Capital Health Data Breach Settlement: How Payments Are Calculated

Payments in the Capital Health data breach settlement are calculated through three distinct tiers drawn from a $4.5 million fund.

Payments in the Capital Health data breach settlement are calculated through three distinct tiers drawn from a $4.5 million fund. Class members who can document out-of-pocket losses tied to the breach may recover up to $5,000 in reimbursement. Those without documented expenses can instead claim an estimated flat cash payment of roughly $100, though that figure will shift up or down depending on how many people file. All eligible claimants can also receive three years of credit monitoring regardless of which cash option they select.

For someone who spent $200 on credit monitoring services and $50 on credit report fees after the breach, the documented losses route would yield a $250 reimbursement — far more than the flat payment alternative. The settlement resolves consolidated class action litigation in New Jersey stemming from a November 2023 ransomware attack by the LockBit group, which claimed to have stolen 7 terabytes of data from Capital Health’s systems. A total of 503,071 individuals were affected according to reports filed with the HHS Office for Civil Rights. The claim filing deadline is April 6, 2026, and the final fairness hearing is scheduled for July 14, 2026.

Table of Contents

How Are Capital Health Data Breach Settlement Payments Calculated for Each Claim Type?

The settlement splits compensation into two mutually exclusive cash options. The first is a documented losses reimbursement capped at $5,000 per person. This covers unreimbursed, out-of-pocket expenses that are directly traceable to the breach — things like identity theft remediation costs, unauthorized charges you were unable to reverse, bank fees triggered by fraudulent activity, credit report fees, credit monitoring purchases you made on your own, and identity theft insurance products. You must provide supporting documentation such as receipts, bank statements, or account statements for every dollar you claim. The settlement administrator will review the documentation and may reduce or deny claims that lack adequate proof. The second option is the alternative flat cash payment, estimated at approximately $100 per claimant. This is designed for people who were affected by the breach but either did not incur measurable out-of-pocket costs or cannot locate the documentation to prove them. The critical detail here is that the $100 figure is an estimate, not a guarantee.

It will be adjusted pro rata based on the total number of valid claims filed against the settlement fund. If relatively few people file, the per-person amount could increase. If hundreds of thousands of the 503,071 eligible individuals submit claims, the payment could shrink significantly. You cannot combine the two cash options — you pick one or the other when you file your claim. To put this in perspective, consider the math. The $4.5 million fund must cover documented losses claims, flat payments, credit monitoring costs, attorney fees, and administrative expenses. If even 10 percent of eligible individuals filed flat payment claims, that would be over 50,000 claimants competing for whatever portion of the fund remains after other costs. Settlement participation rates in data breach cases often run between 3 and 10 percent, but the actual payout per person depends entirely on the final numbers.

How Are Capital Health Data Breach Settlement Payments Calculated for Each Claim Type?

What Expenses Qualify as Documented Losses Under This Settlement?

The documented losses category is broader than many people assume, but it comes with strict proof requirements. Eligible expenses include costs you incurred specifically because of the Capital Health breach: fees paid to freeze or unfreeze your credit, charges for credit monitoring services you purchased after learning of the breach, costs associated with replacing compromised identification documents, bank fees resulting from unauthorized transactions, and time spent dealing with identity theft if it can be linked to this incident. If you paid for an identity theft insurance product following the breach notification, that cost qualifies too. However, there are important limitations. Expenses that were reimbursed by your bank, credit card company, or insurance provider do not count — the settlement only covers unreimbursed losses. If your bank reversed a fraudulent charge in full, you cannot claim that amount again here.

