The short answer is that the Capital Health data breach settlement does not require proof for its most accessible payout. If you were among the 503,071 individuals affected by the November 2023 ransomware attack on Capital Health Systems, you can file a claim for an estimated $100 flat cash payment without submitting a single receipt, statement, or document. You just select the option on the claim form and submit it. That is the entire process for what the settlement calls “Cash Payment B.” For example, if you were a Capital Health patient who received a breach notification letter but never actually spotted fraudulent charges on your accounts, you can still collect this payment with zero documentation. However, the settlement also offers a second, larger payout of up to $5,000 for people who did suffer documented financial losses from the breach, and that track requires real proof.
The distinction between these two claim types is where most of the confusion sits, and it matters because choosing the wrong option or failing to gather paperwork could leave money on the table. The claim filing deadline is April 6, 2026, so the window is still open but not indefinitely. Beyond the cash payments, every eligible class member can also enroll in three years of free credit monitoring regardless of which payment option they choose, and that requires no proof either. We will walk through all of it below.
Table of Contents
- What Proof Does The Capital Health Data Breach Settlement Actually Require For Each Claim Type?
- What Happened In The Capital Health Breach And Who Is Eligible To File
- How The $4.5 Million Settlement Fund Breaks Down In Practice
- Should You File For The $100 Flat Payment Or The $5,000 Documented Losses Claim?
- Documentation Pitfalls That Could Sink Your Claim
- The Free Credit Monitoring Benefit Most People Overlook
- Key Deadlines And What Comes Next
- Frequently Asked Questions
What Proof Does The Capital Health Data Breach Settlement Actually Require For Each Claim Type?
The settlement created two distinct cash payment tracks with fundamentally different proof requirements. Cash Payment A covers documented out-of-pocket losses up to $5,000 per class member. This is designed for people who can show they spent real money dealing with the fallout of the breach. You need to submit receipts, bank or credit card statements, notices from creditors, or other third-party records that substantiate your expenses. The categories of reimbursable costs include identity theft losses, fraud charges, money spent on credit monitoring services you purchased yourself, fees for freezing and unfreezing your credit, professional consultation fees, mileage to deal with fraud-related errands, and even postage costs. One critical detail: self-prepared documents like handwritten receipts or personal affidavits are not sufficient on their own. The settlement administrator wants third-party verification.
Cash Payment B is the no-proof option. It is a flat pro rata cash payment estimated at approximately $100, available to every class member regardless of whether they experienced any documented harm. You do not need to show that you suffered identity theft, that you spent money on protective measures, or that you even checked whether your data was misused. You simply select this option on the claim form at [CapitalHealthDataBreachSettlement.com](https://capitalhealthdatabreachsettlement.com/) and submit. The actual payout amount could shift slightly depending on how many people file claims against the $4.5 million settlement fund, but $100 is the current estimate. The comparison is straightforward: Payment A has a higher ceiling but demands documentation. Payment B has a lower payout but demands nothing beyond the claim form itself. Most class members who did not experience direct financial harm will find Payment B to be the practical choice.

What Happened In The Capital Health Breach And Who Is Eligible To File
Capital Health Systems, which operates hospitals and healthcare facilities in New Jersey, was hit by a LockBit ransomware attack that caused an IT systems outage lasting from November 11 through November 26, 2023. The attack did not just lock systems. In January 2024, the LockBit ransomware group publicly claimed it had stolen more than 10 million files containing over 7 terabytes of data from Capital Health, and threatened to release it unless a ransom was paid. That volume of stolen data from a healthcare provider is significant because it likely included protected health information, Social Security numbers, financial records, and other sensitive personal data covered by HIPAA. The breach was reported to the HHS Office for Civil Rights as affecting 503,071 individuals, including both patients and employees. If you received a notification letter from Capital Health about the breach, you are almost certainly a class member.
Eligibility extends to individuals whose private information was potentially compromised during the November 11 through 26, 2023 incident window. However, if you are unsure whether you were affected, the settlement website allows you to check your eligibility. One important caveat: “potentially compromised” means you do not need to prove your data was actually accessed or misused. The exposure alone qualifies you. If you were a Capital Health employee whose personnel records were stored on the affected systems, you are also eligible. This is not limited to patients. The class definition is broad enough to cover anyone whose information was in the compromised systems during the breach window.
How The $4.5 Million Settlement Fund Breaks Down In Practice
The total settlement fund is $4.5 million, which sounds substantial until you divide it among half a million eligible people. If every single class member filed for the $100 flat payment, the math would not work. The pro rata estimate of $100 assumes a typical claims rate, which in data breach settlements usually falls somewhere between 5 and 15 percent of eligible class members. So the actual per-person payout depends heavily on participation. If fewer people file, each person gets more. If there is an unusually high filing rate, the per-person amount could drop below $100.
For context, consider how this compares to other healthcare data breach settlements. A $4.5 million fund for roughly 500,000 affected individuals works out to about $9 per person if everyone filed. The $100 estimate reflects the reality that most people will not bother. This is a recurring pattern in class action settlements: the people who actually file claims tend to do reasonably well precisely because most eligible people never get around to it. If you are reading this article and you are eligible, filing the claim takes a few minutes and could net you $100 or more for essentially no effort. The $5,000 cap on documented losses claims is per class member, not per incident. So if you had multiple fraudulent charges, paid for credit monitoring, drove to your bank to dispute transactions, and hired a service to help restore your identity, you would bundle all of those into a single claim up to the $5,000 limit.

