Liberty Hospital in Missouri agreed to pay $1.5 million to resolve a class action lawsuit stemming from a 2023 data breach that exposed the protected health information of 264,541 people. The settlement compensates individuals whose medical records, insurance information, social security numbers, and other sensitive health data were accessed during the breach. Class members can receive up to $500 per person for documented, unreimbursed losses related to the breach, or opt for an alternative cash payment of approximately $150 per class member.
This settlement represents one of the largest healthcare data breach class actions in recent years. In addition to the cash compensation, Liberty Hospital committed to investing over $1 million in cybersecurity enhancements to prevent future incidents. The settlement received preliminary court approval and is moving toward final approval, with a deadline of January 12, 2026 for class members to submit claims or file objections.
Table of Contents
- What Happened in the Liberty Hospital Data Breach?
- How Much Money Is Available and How Do Claims Work?
- Who Qualifies as a Class Member?
- How Do You Submit a Claim?
- What Are the Key Limitations of This Settlement?
- Liberty Hospital’s Cybersecurity Commitments
- Healthcare Data Breaches and Settlement Trends
What Happened in the Liberty Hospital Data Breach?
Liberty Hospital experienced a significant cybersecurity incident in 2023 that compromised the protected health information of more than 264,000 patients and individuals. The breach exposed sensitive data including names, dates of birth, medical record numbers, insurance information, and in many cases, social security numbers and financial account details. This information could be used for identity theft, fraudulent insurance claims, or other malicious purposes, putting affected individuals at substantial risk.
The scope of the breach—affecting nearly a quarter-million people—triggered mandatory notification requirements under federal HIPAA regulations and state data protection laws. healthcare organizations are required to notify individuals of breaches affecting more than 500 people and to notify major media outlets, which brings public attention and potential regulatory scrutiny. The breach led to the class action lawsuit that resulted in this settlement, demonstrating that hospitals can be held financially accountable when they fail to adequately protect patient data.

How Much Money Is Available and How Do Claims Work?
The $1.5 million settlement fund is divided among eligible class members, with individual compensation based on documentation of actual losses. Class members who can document unreimbursed expenses caused by the breach—such as credit monitoring services, identity theft recovery costs, or financial losses from fraudulent accounts opened in their names—can claim up to $500 per person. Those who cannot provide documentation or prefer a simpler process can accept an alternative cash payment of approximately $150 per class member.
The claims process requires submitting proof of losses to receive the maximum $500 payment, which is a significant limitation for people who did not experience direct financial harm from the breach or who cannot locate receipts from services used in response. Most people who simply want compensation without documentation will likely receive the $150 option, which provides immediate payment without the burden of proof. The actual per-person amount may vary depending on how many class members submit claims, as the settlement fund is fixed at $1.5 million and must be divided among all approved claims.
Who Qualifies as a Class Member?
You are a class member if your personal health information was accessed in the Liberty Hospital 2023 data breach and you received a breach notification letter from the hospital. The class includes current and former patients whose records were stored in Liberty Hospital’s systems, regardless of whether they actively sought treatment at the hospital or had only minimal contact with the organization. This broad definition ensures that even individuals with just one medical visit are included in the settlement.
To receive compensation, you must submit a claim form or settlement notice response by the January 12, 2026 deadline. If you received a data breach notification from Liberty Hospital about the 2023 incident, you are almost certainly part of the eligible class and can file a claim. Even individuals who do not submit claims will benefit indirectly from the settlement’s requirement that Liberty Hospital invest over $1 million in cybersecurity improvements, which will help protect current and future patients from similar breaches.

How Do You Submit a Claim?
To file a claim, you must complete a claim form available on the official settlement website at libertyhospitaldataincidentsettlement.com and submit it by January 12, 2026. If you are claiming the maximum $500 for documented losses, you will need to include supporting documentation such as receipts for credit monitoring services, medical reports related to identity theft recovery, bank statements showing fraudulent charges, or other evidence of out-of-pocket expenses directly caused by the breach. The alternative is simpler: you can skip documentation and accept the $150 cash payment without providing proof of losses.
This option is practical for people who experienced concern and disruption from the breach but did not incur quantifiable expenses, or who no longer have receipts from services purchased years ago. Claims submitted online typically receive faster processing than paper submissions, though the settlement website provides instructions for both methods. The court’s final approval hearing is scheduled for January 20, 2026, so claims submitted closer to the deadline may be processed more slowly.
What Are the Key Limitations of This Settlement?
One significant limitation is that the $1.5 million fund may be stretched thin across 264,541 eligible class members. If most people submit claims for the maximum $500, the fund could be insufficient, and per-person amounts would be reduced proportionally. This creates an incentive to claim losses early, as those who wait risk receiving less.
Additionally, the settlement requires proof of actual losses for the $500 payment, which excludes people who were worried about the breach but did not spend money on protective services. Another important consideration is that the settlement does not prevent Liberty Hospital from facing additional penalties or regulatory fines from HIPAA enforcement. The settlement compensates class members but does not necessarily resolve the hospital’s obligations to the Department of Health and Human Services. Also, while the hospital’s commitment to invest over $1 million in cybersecurity is positive, there is no guarantee that these investments will prevent future breaches, as new cybersecurity threats emerge constantly and no system is completely immune to sophisticated attacks.

Liberty Hospital’s Cybersecurity Commitments
As part of the settlement agreement, Liberty Hospital committed to investing over $1 million in cybersecurity enhancements. These improvements typically include upgrading encryption systems, implementing multi-factor authentication, enhancing network monitoring, conducting regular security audits, and providing employee cybersecurity training. For a hospital of Liberty Hospital’s size, this is a meaningful investment that reflects the seriousness of the breach and the court’s intent to use settlements as a mechanism to drive industry-wide security improvements.
The cybersecurity investment requirement is one of the most valuable aspects of this settlement because it addresses the root cause of the problem rather than simply compensating victims after the fact. Healthcare organizations often spend heavily on patient care and administrative systems but underinvest in cybersecurity until a breach forces them to do so. By requiring substantial cybersecurity investments as a condition of settlement, courts incentivize hospitals to proactively protect patient data and reduce the likelihood of future breaches affecting other patients.
Healthcare Data Breaches and Settlement Trends
Healthcare data breaches have become increasingly common, with hospitals and medical providers accounting for a significant portion of major data breaches in the United States. The Liberty Hospital settlement reflects a broader trend of courts holding healthcare organizations financially accountable for inadequate data protection. As healthcare systems continue to digitize patient records and adopt connected medical devices, the volume of sensitive health data at risk continues to grow, making cybersecurity a critical concern for the entire industry.
Future healthcare data breach settlements will likely include similar provisions requiring cybersecurity investments and compensation for affected individuals. The healthcare sector is increasingly targeted by cybercriminals because patient data is extremely valuable—a single medical record can sell for 10 to 50 times the price of a stolen credit card number on the dark web. As these settlements accumulate and become more expensive for healthcare organizations, they create financial incentives for hospitals to invest in security proactively rather than waiting for a breach to occur.
You Might Also Like
- Varsity Brands $1.1 Million Data Breach Class Action Settlement
- T-Mobile $350 Million Customer Data Breach Class Action Settlement
- PharMerica $5.275 Million Patient Data Breach Class Action Settlement
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase:
