Okanogan Behavioral Healthcare Data Breach Settlement Up to 5300 for Patient Info

The Okanogan Behavioral Healthcare Data Breach Settlement Up to 5300 for Patient Info settlement, with individual payouts of $300 to $5.30K to eligible claimants who be a current or former patient who received a written notice from okanogan behavioral healthcare about a data breach discovered in may 2024. The deadline to file is September 3, 2026. Proof of purchase is required.
Deadline: September 3, 2026
Total amount allocated for all claims
Estimated amount per eligible claim
Online claims require the unique ID and PIN from the notice. Ordinary losses reimbursement up to $300 requires documentation such as receipts/statements and other proof of unreimbursed expenses incurred between May 13, 2024 and May 7, 2026 (examples include bank fees, postage, gas/mileage). Extraordinary losses reimbursement up to $5,000 requires documentation showing the breach is related to the losses and that reasonable efforts were made to avoid or seek reimbursement; examples include invoices for services, bank/credit card statements showing fraudulent charges, police reports, and proof of identity theft/fraud. Fraud-related proof should connect the monetary harm to the alleged breach.
Settlement Summary
Okanogan Behavioral Healthcare is settling a class action stemming from a cybersecurity incident it says was discovered in May 2024, after which certain current and former patients received written notices that their personal and protected health information may have been accessed without authorization. Depending on the notice, the potentially exposed data included names, addresses, Social Security numbers, dates of birth, driver’s license numbers, and medical or treatment details as well as health insurance information—highly sensitive records that can be used for identity theft or fraud. Because healthcare providers handle protected health information, incidents like this often trigger concerns under industry rules such as the Health Insurance Portability and Accountability Act (HIPAA), and related security and breach-handling expectations, which require safeguards and prompt responses when data exposure occurs. The lawsuit was filed by a plaintiff alleging the breach resulted from inadequate cybersecurity protections and potentially caused patients to suffer real-world harms, prompting the case’s significance: it offers a structured way for affected people to seek compensation without having to prove damages individually in court. Under the settlement, eligible class members can claim up to $300 for documented ordinary out-of-pocket losses, up to $5,000 for documented extraordinary losses linked to the breach, and most can also choose two years of identity and credit monitoring services (with an insurance component). Those who don’t claim monitoring can seek a one-time cash payment of $50, and claims must be filed by Sept. 3, 2026, making the settlement a practical—though limited—route to reimbursement for expenses and fraud-related impacts that often follow data breaches. More broadly, this case fits a wider pattern in the U.S. where healthcare organizations face class actions after breaches, even when the company disputes wrongdoing, because settlement can reduce legal costs and uncertainty. Similar lawsuits frequently focus on whether reasonable security measures were in place, whether patient information was sufficiently protected, and whether affected individuals can show how the incident led to monetary harm—issues that keep recurring across the sector as regulators and courts continue to scrutinize cybersecurity practices, incident response, and data-handling controls in an environment where ransomware, third-party risk, and system misconfigurations are common causes of breaches.
Entities Involved
Related Topics
Eligibility Requirements
- Be a current or former patient who received a written notice from Okanogan Behavioral Healthcare about a data breach discovered in May 2024
- The notice must indicate the breach may have compromised the individual’s private/protected health information
- For reimbursement: submit a valid claim and provide required documentation for ordinary and/or extraordinary losses
- For extraordinary losses: demonstrate the losses were most likely caused by the breach and that reasonable efforts were made to avoid or seek reimbursement
Featured Investigations
Important Notice About Filing Claims
Submitting false information in a settlement claim is considered perjury and will result in your claim being rejected. Fraudulent claims harm legitimate class members and may result in legal consequences.
If you are unsure about your eligibility for this settlement, please visit the official settlement administrator’s website using the link provided above. Review the eligibility criteria carefully before submitting a claim.
Class Action Champion is an independent information resource and is not affiliated with any settlement administrator, law firm, or court. We provide settlement information as a service to help connect eligible class members with legitimate settlements.
