Open data breach settlements you can still claim
18 breach settlements are taking claims right now. Each one below was read off the claim site the court authorized — the deadline, who qualifies, and what a valid claim actually pays.
As of September 19, 2026, 18 US data breach settlements are still accepting claims, and the next one to close is 700Credit on September 22, 2026. You file free, on the settlement administrator’s own site, without a lawyer. Most funds pay for documented losses, add a flat cash payment for people with nothing to document, and include a period of credit monitoring.
Taking claims now
700Credit
$17.5M fundA break-in at 700Dealer.com, the web application car dealerships use to run credit checks, detected on or about 25 October 2025.
People who got a notice by email or postcard in July or August 2026. Most never dealt with 700Credit directly — it ran the credit application at the dealership. Names, dates of birth and Social Security numbers were in the files.
- Up to $2,500 for documented ordinary losses
- Or a $50 alternative cash payment, adjusted pro rata by how many people file
- Credit monitoring, activated with the code on your notice — available even if you file nothing
Exclusion deadline September 8, 2026 — already passed, so filing a claim is the remaining option.
Central Maine Healthcare
$1.37M fundUnauthorised access to files at the Lewiston hospital group and Central Maine Medical Center, running from roughly March to June 2025.
People in the US who were sent an individual notice that their private information was involved — names together with health details or other non-public personal information. Notices went out on 10 August 2026, so the letter is recent enough to still be in the pile on the counter.
- Up to $5,000 for documented losses traceable to the incident
- Or an alternative cash payment estimated at $50, adjusted pro rata
- One year of medical-records monitoring, on top of whichever cash payment you claim
Exclusion deadline September 13, 2026 — already passed, so filing a claim is the remaining option.
University of St. Thomas
An intrusion into the Houston university’s network between 25 July and 12 August 2025.
People in the US who were mailed a notice letter by the university — students, staff and donors alike. The files ran unusually wide: card and bank account numbers, Social Security numbers, passports and licences, logins and passwords for work accounts, home addresses, phone numbers and donor records.
- Up to $500 for documented ordinary losses, and up to $4,500 for extraordinary ones
- Up to $100 more for losses tied to sensitive personal information
- Three years of single-bureau credit monitoring and identity-theft protection
- Or, instead of the loss and monitoring claims, a flat $50 alternative cash payment
Exclusion deadline August 28, 2026 — already passed, so filing a claim is the remaining option.
Healthcare Services Group
$3M fundA cybersecurity incident on or around 27 September 2024 at the company that runs dining and housekeeping inside long-term care facilities.
Living people in the US who were sent a notice by HCSG, or were otherwise identified as affected. This one is mostly staff rather than patients: the files held names, Social Security numbers, driver’s licence and state ID numbers, financial account details, full account credentials, and medical and health-insurance information.
- Up to $5,000 for documented monetary loss
- A pro rata cash payment, sized by how many people file
- Three years of credit monitoring
Exclusion deadline September 4, 2026 — already passed, so filing a claim is the remaining option.
Total Vision
$0.47M fundA data security incident at the California eye-care group on 30 October 2020.
California residents who were mailed a notice by Total Vision about the October 2020 incident. The class is drawn from the company’s own mailing list, so no notice means no claim here.
- A pro rata cash payment, sized by how many people file
- Up to $1,000 more for documented out-of-pocket losses — that part has to be posted with the paperwork, it cannot be filed on the site
Exclusion deadline September 4, 2026 — already passed, so filing a claim is the remaining option.
Ernst & Young / Bank of America (MOVEit)
$2.5M fundThe MOVEit file-transfer attack of 27–31 May 2023, which reached Bank of America customer data that Ernst & Young was handling.
Living people in the US whose personal information sat in the files EY held for Bank of America. The notice came from EY rather than the bank, which is why a lot of people binned it as junk. This settlement covers EY and Bank of America only — the case against the MOVEit software maker carries on.
- Up to $2,500 for documented ordinary losses, and up to $10,000 for extraordinary ones
- Or a flat $100 cash payment with nothing to document
- Two years of identity-theft protection, claimable either way
Exclusion deadline September 8, 2026 — already passed, so filing a claim is the remaining option.
Globe Life / American Income Life
$3.4M fundA data incident at the insurers on or about 2 October 2024.
Current and former customers who were sent a letter saying their information may have been exposed. Names, addresses, phone numbers, Social Security numbers and health and policy information were in the files.
- Up to $5,000 for documented losses
- Up to four hours of lost time at $18 an hour
- Two years of credit monitoring for everyone in the class, claim form or not
Exclusion deadline November 16, 2026 — the last day to keep your own right to sue.
Lands’ End
A targeted attack on part of the retailer’s computer systems in December 2024.
People identified in Lands’ End’s own records as affected — many were told directly at the time. The files could hold names, dates of birth, Social Security numbers, driver’s licence or passport details, and in a few cases medical information.
