GRIPA MOVEit Data Breach Settlement: Up to $12,500 for Exposed PHI and PII

The GRIPA MOVEit Data Breach Settlement: Up to $12,500 for Exposed PHI and PII settlement offers $2.15M in total, with individual payouts of $12.50K to eligible claimants who you are a gripa patient or an individual health care provider/physician in the united states whose personally identifiable information and/or protected health information was potentially impacted by the moveit breach.. The deadline to file is September 3, 2026. Proof of purchase is required.
Deadline: September 3, 2026
Total amount allocated for all claims
Estimated amount per eligible claim
For ordinary or extraordinary loss reimbursement, provide documentation showing the loss amount and how it is reasonably attributable to the MOVEit data breach (e.g., receipts, bank/credit card statements, invoices/records for out-of-pocket expenses; proof of purchase for credit monitoring or identity theft insurance; and invoices/statements for professional fees such as attorney, accountant, or credit repair charges). For online claims, include the claimant ID and PIN from the settlement notice. For alternative cash payment or identity theft/monitoring options, complete the claim form by attesting to eligibility and selecting the requested option.
Settlement Summary
In May 2023, a cyberattack exposed sensitive information tied to Greater Rochester Independent Practice Association (GRIPA) users after attackers exploited a known vulnerability in MOVEit, a widely used file-transfer software platform. People received notices saying the breach may have compromised personally identifiable information (like names, dates of birth, and Social Security numbers) and protected health information (including details about health and treatment, insurance information, prescription records, and the identity of prescribers). This kind of breach is especially serious because it can enable identity theft, medical fraud, and other harmful activity for both patients and health care professionals. The lawsuit was filed as a class action to seek compensation for the alleged failure to adequately protect that data, claiming GRIPA’s security practices were negligent and that the exposure led to measurable losses such as out-of-pocket expenses, time spent dealing with the fallout, and documented professional costs (for example, attorney or credit-repair fees). GRIPA agreed to settle for $2.15 million—without admitting wrongdoing—to resolve claims and distribute potential benefits, which can include up to $2,500 for ordinary losses, up to $10,000 for extraordinary losses, an estimated cash alternative (roughly $100 to $1,000 depending on claims and deductions), and two years of identity theft and monitoring services with medical identity theft insurance. Beyond this case, MOVEit-related incidents have generated similar litigation across the health care industry, reflecting a broader trend: regulators and courts increasingly scrutinize whether organizations meet security and breach-handling obligations under HIPAA and related rules, including requirements to protect electronic protected health information and respond appropriately to breaches, even when the initial intrusion stems from third-party software vulnerabilities. These settlements also highlight the practical compliance reality for health providers and insurers: as HIPAA’s Security Rule and broader state privacy laws push organizations toward stronger technical safeguards (and documented risk management), incidents like this can lead to both direct consumer relief and indirect pressure to improve vendor management, patching, access controls, and monitoring for third-party systems. Here, the class settlement’s structure—non-reversionary funds, claim documentation standards, and identity protection components—aims to compensate people while signaling that data security failures can carry legal and financial consequences, and it underscores why MOVEit exploit cases have become a touchstone for how the health care sector addresses cyber risk and patient trust
Entities Involved
Related Topics
Eligibility Requirements
- You are a GRIPA patient or an individual health care provider/physician in the United States whose personally identifiable information and/or protected health information was potentially impacted by the MOVEit breach.
- You received notice from GRIPA about the MOVEit data breach (class membership is tied to those notices).
- If filing online, you must provide the claimant ID and PIN from your settlement notice.
- Claims for reimbursement must include documentation showing the amount of the loss and how it is reasonably attributable to the MOVEit data breach.
- If choosing the alternative cash payment/identity theft-related option, you must attest to your eligibility and select the appropriate option on the claim form.
Featured Investigations
Important Notice About Filing Claims
Submitting false information in a settlement claim is considered perjury and will result in your claim being rejected. Fraudulent claims harm legitimate class members and may result in legal consequences.
If you are unsure about your eligibility for this settlement, please visit the official settlement administrator’s website using the link provided above. Review the eligibility criteria carefully before submitting a claim.
Class Action Champion is an independent information resource and is not affiliated with any settlement administrator, law firm, or court. We provide settlement information as a service to help connect eligible class members with legitimate settlements.
