Blog Healthcare Security

The $65M Lesson: Why Identity, Not Footage, Is the Real Ransomware Leverage

A hospital refused to pay a $5 million ransom. Hackers leaked patient photos anyway. The settlement that followed shows exactly what security teams are still missing about clinical imaging risk.

⚡ Quick Answer

Lehigh Valley Health Network (LVHN) agreed to pay a $65 million settlement after the BlackCat/ALPHV ransomware group leaked nude patient photos and other data belonging to roughly 135,000 patients and employees. LVHN refused to pay the ~$5 million ransom demand; a Pennsylvania judge granted final settlement approval on November 15, 2024. The case shows that encryption and access controls don't remove ransomware leverage — only removing the identity from the file, before it's ever stored, does that.

Akash Dewangan
Technical Marketing Manager· ·6 min read·Privacy & Security
Conceptual illustration of a locked patient file with a face silhouette, representing identity as the true asset at risk in clinical data breaches

The file wasn't the target. The identity attached to it was.

FactDetail
Healthcare systemLehigh Valley Health Network (LVHN), Allentown, PA
AttackerBlackCat / ALPHV (Russian-speaking ransomware group)
Breach detectedFebruary 6, 2023
Ransom demandedIn excess of $5 million
Ransom paid$0 — LVHN refused to pay
Data leaked~132 GB, including nude radiation-oncology images and patient records
Settlement amount$65 million
Patients/employees covered~135,000
Final court approvalNovember 15, 2024
Top individual payout$125,000 (lead plaintiff, "Jane Doe")
In 2023, a cancer patient got a phone call from her hospital: nude photos taken during her radiation treatment had been stolen by hackers and posted to the dark web. She had no idea the photos even existed on the hospital's network.

The hospital was Lehigh Valley Health Network (LVHN), a nonprofit system operating 13 hospitals and dozens of health centers across eastern Pennsylvania. The attacker was BlackCat (also known as ALPHV), a Russian-speaking ransomware group that had broken into a physician practice's network supporting radiation oncology imaging.

LVHN refused to pay the ransom demand, reported at the time as in excess of $5 million. BlackCat leaked the images anyway — including photos of breast cancer patients, taken during clinically appropriate exams, published naked from the waist up on the group's dark web leak site alongside patient names and diagnoses. [1]

What Happened at Lehigh Valley Health Network#

The breach was detected on February 6, 2023. A class-action lawsuit followed on March 13, 2023, led by a plaintiff identified only as "Jane Doe" to protect her privacy. It alleged LVHN routinely photographed cancer patients as part of treatment documentation — sometimes without patients being clearly told the images existed or how they were stored — and failed to adequately secure that imaging archive. [2]

$65M Total settlement — called by plaintiffs' counsel the largest per-patient healthcare ransomware payout on record [1]
135K Patients and employees covered by the settlement class
$125K Damages awarded to the lead plaintiff whose images were leaked

The Leverage Was Never the File#

Here's the part information security teams are still missing: the leverage in this attack was never the video or image file itself. It was the patient's face and identity attached to it.

Take away the identity, and the same footage becomes worthless to extort with. No face to threaten someone with. No name to attach to a diagnosis. No leverage — and, in all likelihood, no six-figure settlement.

🚨 The Uncomfortable Math

Ransom demanded: roughly $5 million. Ransom paid: $0. Cost of the breach anyway: $65 million in settlement, plus legal fees, remediation, and reputational damage that outlasts any single fiscal year. Refusing to pay didn't remove the leverage — the identity was already exposed the moment the file left the building unprotected.

This is the mechanism most breach post-mortems miss. Encryption protects a file from being read in transit or at rest — but once it's decrypted for legitimate clinical use, the identity is fully intact and fully exploitable if that copy is ever exfiltrated. Access controls limit who can open a file — they do nothing once an attacker is already inside the perimeter. Neither approach touches the actual asset being weaponized: the identifiable human being in the frame.

A Different Security Posture#

That reframing implies a fundamentally different security posture than "encrypt the drive and hope." It means treating de-identification as a workflow requirement for any clinical imaging or video — not a compliance checkbox applied after the fact, and not a manual redaction step queued up for whenever staff have time.

