How Long Does a Hospital Have to Tell You About a Data Breach?
Federal law gives a hospital sixty days. Once a covered health care provider discovers that patient information has been breached, the HIPAA Breach Notification Rule requires notice to each affected individual without unreasonable delay, and in no case later than sixty days after discovery. That is an outer limit, not a target.
Patients of Marshall Health Network received their letters in June 2026, describing an intrusion that began on a vendor’s servers in January 2025. According to a class action complaint filed in the Circuit Court of Putnam County, the health system itself learned of the incident in October 2025 — roughly eight months before the letters went out. Powell & Majestro P.L.L.C. filed that lawsuit on June 11, 2026 on behalf of West Virginia patients whose records were exposed, and anyone who received a notice can call (304) 346-2889 for a free case review.
The gap is the case. Every protective step available to a breach victim (freezing credit, watching for medical billing you do not recognize, placing fraud alerts) depends first on knowing it happened.
What Does Federal Law Require, and How Fast?
HIPAA gives a covered health care provider sixty calendar days from discovery of a breach to notify each affected individual, and the rule requires notice without unreasonable delay even inside that window.
The requirement sits in the Breach Notification Rule at 45 C.F.R. §§ 164.400–414. Separately, the HIPAA Security Rule obligates covered entities and their business associates to ensure the confidentiality, integrity, and availability of electronic protected health information, to guard against reasonably anticipated threats, and to implement technical controls limiting access to authorized users. 45 C.F.R. §§ 164.306, 164.312.
There is a law enforcement exception, and its details matter here. Under 45 C.F.R. § 164.412, a provider may delay notification if a law enforcement official states that notice would impede a criminal investigation — but the form of the request controls how long the delay can run:
- A written statement must specify the period of delay, and the provider may hold notice for that period.
- An oral request permits a delay of no more than thirty days, unless a written statement follows within that window.
Marshall Health Network’s notice letters told patients that the vendor had informed the health system that law enforcement investigators directed a delay in notifying patients. The complaint points out what the letter does not say: whether any such request was made in writing, who issued it, what period it covered, whether it reached patient notification as opposed to notification of hospital customers, when it expired, and whether notice followed promptly once it lifted.
One clarification worth making, because it shapes how these cases are built. HIPAA creates no private right of action, and the complaint asserts none. The regulations are used as evidence of the duty and the standard of care that applies to a health care provider handling patient information — not as a statute a patient can sue under directly.
What Does West Virginia Law Require?
West Virginia’s breach notification statute requires notice without unreasonable delay and permits a provider to hold notice only for as long as disclosure would impede a criminal investigation.
The statute is codified at W. Va. Code §§ 46A-2A-101 et seq. It does not set a fixed ceiling the way HIPAA’s sixty-day rule does. Instead, it applies a reasonableness standard, which means the length of any delay has to be justified by something — and once an investigation no longer requires silence, the obligation to notify runs.
The two frameworks stack rather than compete. A West Virginia hospital answers to both, and satisfying neither is a problem the provider has to explain.
What Happened in the Oracle Health Breach?
An unauthorized party used stolen credentials to reach legacy Cerner servers in January 2025, and the consequences have been reaching patients at hospitals across the country ever since.
Oracle acquired Cerner in 2022 in a deal valued at roughly $28 billion and renamed it Oracle Health. The servers involved held records that had not yet been migrated to Oracle’s cloud environment. Oracle has said the stolen credentials were used on or around January 22, 2025, and that the incident was identified on or around February 20, 2025.
What followed is the part patients find hardest to accept. Oracle did not announce the breach publicly and did not notify patients directly. It left notification to its health care clients and asked those organizations to hold off while its investigation continued. In litigation, the company’s attorneys indicated as many as eighty hospitals may have been affected. Health systems have been sending letters one at a time ever since, some more than a year after the intrusion.
Marshall Health Network posted its notice on June 5, 2026 and mailed individual letters the same day. Per that notice, the information involved varied by person but may have included names, Social Security numbers, and details drawn from patient medical records — medical record numbers, treating doctors, diagnoses, medications, test results, images, and information about care and treatment.
