How a Data Breach Cost Palomar Health Medical Group Ten Times What Prevention Would Have

On May 5, 2024, Palomar Health Medical Group (PHMG) found a ransom note sitting on its network alongside encrypted systems. Threat actors had been inside since April 23, copying files for twelve days. By September 4, 2025, the final tally stood at 1,132,116 people whose Social Security numbers, medical histories, payment card data, and in some cases biometric identifiers were exposed.

This was a business decision made through inaction. The precise costs weren’t knowable in advance, but the inputs were, from breach probability for an under-secured provider to the average sector breach cost and the going rate for prevention. Any CFO could have run them. The aftermath is now public record, and it shows failure cost roughly ten times what a credible security program would have.

The Breach Timeline

Discovery and Scope

Threat actors accessed PHMG’s network from April 23 to May 5, 2024, before detonating ransomware. The data-type list that emerged in the official notice of data breach reads like a taxonomy of everything you don’t want leaked in one place:

  • Names, addresses, and dates of birth
  • Social Security numbers, driver’s license numbers, and passport numbers
  • Financial account, payment card, and health savings account details
  • Medical history, diagnosis, and treatment records
  • Medicare and Medicaid identification numbers
  • Email credentials, usernames and passwords, and biometric data in some cases

PHMG finished identifying who was affected on September 4, 2025, nearly sixteen months after the incident closed. Patients spent that stretch wondering exactly what had been taken.

The Lawsuit

Clarissa Castro and four other named plaintiffs sued Arch Health Partners, the corporate entity that operates Palomar Health Medical Group, in the Superior Court of California, County of San Diego on May 28, 2024, three weeks after discovery. The amended class action complaint arrived September 16, 2024. Fourteen months later, after a full-day mediation before retired judge David E. Jones, the parties executed a settlement agreement on October 31, 2025. Arch Health Partners admitted nothing.

The Settlement Numbers

Judge Loren Freestone granted preliminary approval on July 17, 2026, capping plaintiffs’ attorney fees at $1,033,230, with the final approval hearing set for November 6, 2026. The terms are standard breach-lawsuit fare:

ComponentAmountDetails
Settlement Fund$3,100,000Non-reversionary cash
Attorney Fees≤$1,033,230One-third cap
Class Representative Awards$12,500$2,500 each × 5 plaintiffs
Affected Individuals1,132,116Per court order
Credit Monitoring2 yearsCyEx Identity Defense Complete

Run those numbers and the headlines flatten. After the fee cap, service awards, and the administrator’s cut, a class of 1.1 million people divides a $3.1 million fund into pocket change. Against PHMG’s audited segment revenue of $168.1 million for fiscal 2024, per Palomar Health’s audited financial statements, the settlement equals roughly 1.8 percent of one year’s revenue.

The fund works out to $2.74 per affected person, about $1.80 to $1.83 after fees, awards, and administration. That’s the sticker price of failure.

What Prevention Would Have Cost

There’s a market rate for everything that could have prevented this.

Healthcare already spends less on security than almost any regulated sector. The 2025 Censinet benchmark found providers allocating just 4 to 7 percent of IT budgets to cybersecurity, while IANS Research pegs hospitals around 8 percent of IT spend and under 1 percent of revenue. Meanwhile, IBM’s Cost of a Data Breach Report put the average healthcare breach at $9.8 million in 2024, the costliest sector for the fourteenth straight year.

Build the security stack a 25-clinic medical group actually needs, component by component, and the totals land like this:

TierAnnual CostWhat It Buys
Low~$500,000Commodity endpoint detection and response (EDR) on ~1,500 endpoints, annual awareness training, basic multi-factor authentication, one penetration test, fractional vCISO
Mid~$1M to $1.5MManaged 24/7 detection and response, hardened immutable backups, systematic patching, in-house security lead, regular testing
High~$2M to $3MDedicated CISO and team, security operations capability, network segmentation, third-party risk management, multi-year modernization

The unit economics come straight from vendor pricing surveys. EDR runs $36 to $180 per endpoint per year self-managed, or $96 to $300 fully managed, per Bellator Cyber and ITSecOps 2026 pricing data. Security awareness training costs $10 to $72 per employee per year, with most organizations paying $18 to $36, according to Symbol Security’s 2026 guide. Outsourced managed detection starts around $18,000 to $60,000 a year at small scale and climbs with headcount, per Petronella Tech’s MDR survey, while annual penetration testing plus a virtual chief information security officer runs $50,000 to $150,000 combined.

The middle tier is the version I’d have budgeted for a group holding 1.1 million patient records, and it runs $1 million to $1.5 million a year. That’s 0.6 to 0.9 percent of segment revenue. A three-year program costs roughly 2 to 3 percent of one year’s revenue, or about what the settlement fund alone came to before a single defense invoice, forensic bill, or lost patient was counted.

Call that insurance too expensive if you want. Know what the deductible on the other option looks like.

Defending the Lawsuit

Arch Health Partners never disclosed what it spent defending Castro v. Arch Health Partners, so we model it. I’m including my assumptions in case you want to check.

