Wolf Popper LLP, together with co-counsel Kreher & Trapani LLP, represents a class of individuals whose personal and medical information was compromised in a data breach affecting BAYADA Home Health Care, Inc. (“BAYADA”), one of the largest home health care providers in the country. The lawsuit alleges that an unauthorized person accessed BAYADA’s computer network and copied files containing patients’ private medical and personal information, and that BAYADA waited far longer than the law allows before telling anyone.
According to the complaint, an unauthorized actor accessed BAYADA’s systems and copied data between February 18, 2026 and March 2, 2026. BAYADA discovered the intrusion on March 2, 2026, but did not complete its review of the affected data until July 1, 2026, and did not begin mailing notice letters to affected individuals until on or about July 17, 2026 — 137 days after discovery. The complaint alleges this exceeded the 60-day notification deadline set by HIPAA’s Breach Notification Rule, 45 C.F.R. § 164.404(b), by more than ten weeks.
The named plaintiff, Maria D. Cappuccino, brings the case as court-appointed guardian of Angelo J. Monaco, an incapacitated person who received home- and community-based services through BAYADA under Pennsylvania’s Consolidated Waiver program. Per BAYADA’s notice letter, the information involved for Mr. Monaco included his name, admission date, date of birth, diagnosis, diagnosis code, Medicaid identification, medical record number, payor authorization number, procedure type, subscriber member number, treating and referring physician, treatment cost information, and treatment location. Across the broader affected population, the complaint alleges the categories of compromised information include name, date of birth, diagnosis and medical or physical treatment information, provider information, health insurance plan information, prescription information, hospital admission and discharge information, disability information, and Social Security numbers.
The complaint further alleges that BAYADA reported to the Texas Attorney General that at least 1,270 individuals were affected, and reported to the Vermont Attorney General that at least 6,097 Vermont residents alone were affected — a figure the complaint contends suggests the nationwide total is far larger, though BAYADA has not disclosed an overall number.
The lawsuit alleges that BAYADA’s offer of twelve months of single-bureau credit monitoring through Cyberscout, a TransUnion company, is inadequate to address the risks created by the breach, given that stolen medical and Medicaid information cannot be changed or cancelled and creates a lifetime risk of medical identity theft and fraudulent billing that standard credit monitoring is not designed to detect.
The class action asserts claims for negligence, negligence per se, breach of implied contract, breach of fiduciary duty, invasion of privacy, unjust enrichment, violation of the New Jersey Consumer Fraud Act, and declaratory judgment on behalf of a nationwide class, as well as a claim under the Pennsylvania Unfair Trade Practices and Consumer Protection Law on behalf of a Pennsylvania subclass.
The case is Cappuccino, as guardian of Angelo J. Monaco v. BAYADA Home Health Care, Inc., No. 1:26-cv-10946, filed August 25, 2026 and pending in the U.S. District Court for the District of New Jersey.
Contact Instructions