Why an Eight-Month Delay Matters More Than It Sounds
A notification delay is not a paperwork problem. It is a stretch of time during which a patient carries all of the risk and none of the information needed to reduce it.
Consider what a person does on day one after learning their Social Security number is in criminal hands. Freeze credit at all three bureaus. Place fraud alerts. Start reading every explanation of benefits for treatment that never happened. Treat any call or email referencing their hospital as suspect. None of that occurs while the letter is still unwritten.
Medical data compounds the problem. A compromised credit card gets cancelled and reissued in a week. A Social Security number cannot be changed except through a difficult process carrying its own consequences for credit and employment, and a medical history never expires. Diagnoses, medications, and treatment records describe a person accurately for life, which is why this information holds its value to criminals for years.
That mismatch is the argument against the remedy offered. Twenty-four months of credit monitoring and identity restoration is a real benefit, and patients should use it. It is also a two-year answer to a lifetime exposure.
Can You Sue If Nobody Has Stolen Your Identity Yet?
In West Virginia, yes. The Supreme Court of Appeals held in 2014 that patients have standing to pursue breach of confidentiality and invasion of privacy claims, and can obtain class certification on them, without evidence that any class member suffered identity theft or economic loss.
The case is Tabata v. Charleston Area Medical Center, 233 W. Va. 512, 759 S.E.2d 459 (2014). Personal and medical information belonging to roughly 3,655 patients had been placed on an electronic database accessible over the internet. Discovery turned up no evidence that anyone had suffered identity theft, and none that the information had even been viewed. The Circuit Court of Kanawha County denied class certification. The Supreme Court of Appeals reversed.
The reasoning rests on the elements of the claims themselves. Under West Virginia law, breach of the duty of confidentiality does not require proof of a concrete injury, and invasion of privacy does not require pleading special damages. Where the underlying causes of action do not demand economic harm, the absence of economic harm does not defeat standing or certification.
The Court was careful to limit itself. It held only that the circuit court erred on standing and abused its discretion on commonality, typicality, and predominance, and it made no determination about whether the plaintiffs could ultimately prove their claims. Justice Ketchum dissented.
Results differ by forum, and honesty about that is worth more than salesmanship. In the consolidated federal litigation over this same Oracle Health breach, a judge in the Western District of Missouri ruled in June 2026 that negligence claims could proceed against the vendor and eight health systems, and rejected the argument that a hospital can hand its data protection duties to a vendor — while dismissing unjust enrichment and invasion of privacy claims and narrowing several state statutory claims. Different law, different forum, different outcome.
Is a Data Breach Claim a Medical Malpractice Claim?
No. West Virginia settled that question in 2012, in a case brought against a hospital that is now part of Marshall Health Network.
In R.K. v. St. Mary’s Medical Center, Inc., 229 W. Va. 712, 735 S.E.2d 715 (2012), hospital employees improperly accessed a patient’s records and disclosed details of his psychiatric hospitalization. The Supreme Court of Appeals reached two conclusions that still govern these cases.
- HIPAA does not preempt state claims. Common law tort claims based on the wrongful disclosure of medical or personal health information survive alongside the federal scheme. The United States Supreme Court denied review in 2013.
- The Medical Professional Liability Act does not apply. Allegations about the improper disclosure of medical records fall outside the Act’s definition of “health care,” so the MPLA does not govern them.
The practical weight of that second holding is easy to underestimate. The MPLA imposes pre-suit notice, a screening certificate of merit sworn by a qualified physician, a two-year filing deadline, and statutory caps on noneconomic damages. If those requirements attached to data breach claims, very few patients would ever be able to bring one — no physician can meaningfully certify the merits of a claim about server security.
What Should You Do If You Received a Data Breach Letter?
Freeze your credit first, enroll in the monitoring being offered, then start watching your medical billing as closely as your bank statements.
- Freeze your credit at all three bureaus. Freezes are free; they can be lifted temporarily when you need credit, and they stop new accounts in a way that monitoring alone does not. Monitoring tells you after something happens. A freeze prevents it.
- Enroll in the offered service. Marshall Health Network and the vendor are offering twenty-four months of Experian IdentityWorks Credit Plus 3B along with identity restoration. The credit monitoring requires you to enroll; it does not start on its own.