- Up to $5,000 for documented losses incurred between 6 December 2024 and 22 October 2026
- Or a flat $60 cash payment with nothing to document
- Two years of CyEx Financial Shield Complete, claimed with the code mailed to you
Exclusion deadline October 7, 2026 — the last day to keep your own right to sue.
Palomar Health Medical Group (Arch Health Partners)
$3.1M fundSomeone reached the medical group’s systems between 23 April and 5 May 2024.
People in the US whose information was caught up in the 2024 incident at the San Diego County medical group. The files held names, addresses, dates of birth, medical history, health-savings-account details and payment card information.
- Up to $5,000 for documented losses
- Or a cash payment estimated at $60 instead
- Two years of credit monitoring on top of either one
Exclusion deadline October 7, 2026 — the last day to keep your own right to sue.
Americold
$5.25M fundTwo separate incidents at the cold-storage and logistics company, one on or about 16 November 2020 and one on or about 26 April 2023.
People in the US whom Americold notified that their information was in either incident. The class is current and former employees and job applicants, and the files held both personal and health information.
- Up to $25,000 for documented, unreimbursed losses
- A residual cash payment estimated at $100 if you were notified of one incident, or $200 if you were notified of both
- Three years of credit monitoring on top of whichever cash payment you choose
Exclusion deadline September 22, 2026 — the last day to keep your own right to sue.
Equinox, Inc.
$0.69M fundSomeone outside the organisation reached its files on or about 29 April 2024.
People in the US who were sent a notice by Equinox, Inc., the Albany human-services provider — not the gym chain that shares the name. The files held names, addresses, dates of birth, Social Security numbers, driver’s licence numbers, health-insurance and treatment details, medication information and patient IDs.
- Up to $5,000 for documented losses
- A pro rata cash payment estimated at $100, on its own or on top of the losses claim
- Three years of one-bureau credit and dark-web monitoring, with $1M of identity-theft insurance
Exclusion deadline September 23, 2026 — the last day to keep your own right to sue.
ConnectOnCall (Phreesia)
$4.95M fundAn intruder sat in the after-hours on-call answering platform between 16 February and 12 May 2024 and copied provider-patient messages.
Anyone living in the US whose details may have been in the incident. Most people in this class never heard of ConnectOnCall — it is the service that answers the phone when you call your doctor’s office out of hours, so what leaked is the substance of those calls.
- Up to $5,000 for documented losses
- Or a flat alternate payment of up to $75
- Two years of dark-web and medical-data monitoring, with $1M of medical identity-theft insurance
Exclusion deadline October 19, 2026 — the last day to keep your own right to sue.
Modernizing Medicine (ModMed)
$3M fundA targeted attack on two servers the health-records company used to migrate data off retiring platforms, found in July 2025.
People in the US who were sent notice of the incident. ModMed sells software to medical practices rather than to patients, so the records came from the practice you visited: names, dates of birth, Social Security numbers, insurance details, diagnoses, prescriptions and billing codes.
- Up to $5,000 for documented losses
- Or an alternate cash payment estimated at $75
- Two years of medical-data monitoring with $1M of medical identity-theft insurance
Exclusion deadline October 19, 2026 — the last day to keep your own right to sue.
Summit Medical Group (Tennessee)
A targeted attack on the practice’s systems in September 2024.
People who were sent a notice by the Knoxville-area practice. Names, contact details, medical records and Social Security numbers were among the files reached.
- Up to $2,500 for documented losses
- Up to three hours of lost time at $15 an hour
- Two years of medical-data monitoring
- Payments shrink pro rata if valid claims pass $500,000
Exclusion deadline October 20, 2026 — the last day to keep your own right to sue.
YES Communities
Someone was inside the manufactured-housing operator’s network between 9 and 11 December 2024.
People in the US and its territories who were sent notice that their information was in the incident — residents and applicants at the company’s communities, and staff.
- Up to $2,500 for documented losses
- Up to four hours of lost time at $20 an hour, so $80
- Or a flat $50 alternate cash payment
- Three years of single-bureau credit monitoring through IDX
Exclusion deadline October 21, 2026 — the last day to keep your own right to sue.
SitusAMC
$5.3M fundA break-in at the mortgage-services firm, discovered on or about 12 November 2025.
People in the US who were sent notice of the incident. Almost nobody in this class dealt with SitusAMC directly — it works behind the lenders and servicers. Names, dates of birth, Social Security or taxpayer ID numbers, driver’s licence and state ID numbers, financial account numbers, medical records and health-insurance policy numbers were in the files.
- Up to $5,000 for documented losses, with third-party proof
- Or a flat cash payment estimated at $75
- $50 more for California residents
- One year of credit monitoring
Exclusion deadline October 22, 2026 — the last day to keep your own right to sue.
