A federal court in Washington has granted preliminary approval to a $6.1 million class action settlement over a 2025 data breach at Laboratory Services Cooperative, a nonprofit diagnostic testing provider that serves Planned Parenthood facilities in more than 30 states. Up to 1.6 million people had their personal and medical information exposed. The settlement is a healthcare data breach case, not a reproductive-rights case, but the sensitivity of the underlying data is exactly why it is worth a closer look.

The lawsuits accused Laboratory Services Cooperative of failing to protect names, dates of birth, medical and clinical information, health insurance details, billing and claims records, payment card and banking data, Social Security numbers, driver's license or state ID numbers, and passport numbers belonging to both patients and workers. One of the underlying complaints made a point of noting that the breach reached people who had no direct relationship with the lab at all, since it processed data on behalf of the clinics it served rather than collecting all of it directly. That distinction, a data handler holding sensitive information about people who never dealt with it personally, is precisely the kind of exposure a privacy policy needs to account for and disclose.

ClassAction.org article confirming the $6.1 million Laboratory Services Cooperative data breach settlement, case number 2:25-cv-00685, filed in Washington

Source: ClassAction.org, "$6.1M Laboratory Services Cooperative Settlement Wraps Up Data Breach Lawsuit", captured August 2026.

What happened

Laboratory Services Cooperative, a Seattle-based clinical lab, identified unauthorized activity on its network on or about October 27, 2024. A forensic investigation confirmed in February 2025 that an unauthorized third party had accessed files containing sensitive patient and employee data, and the lab began notifying affected individuals in April 2025, roughly six months after the intrusion was first detected. Eight related class action lawsuits were consolidated into In re: Laboratory Services Cooperative Data Breach Litigation in the U.S. District Court for the Western District of Washington, case number 2:25-cv-00685.

The court preliminarily approved the $6.1 million settlement on July 27, 2026. The settlement class covers all United States residents whose personal information was potentially compromised in the breach. Under the terms, eligible class members can claim up to $5,000 for documented out-of-pocket losses tied to identity theft or fraud, an additional pro rata cash payment of up to $1,000 without proof of loss, and two years of medical data monitoring, credit monitoring, and identity theft protection. Final approval is still pending a hearing date that has not yet been scheduled.

Per-claimant payout caps in the $6.1M Laboratory Services Cooperative settlement, covering up to 1.6M affected individuals 01,5003,0004,5006,000 USD5,000Documented-loss reimbursement1,000Pro rata cash payment

Figure: Maximum per-claimant payout tiers under the preliminarily approved $6.1 million Laboratory Services Cooperative settlement, which covers up to 1.6 million people affected by the October 2024 breach.

Why the notification gap matters

A five-to-six-month gap between discovering a breach and notifying the people affected by it is not unusual in large-scale incidents, since forensic investigations into exactly what was accessed and who it belongs to take time. But that gap is also where a business's privacy policy language gets tested. A policy that promises a specific notification timeline, describes a retention schedule that no longer matches practice, or is silent on how long sensitive health data is kept after a service relationship ends creates a mismatch that plaintiffs' attorneys and state regulators are quick to point to once a breach happens.

For a lab, clinic, health app, or any business that processes medical, biometric, or other sensitive health information, this case is a reminder that Washington and a growing number of states now treat consumer health data as its own protected category, separate from general personal information, with its own consent and disclosure expectations. A privacy policy that lumps health information in with ordinary account data, without addressing how long it is retained, who it is shared with, and what happens to it if the vendor holding it is breached, is exactly the kind of gap this settlement traces back to.

What this means for your privacy policy

If your business collects, stores, or processes health data on behalf of another organization, or if a lab, testing service, or health-adjacent vendor processes it on your behalf, your privacy policy needs to say so in plain terms: what sensitive health data you or your vendors hold, how long you retain it, and what your breach notification process looks like if that data is ever exposed. Vague or boilerplate language on data retention and incident response is a liability, not a formality, once a breach actually occurs. Our Privacy Policy Generator builds sensitive-data retention and breach-notification disclosures directly into your policy, so the commitments on your site match what your business can actually deliver if something goes wrong.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.