Medical Device Data Privacy Lawsuit

The Lyon Firm is actively involved in Health Data Misuse Class Action Lawsuits on behalf of consumers nationwide.

Legally Reviewed By
Legally Reviewed By
This is some text inside of a div block.
Legally Reviewed By
This is some text inside of a div block.
Legally Reviewed By
This is some text inside of a div block.
Legally Reviewed By
This is some text inside of a div block.

Request A Free Consultation

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Person checking a wearable health device, representing a medical device data privacy lawsuit.

Connected medical devices can collect highly personal information about your health. An insulin pump may record your glucose levels and insulin delivery. A cardiac device can transmit information about your heart to a remote monitoring system. Wearables and connected health apps may collect your heart rate, sleep, activity, location, and other information throughout the day.

You rely on these technologies to help manage your health and share important information with your healthcare providers. You also expect the companies that collect, transmit, and store that information to protect it.

A medical device data privacy lawsuit may be an option if your sensitive health information was improperly accessed, disclosed, shared, or used and you suffered harm as a result.

The Lyon Firm is currently investigating healthcare data privacy, data theft, and identity theft claims for plaintiffs nationwide. Contact our data privacy lawyers at (513) 381-2333 if you believe your medical information was exposed or improperly shared.

“People trust their doctors and hospitals with the most private parts of their lives. When that data gets shared without consent, it’s not a technical error, it’s a violation.”

– Joe Lyon | Founding Partner, The Lyon Firm

What Is Medical Device Data Privacy?

Medical device data privacy concerns what happens to the information your medical devices generate or collect, including how that information is stored, transmitted, accessed, used, and shared.

Your information does not necessarily remain inside the device. A connected medical device may transmit data to your smartphone, healthcare provider, the device manufacturer, a cloud platform, a monitoring service, or another technology provider.

Pacemakers, insulin pumps, glucose monitors, wearable devices, and other medical technologies increasingly use software and network connections to exchange information. These connections can allow your doctor to monitor your condition remotely or give you access to your health information through an app.

Each connection also creates another place where your information must be protected. Your privacy may be affected if someone accesses your data without authorization, a company shares it with an unintended recipient, or your information is collected or used for a purpose you did not agree to.

What Data Do Medical Devices Collect?

The information collected depends on the device you use and how it connects with other systems. If you use a connected device every day, it may create an extensive record of your health over months or years.

Your medical devices and connected health technologies may collect:

  • Personal identifiers: Your name, date of birth, address, email address, phone number, patient ID, or account information.
  • Medical conditions and diagnoses: Information showing that you have diabetes, heart disease, sleep apnea, or another health condition.
  • Treatment information: Medication doses, treatment schedules, therapy settings, and changes made by your healthcare professionals.
  • Biometric and physiological data: Your heart rate, blood glucose readings, blood pressure, oxygen levels, cardiac rhythms, temperature, and other measurements.
  • Device information: Serial numbers, device identifiers, settings, usage records, error logs, and software information.
  • Activity information: Your exercise, movement, sleep patterns, and other information recorded by wearables or monitoring devices.
  • Technical and location information: Connected technology may also collect your IP address, device ID, location, or information about how you use an app or service.

Taken together, this information can reveal far more than a single medical reading. It can show what health conditions you have, which medications you take, how you respond to treatment, when you sleep or exercise, and other details you may expect to remain private.

What Medical Devices Can Collect or Transmit Your Data?

Connected healthcare technology includes implanted devices, equipment used in hospitals, home monitoring systems, wearables, and the software and apps that allow these technologies to communicate.

Insulin Pumps and Continuous Glucose Monitors

If you use an insulin pump or continuous glucose monitor, the device may record your blood glucose readings, insulin doses, device settings, alerts, and treatment trends. Depending on the system, that information can also be transmitted to your smartphone, a cloud platform, or your healthcare provider.

Pacemakers and Implantable Cardiac Devices

Your implanted cardiac device may transmit heart rhythm information, device performance data, alerts, and other clinical measurements for remote monitoring. This allows your medical team to receive important information about your heart and the device without requiring you to be physically present.

Drug Infusion Pumps

If you receive medication through a connected infusion pump, the system may contain information about your medication, dosage, treatment schedule, and device operation. Pumps used in hospitals may also communicate with other systems on the hospital network.

CPAP and Other Respiratory Devices

A connected CPAP machine or other respiratory device may collect information about how often you use it, breathing events, therapy settings, mask leaks, and treatment compliance. That information may be transmitted to your healthcare provider or other companies involved with the equipment or your care.

Remote Patient Monitoring Devices

You may use a blood pressure monitor, pulse oximeter, cardiac monitor, connected scale, or another device at home and have the readings sent directly to your healthcare provider or a remote monitoring platform.

Because these devices can be used every day, the information collected can create an ongoing record of changes in your health rather than a snapshot from a single doctor's appointment.

Imaging and Diagnostic Equipment

Information about you can also be stored or transmitted through MRI machines, CT scanners, and other diagnostic systems. This may include your name and other identifiers, imaging files, examination information, and clinical data.