- Read every explanation of benefits. Medical identity theft shows up as treatment you never received, providers you have never seen, or a deductible that has somehow been met. It can also corrupt your own chart, which carries clinical risk beyond the financial harm.
- Treat breach-related contact as suspect. Criminals follow breach coverage and call victims posing as the hospital, the vendor, or the monitoring service. Verify independently before giving information to anyone who contacts you first.
- Keep the letter and log your time. Save the notice and its engagement number, and write down hours spent and money paid dealing with the fallout. Time spent mitigating a breach is a recognized element of damages.
Anyone who was treated within the network but never received a letter can reach the dedicated line the health system established at 833-918-4335 to check their status.
Why These Cases Are Being Filed in West Virginia Courts
West Virginia’s own law on medical confidentiality and patient privacy gives these claims firmer footing than the federal alternative, and plaintiffs are filing accordingly.
The Marshall Health Network case sits in the Circuit Court of Putnam County before Judge Phillip Stowers, filed under Rule 23 of the West Virginia Rules of Civil Procedure. The complaint proposes a class of West Virginia citizens who received the health system’s notice, and a subclass of West Virginia citizens whose information appeared inside a class member’s records but who received no letter of their own — spouses and family members whose details sit in someone else’s chart. It alleges the class runs well in excess of one hundred members.
That subclass reflects something people rarely think about until it matters. Your medical file contains information about the people around you, and a breach of your records is a breach of theirs.
The reach here is regional. Marshall Health Network is an academic health system headquartered on Hal Greer Boulevard in Huntington, comprising Cabell Huntington Hospital, St. Mary’s Medical Center, Hoops Family Children’s Hospital, and Rivers Health, along with the employed physician practices of those hospitals. The network describes itself as serving more than a million children and adults across twenty-three counties in West Virginia, southern Ohio, and eastern Kentucky. Anyone treated anywhere in that footprint may have information in the affected systems.
Frequently Asked Questions (FAQs)
I was a patient but never received a letter. Am I affected?
Possibly. Notification lists are assembled from vendor-supplied data and are not always complete, and mail goes astray. Call the health system’s dedicated line at 833-918-4335 to confirm your status and update your address rather than assuming silence means safety.
My spouse received a letter and I did not, but my information is in their records. Do I have a claim?
That situation is specifically addressed in the lawsuit through a proposed subclass. When one person provides a family member’s information in the course of receiving care, that information can be exposed even though the family member was never the patient and never receives a notice.
Is twenty-four months of credit monitoring enough?
It is a genuine benefit and worth enrolling in. It also expires long before the risk does. A Social Security number is effectively permanent, and medical history never becomes stale, which is why longer-term monitoring is among the remedies these cases seek.
Nothing bad has happened to me yet. Do I still have a case?
Under West Virginia law, claims for breach of the duty of confidentiality and invasion of privacy do not require proof that anyone misused your information. Whether a particular person has a viable claim depends on their own facts, but the absence of identity theft so far is not by itself a bar.
The breach happened at a vendor, not at the hospital. Does that matter?
A health system that collects patient information retains obligations over how that information is protected, including when it hands the data to a contractor. A federal judge reached that conclusion in the consolidated litigation over this breach in June 2026, rejecting the argument that hospitals could avoid liability by pointing at their electronic health record vendor.
What does it cost to have my situation reviewed?
Nothing. These matters are handled on a contingency fee basis, and the initial consultation is free.
Talk With a West Virginia Data Breach Class Action Attorney
Powell & Majestro P.L.L.C. represents West Virginia patients whose personal and medical information was exposed in the breach of Marshall Health Network’s electronic health record vendor. The firm has litigated consumer and privacy class actions in West Virginia and nationally for more than two decades, often as co-counsel and on referral from attorneys whose practices do not handle complex class litigation.
If you received a notice letter, or believe your information was in the records of someone who did, we can review your situation at no cost and explain what options are available to you.
Call (304) 346-2889 or reach us through our online contact form. We work on a contingency fee basis, and there are no fees unless we recover on your behalf.







Leave a Reply
Want to join the discussion?Feel free to contribute!