California Casualty
A targeted attack on the insurer’s systems in September 2025 reached files holding customer records.
Living US residents whose information was in the September 2025 breach, including everyone who was sent a notice. What the files could hold runs long: names, Social Security numbers, driver’s licence or state ID numbers, passport numbers, dates of birth, medical and health-insurance details, and account or card numbers.
- Up to $4,000 for documented out-of-pocket losses
- Or a flat $50 cash payment with nothing to prove
- Two years of credit monitoring with $1M of fraud insurance
Exclusion deadline November 4, 2026 — the last day to keep your own right to sue.
Steel Warehouse
A targeted attack on the steel processor’s systems in January 2025.
People on the class list the company gave the court — mostly current and former employees. The files held Social Security numbers, driver’s licence and government ID numbers, dates of birth and financial account details.
- Up to $5,000 for documented losses
- Up to three hours of lost time at $20 an hour
- Or a flat $40 alternate cash payment
- One year of credit monitoring with $1M of fraud insurance
Exclusion deadline October 2, 2026 — the last day to keep your own right to sue.
General information, not legal advice. Caps, class definitions and dates come from the administrator’s site and can change by court order — the notice and that site govern. We are not affiliated with any settlement, take no cut of any payout, and link only to court-authorized claim sites.
Announced — claims not open yet
A judge has signed off on these in principle, but the administrator has not opened a claim site, so nobody can file yet. A page that offers you a claim form for one of them today is not the real one. We move each settlement up into the list above, with its deadline, once the official site is live.
DaVita
$15M settlement· claims not open yetA ransomware attack on the dialysis provider found on 12 April 2025. Names, addresses, Social Security numbers, health insurance details and clinical information were taken, and about 2.7 million people were notified.
A federal court in Colorado gave the settlement preliminary approval on 21 August 2026 (Jenkins v. DaVita Inc.). The administrator has not opened a claim site yet, so there is no form and no deadline, and the final approval hearing is expected in 2027.
- Up to $2,500 for documented out-of-pocket losses
- A pro rata cash payment, estimated in coverage of the filings at around $50
Reported by Healthcare Dive (September 2, 2026) and The HIPAA Journal (September 1, 2026). Checked September 19, 2026: no court-authorized claim site yet.
What to do after a medical data breach →Recently closed
The claim window has shut on these. They stay listed because people keep searching for them, and because the steps that still help after a missed deadline are the same ones as before it.
American Consumer Credit Counseling
A criminal third party got into employee email accounts at the credit counselling agency, found in January 2025.
People in the US whose personal information was potentially caught in the January 2025 incident, including everyone sent a notice. Names, Social Security numbers, driver’s licence numbers, financial account numbers and payment card details were in the mailboxes that were reached.
- Up to $3,500 for documented losses
- Plus up to four hours of lost time at $20 an hour
- Or a flat $45 payment with nothing to prove
- Three years of credit monitoring with $1M of fraud insurance
Comcast (Xfinity)
$117.5M fundThe October 2023 attack on Xfinity, with notices going out around 18 December 2023.
Xfinity customers who were told their personal information was involved — including people who have since cancelled the service.
- Reimbursement for documented out-of-pocket losses and for time you lost dealing with it
- Or an alternative cash payment with nothing to document
- Identity-defence and restoration services through an enrolment code
Payactiv
A data incident at the earned-wage-access provider in April 2025.
People whose information was compromised in the April 2025 incident. The exposed fields included names, dates of birth, financial account numbers and Social Security numbers.
- Reimbursement for documented out-of-pocket losses — the claim form states the cap
- A cash payment and credit monitoring
STIIIZY
$2.95M fundA breach at the cannabis retailer in October 2024, disclosed on 7 January 2025.
People whose personal information may have been taken in the incident STIIIZY announced in January 2025 — the ID-scan data collected at checkout makes this one worth reading closely.
- Up to $7,500 for documented losses
- A pro rata cash payment, with double shares for California class members
- Two years of three-bureau credit monitoring with $1,000,000 of identity-theft insurance
Labcorp (AMCA breach)
$35M fundThe break-in at American Medical Collection Agency, the billing vendor Labcorp used, running from roughly 1 August 2018 to 30 March 2019.
People in the US whose personal or health information Labcorp had passed to AMCA and that sat in the systems caught up in the breach. In practice: anyone who had diagnostic testing done, most of whom had never heard of AMCA.
- Up to $5,000 for documented out-of-pocket losses
- Or an alternative cash payment estimated at $50, adjusted pro rata
- Two years of CyEx Medical Shield Pro medical-information monitoring
Circle K (Gas Express)
A targeted cyberattack in May 2024 on Gas Express, the company operating the Circle K stores in question.
