Six Hundred Fifty Thousand Dollars and a Hospital With No Profits
On June 2, 2024, threat actors broke into Roseland Community Hospital Association’s systems and walked off with data on 101,354 patients, including names, addresses, medical diagnoses, health insurance details, and Social Security numbers for a subset of the group. Twenty-five months later, the hospital agreed to pay $650,000.
That number sounds small until you run it against the balance sheet. Roseland lost $14.2 million on operations in fiscal 2025 and carried net assets of negative $39.8 million. It had bled money for three straight years, with the red ink well established before anyone touched its network. The settlement works out to about 0.95 percent of annual revenue and 4.6 percent of that year’s operating deficit, which is a rounding error in most industries and a real wound for this one.
“Defendant’s decision not to invest enough resources in its cyber defenses amounts to gross negligence.” From the amended class action complaint, in the plaintiffs’ own words
Someone at a safety-net hospital on Chicago’s Far South Side either decided that accepting this risk was cheaper than fixing it, or nobody decided anything at all. Both are business risks with a computer attached.
What Happened, On the Record
| Date | Event |
|---|---|
| June 2, 2024 | Unauthorized access detected; investigation begins |
| Aug. 1 – Nov. 12, 2024 | Patient notifications mailed; substitute notice posted |
| Nov. 25, 2024 | Class action filed in Cook County (case 2024CH10367) |
| Oct. 6, 2025 | Partial motion to dismiss granted |
| May 13, 2026 | Mediation |
| July 17, 2026 | Settlement executed |
| Jan. 6, 2027 | Final approval hearing |
Roseland’s own substitute notice says the forensic investigation ran until October 21, 2024, a four-and-a-half-month span suggesting the intrusion was neither trivial nor quickly contained. Becker’s Hospital Review confirmed by mid-August 2024 that files had been copied and removed, establishing exfiltration rather than mere access.
The amended complaint filed April 29, 2025 named the missing controls with unusual specificity: no adequate logging, monitoring, or alerting tools; no encryption or masking of stored protected health information (PHI); and HIPAA Security Rule noncompliance. Baker & Hostetler appeared for the defense in January 2025, the negligence per se count died at the motion-to-dismiss stage in October 2025, and what survived reached mediation in May 2026. The settlement agreement was signed that July, and a preliminary approval order followed on August 18, 2026.
There’s a discrepancy warrants mentioning. The HHS Office for Civil Rights (OCR) breach portal lists 500 individuals affected for Roseland’s August 2024 submission, while the settlement class covers 101,354. Nothing in the public record reconciles the gap. The 101,354 figure comes from binding court documents, and that’s the number we’ll use.
The Receipts
The documented piece is straightforward. The settlement fund is $650,000, non-reversionary (none flows back to Roseland), and a hard cap on liability. Class counsel seeks one-third of it, $216,666.67 in fees, plus up to $20,000 in expenses, while three class representatives get up to $2,500 apiece in service awards. What’s left funds medical records monitoring through CyEx, documented-loss payments up to $5,000, and pro-rata payments around $50 for the rest, per the settlement FAQ. The one-third fee request sits slightly above the 30 percent norm identified across comparable breach settlements.
| Cost category | Documented or estimated | Range | Basis |
|---|---|---|---|
| Settlement fund | Documented | $650,000 | Settlement agreement |
| Defense fees (filing through preliminary approval, ~21 months) | Estimated | $150,000-$500,000 | TCCubed, Daeryun Law |
| Forensic investigation (4.5 months) | Estimated | $100,000-$250,000 | SecurityMetrics, IncidentCost |
| Notification and call center | Estimated | $150,000-$400,000 | DataBreachCost |
| Credit monitoring (SSN subset, separate from settlement’s CyEx) | Estimated | $150,000-$500,000 | DataBreachCost |
| Total incident cost | Mixed | $1.2M-$2.3M | Sum, with overlap caveats |
On defense, single-venue breach litigation in state court, settled at mediation with no federal multidistrict litigation (MDL) and no federal regulator involved, tends to be at the low end of published defense cosr benchmarks. On notification, figure 101,354 letters at $1-$3 each plus a toll-free line staffed Monday through Friday for months. For credit monitoring, the subset size with exposed SSNs is undisclosed, so 10 to 20 percent of the class is the working assumption. The estimated credit-monitoring line reflects what Roseland would have borne operationally, distinct from the CyEx medical records monitoring the settlement funds.
When considered alongside Roseland’s finances, the picture is grim.
| Fiscal year | Revenue | Operating result | Net assets |
|---|---|---|---|
| FY2023 | $64.6M | -$13.7M | -$24.6M |
| FY2024 | $75.8M | -$4.7M | -$25.6M |
| FY2025 | $68.2M | -$14.2M | -$39.8M |
Those figures come from the hospital’s FY2023, FY2024, and FY2025 Form 990 filings. The total incident cost of $1.2M-$2.3M works out to 1.8 to 3.4 percent of FY2025 revenue, and 8 to 16 percent of that year’s operating loss. There’s no percent-of-profit comparison available because there are no profits; at Roseland, the better measure is what share of an already growing deficit this consumed by breach and remediation costs.
