Four Years, Fourteen Lawsuits, $136 Million in Revenue: what OneTouchPoint’s ransomware bill actually added up to
On November 18, 2026, a Wisconsin state judge in Waukesha County will convene a final approval hearing for a class action settlement arising from a ransomware attack that began on April 27, 2022. Four years, six months, and a courtroom transfer separate the two dates, along with fourteen lawsuits, three failed mediations, a partially successful motion to dismiss, and one deliberate decision by the parties to abandon their own consolidated federal case in favor of a state forum. The case is Dusterhoft v. OneTouchPoint, and by the time it lands on Judge Arthur Melvin’s bench, almost nobody involved will have asked the only question that matters to everyone reading this. What did it cost, and what would prevention have cost?
Here’s the tally.
The incident, compressed
OneTouchPoint (OTP) is a Hartland, Wisconsin print and mail vendor serving more than thirty healthcare payers and providers, including Humana, Aetna, Kaiser, and a wall of Blue plans. Under HIPAA, that made it a business associate sitting on subscriber data, health assessment answers, and in some cases Social Security numbers. Its annual revenue ran about $135.7 million with roughly 606 employees, based on the Printing Impressions 300 industry ranking, which matters more than it sounds because everything below divides by that number.
The timeline
| Date | Event |
|---|---|
| April 27, 2022 | Unauthorized actors first access OTP’s network |
| April 28, 2022 | Encrypted files discovered; forensic investigation begins |
| June 3, 2022 | OTP notifies its business customers |
| July 27, 2022 | Public notice and state AG filings begin |
| August 2022 | Affected count revised from 1.1 million to 2,651,396 |
That’s a one-day dwell time between first access and encryption. Encrypted files on a network are ransomware by behavior, though no ransomware group ever claimed the attack, per The Record’s reporting, and the initial access vector was never publicly identified. Not by OTP, not by its forensics firm, not by the litigation that followed.
The notification mess
Maine’s attorney general initially received a report of about 1.1 million people, quietly revised upward after customers like Common Ground Healthcare Cooperative reported their own affected counts. BankInfoSecurity catalogued the tally climbing in near real time.
A company in the business of knowing whose name goes on which envelope did not know how many people’s data it held. That failure isn’t a cybersecurity problem. It’s a data-inventory problem, and it cost real money to fix retroactively.
How the money moved, procedurally
The lawsuits arrived in pairs and clusters starting mid-2022, fourteen in total across multiple jurisdictions, all alleging inadequate data safeguards. The procedural record, drawn from the settlement agreement’s recitals and the Waukesha County docket:
| Date | Event |
|---|---|
| September 29, 2022 | Consolidation in E.D. Wis. as Dusterhoft v. OneTouchPoint, 22-cv-0882, with Lynch Carpenter and Milberg as co-lead counsel |
| April and May 2023 | Two mediations with a JAMS neutral fail |
| October 2023 | Third mediation, with a magistrate judge, fails |
| November 2023 | Motion to dismiss briefed |
| September 2024 | Motion partially granted |
| October 2024 | Answer filed; discovery begins |
| November 2025 | Federal case dismissed; refiled in Waukesha County as 2025CV002181 |
| July 2026 | Settlement executed |
The settlement agreement recites, with remarkable candor, that the parties “deemed that federal court may not be an appropriate jurisdiction to seek Court approval of the Settlement.” With the case fully litigated in federal court, the parties voluntarily dismissed it there and restarted the whole apparatus in state court, where OTP’s breach defense firm Mullen Coughlin arranged pro hac admissions.
Executives should read that table as a billing statement. Every event on it is an event defense counsel invoiced, from appearances across fourteen dockets through consolidation briefing, mediation statements and prep, a full motion to dismiss, written discovery into a 2.65-million-person incident, and a second litigation just to approve the deal.
The ledger
| Cost item | Low | Mid | High | Basis |
|---|---|---|---|---|
| Defense costs | $1.9M | $3.2M | $4.5M | Estimate; hourly model vs. NetDiligence benchmarks |
| Plaintiffs’ fees | $1.5M | $1.5M | $1.5M | Documented cap in settlement |
| Security commitments | $2.0M | $2.0M | $2.0M | Documented, spread over 5 years |
| 2022 response (forensics, notice, support) | $1.0M | $2.0M | $3.5M | Estimate; NetDiligence benchmark |
| Administration and claims payouts | $0.5M | $1.0M | $3.0M | Scenario; claim-rate dependent |
| Total | $6.9M | $9.7M | $14.5M |
The numbers we know are real
The documented pieces come from the settlement site and HIPAA Journal’s coverage, establishing the $1.5 million fee cap, the roughly $2 million in security commitments, and a claim structure allowing up to $5,000 for documented extraordinary losses, $500 for lost time, $100 for ordinary expenses, or a $75 alternative payment for anyone in the confirmed-impact class who skips the paperwork.
