MedStar Settlement: Eligibility, Claims, and Key Dates

The MedStar settlement most searches point to is a $1.35 million class action resolving claims that a 2023 data breach at MedStar Health exposed the personal information of roughly 183,000 patients. A federal judge in Maryland granted final approval on November 4, 2025, and Kroll Settlement Administration mailed checks to approved claimants on December 24, 2025.1Mealey’s Litigation Report. Federal Judge Grants Final Approval of $1.35M Settlement of Data Breach Suit2MedStarSettlement.com. MedStar Settlement Home

What the Case Was About

Between January 25, 2023, and October 2023, an unauthorized third party accessed the email accounts of three MedStar Health employees. The intrusion potentially exposed the sensitive personal information of 183,079 patients, including health insurance and provider information.3HIPAA Journal. MedStar Health Data Breach Settlement4Bloomberg Law. MedStar $1.35 Million Data Breach Settlement Gets Final Approval MedStar disclosed the breach to affected individuals on May 4, 2024, and Gwendolyn Riddick and other named plaintiffs sued three days later in the U.S. District Court for the District of Maryland.5PACER Monitor. Riddick v MedStar Health, Inc The consolidated case, In re MedStar Health Data Security Incident Litigation, alleged MedStar failed to adequately protect patient data. MedStar agreed to create a non-reversionary $1,350,000 settlement fund without admitting wrongdoing.6ClassAction.org. Riddick v MedStar Health Inc Settlement Agreement

Who Qualified

The class covered all U.S. residents whom MedStar Health identified as having personal information involved in the breach that occurred between January 25, 2023, and October 18, 2023. Eligible people received notice by mail or email containing a unique class member ID needed to file a claim.7MedStar Health. Class Action Settlement Notice Only four people opted out.4Bloomberg Law. MedStar $1.35 Million Data Breach Settlement Gets Final Approval

What Class Members Could Claim

Claimants chose one of three benefits.

Documented-loss claims and monitoring costs were paid first out of the net settlement fund, with alternate cash payments drawn from whatever remained.6ClassAction.org. Riddick v MedStar Health Inc Settlement Agreement

Key Dates

The deadline to opt out or object was September 15, 2025. The claim filing deadline was October 14, 2025. The court granted preliminary approval on June 16, 2025, and final approval on November 4, 2025, finding the deal “fair, reasonable, and adequate” under Federal Rule of Civil Procedure 23.10ClassAction.org. Riddick v MedStar Health Inc Preliminary Approval1Mealey’s Litigation Report. Federal Judge Grants Final Approval of $1.35M Settlement of Data Breach Suit Payments went out on December 24, 2025. Uncashed checks become void after June 16, 2026.2MedStarSettlement.com. MedStar Settlement Home

If Your Notice Was About the 2025 Ransomware Breach

A separate, much larger incident is not covered by this settlement. Between September 12 and September 16, 2025, the ransomware group Rhysida accessed MedStar’s systems. MedStar discovered the intrusion on October 4, 2025, and began mailing patient notifications on December 3, 2025.11MedStar Health. Data Incident12ISMG. MedStar Amended Rhysida Breach Complaint A consolidated case, In re: MedStar Health 2025 Data Security Litigation (No. 1:25-cv-03325), is pending in the U.S. District Court for the District of Maryland, with MedStar’s motion to dismiss filed on March 16, 2026, and no ruling issued as of early April 2026.13Justia. In Re: MedStar Health 2025 Data Security Litigation MedStar has offered complimentary identity monitoring to patients whose Social Security or driver’s license numbers were compromised in that incident.

Other MedStar Settlements

Two other MedStar cases resolved recently are unrelated to the data breach.

In September 2024, Judge James K. Bredar granted final approval to an $11.8 million settlement in In re MedStar ERISA Litigation (No. 1:20-cv-01984-JKB), which alleged MedStar mismanaged its 403(b) retirement plan. MedStar denied the allegations.14Law360. MedStar’s $11.8M ERISA Deal Gets Final OK15Strategic Claims Services. MedStar ERISA Litigation Settlement Notice

In January 2024, the Department of Justice announced a $440,000 consent decree resolving allegations that MedStar’s COVID-19 visitor restrictions violated Title III of the Americans with Disabilities Act by preventing support persons from accompanying patients with disabilities such as dementia, intellectual disabilities, and autism spectrum disorder. Up to $200,000 of the fund went to DOJ-designated individuals, with at least $240,000 distributed pro rata to additional claimants. MedStar also agreed to revise its policies, provide annual ADA training to staff with a passing score of at least 80 percent, and submit semi-annual compliance reports for three years. MedStar denied violating the ADA.16U.S. Department of Justice. Justice Department Secures Agreement With MedStar Health Inc to Provide People With Disabilities Equal Access17U.S. Department of Justice. Consent Decree – U.S. v. MedStar Health Inc