ProPublica’s records add what breach press never covers. The independent auditor flagged a going concern for FY2025, and material weaknesses in internal controls appear in audit findings going back to FY2023. The breach didn’t create that dysfunction, but that weakness might have been a contributing factor.
What Prevention Would Have Cost
The complaint conveniently scoped the fix. Logging, monitoring, alerting, and encryption of stored PHI weren’t unusual capabilities in 2024; they’re the minimum anyone would expect of a HIPAA-covered entity, purchasable at prices a 563-employee hospital can see beforehand.
- Managed detection and response (MDR) or security operations center (SOC) monitoring, $50,000-$150,000 annually
- Encryption and multi-factor authentication (MFA) projects, $100,000-$250,000 one-time, plus $50,000-$100,000 a year to maintain
- Security awareness training and phishing simulations, $20,000-$50,000 per year
- Fractional chief information security officer (CISO) or senior security engineer, $150,000-$300,000 annually
- Incident response (IR) retainer, $10,000-$100,000 per year
In total, the recurring pieces run roughly $280,000 to $700,000 a year. For context, Guardian IT reports small hospitals spend $60,000 to $600,000 annually on cybersecurity, and StationX cites Deloitte’s per-employee healthcare benchmark of $1,200 to $2,100, which implies $675,000 to $1.2 million for a hospital of Roseland’s headcount. The HIMSS 2024 Healthcare Cybersecurity Survey, covered by Chief Healthcare Executive, found only 19 percent of healthcare respondents allocated even 3 to 6 percent of their IT budgets to security. Roseland was, charitably, at the bottom of that distribution.
The annual prevention spend equals 0.41 to 1.03 percent of Roseland’s revenue. The incident cost 1.8 to 3.4 percent, plus two years of litigation, plus the reputational hit of being the South Side hospital that let over 100,000 patients’ data walk out the door. At the midpoints, roughly $490,000 a year in prevention against a $1.75 million incident, prevention runs about a quarter to a third of the cleanup bill, and unlike the breach, it was budgetable beforehand.
The IR retainer is the rare line item would have carried additional savings. IncidentCost reports retained forensic rates of $175-$400 per hour versus $800-$1,500 at emergency pricing, so retained rates typically run a quarter to a third of what an unplanned engagement bills. Roseland had no retainer, so it paid whatever the four-and-a-half-month emergency engagement cost. A hospital that had kept a modest retainer on file would have gutted the single largest discretionary expense in its incident response.
Why the IBM Number Doesn’t Describe This Hospital
IBM’s 2025 Cost of a Data Breach Report, based on a study of 600 organizations across 17 industries and 16 countries, puts the healthcare average at $7.42 million per breach, with the US average at $10.22 million. Those figures are real, and also useless for predicting what happened here, because they blend lost business, regulatory penalties, and mega-breaches affecting millions of records.
Roseland’s incident featured none of that. No OCR fine is visible on the record. No lost-business cliff, since the hospital’s patient base isn’t exactly shopping competitors. One consolidated class action in state court, not a federal MDL. Whether a cyber policy existed and who funded the settlement is unknown, so we won’t guess. Multiply 101,354 records by IBM’s $264 US per-record average and you get $26.7 million, which bears no relationship to anything that occurred.
The market rate for this kind of case is far more mundane. Roseland’s settlement works out to $6.41 per class member before fees, sitting comfortably inside the $0.50 to $12.65 per-member range that Womble Bond Dickinson identifies across comparable breach settlements, with roughly 30 percent attorney fees as the norm. That’s what a hacked, insolvent, 127-bed community hospital pays. The $7.42 million figure is what an average participant in IBM’s sample pays, and the two populations share almost nothing except PHI.
Who Signed For All This
Timothy Egan, president and CEO, signed the settlement agreement in July 2026. His compensation went from $525,000 in FY2023 to $575,000 in FY2024 to $871,746 in FY2025, a 66 percent raise over the two years covering the breach, its investigation, and the litigation, while headcount fell from 616 employees to 563. He held the chief restructuring officer title back in FY2014, so the hospital’s proximity to death is not a new condition for him.
The auditor’s findings tell the governance story. Material weakness in FY2023, material weakness in FY2024, material weakness plus going concern in FY2025. The FY2023 and FY2024 990s arrived late, amended, and filed the same July day. A board that tolerated three consecutive years of material-weakness findings was never going to hold the line on a security budget either.
Roughly four-tenths to one percent of annual revenue, per year, would have bought the controls HIPAA expected Roseland to have anyway. Instead, the bill came to 1.8 to 3.4 percent of revenue, 31 months from breach to final approval hearing with 26 of them spent in litigation, and the distinction of a breach whose real scale, 101,354 patients, dwarfs the 500-person figure it reported to federal regulators. Executives will say they understand risk trade-offs. Roseland’s board didn’t make one. They just skipped the invoice and let it compound.