Yes, Rite Aid customers affected by a 2024 data breach can file claims against the pharmacy chain through an active class action settlement. The settlement, valued at $6.8 million in the case *Margaret Bianucci v. Rite Aid Corporation*, covers approximately 2.2 million people whose personal information—including names, addresses, dates of birth, and government ID numbers—was compromised by an unauthorized third party between June 2017 and July 2018.
The deadline to submit claims has passed (July 7, 2025), but the settlement is now in its distribution phase, with eligible claimants who filed timely claims expected to receive payments based on their documented losses. The data breach and settlement represent one of several legal actions against Rite Aid in recent years. While the pharmacy chain also settled a separate $7.5 million federal case related to improper opioid dispensing, the data breach settlement is the primary action affecting individual consumers seeking compensation. Understanding which lawsuit applies, what evidence you need, and where your claim stands requires knowing the specific dates involved and the settlement administrator’s process.
Table of Contents
- What Exactly Happened in the Rite Aid Data Breach?
- How Much Money Can I Receive From This Settlement?
- How Do I File a Claim and What’s the Deadline?
- What Is the Current Status of Settlement Payments?
- What Personal Information Was Exposed, and How Much Risk Do I Face?
- Is There a Separate Opioid Dispensing Settlement?
- How Does Rite Aid’s Bankruptcy Filing Affect This Settlement?
What Exactly Happened in the Rite Aid Data Breach?
On June 6-7, 2024, rite Aid discovered that an unknown third party had gained unauthorized access to customer information by impersonating a company employee. The pharmacy chain identified the intrusion within 12 hours of discovery, but the breach itself exposed data from customers who had made purchases during a specific five-year window: June 6, 2017, through July 30, 2018. This means a customer who shopped at Rite Aid in March 2017 or September 2018 would not be eligible for this particular settlement, even if they received a breach notification letter.
The compromised data included names, home addresses, dates of birth, driver’s license numbers, and other government-issued identification information. The pharmacy did not publicly disclose evidence that Social Security numbers, payment card data, or prescription information was accessed, though the exposure of ID numbers alone created significant identity theft risk for affected customers. The breach was not the result of malware, ransomware, or a system misconfiguration—it was a targeted social engineering attack where the attacker successfully assumed a Rite Aid employee’s identity to access systems.
How Much Money Can I Receive From This Settlement?
The total settlement pool is $6.8 million, but individual payouts depend on how much money remains after administrative costs, settlement notices, and attorney fees are paid out. The settlement allows class members to claim up to $10,000 for documented, unreimbursed expenses directly caused by the data breach. These expenses could include credit monitoring services, identity theft recovery costs, time spent disputing fraudulent charges or credit reports, or out-of-pocket losses from identity theft. However, a major limitation applies: you must have actual documentation of these expenses.
Rite Aid is not paying a flat per-person amount to everyone who received a notification letter; instead, claimants must submit receipts, invoices, credit reports, or other proof of harm. For example, if you paid $199 for a year of credit monitoring after learning about the breach, you would submit the receipt. If you spent 20 hours disputing fraudulent charges on your credit card, the settlement does not compensate for time alone—you would need to document actual out-of-pocket costs. The settlement also offers an alternative: class members who do not submit specific expense claims can elect to receive a pro-rata share of the remaining settlement funds after all claims are paid, though this amount is typically smaller than a documented-expense claim.
How Do I File a Claim and What’s the Deadline?
The claim filing deadline was July 7, 2025—this date has passed as of July 2026. If you did not submit a claim by that date, you are barred from recovering individual compensation through this settlement, even if you were eligible. This is a hard deadline enforced by the court; there are no extensions, and missing it means losing your right to claim. The settlement administrator, reachable at 833-421-7672 or through www.RiteAidDataSettlement.com, can confirm whether a claim was received on time, but they cannot extend or revive expired claims.
Claimants who filed before the July 2025 deadline submitted documentation through the settlement administrator’s website or by mail. The typical process required uploading or mailing copies of receipts for out-of-pocket expenses, filling out a claim form with personal details to match against the breach list, and signing under penalty of perjury. Some claimants submitted claims for credit monitoring ($199–$300 per year), others for credit report disputes or identity theft recovery services, and a smaller number documented actual fraudulent charges or medical identity theft costs. The settlement administrator cross-referenced claimant information against the original breach data to verify eligibility before approving payouts.