Should You File For The $100 Flat Payment Or The $5,000 Documented Losses Claim?
The decision comes down to whether you have paperwork. If you spent money dealing with the aftermath of the Capital Health breach and you kept records, the documented losses claim is obviously the better financial choice. Even $300 in documented expenses would triple what you would get from the flat payment. But the documentation bar is real. You need third-party records like bank statements showing fraudulent charges, receipts from credit monitoring services you purchased, invoices from identity theft restoration services, or records of credit freeze fees. If you paid for something in cash and have no receipt, that expense will be difficult to claim. If you did not experience any tangible financial loss, or if you did but cannot document it, the flat $100 payment is the straightforward path.
There is no advantage to trying to file a documented losses claim without adequate proof. The claims administrator will review the documentation, and unsupported claims will either be reduced or denied. A rejected Payment A claim could complicate your ability to receive Payment B instead, depending on how the administrator handles it, so it is better to be honest about which category fits your situation. One tradeoff worth noting: you can file for either Payment A or Payment B, but not both. They are mutually exclusive. So if you have $80 in documented losses, you would actually do better taking the $100 flat payment than filing a documented claim for $80. Only pursue the documented track if your provable expenses meaningfully exceed the flat payment estimate.
Documentation Pitfalls That Could Sink Your Claim
The biggest trap in the documented losses claim is the rule about self-prepared documents. If you write up a personal statement describing the hours you spent on the phone with your bank, or you create a handwritten log of your expenses, that alone will not satisfy the settlement administrator. You need corroborating third-party records. A bank statement showing a fraudulent charge plus a letter from your bank confirming the dispute would work. A handwritten note saying “I spent $200 dealing with fraud” would not. Another common issue is timing. Your documented losses need to be plausibly connected to the Capital Health breach.
If you experienced identity theft in March 2024, several months after the breach was disclosed, that connection is reasonable. If you are trying to claim expenses from an identity theft incident in 2021, well before the breach occurred, that will not fly. The claims administrator looks for a reasonable temporal and factual link between the breach and the claimed losses. Credit monitoring is another area where people trip up. If you purchased credit monitoring after learning about the breach, that cost is reimbursable under Payment A. But the settlement also offers three years of free credit monitoring to all class members. If you have not yet purchased monitoring, you may want to simply enroll in the free option rather than buying a service and trying to claim reimbursement. The free monitoring includes dark web scanning, public records monitoring, and identity theft insurance, which covers the same ground as most paid services.

The Free Credit Monitoring Benefit Most People Overlook
Every eligible class member can enroll in three years of one-bureau credit monitoring at no cost, and this benefit is available in addition to whichever cash payment you select. You can file for the $100 flat payment and also sign up for credit monitoring. The monitoring is valued at roughly $90 per year, so over three years, that adds approximately $270 in value on top of your cash payment.
No documentation is needed to enroll. The monitoring package includes dark web scanning, which alerts you if your personal information appears on underground marketplaces, plus public records monitoring and identity theft insurance. Given that LockBit claimed to have stolen 7 terabytes of data from Capital Health, the risk of that information surfacing on dark web markets is not hypothetical. Even if you have not seen signs of misuse yet, three years of free monitoring provides a meaningful safety net at zero cost to you.
Key Deadlines And What Comes Next
The claim filing deadline is April 6, 2026. If you miss that date, you get nothing, regardless of how strong your claim might be. The exclusion and objection deadline is March 9, 2026, which is relevant only if you want to opt out of the settlement to pursue your own lawsuit or if you want to formally object to the settlement terms. For most people, neither of those options makes practical sense.
The final approval hearing is scheduled for July 14, 2026, after which payments will be distributed assuming the court grants final approval. Data breach settlements have become routine enough that final approval is rarely denied at this stage, but payments typically take several months after the hearing to actually reach class members. If you file your claim now, a realistic expectation for receiving payment would be late 2026 or early 2027. The credit monitoring benefit, however, can begin as soon as you enroll, so there is no reason to wait on that piece.
Frequently Asked Questions
Do I need to prove my data was actually stolen to file a claim?
No. The settlement covers anyone whose information was “potentially compromised” during the November 11 through 26, 2023 breach. You do not need evidence that your specific data was accessed or misused.
Can I file for both the $100 flat payment and the $5,000 documented losses claim?
No. You must choose one or the other. They are mutually exclusive. Choose the documented losses option only if your provable expenses exceed the estimated flat payment amount.
What if I already have credit monitoring through another breach settlement?
You can still file for the cash payment. The credit monitoring is an additional benefit, not a requirement. If you already have monitoring, simply skip that part and file for whichever cash payment fits your situation.
Will I need to pay taxes on the settlement payment?
Settlement payments may be considered taxable income. The settlement administrator may issue a 1099 form if your payment exceeds IRS reporting thresholds. Consult a tax professional if you are concerned about tax implications.
What happens if too many people file claims and the fund runs out?
The $4.5 million fund is divided among all valid claims on a pro rata basis. If more people file than expected, the per-person flat payment could drop below the $100 estimate. It will not go to zero, but it could be reduced.
I was a Capital Health employee, not a patient. Am I eligible?
Yes. The class includes both patients and employees whose information was potentially compromised during the breach window.
You Might Also Like
- Proof Required Or Not: What The SiriusXM Robocall And Telemarketing Settlement Actually Needs
- Is The Capital Health Data Breach Settlement Legit, And How Do You Check Eligibility
- How To File A Claim In The Capital Health Data Breach Settlement
