If you received a breach notification from ZOLL Medical on or about March 10, 2023, and you are a living U.S. resident, you are potentially eligible for compensation from a $3.5 million settlement. The settlement resolves a class action lawsuit (Smith et al v. ZOLL Medical Corporation) filed in U.S. District Court for the District of Massachusetts against the medical device manufacturer following a significant data breach.
ZOLL Medical is the maker of LifeVest, a wearable cardioverter defibrillator worn by patients at risk of sudden cardiac death. The settlement’s eligibility criteria are straightforward: the settlement class includes any living U.S. resident whose personal information ZOLL notified was exposed in the breach. You do not need to prove individual harm or submit evidence that your data was actually misused. For example, if you were a patient who wore a LifeVest, or if you were evaluated as a candidate for one and your information was in ZOLL’s system, and you received ZOLL’s March 2023 notification letter, you are eligible to file a claim.
Official resource:
- Check eligibility and file a claim — Official settlement administrator website where eligible individuals can verify their status and submit claims before the September 2, 2026 deadline.
Table of Contents
- How Large Was the ZOLL Medical Breach and Who Was Affected?
- What Settlement Payments Are Available and How Are They Calculated?
- What Out-of-Pocket Loss Claims Require and How to Document Them
- How to File Your Claim and Meet the Critical Filing Deadline
- Common Claim Rejection Reasons and Documentation Mistakes to Avoid
- The Prior ZOLL Medical Breach and Repeat Offender Concerns
- Settlement Timeline and What to Expect Before Final Approval
How Large Was the ZOLL Medical Breach and Who Was Affected?
The breach occurred when unauthorized parties gained access to ZOLL Medical’s network between January 22 and 24, 2023. The company discovered the incident on January 28, 2023, and a forensic investigation confirmed unauthorized access on February 2, 2023. The breach exposed the personal information of 1,004,443 individuals—both existing patients using the LifeVest device and people who had been evaluated for use of the device.
The exposed data included names, home addresses, dates of birth, Social security numbers, and protected health information related to cardiac conditions and device management. This combination of SSN and health data is particularly sensitive and is frequently exploited by identity thieves. The breach notification letters, sent on or about March 10, 2023, identified which individuals had information exposed and urged them to monitor their credit reports. It is worth noting that ZOLL Medical had experienced a previous major breach in 2018, when approximately 277,000 users’ protected health information was compromised through a third-party software vendor—a fact that has troubled some class members and regulators who question whether the company adequately strengthened its security practices between the two incidents.
What Settlement Payments Are Available and How Are They Calculated?
The settlement creates two payment subclasses based on whether an individual’s Social Security number was actually exposed in the breach. Members of the SSN Subclass—those whose Social Security numbers were compromised—are eligible for an estimated $100 per person. Members of the Non-SSN Subclass—those whose personal information was exposed but whose Social Security numbers were not included—are eligible for an estimated $50 per person. Both of these amounts are pro-rata payments, meaning the actual dollar figure each claimant receives will depend on how many valid claims are filed in total.
Here is a critical detail: these per-person payments represent only the baseline compensation. On top of these amounts, both subclasses can pursue additional reimbursement for documented out-of-pocket losses related to identity theft—such as credit monitoring fees, fraudulent charge dispute costs, or expenses from stolen account takeovers—up to a maximum of $5,000 per person per subclass. For example, if an SSN Subclass member pays $200 out of pocket for credit monitoring and identity theft resolution services and can provide receipts, she could potentially receive the baseline $100 payment plus a separate reimbursement for the $200 in losses. The settlement fund itself is capped at $3.5 million and must also cover attorneys’ fees and claims administration costs, which typically consume 25 to 35 percent of the total fund depending on claim volume and fee awards.
What Out-of-Pocket Loss Claims Require and How to Document Them
Submitting a claim for out-of-pocket identity-theft losses is optional but requires supporting documentation. Self-written statements describing your losses—such as a note saying “I paid for credit monitoring”—will not be accepted. Instead, you must submit actual receipts, credit card statements, invoices, or other contemporaneous proof that shows the date, vendor, amount, and nature of the expense. Examples of qualifying losses include fees paid to identity-theft resolution services, credit monitoring subscriptions purchased in response to the breach, costs to place a fraud alert or security freeze with credit bureaus, and reimbursements for items purchased fraudulently using your identity (though your credit card company may have already refunded the charge).
The $5,000 per-person cap applies regardless of the actual expenses incurred. If you suffered more than $5,000 in identity-theft losses, the settlement will only reimburse up to $5,000; you would not be able to recover the excess through this settlement, though you might pursue other legal remedies. Importantly, you cannot claim reimbursement for costs incurred before the March 10, 2023 notification date, since the settlement only covers losses that arise after you knew of the breach. Also, you cannot stack claims across both subclasses—if you are an SSN Subclass member, you receive that subclass’s per-person payment plus any approved out-of-pocket reimbursement, not multiple payments.
