Almost every data breach settlement that pays cash without receipts still gates the claim behind a code printed on a notice you may never have received. This one does not. The ConnectOnCall settlement carries a filing path for people with no Unique ID and no PIN — which makes the $75 alternate cash and two years of medical-identity monitoring reachable by anyone who qualifies. Claims close November 2, 2026.
Status: Claims open | Claim deadline November 2, 2026 | Opt out or object by October 19, 2026 | Fund: $4,950,000
What Happened
ConnectOnCall was an after-hours on-call answering service used by healthcare providers across the United States. According to the court-authorized notice, on or about May 12, 2024 the defendants learned that an unknown threat actor had gained access to the ConnectOnCall Platform between February 16, 2024 and May 12, 2024 and exfiltrated data from it, including certain provider-patient communications. Notification of potentially affected individuals began on or about December 11, 2024.
The case is In re ConnectOnCall.com Data Breach Litigation, No. 2:24-cv-08790, before Judge Sanket J. Bulsara in the U.S. District Court for the Eastern District of New York. The defendants are ConnectOnCall.com, LLC and Phreesia, Inc.
One line in the notice is worth quoting for what it rules out: the lawsuit does not allege that any individual’s data was misused as a result of the incident. The claims pleaded were negligence, negligence per se, breach of third-party beneficiary contract, invasion of privacy and intrusion upon seclusion, unjust enrichment, and declaratory judgment. The defendants deny the legal claims and deny any wrongdoing or liability, and the court has made no determination that any law was violated.
Before final approval, the defendants must also give class counsel a written attestation describing the security measures put in place after the incident and estimating what those measures cost. The notice says the defendants bear that cost and that it does not reduce the settlement fund. Because the attestation goes to counsel rather than the public, the specific measures are not disclosed.
Who Qualifies — and the Attestation That Decides It
The Settlement Class is every living individual residing in the United States whose Private Information may have been impacted in the Data Incident. Excluded are the directors, officers and employees of the defendants, and the judges assigned to the case along with their immediate family and court staff. The notice does not publish a class size.
The practical eligibility test for a cash payment is narrower, and it sits on the Claim Form itself. To claim either cash option you must attest under penalty of perjury that you communicated after-hours with a healthcare provider or their office between May 12, 2014 and May 12, 2024.
Notice that the attestation window is ten years wide while the breach window is under three months. The settlement is not asking you to prove you were on the platform during the intrusion — it is asking you to swear you were the kind of person whose messages the platform would have carried. If you ever called a doctor’s office after hours in that decade and reached an answering service, read the Claim Form carefully. If you did not, the attestation is not one to sign.
The Money, and the Order It Is Paid In
A $4,950,000 Settlement Fund pays for everything: all valid claims for monitoring and for cash, all settlement administration costs, and any attorneys’ fees, costs and service awards the court awards. The notice estimates administration costs at $490,000 under current assumptions, and says class counsel will ask for fees of no more than $1,650,000 plus reimbursement of reasonable costs, along with service awards of up to $2,500 for each class representative. The court may award less.
There are two cash options and you take one or the other:
- Cash Payment A — Documented Losses. Up to $5,000 for actual, documented, unreimbursed costs, expenses, losses or charges from identity theft or identity fraud, falsified tax returns, or other possible misuse of your information attributed to the incident.
- Cash Payment B — Alternate Cash. Up to $75, no documentation required.
The pro rata mechanics here have an order to them, and it decides who absorbs a shortfall. If valid claims exhaust the fund, cash payments are reduced pro rata — and the notice fixes the sequence in which the administrator pays: monitoring first, then Cash Payment A, then Cash Payment B. The $75 alternate cash is last in line and the first thing to shrink. Treat it as a ceiling, not a promise.
Cash Payment A is limited to unreimbursed losses. The notice says you will not be reimbursed for a loss already covered by another source, and names one specifically: the identity protection and credit monitoring services the defendants offered in the original notification letter.
Two Years of Medical-Identity Monitoring, Stacked on Top
Two years of Dark Web and Medical Data Monitoring through CyEx Medical Shield Complete is available, and it is additive — you can claim it alongside whichever cash option you choose rather than instead of one. The notice describes dark web monitoring, medical identity monitoring, real-time alerts, and insurance coverage of up to $1,000,000 for medical identity theft, and puts the value at $360 per class member for the two years.
What is being monitored is worth noting. This breach took provider-patient communications rather than payment-card data, so the product on offer is medical-identity focused rather than a standard credit-bureau watch. Medical identity theft also tends to surface late — through a billing statement or an insurance denial rather than a credit alert — which is part of why a two-year monitoring benefit is on the table at all in a case where the complaint does not allege anyone’s data was actually misused.
Like the cash, the monitoring requires a timely, valid Claim Form. Nothing here arrives automatically.
The No-ID Filing Path
For the $75 and the monitoring, no proof is required. There is no receipt to produce and no administrator-issued code that gates the benefit — the requirement is the sworn attestation described above.
The online portal does open with a request for a Unique ID and PIN printed on the mailed or emailed notice, which makes this settlement look at first glance like the ID-gated data breach cases that dominate the category — the SitusAMC settlement running on a near-identical timetable is exactly that kind. ConnectOnCall is not. The same page carries a link for claimants who do not have a Unique ID or PIN, so someone who never received a notice, or threw it away, can still file.
