• Call Today:
  • (304) 346-2889
405 Capitol Street, Suite 807•Charleston, WV 25301
Powell & Majestro P.L.L.C.
  • Home
  • About Us
  • Attorneys
    • Anthony J. Majestro
    • James C. Powell
    • Christina L. Smith
    • Graham B. Platz
    • Thomas J. Hurney IV
  • Practice Areas
    • Mass Tort Litigation
      • Mass Tort: Opioid Litigation
    • Class Action
      • Nitric Acid Leak at Ames Goldsmith Catalyst Refiners
      • The Greenbrier Clinic Mammography Lawsuit
      • Ultra-Processed Foods Lawsuit
    • Product Liability
    • Government Entity Litigation
    • Personal Injury
      • Motor Vehicle Accidents
      • Truck Accidents
    • Appellate Law
    • Consumer Protection
      • Higher Education Fraud
      • Credit Card Debt
      • Mortgage
      • Utilities
      • West Virginia Lemon Law Attorneys
      • Unfair or Deceptive Acts or Practices
  • In The News
  • Blog
  • Career Opportunities
  • Contact
  • Menu Menu

Tag Archive for: consumer rights

Why Did the FDA Stop Mammograms at The Greenbrier Clinic?

July 30, 2026/by Powell & Majestro P.L.L.C.

Tabitha Martin had her mammogram at The Greenbrier Clinic on February 13, 2026. The report came back benign. It assured her the finding was dependable because high-resolution real-time ultrasound images had been obtained.

Five weeks later, a certified letter told her she could not rely on any of it.

The FDA ordered the clinic to stop performing mammography on February 26, 2026, after determining that the facility failed to meet the clinical image quality standards established by its accreditation body, the American College of Radiology. That finding reaches backward across every mammogram performed there between October 28, 2023, and February 26, 2026, more than two years of screenings and roughly 1,000 patients scattered across the country and overseas. Powell & Majestro P.L.L.C. filed a federal class action on their behalf in April 2026, and women screened during that window can call (304) 346-2889 for a free case review.

The distinction that matters most to those patients is a narrow one. Nobody has said their results were wrong. What the FDA said is that nobody can vouch for them.

What Prompted the FDA to Shut Down Mammography at the Clinic?

The FDA halted mammography at The Greenbrier Clinic because a review of the facility’s clinical images found they did not meet the quality standards its accreditation body requires. A facility that cannot satisfy those standards loses its authority to scan patients, and the loss takes effect immediately.

Every mammography provider in the United States operates under the Mammography Quality Standards Act of 1992, codified at 42 U.S.C. § 263b, with the operating rules at 21 C.F.R. Part 900. Congress passed it because screening quality varied so widely from one facility to the next that the value of a mammogram depended heavily on where a woman happened to get it.

To hold a certificate, a facility must:

  • Hold FDA certification confirming it is capable of providing quality mammography
  • Maintain accreditation through an FDA-approved body — the American College of Radiology, in this clinic’s case
  • Submit clinical images for periodic review
  • Complete an annual survey conducted by or under the supervision of a medical physicist
  • Pass an annual inspection by a certified MQSA inspector
  • Meet federal requirements for personnel qualifications, equipment, radiation dose, quality assurance, and recordkeeping

When the FDA suspects quality at a facility has degraded far enough to endanger patients, 21 C.F.R. § 900.12(j) governs what happens next. The agency can order an Additional Mammography Review, requiring the facility to turn over clinical images to its accreditation body for evaluation. If that review turns up serious image quality deficiencies, accreditation is revoked. Without accreditation, the FDA certificate lapses, and the facility must stop scanning.

What Does the March 23 Letter Actually Mean?

The March 23, 2026, letter was not a courtesy from the clinic. It was a federally mandated notification, and the FDA orders one only after determining that a facility’s mammography quality fell so far outside federal standards as to present a significant risk to human health.

That threshold is written into the regulation. Under § 900.12(j)(2), the agency may require a facility to notify every affected patient and every referring provider once it makes that finding. Routine paperwork lapses do not trigger it.

Staff radiologist Dr. Henry Setliff signed the letters, which went out by certified mail to everyone imaged during the affected period. They disclosed a “serious concern about the quality of the mammography” performed at the facility, explained that the FDA had required the clinic to stop, and told patients to speak with their health care provider as soon as possible. The clinic also acknowledged that most patients would need their prior images reviewed to determine whether a repeat mammogram elsewhere was necessary.

