The Rite Aid data breach that exposed personal information for approximately 2.2 million customers on June 6, 2024, led to a $6.8 million settlement that offered affected individuals up to $10,000 in compensation for documented identity theft expenses. However, the claims filing deadline expired on July 7, 2025, and the settlement is now closed to new claims. If you were affected by the breach but did not file a claim by that deadline, you are no longer eligible for compensation from this settlement, though you still have concrete steps available to protect your identity going forward. The Rite Aid Pharmacy Records class action, officially *Bianucci et al.
v. Rite Aid Corporation* (Case No. 2:24-cv-03356-HB), received final court approval on July 30, 2025. The breach compromised full names, home addresses, dates of birth, and driver’s license numbers—though social security numbers and prescription details were not exposed. Customers who missed the July 7, 2025 deadline cannot recover settlement compensation, making it essential to understand both what was lost in the settlement process and what protective measures remain available.
Table of Contents
- What Personal Information Was Exposed in the Rite Aid Breach?
- How Much Compensation Did the Settlement Offer, and Why Can’t Customers Claim It Now?
- Who Was Eligible for the Rite Aid Settlement, and What Proof Did Claimants Need?
- What Happens to Affected Customers Now That the Claims Deadline Has Passed?
- What Are the Key Limitations and Warnings for Affected Customers?
- How Do Affected Customers Access Free Credit Monitoring and Protective Services?
- Should Affected Customers Monitor the Settlement Administrator’s Website or Contact Them About a Missed Claim?
What Personal Information Was Exposed in the Rite Aid Breach?
The June 2024 breach gave unauthorized users access to a rite Aid customer database containing sensitive identity information on 2.2 million people nationwide. The exposed data included full names, residential addresses, dates of birth, and driver’s license numbers—the core information identity thieves need to open fraudulent accounts or apply for credit in your name. A pharmacy breach is particularly concerning because the breached database was part of Rite Aid’s customer management system, meaning anyone filling prescriptions at Rite Aid locations during that window could have been affected.
Importantly, what was not exposed matters as much as what was. Rite Aid’s HIPAA-protected health information systems remained secure; prescription details, medications, medical conditions, and health histories were not compromised. Social security numbers were also not part of the breach, which limits the scope of potential financial fraud but does not eliminate identity theft risk entirely. Driver’s license numbers alone, combined with name, address, and date of birth, are sufficient for identity theft; many financial institutions use driver’s license verification as a primary authentication method.
How Much Compensation Did the Settlement Offer, and Why Can’t Customers Claim It Now?
The $6.8 million settlement offered affected customers up to $10,000 in compensation for out-of-pocket identity theft expenses—such as credit monitoring enrollment, identity theft recovery services, credit report disputes, and costs associated with freezing or unfreezing credit with the three major bureaus. Claimants without documented expenses received pro-rata cash awards from the settlement fund, though the exact amount depended on the total number of valid claims filed. The median payout for most claimants fell between $20 and $200, depending on how many people filed claims and their individual documentation.
The settlement’s claims filing deadline of July 7, 2025, has now passed, making it impossible to file new claims or submit additional documentation. The court granted no extensions, and settlement administrators have confirmed that the deadline was final. This means anyone who did not receive or process a claim form before that date—whether due to missing the settlement notice, uncertain eligibility, or simply overlooking the deadline—is permanently ineligible for compensation. Approximately $2.4 million of the $6.8 million settlement fund went directly to class counsel for attorney’s fees and litigation costs, further reducing the pool available to individual claimants.
Who Was Eligible for the Rite Aid Settlement, and What Proof Did Claimants Need?
Eligibility for the settlement was straightforward: any individual whose name appeared in Rite Aid’s customer database as of June 6, 2024, qualified as a class member. This included people who filled prescriptions at Rite Aid, had customer reward accounts, or were simply in the pharmacy’s system for any reason. Unlike many settlements that require proof of purchase or prior notice, Rite Aid’s settlement administrator, Kroll Settlement Administration LLC, did not require proof of actual harm to participate—class members only needed to verify their identity and submit a claim form.
