If you received a notice about the Capital Health data breach settlement, you have three options before the deadlines pass: file a claim for up to $5,000 in documented losses or an estimated $100 cash payment, opt out by March 9, 2026 to preserve your right to sue independently, or object to the settlement terms by that same date. The $4.5 million settlement resolves class action litigation stemming from a November 2023 ransomware attack that exposed the personal information of more than 503,000 patients and employees.
For most people, filing a claim is the straightforward choice — but the right decision depends on whether you suffered significant financial harm you might want to pursue on your own. We also cover the credit monitoring benefit, what the final fairness hearing on July 14, 2026 will determine, and the tradeoffs involved in opting out versus staying in the class.
Table of Contents
- What Is the Capital Health Data Breach Settlement and Who Qualifies to File a Claim?
- How Much Money Can You Get from the Capital Health Settlement?
- Filing a Claim Before the April 6, 2026 Deadline
- Opting Out vs. Objecting — Understanding the Tradeoffs
- What the LockBit Ransomware Attack Means for Your Data
- What Happens at the Final Fairness Hearing on July 14, 2026
- Lessons from the Capital Health Case for Future Data Breach Settlements
- Frequently Asked Questions
What Is the Capital Health Data Breach Settlement and Who Qualifies to File a Claim?
capital Health Systems, Inc. agreed to pay $4.5 million to settle consolidated class action lawsuits filed after an unauthorized criminal actor accessed the company’s network between November 11 and 26, 2023. The attacker deployed ransomware to encrypt files across Capital Health’s systems, and the LockBit ransomware group later claimed responsibility, stating it had exfiltrated roughly 7 terabytes of data. Capital Health publicly disclosed the attack in December 2023, and the breach was reported to the U.S. Department of Health and Human Services’ Office for Civil Rights as affecting 503,071 individuals. You qualify as a class member if your private information was impacted during that November 11–26, 2023 breach window.
This includes both patients who received care through Capital Health facilities and employees whose records were stored on the compromised network. The first class action lawsuit was filed on December 19, 2023, and multiple cases were eventually consolidated in May 2025 as Bruce Graycar, et al. v. Capital Health Systems, Inc. in the United States District Court for the District of New Jersey. If you received a settlement notice by mail or email, you are almost certainly a class member — but even if you did not receive a notice, you may still qualify if your data was part of the breach.

How Much Money Can You Get from the Capital Health Settlement?
The settlement offers two paths to compensation. The first is reimbursement for documented, unreimbursed out-of-pocket losses resulting from the data breach, up to $5,000 per person. This covers expenses like costs for credit monitoring you purchased on your own, bank fees from fraudulent transactions, charges related to freezing or unfreezing your credit, and time spent dealing with identity theft or fraud. You will need receipts, statements, or other documentation to support these claims. The second path is a flat cash payment estimated at around $100 per class member, available as an alternative if you did not incur specific documented losses.
However, if a large number of class members file claims, the per-person payment amounts could be adjusted downward on a pro rata basis. The $4.5 million fund has to cover all approved claims, administrative costs, and attorney fees. So while $5,000 is the ceiling for documented losses, the actual amount you receive depends on how many people file and the total value of approved claims. The estimated $100 alternative payment is just that — an estimate, not a guarantee. In addition to cash compensation, every class member who files a valid claim is eligible for three years of credit monitoring services, valued at approximately $90 per year. Given that the breach involved a ransomware group known for selling exfiltrated data, this monitoring benefit has genuine practical value beyond the dollar figure.
Filing a Claim Before the April 6, 2026 Deadline
The claim filing deadline is April 6, 2026. You can submit your claim through the official settlement website at capitalhealthdatabreachsettlement.com. The process typically requires you to verify your identity as a class member, select whether you are claiming documented out-of-pocket losses or the alternative cash payment, and provide supporting documentation if you are pursuing the higher reimbursement.
For example, if you noticed unauthorized charges on a credit card after the breach and spent $45 on a credit monitoring subscription plus three hours on the phone with your bank sorting out fraudulent transactions, those are all compensable expenses. Keep copies of bank statements showing the fraudulent activity, receipts for any monitoring services you purchased, and notes on time you spent resolving the issues. A common mistake is waiting until the last few days to file — online claim portals can slow down near deadlines, and mailed claims need to be postmarked by the deadline date, not just dropped in the mailbox that day.