What’s modeled
The defense estimate comes from a bottom-up hourly model for a three-phase, four-year defense, checked against NetDiligence’s claims data, where legal defense costs on single breach claims have ranged from under $500 to $5 million, and large-company breach claims average in the millions. The 2022 response costs are estimated from the NetDiligence 2025 Cyber Claims Study, which puts notification costs in healthcare-sector breaches at an average of $302K; OTP’s incident is an outlier at that scale, with notifications for 2.65 million people spread across dozens of downstream clients, many of which procured their own monitoring services, plus forensic investigation, a call center, and monitoring offers. Claims payouts are genuinely unknowable until the administrator reports, and breach class actions historically draw single-digit claim rates against a confirmed-impact class whose size is undisclosed.
Against revenue of $135.7 million, the bill lands between 5.1 and 10.7 percent of one year’s revenue.
Call it under three weeks to nearly six weeks of everything the company earned, vaporized.
The control spend that never happened
A defensible security program for a 600-employee, multi-site company functioning as a HIPAA business associate isn’t hard to describe. It’s a known shopping list:
- Multi-factor authentication across the estate
- Endpoint detection and response with a monitored service tier
- Network segmentation between print operations and the PHI-bearing systems
- Patch discipline with defined windows
- Tested offline backups
- Vendor access governance
That probably costs around $300,000 to $700,000 a year, or 0.2 to 0.5 percent of OTP’s revenue. Buy everything on the high end, every year, from 2019 forward, and you spend $2.8 million before the attackers arrived.
The mid-estimate breach bill is more than triple that. Spread across the four years those costs accrued, the incident consumed roughly fourteen years of a top-end security program’s budget, or north of three decades if you’d gone lean.
Would those controls have stopped the attack? Nobody can say for certain, because nobody ever established how the attackers got in, and certainty theater is the oldest trick in security vendor math. The honest comparison doesn’t need it. Annualized loss expectancy models fail executives here because the frequency term is a guess; realized-loss accounting doesn’t have that problem, because the losses are documented. OTP didn’t buy the controls, an incident happened, and years of invoices followed. At $10 million against $700,000, even a one-in-ten annual chance of this outcome justified the program.
That’s the pitch the security team probably made in 2021, or would have, if anyone had asked.
Who actually paid
OTP’s tally understates the damage, because a business associate’s breach externalizes costs down the chain. More than thirty covered entities ate their own notification expenses, including:
| Covered entity | What it absorbed |
|---|---|
| Common Ground Healthcare Cooperative | 133,714 affected individuals, own notification costs |
| Arkansas Blue Cross | 1,423 affected members |
| Blue Shield of California Promise | Experian IdentityWorks monitoring for affected members |
Every one of them fielded its own regulator inquiries, including filings like Massachusetts AG record 27961. None of that appears anywhere in OTP’s tally. When executives ask why their vendors’ security posture matters, the answer is that the customers of a breached business associate pay retail for the associate’s discount. The systemic figure is unknowable from public records, but it plausibly rivals or exceeds OTP’s own bill. This wasn’t an IT failure that inconvenienced a company. It was an uninsured liability that transferred itself to dozens of counterparties.
Remediation on the honor system
Buried in the settlement is the remediation OTP agreed to afterward, about $2 million in security commitments over five years, certified by letter to class counsel. No auditor. No scheduled compliance reporting. No penalty for quiet abandonment. And $2 million spread over five years is $400,000 a year, which sits below the midpoint of the annual control spend for a company of OTP’s size. $400,000 a year in remediation is less than what a single month of incident response cost at the middle of the range above. Even the accountability mechanism ended up on the honor roll.
What we still don’t know
- Cyber insurance. No coverage details ever surfaced in any public document, and whether a carrier funded any part of this remains unknown. Worth remembering the next time someone quotes an “average breach cost” figure that quietly assumes you know who paid.
- Initial access. Never identified by anyone.
- Exfiltration scope. Never confirmed; OTP itself said it couldn’t determine what files the actor viewed.
- Court data quality. The county docket lists OTP’s address one digit off from its actual headquarters and classifies the case as an intentional tort, which tells you something about how well county court systems handle data about data breaches.
The takeaway
Build your next budget pitch from real numbers. Realized loss, plus the defense tail, plus the externality your customers absorb, divided by revenue, set against control spend as a percent of revenue. At OTP, that was roughly 7 percent of revenue lost against 0.5 percent not spent. The decision to skip the controls wasn’t reckless in any specific moment; it was unpriced, because nobody ran the numbers. The numbers existed the whole time. It just took a courtroom in Waukesha to make anyone write them down.