The letter is careful to say individual results are not necessarily incorrect. That is accurate, and it is also the heart of the problem. A screening mammogram is purchased for one reason: to replace uncertainty with an answer. These patients paid for an answer and were left holding a question.

Local reporting suggests some affected patients never received their certified letter. Anyone screened at the clinic between October 28, 2023, and February 26, 2026 should assume they fall inside the affected group regardless of what arrived in the mail.

What Should You Do If You Were Screened at The Greenbrier Clinic?

Patients imaged at the clinic during the affected period should have their prior images reviewed by another provider, preserve every document connected to the screening, and obtain a repeat mammogram if their physician recommends one. The clinical steps come first. The legal ones can follow.

  1. Call your physician. Bring the date of your mammogram and the clinic’s letter if you have it. Your provider decides whether the prior images are usable for comparison or whether you need fresh imaging.
  2. Request your original images and report. Patients have a right to their mammography records. Ask in writing and have them routed to whichever facility handles your follow-up.
  3. Do not wait on the clinic. The FDA has not restored the facility’s authority to perform mammography, and no date has been announced for its return. Your follow-up needs to happen somewhere else.
  4. Keep the paper. The letter, the envelope, your bill, your explanation of benefits, receipts for out-of-pocket costs, and every invoice generated by repeat screening. These establish both class membership and damages.
  5. Write down the timeline. When you were screened, what you were told, when the letter arrived, and what it cost you to sort out. Memory fades faster than litigation moves.

Who Pays for the Repeat Mammogram?

No patient has been reimbursed. The clinic billed for the original screenings, collected from patients and their insurers, and as of the filing of the federal complaint had issued no refund, rebate, or credit for imaging the FDA determined was unreliable.

The cost lands in two places. Insurers commonly cover one screening mammogram per plan year, so a second scan inside the same twelve months can be denied outright or applied to a deductible. And every patient who paid coinsurance or a deductible on the first mammogram paid it for a service she did not receive.

That is the economic core of the litigation. The claims are not built on a misread scan. They are built on money changing hands for a diagnostic service that did not meet the standard it was sold as meeting.

What Lawsuits Have Been Filed Against The Greenbrier Clinic?

Three proposed class actions were filed within roughly six weeks of the notification letters — two in federal court and one in state court.

The first, Martin v. The Greenbrier Clinic, Inc., No. 5:26-cv-00252, was filed April 7, 2026 in the United States District Court for the Southern District of West Virginia, Beckley Division, and assigned to Judge Frank Volk. It advances five causes of action:

  • Unfair and deceptive acts and practices under the West Virginia Consumer Credit and Protection Act
  • Unjust enrichment
  • Breach of contract
  • Fraudulent, deceptive, or misleading representations
  • Negligent infliction of emotional distress

The proposed class covers everyone who received mammography services at the clinic between October 28, 2023, and February 26, 2026 and received the March 23 letter. The complaint estimates the class at roughly 1,000 patients and invokes federal jurisdiction under the Class Action Fairness Act, 28 U.S.C. § 1332(d).

A second suit followed on April 8 in Greenbrier County Circuit Court on behalf of a patient identified as E.H., screened around May 2024, pressing breach of contract and unjust enrichment theories.

A third federal complaint arrived in May on behalf of April Wilson of White Sulphur Springs and Erin Dotson of Ronceverte, screened in October 2024 and March 2025. It proposes a nationwide class raising consumer protection, unjust enrichment, contract, and emotional distress claims.

Residency in West Virginia is not a requirement. The clinic serves resort guests from across the country and abroad, and the proposed classes reach patients wherever they live.

Which West Virginia Laws Apply to These Claims?

The claims run primarily through the West Virginia Consumer Credit and Protection Act, which makes it unlawful to use unfair or deceptive acts or practices while engaged in trade or commerce. W. Va. Code § 46A-6-104.

Several provisions map onto these facts:

  • 46A-6-102(7)(B) — causing confusion or misunderstanding about the approval or certification of goods or services. The complaint alleges the clinic held itself out as operating under FDA-approved standards while its imaging did not comply.
  • 46A-6-102(7)(E) — representing that services carry approval, characteristics, or benefits they do not have.
  • 46A-6-102(7)(G) — misrepresenting that services are of a particular standard, quality, or grade.
  • 46A-6-102(7)(M) — deception or concealment of a material fact intended to be relied upon in connection with the sale of services.