Similarly, if you were already paying for credit monitoring before the breach occurred, you cannot retroactively classify that existing subscription as a breach-related expense. The losses must have been incurred after the breach and because of the breach, not merely coincidental. If you experienced identity theft but cannot establish a plausible connection to the Capital Health incident — say, your information was also compromised in a separate, unrelated breach — the administrator may challenge your claim. Documentation is not optional. Claims submitted without receipts, billing statements, or bank records showing the charges will almost certainly be denied or reduced. If you have already discarded those records, check your email for digital receipts, log into your bank’s online portal for historical statements, or contact service providers for duplicate invoices. The time to gather this documentation is now, before the April 6, 2026 deadline.

Capital Health Settlement Payment Options ComparisonDocumented Losses (Max)$5000Flat Cash Payment (Est.)$100Credit Monitoring (Annual Value)$90Per-Person Fund Share (If All Filed)$8.9Total Settlement Fund (Millions)$4.5Source: Capital Health Data Breach Settlement Official Terms

Who Qualifies for the Capital Health Data Breach Settlement?

Eligibility is straightforward but narrowly defined. You qualify if you received a notice from Capital Health informing you that your personal information was potentially compromised during the cyberattack that occurred between November 11 and November 26, 2023. The affected group includes both patients and employees of Capital Health whose data was stored in the systems that the LockBit ransomware group accessed during that window. Capital Health reported the breach to federal regulators in January 2024, and notification letters were sent to impacted individuals afterward. If you did not receive a notification letter, that does not automatically disqualify you, but it makes your claim significantly harder to establish.

The settlement class is generally defined by the list Capital Health compiled and reported to the HHS Office for Civil Rights, which totaled 503,071 individuals. If you believe your data was compromised but you never received a notice — perhaps because you moved and the letter went to an old address — you can contact the settlement administratorsettlement administrator[contact via the official settlement website] to verify your eligibility. The official settlement website at capitalhealthdatabreachsettlement.com also provides tools to check your status. One important note for people who may have been patients at Capital Health facilities but whose data was not in the affected systems: the breach did not necessarily compromise every record the organization held. The LockBit group’s access was confined to a specific window and set of systems. Simply having been a Capital Health patient at some point does not automatically make you a class member.

Who Qualifies for the Capital Health Data Breach Settlement?

Flat Cash Payment vs. Documented Losses — Which Option Should You Choose?

The decision between the flat payment and documented losses claim is essentially a risk-reward calculation. The flat payment of roughly $100 requires no documentation, no receipts, and minimal effort. You file the claim, attest that you were affected, and wait. The downside is that $100 is the estimate, not the floor. If claim volume is high, you could receive less. But if you genuinely did not spend money dealing with the breach aftermath, this is your only cash option. The documented losses route offers up to $5,000 but demands proof for every dollar. If you spent $300 on credit monitoring and $150 on credit freeze fees, filing for documented losses nets you $450 — well above the flat payment estimate.

But if your provable expenses total only $60, you would be better off taking the flat payment at its estimated $100 value, assuming the pro rata adjustment does not reduce it below $60. The breakeven point depends on how many total claims are filed, which no one can predict with certainty before the deadline. There is no option to file for both. You must choose one path when you submit your claim. If you have any documented expenses at all, add them up and compare the total against the likely flat payment range. For most people with even moderate out-of-pocket costs, the documented losses option will yield more money. For those who took no action after the breach notification, the flat payment is the practical choice. Either way, all claimants can also elect three years of credit monitoring valued at $90 per year, which is available on top of whichever cash option you select.

Key Deadlines and What Happens If You Miss Them

The most critical date is April 6, 2026 — the claim filing deadline. If you do not submit your claim by that date, you receive nothing from the settlement fund regardless of how severely the breach affected you. There is no grace period built into the settlement terms, and courts rarely grant extensions for individual claimants who simply forgot or procrastinated. Before that, there is a March 9, 2026 deadline for objections and opt-outs. If you believe the settlement terms are inadequate and want to preserve your right to sue Capital Health independently, you must opt out by this date. Opting out means you give up any claim to the settlement fund but retain the ability to pursue your own legal action.

