James J. Pizzirusso
Data Breach · Privacy · Consumer Protection · Class Actions
“It’s about getting money in the hands of consumers and deterring this kind of conduct in the future.
The Parts of a Breach Remedy
James J. Pizzirusso approaches data-breach settlements as linked problems of reimbursement, identity protection, claims administration, and security changes that continue after the case ends.
The Costs Arrive in Different Places
A data breach can leave one person disputing a fraudulent account, another replacing identification, and a bank issuing new cards. James J. Pizzirusso’s docket follows those losses to the people and institutions that bear them. The remedies in his T-Mobile, Equifax, Premera, and Target matters have included cash funds, identity-protection services, claims for documented losses, and commitments to change data-security practices. Each component addresses a different part of the same event.
Pizzirusso is a partner and co-founder of Hausfeld in Washington, D.C., and a member of the firm’s Management Committee. He has led its Data Breach/Privacy and Consumer Protection practice groups since the firm’s inception. He earned his J.D., with honors, from George Washington University Law School in 2001 and his B.A., summa cum laude, from the University of Tennessee, Knoxville, in 1998.
T-Mobile: Cash, Services, Security
The federal court overseeing the T-Mobile customer data-security litigation appointed Pizzirusso as one of three co-lead interim class counsel. The litigation followed a 2021 breach in which hackers obtained personal information belonging to an estimated 76.6 million people. The settlement created a $350 million fund. Class members could seek as much as $25,000 for documented losses, including time spent addressing problems tied to the breach; people who did not document a loss could claim a smaller cash payment.
The settlement also offered two years of identity-defense and monitoring services and two years of restoration services. Separately, T-Mobile committed to spend an additional $150 million over two years on data-security improvements. The court granted final approval in June 2023. Keeping the $350 million fund distinct from the $150 million security commitment shows how the resolution divided compensation, individual support, and system changes into separate forms of relief.
PowerSchool Before the Remedy
The PowerSchool litigation is at an earlier stage. The breach of the company’s Student Information System exposed data associated with roughly 62 million students and nearly 10 million educators and staff in the United States and Canada, including names, contact information, dates of birth, Social Security numbers, grades, and medical details. In June 2025, the court appointed Pizzirusso co-lead counsel for individual-action plaintiffs in the centralized multidistrict litigation.
On April 1, 2026, the court denied defendants’ motions to dismiss, including a motion by private-equity firm Bain Capital. The ruling allowed negligence, unjust-enrichment, and California unfair-competition claims to proceed on allegations that Bain exercised operational control over PowerSchool and made decisions affecting cybersecurity operations. No settlement has yet fixed the form of any remedy; the case remains in litigation.
Equifax and the Life of a Claim
Pizzirusso served on the plaintiffs’ steering and settlement committees in the Equifax data-breach litigation. Equifax reported that the 2017 breach exposed personal information belonging to 147 million people. The global settlement included up to $425 million to help those affected, with benefits addressing out-of-pocket losses, time spent responding to the breach, credit monitoring, and identity restoration.
Some consequences do not surface during the original claims period. Under the settlement, an affected person who later discovers misuse of personal information can receive identity-restoration assistance through January 2029, even without having filed an earlier claim for other benefits. That continuing service treats exposure as a risk that can mature after litigation ends and the first payments go out.
Patients, Banks, and the Same Breach
In the Premera Blue Cross litigation, Pizzirusso served on the plaintiffs’ Executive Leadership Committee. The settlement combined a $32 million fund with $42 million that Premera agreed to spend on improved data security from 2019 through 2022. The fund supported credit monitoring, claims for documented losses, and cash benefits; the separate security spending addressed systems that retained sensitive information after the breach.
The Target litigation placed Pizzirusso on a steering committee representing financial institutions rather than individual shoppers. Banks and credit unions claimed the breach forced them to replace cards and absorb fraud losses. The court recorded nearly $60 million in total class benefit, and the settlement required data-security changes at Target. The matter put the downstream cost of a retail breach into the same remedial frame as consumer identity loss.
A Consumer Practice Built for Systems
Pizzirusso’s consumer work predates the modern data-breach docket. In 2010, while discussing a proposed consumer settlement over Tyson Foods’ “Raised Without Antibiotics” advertising, he described the purpose in direct terms: “It’s about getting money in the hands of consumers and deterring this kind of conduct in the future.” The same two objectives—compensation and changed conduct—appear in the breach resolutions that followed.
His work outside individual cases includes co-authoring the LexisNexis treatise Data Breach Litigation. He has taught environmental and toxic torts as an adjunct professor and clinical law as a visiting associate professor at George Washington University Law School, and he served on the steering committee of The Sedona Conference’s Data Security and Privacy Liability Working Group from 2020 through 2023. Across those roles, the recurring question is practical: how to convert a technical failure spread across many people and institutions into relief they can use.