---
title: "The Ransom Was the Cheap Part"
description: "In March 2023, LockBit demanded $10 million from MCNA Dental. Management refused, the attackers published 700 GB of stolen data two days later, and everyone moved on. That refusal tends to get framed as courage in breach retrospectives. It wasn't."
url: https://kaynemcgladrey.com/blog/the-ransom-was-the-cheap-part/
date: 2026-09-04
modified: 2026-09-04
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/09/order-on-unopposed-motion-for-preliminary-approval_1.webp
categories: ["Blog"]
type: post
lang: en-US
---

# The Ransom Was the Cheap Part

In March 2023, LockBit demanded $10 million from MCNA Dental. Management refused, the attackers published 700 GB of stolen data two days later, and everyone moved on. That refusal tends to get framed as courage in breach retrospectives. It wasn’t. It was a capital allocation decision made without anyone pricing the alternatives, and the invoice is now public. Call it $16 million to $23 million once the reconstructable costs are stacked against the settlement’s documented ceiling, before counting an ongoing security bill the company now pays anyway.

The receipts are scattered across a federal docket and a stack of settlement documents, which is probably why nobody has tried to put them together. Reconstructed from the docket, they’re a case study in what an unpurchased security program actually costs.

## Who’s holding the bag

Managed Care of North America administers dental benefits for [Medicaid, CHIP, and Medicare programs](https://www.mcna.net) across multiple states and Puerto Rico, serving roughly 4 million members directly, though its data footprint would prove far wider. It’s private, which means no 10-K to check, but private with an asterisk. UnitedHealth Group has owned MCNA Health Care Holdings since November 2020, so when the loss landed, it landed on a subsidiary of the largest healthcare company in America. That helps explain how this case ground through nearly three years of litigation instead of settling early.

Revenue estimates run from roughly [$224 million a year](https://growjo.com/company/MCNA_Dental) under Growjo’s employee-based modeling to figures an order of magnitude higher from other aggregators. The aggregators can’t both be right, but an Iowa HHS [filing](https://hhs.iowa.gov/media/3380/download?inline=) offers a usable anchor. MCNA Insurance Company reported about $68.3 million in premium revenue from the Iowa Dental Wellness Plan alone, one state program, which pushes a multi-state operation plausibly into the high hundreds of millions. Every point in that band makes the incident cost material.

## The intrusion timeline

- **Late February 2023.** Attackers enter MCNA’s network, sometime between February 22 and February 26 depending on which filing you read.
- **March 6.** Detection, after roughly eight to twelve days of undetected dwell time.
- **March 7.** LockBit claims the attack and demands $10 million.
- **April 7.** The ransom refused, LockBit publishes all 700 GB of stolen data for anyone to download, per [BleepingComputer](https://www.bleepingcomputer.com/news/security/mcna-dental-data-breach-impacts-89-million-people-after-ransomware-attack/).

The haul contained records on 8,923,662 individuals, according to [HIPAA Journal’s review of the breach report](https://www.hipaajournal.com/managed-care-of-north-america-hacking-incident-impacts-8-9-million-individuals/), making it the largest healthcare breach reported in 2023 at the time. Names, Social Security numbers, driver’s licenses, Medicaid and Medicare IDs, and dental treatment histories including x-rays, disproportionately belonging to children on Medicaid and CHIP along with their parents, guardians, and guarantors. MCNA processed data for more than 100 downstream plans and several state agencies, which is how a dental administrator’s breach became everybody’s notification problem.

One disclosure gap matters for everything that follows. The initial access vector was never made public, not in MCNA’s notice and not in three years of litigation. So no one can claim “MFA would have stopped the intrusion cold”. The analysis has to be built against the attack chain on the record instead, which is bad enough.

## The ledger

### Legal and investigation

Hogan Lovells defended all three MCNA entities, appearing by June 26, 2023 per the [CourtListener docket](https://www.courtlistener.com/docket/67474973/crowe-v-managed-care-of-north-america-inc), against 25 consolidated class complaints. The defense survived two motions to dismiss, ran full class certification briefing, argued Daubert motions, filed for summary judgment, and reached the eve of a scheduled trial before mediating a deal. The plaintiffs’ side asked for $6.4 million in risk-enhanced lodestar fees plus $1.3 million in costs. A defense firm billing comparable motion practice across a consolidated docket for three years plausibly lands in the same neighborhood. Investigation and pre-litigation response combined bring the estimated total for this bucket to $5 million to $11 million.

### Remediation

Emergency remediation and hardening added an estimated $1 million to $2.5 million in the first 12 to 18 months, settling into an ongoing uplift of $250,000 to $600,000 a year.

### The settlement

The deal in [*Crowe v. Managed Care of North America*](https://storage.courtlistener.com/recap/gov.uscourts.flsd.648272/gov.uscourts.flsd.648272.426.0.pdf) was preliminarily approved July 14, 2026, in the Southern District of Florida, Judge Singhal presiding. Defendants pay plaintiffs’ fees up to $6.4 million, litigation costs up to $1.313 million, Kroll administration capped at $2 million, and a documented out-of-pocket loss pool capped, in aggregate, at $250,000 per [ClassAction.org’s summary](https://www.classaction.org/news/managed-care-of-north-america-settlement-resolves-lawsuit-over-2023-data-breach). Those 8.9 million people share a quarter million dollars in reimbursement, pro rata if claims exceed it. All of it stays provisional until the fairness hearing on November 16, 2026, and Judge Singhal’s order carries an unusual footnote. The court has reservations about the class size under Eleventh Circuit precedent but approved anyway, deferring those concerns.

