McKenzie Health System Data Breach Settlement Up to $4,000 for Patient Records

The McKenzie Health System Data Breach Settlement Up to $4,000 for Patient Records settlement, with individual payouts of $50 to $4K to eligible claimants who be a current or former patient in the united states whose private information was potentially compromised by the april 2025 cyberattack. The deadline to file is August 24, 2026. Proof of purchase is required.
Deadline: August 24, 2026
Total amount allocated for all claims
Estimated amount per eligible claim
Online claims require the login ID and PIN provided in the settlement notice. Claims for out-of-pocket losses must include supporting documentation such as receipts and/or bank or credit card statements showing unreimbursed fees or fraudulent charges, and/or evidence of identity theft or fraud connected to the breach. Claims that do not involve documented losses generally rely on submitting a claim for the alternative payment option.
Settlement Summary
In April 2025, McKenzie Memorial Hospital, doing business as McKenzie Health System, suffered a targeted cyberattack that potentially exposed sensitive patient information. Notices sent to affected people indicate the breach may have compromised the personal and protected health information of more than 58,000 individuals, including details such as dates of birth, Social Security numbers, and portions of medical records. For many patients, the worry doesn’t end at the hack itself—exposed data can be used for identity theft or fraud—so affected individuals were given the chance to seek recovery through a class action settlement. The lawsuit was filed by patients who alleged the hospital failed to adequately safeguard data before and during the attack, framing the case around the duty of healthcare organizations to protect sensitive information. Even though McKenzie Health denies wrongdoing, it agreed to settle to avoid the cost and uncertainty of further litigation, making the settlement significant because it offers compensation options and services without each person having to file a separate lawsuit. Claimants may seek reimbursement for documented out-of-pocket losses (up to $4,000) tied to the breach, or receive a simpler one-time payment if they don’t file for losses, and everyone can generally elect two years of credit monitoring and fraud protection, reflecting how courts and regulators increasingly treat data security failures as a consumer harm issue rather than a purely technical incident. Broader implications follow a familiar pattern in the healthcare industry: as hospitals and health systems digitize records, they must comply with safeguards under rules like HIPAA (the Health Insurance Portability and Accountability Act) and related guidance that require appropriate administrative, technical, and physical protections for protected health information. Similar class actions have emerged nationwide after breaches expose personally identifiable information and medical data, often leading to settlements that blend partial monetary recovery with credit monitoring, reflecting both the regulatory pressure on covered entities and the high risk of downstream fraud when highly sensitive data is compromised.
Entities Involved
Related Topics
Eligibility Requirements
- Be a current or former patient in the United States whose private information was potentially compromised by the April 2025 cyberattack
- Have received a notice letter about the incident (i.e., be included as a class member based on the notice)
- For the up to $4,000 cash option: submit a documented out-of-pocket losses claim for eligible expenses incurred between April 14, 2025 and Aug. 24, 2026 that are traceable to the data breach
- For the alternative cash option: submit a claim even if no documented losses are provided (one-time $50)
- For credit monitoring: choose the credit monitoring benefit option (available to all class members)
Featured Investigations
Important Notice About Filing Claims
Submitting false information in a settlement claim is considered perjury and will result in your claim being rejected. Fraudulent claims harm legitimate class members and may result in legal consequences.
If you are unsure about your eligibility for this settlement, please visit the official settlement administrator’s website using the link provided above. Review the eligibility criteria carefully before submitting a claim.
Class Action Champion is an independent information resource and is not affiliated with any settlement administrator, law firm, or court. We provide settlement information as a service to help connect eligible class members with legitimate settlements.