Objecting is different — it means you stay in the class but formally tell the court you disagree with some aspect of the settlement terms. Very few objections result in changes to settlement terms, but the option exists. If you take no action at all, you remain a class member bound by the settlement and forfeit your right to sue separately, but you still must file a claim to receive payment. After the final fairness hearing on July 14, 2026, approved payments are expected to be distributed within 90 to 180 days, depending on the payment method selected. Direct deposit or digital payments tend to arrive faster than mailed checks. If the court does not grant final approval, the timeline resets and all deadlines may shift — though outright rejection of data breach settlements at the fairness hearing stage is uncommon.

Key Deadlines and What Happens If You Miss Them

The LockBit Attack and Why the Settlement Amount Matters

The LockBit ransomware group’s attack on Capital Health was not a minor incident. The group claimed to have exfiltrated 7 terabytes of data during the unauthorized access window of November 11 through November 26, 2023. The attack caused IT system outages and involved ransomware encryption of files, disrupting operations at Capital Health facilities. For context, 7 terabytes of data could contain millions of patient records, insurance details, Social Security numbers, and employment information.

Against that backdrop, the $4.5 million settlement fund works out to roughly $8.95 per affected individual if every single one of the 503,071 class members filed a claim. In practice, participation rates are always a fraction of the total class, so actual per-person payments will be higher. But this arithmetic illustrates a persistent tension in data breach settlements: the fund sounds large in absolute terms yet is modest relative to the number of people whose information was compromised. For individuals with significant documented losses, the $5,000 cap provides meaningful recovery. For everyone else, the settlement offers a modest flat payment and credit monitoring — useful, but unlikely to feel proportionate to the scope of the breach.

What to Watch After the Final Hearing

The July 14, 2026 fairness hearing will determine whether the settlement receives final court approval. Assuming it does, the settlement administrator will begin processing claims and distributing payments in the months that follow. Class members should ensure their contact information and payment preferences are current with the administrator, as outdated addresses or bank details are the most common reason payments are delayed or returned.

Looking ahead, this settlement is part of a broader pattern of healthcare data breach litigation resulting in multi-million dollar funds. Organizations handling sensitive health data continue to face ransomware threats, and courts are increasingly willing to certify class actions when breach notification lists exceed hundreds of thousands of individuals. For affected Capital Health patients and employees, the practical next step is to file a claim before April 6, 2026, and to keep records of any ongoing identity theft or fraud that may surface in the coming years.

Frequently Asked Questions

How much will I actually receive from the Capital Health data breach settlement?

It depends on which option you choose. Documented losses are reimbursed up to $5,000 with proof. The flat cash payment is estimated at $100 but will be adjusted pro rata based on how many people file claims. If claim volume is very high, the flat payment could drop below $100.

Can I file for both documented losses and the flat cash payment?

No. You must choose one or the other. However, all claimants can receive three years of credit monitoring regardless of which cash option they select.

What documentation do I need to file for the $5,000 maximum?

You need receipts, bank statements, or account records showing unreimbursed expenses caused by the breach. This includes credit monitoring costs, credit freeze fees, identity theft remediation expenses, and bank fees from unauthorized transactions. Claims without documentation will likely be denied.

When will payments be sent out?

Payments are expected 90 to 180 days after final court approval. The final fairness hearing is scheduled for July 14, 2026, so the earliest payments would likely arrive in late 2026. Digital payment methods may arrive faster than mailed checks.

I was a Capital Health patient but never received a breach notice. Am I eligible?

Not necessarily. Eligibility is based on whether your data was in the compromised systems. Contact the settlement administratorsettlement administrator[contact via the official settlement website] or visit capitalhealthdatabreachsettlement.com to verify your status.

What happens if I do nothing?

You remain bound by the settlement and lose the right to sue Capital Health over this breach, but you receive no payment. If you want to preserve your right to pursue separate legal action, you must opt out by March 9, 2026.


You Might Also Like

Leave a Reply