The Arietis Health data breach settlement is a $2.8 million class action resolution covering roughly 1.97 million people whose personal and medical information was exposed in the May 2023 MOVEit cyberattack. A federal judge granted final approval on April 3, 2025, and the deadline to file a claim has already passed.1Arietis Data Settlement. Arietis Health Data Breach Settlement If you received a notice but didn’t submit a claim by April 3, 2025, you are no longer eligible to receive a payment or free monitoring under this settlement.
What the Settlement Offered
Class members who filed a valid claim by the deadline could choose from three benefits, and could combine the cash options with the monitoring option:2ClassAction.org. $2.8M Arietis Health Settlement Wraps Up MOVEit Data Breach Class Action Lawsuit
- Reimbursement of up to $5,000 for documented out-of-pocket losses that were “more likely than not” caused by the breach, supported by receipts, bank statements, or similar records.
- Up to four hours of lost time at $25 per hour, capped at $100, for time spent responding to the breach notification.
- Four years of medical data monitoring, one-bureau credit monitoring, and identity theft protection, plus $1 million in medical identity theft insurance with no deductible.3Arietis Data Settlement. Arietis Health Data Breach Settlement FAQ
Choosing only the monitoring services did not come with a cash payment. Attorneys’ fees were expected to take about one-third of the $2.8 million fund.4HIPAA Journal. Arietis Health Data Breach Settlement MOVEit
Who Was Covered
The settlement class included all U.S. individuals whose personal information was in files affected by the May 2023 MOVEit incident involving Arietis Health. According to the HHS Office for Civil Rights HIPAA breach portal, 1,975,066 people were affected.5HIPAA Journal. Arietis Health Notifies 54 Entities About Exposure of Patient Data Most were patients of practices affiliated with NorthStar Anesthesia, an Irving, Texas-based anesthesia staffing company for which Arietis handled billing. The breach touched 54 healthcare entities in more than 20 states, spanning anesthesia, pain management, and gastroenterology practices.6BankInfoSecurity. NorthStar/Arietis Breach
The information exposed was extensive. It included names, dates of birth, Social Security numbers, driver’s license or state ID numbers, addresses, and parents’ maiden names; medical record and patient account numbers, diagnosis and treatment information, clinical and prescription details, provider information, and digital signatures; and health insurance account and group numbers along with Medicare and Medicaid numbers.3Arietis Data Settlement. Arietis Health Data Breach Settlement FAQ
How the Breach Happened
Arietis Health, a Fort Myers, Florida-based medical billing and coding company, used Progress Software’s MOVEit Transfer tool to move files.7ClassAction.org. Swekoski v. Arietis Health, LLC et al.8CISA. StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability6BankInfoSecurity. NorthStar/Arietis Breach
Progress notified Arietis of the flaw on May 31 and Arietis patched its server that day, but the attackers were already in. Arietis confirmed on July 26, 2023, that patient files had been taken, told its client NorthStar Anesthesia on August 3, and began sending notices to affected patients on September 29.6BankInfoSecurity. NorthStar/Arietis Breach The lawsuits that followed alleged Arietis had inadequate data security in place before the breach and waited more than two months after confirming the compromise to notify patients.7ClassAction.org. Swekoski v. Arietis Health, LLC et al. Arietis agreed to pay $2.8 million without admitting wrongdoing.9Cohen Milstein. Medical Tech Co. Exits MOVEit Hack MDL for $2.8M
Current Status of the Case
Judge Allison D. Burroughs of the U.S. District Court for the District of Massachusetts held the final approval hearing on April 3, 2025. No class members objected, and only 34 of the nearly two million affected individuals opted out.10Arietis Data Settlement. Declaration of Cameron R. Azari in Support of Final Approval The court approved the settlement, certified the class, and granted the attorneys’ fees motion the same day.11PACER Monitor. Swekoski v. Progress Software Corporation et al. The claim window has closed, and the settlement administrator’s site confirms that final approval has been granted.1Arietis Data Settlement. Arietis Health Data Breach Settlement The Arietis case was consolidated into the broader MOVEit multidistrict litigation, In Re: MOVEit Customer Data Security Breach Litigation (Case No. 1:23-md-03083-ADB).3Arietis Data Settlement. Arietis Health Data Breach Settlement FAQ
Other MOVEit Settlements You May Be Eligible For
The MOVEit campaign hit more than 2,500 organizations and over 67 million people worldwide, and Arietis was only the first defendant to reach final approval.12Cohen Milstein. In Re: MOVEit Customer Data Security Breach Litigation If you received notices from other companies about the same 2023 MOVEit incident, one of these separate settlements may still apply to you:
- National Student Clearinghouse: $9.95 million, final approval in May 2025. Claims allowed up to $12,500 in documented losses plus two years of credit monitoring.13Cohen Milstein. Student Clearinghouse Gets Final OK for $10M Breach Deal
- Nuance Communications, a Microsoft subsidiary: $8.5 million covering roughly 1.225 million patients, preliminarily approved in August 2025. Options included a $100 alternative cash payment or up to $10,000 for documented extraordinary losses.14Cohen Milstein. Microsoft Unit Agrees to Pay $8.5M in MOVEit Hack MDL
- Cadence Bank: $5.25 million, announced December 2025.12Cohen Milstein. In Re: MOVEit Customer Data Security Breach Litigation
- Bank of America and EY: $2.5 million covering roughly 200,000 people, announced April 2026.12Cohen Milstein. In Re: MOVEit Customer Data Security Breach Litigation
- Nebraska Bank: $2.4 million, reached March 2026.12Cohen Milstein. In Re: MOVEit Customer Data Security Breach Litigation
Progress Software, which built MOVEit, is still in active litigation. On July 31, 2025, Judge Burroughs largely denied motions to dismiss in bellwether cases against Progress and other defendants, letting claims for negligence, breach of contract, unjust enrichment, and various state consumer protection violations proceed.12Cohen Milstein. In Re: MOVEit Customer Data Security Breach Litigation If your data was exposed by a MOVEit user that has not yet settled, that ongoing litigation may eventually produce a claims process you can join. Check the notice you received or the specific defendant’s settlement website for deadlines.