Arietis Health Data Settlement: MOVEit Breach and Payouts

The Arietis Health data breach settlement is a $2.8 million class action resolution covering roughly 1.97 million people whose personal and medical information was exposed in the May 2023 MOVEit cyberattack. A federal judge granted final approval on April 3, 2025, and the deadline to file a claim has already passed.1Arietis Data Settlement. Arietis Health Data Breach Settlement If you received a notice but didn’t submit a claim by April 3, 2025, you are no longer eligible to receive a payment or free monitoring under this settlement.

What the Settlement Offered

Class members who filed a valid claim by the deadline could choose from three benefits, and could combine the cash options with the monitoring option:2ClassAction.org. $2.8M Arietis Health Settlement Wraps Up MOVEit Data Breach Class Action Lawsuit

  • Reimbursement of up to $5,000 for documented out-of-pocket losses that were “more likely than not” caused by the breach, supported by receipts, bank statements, or similar records.
  • Up to four hours of lost time at $25 per hour, capped at $100, for time spent responding to the breach notification.
  • Four years of medical data monitoring, one-bureau credit monitoring, and identity theft protection, plus $1 million in medical identity theft insurance with no deductible.3Arietis Data Settlement. Arietis Health Data Breach Settlement FAQ

Choosing only the monitoring services did not come with a cash payment. Attorneys’ fees were expected to take about one-third of the $2.8 million fund.4HIPAA Journal. Arietis Health Data Breach Settlement MOVEit

Who Was Covered

The settlement class included all U.S. individuals whose personal information was in files affected by the May 2023 MOVEit incident involving Arietis Health. According to the HHS Office for Civil Rights HIPAA breach portal, 1,975,066 people were affected.5HIPAA Journal. Arietis Health Notifies 54 Entities About Exposure of Patient Data Most were patients of practices affiliated with NorthStar Anesthesia, an Irving, Texas-based anesthesia staffing company for which Arietis handled billing. The breach touched 54 healthcare entities in more than 20 states, spanning anesthesia, pain management, and gastroenterology practices.6BankInfoSecurity. NorthStar/Arietis Breach

The information exposed was extensive. It included names, dates of birth, Social Security numbers, driver’s license or state ID numbers, addresses, and parents’ maiden names; medical record and patient account numbers, diagnosis and treatment information, clinical and prescription details, provider information, and digital signatures; and health insurance account and group numbers along with Medicare and Medicaid numbers.3Arietis Data Settlement. Arietis Health Data Breach Settlement FAQ

How the Breach Happened

Arietis Health, a Fort Myers, Florida-based medical billing and coding company, used Progress Software’s MOVEit Transfer tool to move files.7ClassAction.org. Swekoski v. Arietis Health, LLC et al.8CISA. StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability6BankInfoSecurity. NorthStar/Arietis Breach

Progress notified Arietis of the flaw on May 31 and Arietis patched its server that day, but the attackers were already in. Arietis confirmed on July 26, 2023, that patient files had been taken, told its client NorthStar Anesthesia on August 3, and began sending notices to affected patients on September 29.6BankInfoSecurity. NorthStar/Arietis Breach The lawsuits that followed alleged Arietis had inadequate data security in place before the breach and waited more than two months after confirming the compromise to notify patients.7ClassAction.org. Swekoski v. Arietis Health, LLC et al. Arietis agreed to pay $2.8 million without admitting wrongdoing.9Cohen Milstein. Medical Tech Co. Exits MOVEit Hack MDL for $2.8M

Current Status of the Case

Judge Allison D. Burroughs of the U.S. District Court for the District of Massachusetts held the final approval hearing on April 3, 2025. No class members objected, and only 34 of the nearly two million affected individuals opted out.10Arietis Data Settlement. Declaration of Cameron R. Azari in Support of Final Approval The court approved the settlement, certified the class, and granted the attorneys’ fees motion the same day.11PACER Monitor. Swekoski v. Progress Software Corporation et al. The claim window has closed, and the settlement administrator’s site confirms that final approval has been granted.1Arietis Data Settlement. Arietis Health Data Breach Settlement The Arietis case was consolidated into the broader MOVEit multidistrict litigation, In Re: MOVEit Customer Data Security Breach Litigation (Case No. 1:23-md-03083-ADB).3Arietis Data Settlement. Arietis Health Data Breach Settlement FAQ

Other MOVEit Settlements You May Be Eligible For

The MOVEit campaign hit more than 2,500 organizations and over 67 million people worldwide, and Arietis was only the first defendant to reach final approval.12Cohen Milstein. In Re: MOVEit Customer Data Security Breach Litigation If you received notices from other companies about the same 2023 MOVEit incident, one of these separate settlements may still apply to you:

Progress Software, which built MOVEit, is still in active litigation. On July 31, 2025, Judge Burroughs largely denied motions to dismiss in bellwether cases against Progress and other defendants, letting claims for negligence, breach of contract, unjust enrichment, and various state consumer protection violations proceed.12Cohen Milstein. In Re: MOVEit Customer Data Security Breach Litigation If your data was exposed by a MOVEit user that has not yet settled, that ongoing litigation may eventually produce a claims process you can join. Check the notice you received or the specific defendant’s settlement website for deadlines.