The clinic’s own marketing supplies the comparison. Its website advertised “state-of-the-art diagnostic technologies” and described its 3D mammography as one of the latest innovations in women’s health care, capable of detecting breast cancer earlier and allowing treatment sooner.

Section 46A-6-106 gives consumers a private right of action. Sections 46A-5-104 and 46A-5-106 shift attorney’s fees and costs onto a defendant that violates the Act — which matters in a case where individual economic losses are measured in hundreds of dollars rather than thousands.

How Long Do Patients Have to File a Claim in West Virginia?

Filing deadlines vary by claim, and the shortest one that applies to your situation controls your planning.

  • Consumer protection claims — four years. Va. Code § 46A-5-101 sets a four-year limitations period running from the date the violation occurred, for actions filed on or after September 1, 2015. The West Virginia Supreme Court of Appeals applied that framework in Harper v. Jackson Hewitt, Inc., 706 S.E.2d 63 (W. Va. 2010).
  • Negligent infliction of emotional distress — two years. Va. Code § 55-2-12.
  • Breach of a written contract — ten years. Va. Code § 55-2-6. Oral contracts carry five.

For patients screened in late 2023, the two-year window on emotional distress claims is the one to watch. Waiting carries a practical cost unrelated to the calendar as well: billing records get purged, imaging archives get overwritten, and the memory of what a technologist said in the exam room stops being reliable evidence.

What Mistakes Do Patients Make After a Notification Like This?

  • Reading “not necessarily incorrect” as “probably fine.” The phrase describes uncertainty, not reassurance.
  • Throwing the letter away. It is the cleanest single proof of class membership.
  • Waiting for a refund that has not been offered. No reimbursement has been issued.
  • Skipping the repeat scan over cost. The cost is recoverable. A delayed diagnosis is not.
  • Assuming distance disqualifies them. Patients who traveled to the resort from other states are inside the proposed classes.

What the Shutdown Means for Screening in the Greenbrier Valley

The gap left behind is wider than the patient count suggests, because southern West Virginia was already losing ground on breast cancer.

The state data tells an uncomfortable story. West Virginia women are diagnosed with breast cancer at a lower rate than the national average — 126.8 cases per 100,000 against 131.3 nationally — yet they die of it at a higher rate, 20.8 per 100,000 against 19.2. Fewer diagnoses and more deaths point in one direction: cancers found later, when they are harder to treat. Roughly 32 percent of West Virginia breast cancer cases are caught at a late stage.

Two years of screening that cannot be relied on, in a rural corner of that state, sits badly against those numbers.

Geography compounds the problem. For women in Greenbrier, Monroe, Summers, and Pocahontas counties, follow-up imaging means a drive. CAMC Greenbrier Valley Medical Center in Ronceverte is the nearest hospital to White Sulphur Springs. Beyond that, patients look west along I-64 toward Raleigh General Hospital and Beckley ARH, or further to CAMC in Charleston and WVU Medicine in Morgantown for subspecialty follow-up. A repeat mammogram is not an errand in this part of the state. It is a half-day.

For the clinic’s out-of-state patients — many of whom booked a screening as part of a resort stay — the logistics differ but are no simpler. Records have to be requested from a facility hundreds of miles away and routed to a provider back home.

Frequently Asked Questions (FAQs)

Does the letter mean I have breast cancer?

No. The letter says nothing about your health. It says the imaging used to assess your health did not meet federal quality standards, which is why your provider needs to determine whether a repeat scan is warranted.

I live in another state. Can I still be part of the class?

Yes. The proposed classes cover everyone who received mammography at the clinic during the affected window and received the notification, regardless of where they live. Many of the clinic’s patients came through the resort from other states and other countries.

I was screened during that period but never received a letter. What now?

Contact the clinic to confirm your status and update your address, and speak with your physician about follow-up imaging. Some patients reportedly did not receive their certified letter. The date of your screening, not the arrival of an envelope, determines whether you were affected.

Is this a medical malpractice case?

