A federal judge in Tennessee has allowed a class action over a 2025 data breach to proceed against Nashville-based Covenant Surgical Partners and two Maryland gastroenterology groups.
Judge Waverly Crenshaw Jr. of the U.S. District Court for the Middle District of Tennessee dismissed plaintiff Judith Nelson’s negligence per se and unjust enrichment claims on Sept. 22, according to the memorandum opinion. He let her negligence, breach of implied contract and breach of fiduciary duty claims move forward. The court also refused to strike the class allegations, finding Ms. Nelson plausibly alleged gross negligence. That finding is enough to get around Tennessee’s cybersecurity safe harbor law, which otherwise blocks class actions over data breaches. The complaint alleges the defendants failed to use encryption, multifactor authentication and adequate malware detection.
The Feb. 22, 2025, breach hit a computer network shared by Covenant, Anne Arundel Gastroenterology Associates and the Maryland Center for Digestive Health. It exposed patient names, dates of birth, insurance information, diagnoses and treatment details. More than 88,000 people were affected.
Becker’s has reached out to USPI and will update this story if more information becomes available.
At the Becker’s 32nd Annual Meeting: The Business and Operations of ASCs, taking place October 29-31 in Chicago, ASC leaders, surgeons and healthcare executives will explore strategies to drive growth, enhance operational performance, navigate reimbursement challenges and prepare for the future of ambulatory surgery. Apply for complimentary registration now.