However, to receive the maximum $10,000 in compensation, claimants needed to provide documentation of identity theft-related expenses: receipts for credit monitoring services, invoices for identity theft recovery companies, or evidence of costs paid to dispute fraudulent accounts. Claimants who filed without documentation still received compensation, but it was calculated as a pro-rata share of remaining settlement funds rather than a dollar-for-dollar reimbursement. This two-tier system incentivized people to gather documentation but did not exclude those who could not provide receipts.
What Happens to Affected Customers Now That the Claims Deadline Has Passed?
For the majority of affected customers who did not file claims before July 7, 2025, the settlement is no longer an avenue for compensation. There are no appeals, no secondary filing periods, and no way to reopen the claims window. However, this does not mean affected individuals are without recourse or protection; it simply means compensation must come from other sources or through preventive action rather than the settlement.
The most practical immediate steps are to lock down your identity: place a credit freeze with all three major credit bureaus (Equifax, Experian, and TransUnion) at no cost, and consider enrolling in any free credit monitoring services Rite Aid continues to offer (typically 2–3 years following a breach). A credit freeze prevents anyone from opening new accounts in your name, even if they have your full identity information. Monitor your credit reports quarterly for fraudulent accounts or inquiries you don’t recognize, and consider setting up fraud alerts with your banks and creditors. These actions cost nothing and provide meaningful protection against the specific risk posed by the exposed driver’s license numbers and personal identifiers.
What Are the Key Limitations and Warnings for Affected Customers?
The most critical limitation is finality: once the July 7, 2025, deadline passed, Rite Aid’s settlement became unavailable forever. No court motion, appeal, or legal argument can reopen it. This is a hard deadline, not a guideline, and settlement law typically does not provide do-overs. Anyone who received a settlement notice and failed to act before the deadline waived their right to any proceeds from the fund.
A second limitation is that even for claimants who filed on time, compensation was modest for most people. The pro-rata awards—often $20 to $200—would not fully reimburse significant identity theft recovery costs, and the $10,000 maximum was only available to claimants with substantial documented expenses. The settlement was designed to provide baseline compensation for inconvenience and risk, not to fully cover all identity theft scenarios. If you are a victim of active identity theft now, your remedies lie with federal identity theft protections (through the FTC) and potential lawsuits against the perpetrators, not through the Rite Aid settlement.
How Do Affected Customers Access Free Credit Monitoring and Protective Services?
Rite Aid typically offers affected customers two to three years of free credit monitoring through a third-party service. Details about enrollment are usually included in breach notification letters or available through Rite Aid’s official customer service line.
However, if you did not receive or keep that notice, free credit monitoring services may no longer be available directly from Rite Aid—the company’s obligation to provide such services expires when the breach notification period ends. Alternative free services exist through government programs: the Federal Trade Commission (FTC) provides free credit report access through www.annualcreditreport.com, where you can check your Equifax, Experian, and TransUnion reports once per year at no cost. The FTC also provides free identity theft recovery resources and will assist in disputing fraudulent accounts if identity theft occurs.
Should Affected Customers Monitor the Settlement Administrator’s Website or Contact Them About a Missed Claim?
The settlement administrator, Kroll Settlement Administration LLC, closed the claims submission window permanently on July 7, 2025. Contacting Kroll now—via their phone line (833) 421-7672 or the settlement website www.RiteAidDataSettlement.com—will not reopen your eligibility or allow you to file a late claim.
However, if you filed a valid claim before the deadline, the settlement administrator website is the appropriate place to check the status of your claim, which may still be under review or awaiting final payment. For anyone who missed the deadline, contact with the settlement administrator serves no practical purpose regarding new claims, though you may still inquire about any free credit monitoring services that were offered to your address. The resources should be focused instead on proactive identity protection: credit freezes, credit monitoring enrollment through other providers if needed, and ongoing vigilance with credit reports.
- —