No. These are consumer protection and contract claims. They rest on what patients were sold and what they paid for, not on an allegation that a radiologist misread a particular film. A patient later diagnosed with breast cancer that earlier imaging should have caught has a different and separate claim, and should have it reviewed individually.

What does it cost to have my situation reviewed?

Nothing. These matters are handled on a contingency fee basis, and the initial consultation is free.

 

Talk With a West Virginia Class Action Attorney

Powell & Majestro P.L.L.C. filed the first federal class action arising from the mammography failures at The Greenbrier Clinic and represents patients affected by the FDA’s determination. The firm has handled complex consumer class actions in West Virginia and nationwide for more than two decades, including litigation involving contaminated water supplies, defective products, and deceptive business practices.

If you were screened at The Greenbrier Clinic between October 28, 2023, and February 26, 2026, we can review your situation at no cost and explain your options.

Call (304) 346-2889 or reach us through our online contact form. You can also read more about the case on our Greenbrier Clinic mammography lawsuit page. There are no fees unless we recover compensation on your behalf.

https://www.powellmajestro.com/wp-content/uploads/2026/07/Why-Did-the-FDA-Stop-Mammograms-at-The-Greenbrier-Clinic.jpg 768 1344 Powell & Majestro P.L.L.C. https://powellmajestro.wpenginepowered.com/wp-content/uploads/2024/01/logo.png Powell & Majestro P.L.L.C.2026-07-30 00:06:372026-07-30 00:06:46Why Did the FDA Stop Mammograms at The Greenbrier Clinic?

How Long Does a Hospital Have to Tell You About a Data Breach?

July 30, 2026/by Powell & Majestro P.L.L.C.

Federal law gives a hospital sixty days. Once a covered health care provider discovers that patient information has been breached, the HIPAA Breach Notification Rule requires notice to each affected individual without unreasonable delay, and in no case later than sixty days after discovery. That is an outer limit, not a target.

Patients of Marshall Health Network received their letters in June 2026, describing an intrusion that began on a vendor’s servers in January 2025. According to a class action complaint filed in the Circuit Court of Putnam County, the health system itself learned of the incident in October 2025 — roughly eight months before the letters went out. Powell & Majestro P.L.L.C. filed that lawsuit on June 11, 2026 on behalf of West Virginia patients whose records were exposed, and anyone who received a notice can call (304) 346-2889 for a free case review.

The gap is the case. Every protective step available to a breach victim (freezing credit, watching for medical billing you do not recognize, placing fraud alerts) depends first on knowing it happened.

What Does Federal Law Require, and How Fast?

HIPAA gives a covered health care provider sixty calendar days from discovery of a breach to notify each affected individual, and the rule requires notice without unreasonable delay even inside that window.

The requirement sits in the Breach Notification Rule at 45 C.F.R. §§ 164.400–414. Separately, the HIPAA Security Rule obligates covered entities and their business associates to ensure the confidentiality, integrity, and availability of electronic protected health information, to guard against reasonably anticipated threats, and to implement technical controls limiting access to authorized users. 45 C.F.R. §§ 164.306, 164.312.

There is a law enforcement exception, and its details matter here. Under 45 C.F.R. § 164.412, a provider may delay notification if a law enforcement official states that notice would impede a criminal investigation — but the form of the request controls how long the delay can run:

  • A written statement must specify the period of delay, and the provider may hold notice for that period.
  • An oral request permits a delay of no more than thirty days, unless a written statement follows within that window.

Marshall Health Network’s notice letters told patients that the vendor had informed the health system that law enforcement investigators directed a delay in notifying patients. The complaint points out what the letter does not say: whether any such request was made in writing, who issued it, what period it covered, whether it reached patient notification as opposed to notification of hospital customers, when it expired, and whether notice followed promptly once it lifted.

One clarification worth making, because it shapes how these cases are built. HIPAA creates no private right of action, and the complaint asserts none. The regulations are used as evidence of the duty and the standard of care that applies to a health care provider handling patient information — not as a statute a patient can sue under directly.

What Does West Virginia Law Require?

West Virginia’s breach notification statute requires notice without unreasonable delay and permits a provider to hold notice only for as long as disclosure would impede a criminal investigation.

The statute is codified at W. Va. Code §§ 46A-2A-101 et seq. It does not set a fixed ceiling the way HIPAA’s sixty-day rule does. Instead, it applies a reasonableness standard, which means the length of any delay has to be justified by something — and once an investigation no longer requires silence, the obligation to notify runs.