The deal is also built to survive challenge. Objectors face the most aggressive standing requirements this side of a deposition transcript, down to disclosing whether AI helped draft the objection.

| Cost component | Range | Basis |
| --- | --- | --- |
| Forensic investigation | $500K – $1.5M | Estimate; enterprise IR benchmarks, scaled to incident scope |
| Defense litigation, 2023-2026 | $4M – $8M | Estimate; anchored to plaintiffs’ $6.4M lodestar and docketed motion practice |
| Pre-litigation regulatory/notification response | $300K – $1M | Estimate; possible partial overlap with defense fees |
| Post-incident remediation, year one | $1M – $2.5M | Estimate; engineering list-price, ~700-employee scale |
| Settlement fees, costs, administration, claims | Up to ~$10.0M | Ceilings from preliminary approval order, DE 426 |
| **Estimated total, ex-ransom** | **~$16M – $23M** | Sum of non-overlapping components |
| Ongoing security uplift | $250K – $600K / yr | Estimate; post-incident run rate |

### The $3.2 billion illusion

Plaintiffs’ attorney Jeffrey Ostrow told [BankInfoSecurity](https://www.bankinfosecurity.com/multimillion-dollar-settlement-reached-in-mcna-dental-hack-a-32017) the monitoring benefit’s retail value exceeds $3.2 billion. That’s $179.40 per year per class member in CyEx medical data monitoring, multiplied by two years, multiplied by every notice recipient as if all of them enroll. They won’t. An anonymous source familiar with the case valued the deal at around $19 million using the conventional one-third fee heuristic. Same settlement, two accounting frames, a 168-fold spread.

![" class="kb-img wp-image-4261" srcset="https://kaynemcgladrey.com/wp-content/uploads/2026/09/what-the-refusal-cost.webp 1024w, https://kaynemcgladrey.com/wp-content/uploads/2026/09/what-the-refusal-cost-300x197.webp 300w, https://kaynemcgladrey.com/wp-content/uploads/2026/09/what-the-refusal-cost-768x503.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" />

## What $400 grand a year would have bought

Three failures on the record, three corresponding control purchases, all priced from current market data scaled to a company of MCNA’s size.

- **Detection speed.** Eight to twelve days of dwell while 700 GB walked out the door is a monitoring failure, and not an exotic one. Managed detection and response runs $8 to $45 per endpoint per month across vendors, per [verified per-endpoint pricing data](https://mdrcost.com/), which lands at roughly $80,000 to $350,000 a year for MCNA’s endpoint count. That’s the control built for this failure mode.
- **Blast radius.** One intrusion reaching 8.9 million records across 100-plus organizations means broad, unsegmented access was the architecture. Segmentation projects run $100,000 to $400,000 as a one-time cost.
- **Egress blindness.** 700 GB of outbound transfer is loud if anything is listening. Volumetric anomaly detection on network gear MCNA already owned is mostly configuration labor.

Then there’s the cheap controls. MFA on remote access was largely already licensed inside Microsoft’s enterprise tiers, leaving a one-time rollout project of $50,000 to $150,000. Patch SLAs for internet-facing devices, credential hygiene, and predefined incident response planning cost staff discipline and approximately nothing.

| Control | Cost | Failure it addresses |
| --- | --- | --- |
| EDR + MDR, monitored 24/7 | $80K – $350K / yr | Undetected dwell time |
| Network segmentation | $100K – $400K one-time | Unsegmented access to 8.9M records |
| Egress anomaly detection | Mostly configuration labor | 700 GB walking out unnoticed |
| MFA on remote access | $50K – $150K one-time, largely already licensed | Credential replay |
| Patch SLA, credential hygiene, IR planning | ~$0 other than staff time | Multiple entry vectors |

Consolidated, a detection-capable program for MCNA’s size runs $150,000 to $400,000 a year, with the full structural program at $400,000 to $800,000 amortized.

By comparison, New York regulators fined MCNA’s Healthplex unit a [combined $2.4 million](https://www.healthcareinfosecurity.com/ny-state-fines-dental-plan-firm-2m-in-phishing-breach-a-29247) across actions in 2023 and 2025, specifically citing the absence of multifactor authentication. Regulators had already told this corporate family that MFA was missing before LockBit demonstrated it. And the consolidated complaint didn’t allege a zero-day or an APT. It pleaded failure to implement commercially reasonable security measures, the boring stuff.

## The numbers nobody ran

We can run the investment case on a napkin. Spend $400,000 a year, the top of the detection-capable range, starting in 2019. Four years of that costs $1.6 million by the morning of the breach. Against the $16 million floor of realized costs, that investment returns roughly $10 for every dollar spent, and the ratio stretches toward 14 to 1 at the top of the range. Drop the annual spend to the $150,000 baseline and the return passes 25 to 1. Compare a three-year run of the full structural program, about $1.2 million to $2.4 million, against what the incident actually burned.
