-rays, disproportionately belonging to children on Medicaid and CHIP along with their parents, guardians, and guarantors. MCNA processed data for more than 100 downstream plans and several state agencies, which is how a dental administrator’s breach became everybody’s notification problem.

One disclosure gap matters for everything that follows. The initial access vector was never made public, not in MCNA’s notice and not in three years of litigation. So no one can claim “MFA would have stopped the intrusion cold”. The analysis has to be built against the attack chain on the record instead, which is bad enough.

The ledger

Legal and investigation

Hogan Lovells defended all three MCNA entities, appearing by June 26, 2023 per the CourtListener docket, against 25 consolidated class complaints. The defense survived two motions to dismiss, ran full class certification briefing, argued Daubert motions, filed for summary judgment, and reached the eve of a scheduled trial before mediating a deal. The plaintiffs’ side asked for $6.4 million in risk-enhanced lodestar fees plus $1.3 million in costs. A defense firm billing comparable motion practice across a consolidated docket for three years plausibly lands in the same neighborhood. Investigation and pre-litigation response combined bring the estimated total for this bucket to $5 million to $11 million.

Remediation

Emergency remediation and hardening added an estimated $1 million to $2.5 million in the first 12 to 18 months, settling into an ongoing uplift of $250,000 to $600,000 a year.

The settlement

The deal in Crowe v. Managed Care of North America was preliminarily approved July 14, 2026, in the Southern District of Florida, Judge Singhal presiding. Defendants pay plaintiffs’ fees up to $6.4 million, litigation costs up to $1.313 million, Kroll administration capped at $2 million, and a documented out-of-pocket loss pool capped, in aggregate, at $250,000 per ClassAction.org’s summary. Those 8.9 million people share a quarter million dollars in reimbursement, pro rata if claims exceed it. All of it stays provisional until the fairness hearing on November 16, 2026, and Judge Singhal’s order carries an unusual footnote. The court has reservations about the class size under Eleventh Circuit precedent but approved anyway, deferring those concerns.

The deal is also built to survive challenge. Objectors face the most aggressive standing requirements this side of a deposition transcript, down to disclosing whether AI helped draft the objection.

Cost componentRangeBasis
Forensic investigation$500K – $1.5MEstimate; enterprise IR benchmarks, scaled to incident scope
Defense litigation, 2023-2026$4M – $8MEstimate; anchored to plaintiffs’ $6.4M lodestar and docketed motion practice
Pre-litigation regulatory/notification response$300K – $1MEstimate; possible partial overlap with defense fees
Post-incident remediation, year one$1M – $2.5MEstimate; engineering list-price, ~700-employee scale
Settlement fees, costs, administration, claimsUp to ~$10.0MCeilings from preliminary approval order, DE 426
Estimated total, ex-ransom~$16M – $23MSum of non-overlapping components
Ongoing security uplift$250K – $600K / yrEstimate; post-incident run rate

The $3.2 billion illusion

Plaintiffs’ attorney Jeffrey Ostrow told BankInfoSecurity the monitoring benefit’s retail value exceeds $3.2 billion. That’s $179.40 per year per class member in CyEx medical data monitoring, multiplied by two years, multiplied by every notice recipient as if all of them enroll. They won’t. An anonymous source familiar with the case valued the deal at around $19 million using the conventional one-third fee heuristic. Same settlement, two accounting frames, a 168-fold spread.

What $400 grand a year would have bought

Three failures on the record, three corresponding control purchases, all priced from current market data scaled to a company of MCNA’s size.

  • Detection speed. Eight to twelve days of dwell while 700 GB walked out the door is a monitoring failure, and not an exotic one. Managed detection and response runs $8 to $45 per endpoint per month across vendors, per verified per-endpoint pricing data, which lands at roughly $80,000 to $350,000 a year for MCNA’s endpoint count. That’s the control built for this failure mode.
  • Blast radius. One intrusion reaching 8.9 million records across 100-plus organizations means broad, unsegmented access was the architecture. Segmentation projects run $100,000 to $400,000 as a one-time cost.
  • Egress blindness. 700 GB of outbound transfer is loud if anything is listening. Volumetric anomaly detection on network gear MCNA already owned is mostly configuration labor.