How to File Your Claim and Meet the Critical Filing Deadline
To participate in this settlement, you must submit a claim form on or before September 2, 2026. The deadline is firm; claims submitted after September 2, 2026 will be rejected, and no exceptions are typically granted unless you can demonstrate extraordinary circumstances (such as a serious illness that prevented you from filing). You can file your claim online through the settlement website or by mailing a paper claim form to the claims administrator. The claim form will ask for basic personal information (name, address, date of birth, email), confirmation that you received the ZOLL breach notification, which subclass you belong to (SSN or Non-SSN), and, if applicable, documentation of out-of-pocket losses. If you do not file a claim by September 2, 2026, you will not receive any settlement money, but you will still be bound by the settlement unless you opt out.
The opt-out deadline is August 3, 2026—earlier than the claim filing deadline—so if you want to stay out of the settlement and pursue an individual lawsuit (which is not practical for most people given the costs involved), you must submit an opt-out request by August 3. The final approval hearing is scheduled for September 10, 2026 at 2:30 p.m. Eastern Time at the U.S. District Court for the District of Massachusetts in Boston. At this hearing, the judge will review the settlement terms and decide whether to grant final approval, at which point the settlement becomes binding on all non-opted-out class members.
Common Claim Rejection Reasons and Documentation Mistakes to Avoid
Claims are rejected most often for three reasons. First, the claimant did not provide sufficient proof of identity or eligibility—for example, no proof that they received the ZOLL notification letter or no confirmation that their personal information was in ZOLL’s breach database. Second, the claimant submitted a claim after the September 2, 2026 deadline. Third, the claimant’s documentation of out-of-pocket losses is incomplete or vague—receipts are missing, or the expense does not clearly relate to the breach (such as a general credit monitoring service purchased years earlier, not in response to this specific breach).
A common trap is submitting receipts or statements that lack a date or amount, or that refer only vaguely to “identity theft services” without specifics. Credit card statements or bank statements that show a charge to “ABC Security Corp” without explanation of what service was provided may not be accepted; the claims administrator needs clarity that the expense is a direct result of this breach. Similarly, if you incurred out-of-pocket losses from identity theft that occurred before you received the March 10, 2023 notification, those losses will not be reimbursed even if you report them now, because they cannot be causally tied to this specific breach incident. Finally, do not assume that your claim is automatically approved once you file—the claims administrator will review each claim and may request additional documentation if the initial submission is incomplete.
The Prior ZOLL Medical Breach and Repeat Offender Concerns
ZOLL Medical disclosed a previous major data breach in 2018, affecting approximately 277,000 users. That earlier breach resulted from unauthorized access through a vulnerability in a third-party software vendor’s system—a route that, while common, also suggests that ZOLL’s vendor management and network segregation may not have been state-of-the-art even after that incident. When the 2023 breach occurred, some class members and cybersecurity observers questioned whether ZOLL had implemented sufficient security enhancements following the 2018 incident.
In settlement negotiations, ZOLL did not admit negligence or wrongdoing but agreed to pay $3.5 million in part to avoid the uncertainty and cost of litigation. The settlement also does not prevent ZOLL from continuing to operate or use similar systems; it is a monetary resolution, not a mandate to overhaul security practices. For this reason, individuals who were affected by the 2018 breach and are now affected again by the 2023 breach may file separate claims for both events under their respective settlement agreements.
Settlement Timeline and What to Expect Before Final Approval
Preliminary approval of the settlement was granted on May 5, 2026, which allowed the settlement to move forward and the notice period to begin. From that point, class members had time to submit claim forms, opt out, or file objections. The claim filing deadline of September 2, 2026 and the opt-out/objection deadline of August 3, 2026 are the two key dates that directly affect your eligibility and compensation. The final approval hearing on September 10, 2026 is when the judge will review the final claim tally and approve the settlement for distribution.
After final approval, the claims administrator typically has 60 to 90 days to process all approved claims and issue payments. Payments are usually distributed by check or direct deposit to the account or address you provided on your claim form. If your address or payment information changes between now and distribution, you should update it with the claims administrator as soon as possible to avoid having a check returned as undeliverable. The settlement website, typically maintained by the claims administrator, will provide updates on the status of the claims processing and the expected payment date, so monitor that resource in the fall and winter of 2026.
- —
Sources
- ZOLL Medical Data Breach Settlement — Claim 2026 — full settlement breakdown, with eligibility, payout tiers and filing steps, from our sister site OpenClassActions.com.
You Might Also Like
- Vector Security Data Breach Settlement: Eligibility and Claim Details
- Equinox $685,000 Data Breach Settlement: Claim Eligibility and Deadlines
- Costco $14 Million Email Settlement: Washington Consumers May Qualify