The two frameworks stack rather than compete. A West Virginia hospital answers to both, and satisfying neither is a problem the provider has to explain.

What Happened in the Oracle Health Breach?

An unauthorized party used stolen credentials to reach legacy Cerner servers in January 2025, and the consequences have been reaching patients at hospitals across the country ever since.

Oracle acquired Cerner in 2022 in a deal valued at roughly $28 billion and renamed it Oracle Health. The servers involved held records that had not yet been migrated to Oracle’s cloud environment. Oracle has said the stolen credentials were used on or around January 22, 2025, and that the incident was identified on or around February 20, 2025.

What followed is the part patients find hardest to accept. Oracle did not announce the breach publicly and did not notify patients directly. It left notification to its health care clients and asked those organizations to hold off while its investigation continued. In litigation, the company’s attorneys indicated as many as eighty hospitals may have been affected. Health systems have been sending letters one at a time ever since, some more than a year after the intrusion.

Marshall Health Network posted its notice on June 5, 2026 and mailed individual letters the same day. Per that notice, the information involved varied by person but may have included names, Social Security numbers, and details drawn from patient medical records — medical record numbers, treating doctors, diagnoses, medications, test results, images, and information about care and treatment.

Why an Eight-Month Delay Matters More Than It Sounds

A notification delay is not a paperwork problem. It is a stretch of time during which a patient carries all of the risk and none of the information needed to reduce it.

Consider what a person does on day one after learning their Social Security number is in criminal hands. Freeze credit at all three bureaus. Place fraud alerts. Start reading every explanation of benefits for treatment that never happened. Treat any call or email referencing their hospital as suspect. None of that occurs while the letter is still unwritten.

Medical data compounds the problem. A compromised credit card gets cancelled and reissued in a week. A Social Security number cannot be changed except through a difficult process carrying its own consequences for credit and employment, and a medical history never expires. Diagnoses, medications, and treatment records describe a person accurately for life, which is why this information holds its value to criminals for years.

That mismatch is the argument against the remedy offered. Twenty-four months of credit monitoring and identity restoration is a real benefit, and patients should use it. It is also a two-year answer to a lifetime exposure.

Can You Sue If Nobody Has Stolen Your Identity Yet?

In West Virginia, yes. The Supreme Court of Appeals held in 2014 that patients have standing to pursue breach of confidentiality and invasion of privacy claims, and can obtain class certification on them, without evidence that any class member suffered identity theft or economic loss.

The case is Tabata v. Charleston Area Medical Center, 233 W. Va. 512, 759 S.E.2d 459 (2014). Personal and medical information belonging to roughly 3,655 patients had been placed on an electronic database accessible over the internet. Discovery turned up no evidence that anyone had suffered identity theft, and none that the information had even been viewed. The Circuit Court of Kanawha County denied class certification. The Supreme Court of Appeals reversed.

The reasoning rests on the elements of the claims themselves. Under West Virginia law, breach of the duty of confidentiality does not require proof of a concrete injury, and invasion of privacy does not require pleading special damages. Where the underlying causes of action do not demand economic harm, the absence of economic harm does not defeat standing or certification.

The Court was careful to limit itself. It held only that the circuit court erred on standing and abused its discretion on commonality, typicality, and predominance, and it made no determination about whether the plaintiffs could ultimately prove their claims. Justice Ketchum dissented.

Results differ by forum, and honesty about that is worth more than salesmanship. In the consolidated federal litigation over this same Oracle Health breach, a judge in the Western District of Missouri ruled in June 2026 that negligence claims could proceed against the vendor and eight health systems, and rejected the argument that a hospital can hand its data protection duties to a vendor — while dismissing unjust enrichment and invasion of privacy claims and narrowing several state statutory claims. Different law, different forum, different outcome.

Is a Data Breach Claim a Medical Malpractice Claim?

No. West Virginia settled that question in 2012, in a case brought against a hospital that is now part of Marshall Health Network.

In R.K. v. St. Mary’s Medical Center, Inc., 229 W. Va. 712, 735 S.E.2d 715 (2012), hospital employees improperly accessed a patient’s records and disclosed details of his psychiatric hospitalization. The Supreme Court of Appeals reached two conclusions that still govern these cases.