Defense counsel was Freeman Mathis & Gary, a national firm. The case ran roughly eighteen months from filing in May 2024 to settlement execution in October 2025, through an amended complaint, written discovery, mediation, and settlement drafting. Blended billing for a large-firm litigation team runs $500 to $600 an hour when you mix partners at $600 to $900 with associates at $250 to $450, figures consistent with Wall Street Journal reporting on big-firm rates.

TierEstimateAssumptions
Low~$600K to $800K1,200 to 1,500 hours, lean staffing, early settlement track
Mid~$1.2M to $1.8M2,500 to 3,500 hours over 18 months at a $500 to $600 blended rate
High~$2.5M to $3.5M+Heavy staffing, parallel suits, regulatory inquiries, fee motion practice

The middle tier is the one I’d defend. Even the low tier costs more than an entire year of the mid-range security budget. And defense fees for the class action are just the legal tail of the incident. There’s also forensic investigation, which averaged $273,000 for the twenty largest matters in BakerHostetler’s 2025 Data Security Incident Response Report and rose more than 10 percent in the 2026 update. Add breach coach counsel, a notification program covering 1.1 million people, and settlement administration payable to Angeion Group from the fund. Figure another $500,000 to $1 million across all of it.

Revenue That Walked Out the Door

A medical group that can’t schedule appointments for two months doesn’t just eat response costs; it loses patients.

Peer-reviewed research on breached hospitals found roughly a 6 percent loss in total patient revenue, driven by about a 10 percent decline in inpatient revenue and 5 percent in outpatient. Premier Inc.’s analysis via FierceHealthcare pegged the lifetime value of a lost hospital patient at $108,000. Apply those effects to PHMG’s ambulatory revenue base and the range looks like this:

TierEstimateComposition
Low~$3.4M/year2 percent revenue disruption, partial retention
Mid~$8.4M/yearPublished 5 percent outpatient decline applied to $168M segment revenue
High~$13M to $22M/yearHalf the Graybill patient base departing at an estimated $600 to $1,000 each annually

The high end isn’t hypothetical. On September 10, 2024, Graybill Medical Group, a primary care institution operating since 1932, terminated its management agreement with Palomar Health, the public healthcare district that owns PHMG, citing inadequate support after the May 2024 attack. Roughly 45,000 patients faced the choice of following their doctors or staying put, and Graybill estimated 91 to 93 percent would follow their physicians out. One hundred physicians walked. Even modeling a far more modest half of that base leaving, at an estimated $600 to $1,000 per patient per year in primary care and downstream revenue, that’s $13 million to $22 million gone annually.

The audited financials corroborate the direction of travel even if they can’t isolate causation. Per Palomar Health’s audited fiscal 2024 financial statements, PHMG’s segment operating loss deteriorated by roughly $17 million year over year, from a loss of about $39.8 million to a loss of $56.7 million, the breach year. Moody’s attributed part of the deterioration to the cyberattack; Palomar’s management discussion attributed the decline mainly to a managed care transition. Either way, they lost money.

Things Money Does Not Capture

Some consequences don’t fit in a cell reference. Moody’s downgraded Palomar from Baa3 to B2 in October 2024, citing very thin cash and escalating governance risks in financial strategy, risk management, management credibility, and track record. Days cash on hand fell from 77.4 to 31.2 in a single year, while unrestricted liquidity dropped from $203.1 million to $85.2 million. The district violated a debt covenant and entered forbearance through January 2026, as Becker’s Hospital Review reported. The district poured $51.4 million into PHMG during fiscal 2024, then another $21.5 million after year-end, and the CEO departed in June 2024, mutually, per the internal email.

Every one of those line items traces back to a system that chose, actively or passively, not to fund the boring middle tier of security spending.

The Ledger, Reconciled

Stack the mid-range estimates against segment revenue and the ratio holds no matter which accountant reviews it:

Cost ComponentMid-Range Estimate% of Segment Revenue
Settlement Fund$3.1M1.8%
Defense + Response$1.7M to $2.8M1.0% to 1.7%
Lost Revenue Impact~$8.4M5.0%
Year-One Total~$13M to $14M~8%
Annual Prevention$1M to $1.5M0.6% to 0.9%

A skeptical CFO will note the comparison mixes one-time costs with recurring ones, and that’s a fair objection. Even stripping out the settlement, defense, forensics, and notification, and comparing only the recurring lost-revenue bleed against the recurring prevention budget, failure still runs several times the price of the fix.

This was a healthcare organization that got hit hard but not catastrophically, and the exchange rate between prevention and failure still ran ten to one. No wrongful death claim, no multi-state attorney general coalition, no Office for Civil Rights fine at the top of the range. Just a garden-variety ransomware incident, settled for garden-variety money, on top of a garden-variety operational disaster.

The settlement fund alone would have paid for three full years of the security program PHMG evidently didn’t have. That’s not a cyber risk. It’s a capital allocation decision, and every input is now a matter of public record for any executive who wants to run the same math before their own May 5 arrives.

Security Risks ARE Business Risks. Get the Weekly Context.

Every week, I break down the most important intersections of cybersecurity, AI regulation, and business risk. Plus: early access to 'Cyber Risk is a Myth' chapter resources and course updates.

I don’t spam! Read the privacy policy for more info.

Similar Posts