Opting Out vs. Objecting — Understanding the Tradeoffs
The opt-out and objection deadline is March 9, 2026, which is one day from now. These are two fundamentally different actions, though they share the same deadline. Opting out means you remove yourself from the settlement class entirely. You get no money from this settlement, no credit monitoring, nothing — but you preserve your legal right to file your own individual lawsuit against Capital Health. Objecting means you stay in the class but formally tell the court you disagree with something about the settlement terms, such as the total amount, the fee structure, or how the money is being distributed.
Opting out makes sense in a narrow set of circumstances: if you suffered substantial, well-documented financial harm from the breach — tens of thousands of dollars in identity theft losses, for instance — and you believe an individual lawsuit would yield a significantly better result than the $5,000 cap in this settlement. For the vast majority of class members, opting out is a bad deal. Individual data breach lawsuits are expensive, slow, and uncertain, and most people’s damages fall well within the settlement’s reimbursement limits. Objecting, on the other hand, carries no risk to your claim. You can object to the settlement and still receive benefits if the court approves it. If you think the $4.5 million is too low given that 503,071 people were affected, filing an objection puts that concern on the record for the judge to consider at the final fairness hearing.
What the LockBit Ransomware Attack Means for Your Data
The LockBit ransomware group did not just encrypt Capital Health’s files — they claimed to have exfiltrated 7 terabytes of data from the network. This distinction matters because encrypted data that stays on the victim’s servers is one thing, but stolen data that leaves the network entirely is a more serious long-term threat. Exfiltrated healthcare data can include Social Security numbers, medical records, insurance information, and financial details, and it can surface on dark web marketplaces months or even years after the initial breach. This is why the three-year credit monitoring benefit in the settlement is worth taking seriously, even if you are skeptical about its cash value.
Identity thieves sometimes sit on stolen data, waiting for the initial wave of credit freezes and monitoring to expire before attempting to use it. If you file a claim and activate the monitoring, set a reminder for yourself when the three-year period is about to end. At that point, you may want to continue monitoring on your own or place a long-term fraud alert with the credit bureaus. One limitation to be aware of: credit monitoring only covers financial accounts and credit activity. It will not alert you if your medical records are used for insurance fraud or if someone seeks treatment under your identity, which are real risks with healthcare data breaches.

What Happens at the Final Fairness Hearing on July 14, 2026
The court has scheduled a final fairness hearing for July 14, 2026, at which the judge will decide whether to grant final approval to the settlement. This is where any objections filed by class members will be considered. If the judge determines the settlement is fair, reasonable, and adequate, it will be approved and the claims process will move toward distributing payments.
If the judge has concerns — whether raised by objectors or on the court’s own initiative — the settlement could be modified or, in rare cases, rejected. You do not need to attend the hearing to receive your settlement benefits. If you filed a claim by the deadline, your claim will be processed regardless of whether you show up. However, if you filed an objection, appearing at the hearing gives you the opportunity to explain your concerns directly to the judge.
Lessons from the Capital Health Case for Future Data Breach Settlements
The Capital Health settlement follows a pattern that has become increasingly common in healthcare data breach litigation: a ransomware attack exposes hundreds of thousands of records, lawsuits consolidate within months, and a settlement is reached that offers modest per-person payments alongside credit monitoring. The $4.5 million total, spread across 503,071 affected individuals, works out to less than $9 per person if everyone filed a claim — which underscores why the individual cap of $5,000 for documented losses is the more meaningful benefit for those who actually suffered financial harm.
For anyone affected by this or future breaches, the practical takeaway is to document everything from the moment you learn your data was compromised. Save every notice you receive, screenshot any suspicious account activity, and keep records of time and money spent addressing the fallout. That documentation is what separates a $100 flat payment from a $5,000 reimbursement in settlements like this one.
Frequently Asked Questions
Do I need a lawyer to file a claim in the Capital Health settlement?
No. The claim process is designed for individuals to complete on their own through the official settlement website. Class counsel already represents the class as a whole, and their fees come out of the $4.5 million fund, not from your individual payment.
What if I am not sure whether my data was part of the breach?
If you were a patient or employee of Capital Health during the November 11–26, 2023 timeframe and received a breach notification, you are likely a class member. You can check your eligibility through the settlement website or the settlement administrator.
Can I file a claim and also object to the settlement?
Yes. Objecting does not disqualify you from receiving benefits. You can file your claim by April 6, 2026 and also submit an objection by March 9, 2026 if you believe the settlement terms should be different.
What happens if I do nothing?
If you take no action, you remain a class member, you release your legal claims against Capital Health, but you receive no payment and no credit monitoring. This is generally the worst outcome.
Will I have to pay taxes on the settlement payment?
Settlement payments for personal physical injuries are generally tax-free, but payments for other types of claims may be taxable. The IRS treats data breach settlements on a case-by-case basis. Consult a tax professional if you receive a payment, especially if it is above a few hundred dollars.
You Might Also Like
- SiriusXM Robocall And Telemarketing Settlement: Opt Out, Object, Or File A Claim
- Capital Health Data Breach Settlement: How Payments Are Calculated
- Can You Claim Cash From The Capital Health Data Breach Settlement Without Proof