Cash Payment A is the exception and it is a real one. To claim documented losses you must elect Cash Payment A on the form, make the after-hours attestation, and provide a description of the losses together with supporting documentation that is not self-prepared. Documents should be clear, readable copies; nothing you submit is returned; you may redact unrelated transactions and all but the first and last four digits of an account number. Uploads must be under 20 MB per file in a common document or image format, and if you cannot upload you mail a printed form with the documentation attached.
The fallback is unusually generous. If you do not submit reasonable documentation, or the administrator rejects your claim for any reason and you fail to cure it, the notice says the claim is converted to Cash Payment B rather than denied outright. Reaching for the $5,000 tier and missing does not leave you with nothing.
Dates
- October 19, 2026 — deadline to exclude yourself (postmarked) and to object (filed with the court, with copies to class counsel, defendants’ counsel and the administrator by the same date).
- November 2, 2026 — claim deadline, online or postmarked. The notice gives dates without a cutoff time, so treat the date itself as the deadline.
- November 17, 2026 at 10:00 a.m. ET — final approval hearing in Central Islip, New York. The notice warns the date and time are subject to change and that the court may hold the hearing by video conference or telephone.
The opt-out and objection deadline falls two weeks before claims close, so the decision about whether to stay in the class has to be made before the last day to file. Opting out is the only way to keep the right to sue, and it requires a personally signed written request mailed to the administrator giving your name, address, telephone number and email address. The notice is explicit that you cannot opt out by telephone or email, that mass or group opt-outs signed by an attorney are not accepted, that an opt-out forfeits both the cash and the monitoring, and that if you opt out and also file a claim, the opt-out controls.
A hearing being held is not the same as approval being granted. The notice says benefits are provided after the settlement is approved and becomes final, and asks class members to be patient because that can take time. No payment date had been announced as of August 30, 2026.
How to File
File through the official settlement website, ConnectOnCallSettlement.com. The Submit a Claim page starts with the Unique ID and PIN login, with a separate link below it for filing without them. From there you give your contact details, make the after-hours attestation, and select the monitoring, Cash Payment A, or Cash Payment B.
If you are claiming documented losses, have your files ready before you start — the instructions warn that a partially completed online Claim Form is not saved if you leave and come back. After you submit, the administrator emails a confirmation code worth keeping. A printable Claim Form is available for anyone who would rather file on paper. If your mailing or email address changes after you file, the notice puts the burden on you to tell the administrator.
Source and credit: the settlement terms, deadlines and benefit tiers described above are drawn from our sister site’s reporting — OpenClassActions.com: ConnectOnCall Data Breach Settlement: $75 or Up to $5,000 — which tracks this case against the court-approved notice and the official settlement website and is updated as the court rules.
Frequently Asked Questions
Can I file a ConnectOnCall claim without a Unique ID and PIN?
Yes. The Submit a Claim page on the official settlement website opens with the Unique ID and PIN login, but carries a separate link below it for claimants who do not have them. Someone who never received a notice, or discarded it, can still file. That is unusual for a data breach settlement and it is why the $75 alternate cash and the monitoring are reachable without administrator-issued credentials.
What do I have to swear to on the claim form?
To claim either cash option you must attest under penalty of perjury that you communicated after-hours with a healthcare provider or their office between May 12, 2014 and May 12, 2024. That ten-year attestation window is much wider than the February 16 to May 12, 2024 breach window, because the settlement is not asking you to prove you were on the platform during the intrusion.
Is the $75 payment guaranteed?
No. The $4,950,000 fund pays administration costs, attorneys fees, costs and service awards as well as all benefits, and if valid claims exhaust it cash payments are reduced pro rata. The notice fixes the payment order as monitoring first, then Cash Payment A documented losses, then Cash Payment B. The $75 alternate cash is last in line and the first thing to shrink, so treat it as a ceiling rather than a promise.
Can I claim the monitoring and a cash payment?
Yes. The two years of Dark Web and Medical Data Monitoring through CyEx Medical Shield Complete, valued in the notice at $360, is additive – you claim it alongside whichever cash option you choose. You cannot claim both cash options; Cash Payment A and Cash Payment B are alternatives. Both the monitoring and the cash require a timely, valid Claim Form; nothing is automatic.
What happens if my documented-loss claim is rejected?
It converts rather than dies. The notice says that if you do not submit reasonable documentation, or the administrator rejects the claim for any reason and you fail to cure it, the claim is converted to Cash Payment B instead of being denied outright. Reaching for the $5,000 tier and missing does not leave you with nothing.
Sources
- Official settlement website — ConnectOnCallSettlement.com, including the long-form notice, the settlement FAQs, the documents page and the paper Claim Form.
- In re ConnectOnCall.com Data Breach Litigation, No. 2:24-cv-08790, U.S. District Court for the Eastern District of New York (Hon. Sanket J. Bulsara).
- Settlement agreement, Section XIII (releases), linked from the official settlement website.
- OpenClassActions.com — ConnectOnCall Data Breach Settlement: $75 or Up to $5,000.
Legal Disclaimer
This article is for informational purposes only and is not legal advice. OpenClassActions.org is a consumer news site, not a law firm and not the settlement administrator, and is not affiliated with any party to the case described. The allegations are allegations; the defendants deny wrongdoing and no court has decided the merits. Deadlines, benefit amounts and payment timing can change as the court and the administrator act, so confirm current status on the official settlement website. You never need to pay anyone to file a claim or to receive a settlement payment.