People in the US who were sent a notice about the May 2024 incident; names and Social Security numbers were in the files. This is the Gas Express operator rather than Circle K nationwide, so no notice means no claim.
- Up to $2,000 for documented losses — but only until the $45,000 set aside for them runs out
- Or a flat $50 cash payment, capped at 700 claims across the whole class
- Two years of CyEx Financial Shield Complete with $1M of fraud insurance
ZOLL Medical
$3.5M fundA breach of the cardiac-device maker’s network between 22 and 24 January 2023.
US residents who got a notice from ZOLL about the January 2023 incident. The class splits in two: people whose Social Security number was involved, and people whose was not.
- Up to $5,000 per person for documented out-of-pocket losses
- A pro rata cash payment, doubled if your Social Security number was involved
Flagstar Bank
$31.5M fundTwo breaches at the bank, one in January 2021 and one in December 2021.
About 2.19 million people in the US whose information was in either incident, including roughly 364,000 California residents.
- Up to $25,000 for documented losses
- A residual cash payment estimated around $60 (capped at $599)
- Three years of three-bureau credit monitoring
- Up to $100 more for California residents
Onsite Mammography (Onsite Women’s Health)
An employee email account was accessed by someone outside the company in October 2024.
People in the US whose private information was caught up in the October 2024 incident, whether or not a notice reached them.
- Up to $5,000 for documented out-of-pocket losses, plus a pro rata cash payment
- Or credit monitoring together with medical-data monitoring instead of the cash
Fidelity Investments
$2.5M fundAn August 2024 incident in which two customer accounts were used to pull files on other customers.
The 77,099 people Fidelity notified. Names, Social Security numbers, financial account details and driver’s licence numbers were in the files.
- $100 cash, with another $50 for California residents
- Up to $5,000 for documented losses
- Two years of credit monitoring and identity protection
Before you fill in a claim form
Work out which route you are taking first, because most forms make you pick. The documented-loss route needs paperwork — a statement showing the fraudulent charge, the bank letter, the credit-repair invoice — and pays properly. The flat cash option needs nothing and pays what is left after everyone else has filed. Claiming for time spent is normally self-attested at a set hourly rate, signed under penalty of perjury, so describe honestly what you actually did. Our guide to claiming a breach settlement walks through the whole process, including opting out.
The fake claim sites arrive first
Big settlements draw copies within days, and they are built around what the breach already leaked: the page knows the company, sometimes your name, and asks for the Social Security number or bank details to “verify” you. A genuine administrator wants your contact details, usually the ID from your notice, and at most the last four digits of an SSN. Nobody charges you to file. If a text or email pushes you to a claim page, close it and go to the address printed in the notice instead — the same reflex as checking a breach letter is real.
Most people qualify for more than one
Settlements only cover breaches you know about. PersProtect shows which known breaches hold your email, then finds and removes your profile across 499 broker and people-search sites — the exposure a payout never touches. Free scan, about a minute.
Check which breaches involve me →Filing a settlement claim, answered
How do I know a settlement claim site is the real one?
Every settlement has one website set up by the administrator the court appointed, and the address is printed in the notice and in the court filings. That site never asks for a payment, a full Social Security number, a card number or a banking login. Anything that arrives by text or unsolicited email offering to "release" your award is a copy built to harvest exactly what the breach exposed. Type the address in yourself instead of tapping the link.
I never received a notice. Can I still file?
Usually yes. Notices go to whatever address the company had on file, which is often years out of date, so most administrators let you file without a class-member ID by confirming your details and attesting that you were affected. Claims do get checked against the class list, so filing on a breach you were not part of goes nowhere.
What if the deadline has already passed?
Then that fund is closed to you, and no lawyer or service can reopen it. What is still worth doing is the part a payout never covered: freeze your credit at all three bureaus, kill any password you reused, and check which other breaches hold your details, because most people who qualified for one settlement qualify for another they have not heard about yet.
How long until the money arrives?
Longer than anyone expects. After the claim deadline comes the final approval hearing, then an appeal window, then the administrator works out how far the fund stretches across valid claims. A year between filing and a payment is ordinary, and the amounts get trimmed pro rata when more people file than the estimate assumed.
Does filing a claim stop me suing the company?
Yes, and that is the trade. Filing keeps you in the class and releases your right to sue over that incident. Opting out by the exclusion deadline keeps that right and gives up the fund, which only makes sense with substantial documented losses and legal advice. Doing nothing is the worst of both: the release still binds you and you get nothing.
Why are there so few settlements on this list?
Because we only list ones we have checked on the administrator’s own site this month. Aggregator lists run to dozens of entries, many of them expired, mislabelled, or repeating a claim deadline that moved. A short list you can trust beats a long one you have to re-verify.
A cheque closes the case. It does not close the exposure.
See which breaches hold your data and where your details are still listed for sale — free, in about a minute.
Run my free exposure scan →