Health Gorilla, Inc., et al.
The Health Gorilla, Inc., et al., Data Security Breach litigation was centralized before Judge K. Michael Moore in the Southern District of Florida in August 2026, consolidating claims arising from a data security incident involving Health Gorilla, a health-information-exchange network that connects healthcare providers, laboratories, and other participants to share patient records across a broader care-coordination ecosystem. With only 10 actions filed and pending, this is among the youngest dockets currently active in the federal MDL system.
Health-information-exchange breaches present a structurally distinctive resolution-risk profile even within the healthcare-vendor breach category: because a health-information exchange is specifically designed to route patient data among multiple independent healthcare organizations, determining the scope of affected individuals and the point of compromise may require tracing data flows across several participating entities rather than a single vendor-client relationship. That network structure is likely to shape both the discovery process and how liability is eventually allocated among Health Gorilla and any participating healthcare organizations named as co-defendants.
At this earliest stage, duration risk is driven primarily by how quickly the court establishes a case-management structure and how the ultimate scope of the affected population — and the network of participating organizations implicated — becomes clear through initial discovery. Criterica Intelligence's platform tracks this kind of health-information-exchange breach structure as a distinct pattern within the broader healthcare-vendor breach category, given its unique network-level liability questions, providing a structural read on this docket's earliest development without projecting a specific outcome. A companion capital brief on this docket is available through Criterica Capital.
Health Gorilla is a health-information-exchange network connecting healthcare providers, laboratories, and other participants to share patient records; a data security incident allegedly resulted in unauthorized access to personal and health information flowing through its network.
Because the network is designed to route patient data among multiple independent healthcare organizations, determining the scope of affected individuals and allocating liability may require tracing data flows across several participating entities rather than a single vendor-client relationship.
The earliest formation stage — centralized in August 2026 with only 10 actions filed and pending, and no case-management structure or discovery record has yet developed.
By monitoring its earliest structural development — case-management milestones and the emerging scope of affected organizations — as a distinct health-information-exchange breach pattern within the broader healthcare-vendor breach category.
Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.