Wearables and Health Apps

Your smartwatch, fitness tracker, or health app may collect your heart rate, sleep, exercise, activity, reproductive health information, and other personal data.

HIPAA does not protect all health information simply because it concerns your health. Whether HIPAA applies can depend on who collects or maintains your information. 

For example, health information maintained by your healthcare provider or its business associate may be protected by HIPAA, while information you enter into an independent consumer health app may fall outside HIPAA. Other federal and state privacy laws may still apply.

How Can Your Medical Device Data Be Exposed or Misused?

Someone does not necessarily have to hack your medical device itself for your information to be compromised. Your data may pass through several systems and companies after it leaves the device, creating other opportunities for unauthorized access or disclosure.

Your medical device information could be exposed through:

  • A cyberattack against a device manufacturer, hospital, cloud provider, or another company holding your data
  • Weak passwords, authentication systems, or access controls
  • Software vulnerabilities that have not been patched
  • Misconfigured databases or cloud storage
  • Lost or stolen equipment containing your information
  • An employee accessing your information without authorization
  • Improper sharing with technology vendors or other third parties
  • Tracking technologies incorporated into connected apps or websites
  • Your health information being used for advertising, analytics, or another purpose you did not authorize
  • Inadequate security while your information is transmitted from a device to another system

A medical device data security lawsuit may involve allegations that a company failed to adequately protect your sensitive information before a breach or unauthorized disclosure occurred.

Your data can also be misused without an outside cyberattack. A company might disclose your information to another business, provide unnecessary access to employees or vendors, or use your health information for a purpose you did not authorize.

How Is Medical Device Cybersecurity Different From Data Privacy?

Cybersecurity deals with protecting your medical device and the systems connected to it from unauthorized access, attacks, software vulnerabilities, and other security threats. Data privacy deals with who can collect your information, who can see it, how it can be used, and who it can be shared with.

A single incident can involve both. A vulnerability in your connected device, health app, or healthcare network could allow someone to access information about your health. The security problem allowed the access to occur, and the exposure of your personal information creates the privacy issue.

Cybersecurity also remains important after a connected medical device reaches the market. New vulnerabilities can be discovered after you have already begun using a device, requiring manufacturers to monitor security issues and respond to newly identified threats.

Were You Notified That Your Medical Device or Health Data Was Exposed?

A breach notice may not answer all of your questions about what happened to your information or which companies had access to it. The Lyon Firm can review the incident, the information involved, and the privacy or security issues that may support a claim.

Contact The Lyon Firm at
(513) 381-2333 for a free consultation about your legal options.

When Can Medical Device Data Misuse Lead to a Lawsuit?

Learning that your medical information was exposed or shared without your permission does not necessarily tell you whether you have a legal claim. What happened to your information, who was responsible, which laws apply, and whether you suffered harm can all affect your options.

A medical device cybersecurity lawsuit could involve allegations that a device manufacturer, healthcare organization, software provider, or another company:

  • Failed to use reasonable safeguards to protect your sensitive health information
  • Failed to address known security vulnerabilities
  • Allowed unauthorized employees or third parties to access your data
  • Shared your health information without proper authorization
  • Used your information for a purpose that was not adequately disclosed
  • Failed to provide required notice after certain types of data breaches
  • Made promises about privacy or security that did not match its actual practices

The laws that apply can also depend on who had your information. HIPAA regulates covered healthcare entities and their business associates, but your information may pass through apps, device manufacturers, software platforms, and other companies that are not regulated by HIPAA in the same way.

The FTC's Health Breach Notification Rule can apply to certain health apps, connected devices, and similar technologies that are not covered by HIPAA. The rule also addresses certain unauthorized disclosures of identifiable health information, so a privacy incident does not have to involve a hacker breaking into a system.

What Compensation May Be Available in a Medical Device Data Privacy Lawsuit?

The financial impact of compromised medical information can look different for each person. You may discover fraudulent accounts or charges soon after a breach, or you may spend months monitoring your identity because sensitive information remains exposed.

Depending on the claims involved and the harm you suffered, compensation or other relief may address:

  • Financial losses: Money stolen from your accounts, fraudulent charges, or other losses tied to identity theft or fraud.
  • Identity theft expenses: Costs associated with credit monitoring, identity restoration, replacing documents, or responding to fraudulent activity.
  • Medical identity theft: Expenses and other harm caused when someone uses your information to obtain medical care, prescriptions, insurance benefits, or other services.
  • Privacy-related harm: Certain claims may allow recovery for legally recognized harm caused by the unauthorized disclosure or misuse of private information.
  • Class action relief: When the same incident affects a large group of people, a class action settlement may provide payments, credit monitoring, identity protection services, or other benefits to eligible class members.
  • Injunctive relief: A lawsuit may seek changes to a company's security, privacy, or data-handling practices.
  • Punitive damages: These may be available under certain laws and circumstances involving particularly serious misconduct.
  • Attorney's fees and litigation costs: Certain claims or statutes may allow successful plaintiffs to recover these expenses.

