The San Jose Mercury News reports that Stanford Hospital & Clinics and former contractor Multi-Specialty Collection Services (MSCS) will likely pay $4.1 million to settle a class action lawsuit over a 2010 data breach that exposed approximately 20,000 emergency room patients' medical information (h/t Becker's Hospital Review).

The patients' medical record numbers, hospital account numbers, billing charges and emergency room admission and discharge dates were made available online for almost a year beginning on September 9, 2010.

According to the Mercury News, Stanford Hospital says MSCS sent the data to a third party for help in creating a graph, and the third party posted the information on the Web site Student of Fortune.


Law360 reports that the majority of the settlement will be paid by MSCS -- Stanford will pay $250,000 in administrative costs and $500,000 for an education program aimed at preventing similar breaches in the future.

Photo courtesy of Shutterstock.