  • HIPAA does not preempt state claims. Common law tort claims based on the wrongful disclosure of medical or personal health information survive alongside the federal scheme. The United States Supreme Court denied review in 2013.
  • The Medical Professional Liability Act does not apply. Allegations about the improper disclosure of medical records fall outside the Act’s definition of “health care,” so the MPLA does not govern them.

The practical weight of that second holding is easy to underestimate. The MPLA imposes pre-suit notice, a screening certificate of merit sworn by a qualified physician, a two-year filing deadline, and statutory caps on noneconomic damages. If those requirements attached to data breach claims, very few patients would ever be able to bring one — no physician can meaningfully certify the merits of a claim about server security.

What Should You Do If You Received a Data Breach Letter?

Freeze your credit first, enroll in the monitoring being offered, then start watching your medical billing as closely as your bank statements.

  1. Freeze your credit at all three bureaus. Freezes are free; they can be lifted temporarily when you need credit, and they stop new accounts in a way that monitoring alone does not. Monitoring tells you after something happens. A freeze prevents it.
  2. Enroll in the offered service. Marshall Health Network and the vendor are offering twenty-four months of Experian IdentityWorks Credit Plus 3B along with identity restoration. The credit monitoring requires you to enroll; it does not start on its own.
  3. Read every explanation of benefits. Medical identity theft shows up as treatment you never received, providers you have never seen, or a deductible that has somehow been met. It can also corrupt your own chart, which carries clinical risk beyond the financial harm.
  4. Treat breach-related contact as suspect. Criminals follow breach coverage and call victims posing as the hospital, the vendor, or the monitoring service. Verify independently before giving information to anyone who contacts you first.
  5. Keep the letter and log your time. Save the notice and its engagement number, and write down hours spent and money paid dealing with the fallout. Time spent mitigating a breach is a recognized element of damages.

Anyone who was treated within the network but never received a letter can reach the dedicated line the health system established at 833-918-4335 to check their status.

Why These Cases Are Being Filed in West Virginia Courts

West Virginia’s own law on medical confidentiality and patient privacy gives these claims firmer footing than the federal alternative, and plaintiffs are filing accordingly.

The Marshall Health Network case sits in the Circuit Court of Putnam County before Judge Phillip Stowers, filed under Rule 23 of the West Virginia Rules of Civil Procedure. The complaint proposes a class of West Virginia citizens who received the health system’s notice, and a subclass of West Virginia citizens whose information appeared inside a class member’s records but who received no letter of their own — spouses and family members whose details sit in someone else’s chart. It alleges the class runs well in excess of one hundred members.

That subclass reflects something people rarely think about until it matters. Your medical file contains information about the people around you, and a breach of your records is a breach of theirs.

The reach here is regional. Marshall Health Network is an academic health system headquartered on Hal Greer Boulevard in Huntington, comprising Cabell Huntington Hospital, St. Mary’s Medical Center, Hoops Family Children’s Hospital, and Rivers Health, along with the employed physician practices of those hospitals. The network describes itself as serving more than a million children and adults across twenty-three counties in West Virginia, southern Ohio, and eastern Kentucky. Anyone treated anywhere in that footprint may have information in the affected systems.

Frequently Asked Questions (FAQs)

I was a patient but never received a letter. Am I affected?

Possibly. Notification lists are assembled from vendor-supplied data and are not always complete, and mail goes astray. Call the health system’s dedicated line at 833-918-4335 to confirm your status and update your address rather than assuming silence means safety.

My spouse received a letter and I did not, but my information is in their records. Do I have a claim?

That situation is specifically addressed in the lawsuit through a proposed subclass. When one person provides a family member’s information in the course of receiving care, that information can be exposed even though the family member was never the patient and never receives a notice.

Is twenty-four months of credit monitoring enough?

It is a genuine benefit and worth enrolling in. It also expires long before the risk does. A Social Security number is effectively permanent, and medical history never becomes stale, which is why longer-term monitoring is among the remedies these cases seek.

Nothing bad has happened to me yet. Do I still have a case?

Under West Virginia law, claims for breach of the duty of confidentiality and invasion of privacy do not require proof that anyone misused your information. Whether a particular person has a viable claim depends on their own facts, but the absence of identity theft so far is not by itself a bar.