The information involved can be important when evaluating your losses. A compromised password can be changed. Your Social Security number, medical history, biometric information, diagnoses, and other sensitive health information may be much harder or impossible to replace.

What Does a Health Data Privacy Lawyer Do for Your Case?

After receiving a breach notice, you may know that something happened without knowing exactly what information was involved or how it was exposed. 

A notice may identify the company affected and categories of compromised information but leave you with questions about who received your data and what you can do about it.

A health data privacy lawyer can investigate issues such as:

  • What information was involved: This may include your medical records, diagnosis, Social Security number, insurance information, device data, login credentials, or other personal information.
  • How the incident occurred: Your attorney can examine available information about a cyberattack, unauthorized disclosure, tracking technology, security vulnerability, or other event.
  • Who had access to your information: Your data may have moved among a healthcare provider, device manufacturer, software company, cloud provider, monitoring service, or another third party.
  • Which laws apply: The legal protections available to you can depend on the type of information involved, who possessed it, and how it was accessed, used, or disclosed.
  • What losses you have experienced: Fraudulent charges, identity theft, medical identity theft, expenses, and other harm can become part of the evaluation of your claim.
  • Whether other people were affected: A breach involving the same device, platform, or company may compromise information belonging to hundreds or thousands of people.

Your attorney can also preserve evidence, communicate with the companies involved, evaluate potential defendants, and determine whether your claim is better pursued individually or as part of a class action.

Legal representation can affect how a claim is handled and resolved. In a Martindale-Nolo Research survey of people with personal injury claims, more than 90% of respondents who hired an attorney received a settlement or award, compared with about half of those who pursued their claims without one

Contact a Health Data Privacy Lawyer

You may use a connected medical device because it makes it easier to monitor a health condition, receive treatment, or share important information with your medical team. In the process, information about your health can pass through devices, apps, healthcare networks, cloud systems, and outside technology providers.

If that information is exposed or shared improperly, you may need answers about more than the initial breach. Who collected your information? Where was it stored? Who received it? What were you told about how it would be used?

A medical device data privacy lawsuit can examine those issues and whether the companies responsible for your information complied with the privacy and security obligations that applied to them.

Contact The Lyon Firm at (513) 381-2333 to discuss your potential claim.

Why Hire The Lyon Firm

The Lyon Firm has experience handling cases involving data privacy and cybersecurity, healthcare data, and medical devices. Our attorneys investigate how sensitive information was collected, stored, transmitted, and disclosed and which companies were responsible for protecting it.

We have also obtained numerous settlements and verdicts for our clients and have taken on large companies and healthcare organizations.

If you have concerns about information collected through a medical device, connected health technology, or healthcare system, contact The Lyon Firm at (513) 381-2333.

Handling Complex Data Privacy & Cyber Security Cases

Request A Free Consultation Now

Why Are Data Privacy Cases Important?

Your medical information can reveal your diagnoses, medications, treatments, physical condition, and other details you may share only with people involved in your care. Connected medical technology can place that information in the systems of healthcare providers, device manufacturers, software companies, and other businesses.

When a company fails to protect that information or uses it without proper authorization, the effects can extend beyond the initial disclosure. Medical and identifying information can be used for identity theft, fraud, medical identity theft, or other unauthorized purposes.

Data privacy lawsuits give affected individuals a way to seek compensation when they suffer legally recognized harm and challenge practices that put sensitive health information at risk.

Healthcare Data Privacy Lawsuit FAQs

What information is at risk in data privacy breaches?

Personal health information that is vulnerable to data privacy breaches includes:

  • Health insurance numbers
  • Diagnoses, treatments, and prescription information
  • Financial information like bank and credit card data
  • DNA data
  • Biometric data

Medical device connectivity carries data breach risks, and when hackers gain access to connected medical devices or a larger network of health data, this personal information may forever be compromised.

Who can file a medical device data privacy lawsuit?

Individuals whose medical data has been compromised, healthcare providers, and even regulatory authorities may file such lawsuits, depending on the circumstances. Your lawyer will investigate your situation to identify all of the potentially liable parties you can personally file claims against.

Are medical device manufacturers liable for data breaches?

Manufacturers can be held liable if they are found negligent in securing their devices, especially if the breach was foreseeable or preventable. Under current privacy laws, the agency or organization that is storing user data is responsible for data breaches and will pay any fines or damages that are the result of legal action.

How can I prove that my medical data was breached?

Evidence of a medical data breach may include records of unauthorized access, data breach notifications, and forensic analysis of affected devices or systems.

It is your lawyer’s job to investigate and compile the evidence for your case. We have the resources to enlist cybersecurity experts to assist in gathering and interpreting this evidence. Contact The Lyon Firm at (513) 381-2333 for proven, professional help right away.

Contact Us

Request a Free Consultation

Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there:

  • It begins with a few simple questions about your situation.
  • From there, a member of our legal team reviews your case.
  • Together, we’ll chart the path forward, helping you take the next step toward resolution.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.