Afterthought Approach

Identity Stored, Then Defended

  • Full-face clinical imagery stored indefinitely on shared network drives
  • Identity protected only by perimeter security and access lists
  • A single breach exposes every identifiable image at once
  • Extortion leverage exists for as long as the files exist
Pipeline Approach

Identity Removed at Ingestion

  • Faces are irreversibly de-identified before footage is stored
  • Clinical and behavioral detail (positioning, treatment area, timing) is preserved for care and research use
  • A breach of the archive yields no identifiable images to leak
  • There is no face left to threaten a patient with

How Streamingo Fits Into the Pipeline#

This is exactly the problem we've been building toward at Streamingo Anonymize, our GDPR-compliant video redaction module: automated de-identification built into surgical and clinical video pipelines, stripping identity at the edge — before footage ever sits exposed on a server waiting to be exfiltrated.

In practice, that means facial de-identification happens as part of ingestion, not as a separate project bolted on after a near-miss or an actual breach. Treatment documentation, surgical recordings, and radiation oncology imaging can still support clinical review, quality audits, and research — the behavioral and procedural detail stays fully intact — but the one data point that turns a stolen file into extortion leverage is never stored in the first place.

✓ What Changes

If identity is removed before the file ever touches long-term storage, a network breach can still be a security incident — but it stops being a patient-privacy catastrophe. There's no face left on the leak site, no name to pair with a diagnosis, and no settlement-sized number waiting at the end of the lawsuit.

The Question for Your Team#

LVHN's leadership has said patient and staff privacy remain a top priority and that its defenses have been enhanced since the attack. That's the right response after the fact. The harder question is the one every healthcare security team should be asking before the fact:

🔍 Ask Your Team This Week

Is de-identification part of your clinical video and imaging pipeline today — built in at the point of capture or ingestion — or is it still an afterthought applied only after something has already gone wrong?

The file was never really the asset worth stealing. The identity attached to it was. Once a security team internalizes that distinction, the roadmap for where to invest — encryption, access control, or identity removal at the edge — starts to look very different.

Frequently Asked Questions#

How much did Lehigh Valley Health Network pay in its ransomware settlement?

LVHN agreed to a $65 million class-action settlement in September 2024, covering roughly 135,000 affected patients and employees. A Pennsylvania judge granted final approval on November 15, 2024. Payouts were tiered — about $50 for people whose records were merely accessed, $70,000–$80,000 for the 600+ people whose nude images were posted online, and $125,000 for lead plaintiff "Jane Doe."

What happened in the Lehigh Valley Health Network data breach?

In February 2023, BlackCat (ALPHV) breached the network supporting a Lackawanna County physician practice within LVHN, stealing about 132 GB of data, including radiation oncology treatment images. LVHN refused to pay the ransom demand, reported at over $5 million, so BlackCat published nude images of breast cancer patients on its dark web leak site alongside patient names and diagnoses.

Why didn't refusing to pay the ransom prevent the leak?

Refusing to pay doesn't undo an exfiltration that already happened. Once BlackCat had copied the files off LVHN's network, the identity-linked images existed outside LVHN's control regardless of ransom payment. Not paying avoided funding the criminal group, but it didn't remove the leverage attackers already held.

What is video or photo de-identification in healthcare?

De-identification is the process of irreversibly removing a patient's identifying features — most importantly the face — from clinical images or video before that footage is stored or shared, while preserving the clinical or procedural detail needed for care, quality review, or research. Applied at ingestion, a later breach of the archive yields no identifiable images to leak.

How can healthcare organizations reduce ransomware leverage from patient photos and video?

Encryption and access controls protect files from unauthorized reads, but neither removes leverage once an attacker exfiltrates a copy. Treating de-identification as a workflow requirement — stripping identity from clinical images and video at capture or ingestion, rather than as a manual step applied after the fact — means a network breach can still be a security incident without becoming a patient-privacy catastrophe.

📚 Sources
  1. Saltz Mongeluzzi Bendesky P.C. / The Washington Post (Daniel Gilbert), "Health System to Pay $65 Million After Hackers Leaked Nude Patient Photos," Sept. 22, 2024.
  2. ClassAction.org, "Class Action Claims Lehigh Valley Health Network Lost Control of Patient Data," April 2023; Campus Safety Magazine, "Lehigh Valley Health Network to Pay $65 Million," Sept. 26, 2024.
  3. WHYY, "Pa. judge finalizes $65M settlement in Lehigh Valley Health Network data breach lawsuit," Nov. 15, 2024.
  4. The HIPAA Journal, "Lehigh Valley Health Network Data Breach Lawsuit Settled for $65 Million."
  5. Fierce Healthcare, "Lehigh Valley Health Network agrees to $65M settlement over ransomware attack that leaked nude photos."

Facts in this piece — dates, dollar figures, patient counts, and quotes — have been cross-checked against the sources above. Analysis and commentary (the "identity vs. footage" framing) are Streamingo's own.