The breach happened at a vendor, not at the hospital. Does that matter?

A health system that collects patient information retains obligations over how that information is protected, including when it hands the data to a contractor. A federal judge reached that conclusion in the consolidated litigation over this breach in June 2026, rejecting the argument that hospitals could avoid liability by pointing at their electronic health record vendor.

What does it cost to have my situation reviewed?

Nothing. These matters are handled on a contingency fee basis, and the initial consultation is free.

 

Talk With a West Virginia Data Breach Class Action Attorney

Powell & Majestro P.L.L.C. represents West Virginia patients whose personal and medical information was exposed in the breach of Marshall Health Network’s electronic health record vendor. The firm has litigated consumer and privacy class actions in West Virginia and nationally for more than two decades, often as co-counsel and on referral from attorneys whose practices do not handle complex class litigation.

If you received a notice letter, or believe your information was in the records of someone who did, we can review your situation at no cost and explain what options are available to you.

Call (304) 346-2889 or reach us through our online contact form. We work on a contingency fee basis, and there are no fees unless we recover on your behalf.

https://www.powellmajestro.com/wp-content/uploads/2026/07/How-Long-Does-a-Hospital-Have-to-Tell-You-About-a-Data-Breach.jpg 768 1344 Powell & Majestro P.L.L.C. https://powellmajestro.wpenginepowered.com/wp-content/uploads/2024/01/logo.png Powell & Majestro P.L.L.C.2026-07-30 00:04:342026-07-30 00:04:41How Long Does a Hospital Have to Tell You About a Data Breach?

Our Latest Posts

  • Why Did the FDA Stop Mammograms at The Greenbrier Clinic?
  • How Long Does a Hospital Have to Tell You About a Data Breach?
  • Does West Virginia’s Medical Malpractice Law Apply If You Weren’t Physically Injured?
  • Does a Software Update Count as a Repair Attempt Under West Virginia’s Lemon Law?
  • What Is West Virginia’s Modified Comparative Fault Rule? 50% Bar Explained
  • Negative Option Billing: The Auto-Renewal Trap Costing Billions
  • AFFF Firefighter Cancer Lawsuits: A Guide for West Virginia Fire Departments
  • Historic Jury Verdicts Against Meta: What the $375 Million New Mexico Win Means for West Virginia Families
  • The Insurance Adjuster’s Playbook: Tactics Used Against West Virginia Vehicle Accident Victims
  • DNA Testing Scams: Is Your Genetic Data for Sale?

Since 2002, Powell & Majestro P.L.L.C. has helped West Virginia residents overcome legal problems and secure the justice they deserve. Our firm is well-known as a premier resource for clients who want experienced, dynamic legal representation.

Contact Us

Charleston
405 Capitol Street
Suite 807
Charleston, WV 25301

Phone: 304-346-2889
Toll Free: (800) 650-2889

Maps & Directions

Email

Navigate

  • Home
  • About Us
  • Attorneys
  • Practice Areas
  • Co-Counsel – Attorney Referrals
  • In The News
  • Blog
  • Contact

Follow Us

More Donors, More Hope

Every registered organ donor offers hope to people who need transplants – and to the families who love them.

The information on this site is not, nor is it intended to be, legal advice. You should consult an attorney for advice regarding your individual situation. We invite you to contact us via phone or electronic mail to discuss your potential case. Contacting us does not create an attorney-client relationship. Please do not send any confidential information to us until such time as an attorney-client relationship has been established.

© 2026 Powell & Majestro P.L.L.C. All Rights Reserved. This is a Too Darn Loud - Digital Marketing law firm website.
  • Terms
  • Sitemap
Scroll to top Scroll to top Scroll to top

Urgent Notice: The Greenbrier Clinic Mammography Patients

Did you receive a mammogram at The Greenbrier Clinic between October 28, 2023, and February 26, 2026?

The FDA recently ordered The Greenbrier Clinic to stop performing mammograms after determining the facility failed to meet clinical image quality standards required by federal law. Hundreds of patients have been notified that their results may be unreliable or inaccurate.

You May Be Entitled to Compensation

If you received a notification letter dated March 23, 2026, or underwent screening during the dates above, you may have a legal claim. Powell & Majestro, PLLC is currently accepting clients for a class action lawsuit to hold the clinic accountable.

LEARN MORE