What Is the Current Status of Settlement Payments?
As of July 2026, the settlement has completed its claims review period and is in the distribution phase. Eligible claimants who submitted timely claims with approved expenses were expected to receive payments in late 2025, though the actual distribution timeline depends on how many claims were approved and their amounts. If claim totals exceeded the $6.8 million settlement pool, each approved claim would be reduced proportionally; if claims fell short, the remaining funds would be distributed to claimants who elected the pro-rata alternative benefit.
The settlement does not require claimants to do anything further at this stage if their claims were already approved. However, if you filed a claim and have not yet received payment, contacting the settlement administrator at 833-421-7672 is the appropriate next step to check the status of your individual claim. The website www.RiteAidDataSettlement.com also provides updates on settlement progress and payment schedules. Payments may still be processing or may have been issued; if a check has been lost or you moved after filing, the administrator can reissue payment to a current address.
What Personal Information Was Exposed, and How Much Risk Do I Face?
The data exposed in this breach—names, addresses, dates of birth, and government-issued ID numbers like driver’s license numbers—is precisely what identity thieves need to commit fraud. An attacker with this combination can apply for credit cards, take out loans, file fraudulent tax returns, or create a synthetic identity. The fact that the breach window spanned five years (June 2017 to July 2018) means affected individuals should monitor their credit reports and accounts even years later, as identity thieves sometimes delay using stolen information.
Rite Aid did not disclose Social Security numbers in this breach, which significantly limits (though does not eliminate) the risk of serious financial identity theft. However, if an attacker combined the Rite Aid data with a Social Security number from another source, the risk escalates substantially. The pharmacy’s response—discovering the breach within 12 hours and notifying affected customers—represents faster incident detection than many breaches (some go undetected for months or years), but the damage was already done. Anyone affected by this breach should have enrolled in the free credit monitoring offered by Rite Aid and should continue monitoring credit reports annually or use a free service like AnnualCreditReport.com.
Is There a Separate Opioid Dispensing Settlement?
Rite Aid also settled a separate federal lawsuit related to improper opioid dispensing practices. In that case, the pharmacy agreed to pay $7.5 million to the U.S. Department of Justice to resolve allegations that Rite Aid pharmacists failed to investigate red flags related to opioid prescriptions and improperly submitted claims for government reimbursement under Medicare and Medicaid.
This settlement addressed violations of the False Claims Act and Controlled Substances Act, not data breaches. Unlike the data breach settlement, the opioid settlement does not provide individual consumer claims; instead, the money goes to the government. This settlement is fully resolved and does not affect individual consumers’ eligibility for the data breach settlement. A customer can be affected by both lawsuits independently—for example, if they shopped at Rite Aid during the June 2017 to July 2018 window, they may have been part of the data breach settlement; separately, they may have received opioid prescriptions filled by a Rite Aid pharmacist whose practices violated the opioid settlement terms, but that second issue does not entitle them to additional individual recovery.
How Does Rite Aid’s Bankruptcy Filing Affect This Settlement?
Rite Aid filed for Chapter 11 bankruptcy in 2023 as the pharmacy chain struggled with debt and competitive pressure from larger retailers and online pharmacies. On December 30, 2025, the bankruptcy court closed cases for 117 affiliated Rite Aid debtors, with limited exceptions. The data breach settlement, however, is not affected by the bankruptcy; it is a separate class action settled in federal court and is proceeding independently.
Bankruptcy proceedings address the company’s ability to pay debts to creditors, but consumer class action settlements for wrongdoing (like data breaches) are typically prioritized and protected under bankruptcy law. The closure of Rite Aid’s bankruptcy cases in late 2025 actually clarified the company’s post-restructuring status and removed uncertainty that could have delayed settlement payments. Claimants in the data breach settlement should not experience delayed or reduced payments because of the bankruptcy; the $6.8 million settlement amount was negotiated and funded specifically for this class action. If you have concerns about whether your claim will be paid due to the bankruptcy, the settlement administrator at 833-421-7672 can confirm that the settlement funds remain intact and separate from Rite Aid’s bankruptcy resolution.
- —