Then there’s the cheap controls. MFA on remote access was largely already licensed inside Microsoft’s enterprise tiers, leaving a one-time rollout project of $50,000 to $150,000. Patch SLAs for internet-facing devices, credential hygiene, and predefined incident response planning cost staff discipline and approximately nothing.

ControlCostFailure it addresses
EDR + MDR, monitored 24/7$80K – $350K / yrUndetected dwell time
Network segmentation$100K – $400K one-timeUnsegmented access to 8.9M records
Egress anomaly detectionMostly configuration labor700 GB walking out unnoticed
MFA on remote access$50K – $150K one-time, largely already licensedCredential replay
Patch SLA, credential hygiene, IR planning~$0 other than staff timeMultiple entry vectors

Consolidated, a detection-capable program for MCNA’s size runs $150,000 to $400,000 a year, with the full structural program at $400,000 to $800,000 amortized.

By comparison, New York regulators fined MCNA’s Healthplex unit a combined $2.4 million across actions in 2023 and 2025, specifically citing the absence of multifactor authentication. Regulators had already told this corporate family that MFA was missing before LockBit demonstrated it. And the consolidated complaint didn’t allege a zero-day or an APT. It pleaded failure to implement commercially reasonable security measures, the boring stuff.

The numbers nobody ran

We can run the investment case on a napkin. Spend $400,000 a year, the top of the detection-capable range, starting in 2019. Four years of that costs $1.6 million by the morning of the breach. Against the $16 million floor of realized costs, that investment returns roughly $10 for every dollar spent, and the ratio stretches toward 14 to 1 at the top of the range. Drop the annual spend to the $150,000 baseline and the return passes 25 to 1. Compare a three-year run of the full structural program, about $1.2 million to $2.4 million, against what the incident actually burned.

Normally this kind of comparison needs a probability discount, since insurance math divides loss by likelihood. Not here. The loss event already occurred, so the ROI calculation needs no assumption about whether a breach was probable. It happened, it cost eight figures, and the controls that address its actual failure modes cost six figures a year.

Here’s the detail that should end any boardroom argument about affordability. MCNA’s post-incident security uplift of between $250,000 to $600,000 a year lands inside the same band as the prevention program that was never bought. The controls were affordable before the incident and after it. After, though, the purchase came compressed into quarters, delivered under regulatory and litigation supervision, with a legal surcharge stapled to the invoice.

Someone at MCNA accepted this risk. The adversary helpfully priced the exposure at $10 million, and the decision-maker declined without recording what the alternative would cost. The risk acceptance happened by omission rather than by choice, and it was settled on terms written by LockBit. Unrecorded risk decisions are still decisions.

Caveats, then the close

The access vector was never disclosed, so prevention effectiveness is an inference. Cyber insurance could have absorbed a meaningful share of the response costs, and the public record can’t tell us. Every legal, remediation, and control figure in this piece is an order-of-magnitude estimate anchored to public benchmarks rather than disclosures, and the settlement itself awaits final approval on November 16, 2026. The low end of the total also assumes the settlement’s approved ceilings are fully drawn; if claims come in light, the floor drops accordingly.

None of that rescues the decision. The cash components of the settlement alone top out near $10 million, and the ransom was $10 million. MCNA avoided paying LockBit and then paid its lawyers, Kroll, CyEx, the forensic firm, and the remediation contractors roughly the same amount or more.

The controls were never the expensive option. They were just the ones that required an incident to make them mandatory.

Security Risks ARE Business Risks. Get the Weekly Context.

Every week, I break down the most important intersections of cybersecurity, AI regulation, and business risk. Plus: early access to 'Cyber Risk is a Myth' chapter resources and course updates.

I don’t spam! Read the privacy policy for more info.

Similar Posts