The Octapharma Plasma data breach settlement is a $2.55 million class action resolution in Woodall v. Octapharma Plasma, Inc., resolving claims that a April 2024 ransomware attack exposed the personal and medical information of roughly 272,000 plasma donors and employees. Judge Max O. Cogburn Jr. of the U.S. District Court for the Western District of North Carolina granted final approval on December 23, 2025, and the settlement administrator began issuing payments in February 2026.
Who Was Covered
The settlement class included all living U.S. residents who received a notice from Octapharma stating that their personal information may have been compromised in the April 2024 breach. Current and former employees, officers, and directors of Octapharma, along with the presiding judge and court staff, were excluded.
The information accessed in the breach was extensive. For donors, it included names, addresses, dates of birth, Social Security numbers, health information, donor eligibility information, and financial information. For employees, it included passports, employment contracts, contact details, family information, and medical examination records. General company records were also taken.
Iowa’s breach notification disclosed roughly 1,423 affected residents in that state alone, and a preliminary approval filing put the nationwide count at approximately 272,000.
What Class Members Could Claim
Class members chose between two cash options and could add a California payment and credit monitoring on top.
- Reimbursement of documented out-of-pocket losses tied to the breach, up to $5,000, with valid documentation. Losses already reimbursed elsewhere did not qualify.
- A flat cash payment estimated at $100, offered as an alternative to the documented-loss claim. A class member could take one or the other, not both.
- An additional $50 flat payment for individuals who lived in California as of April 17, 2024. This stacked with either cash option above.
- Three years of three-bureau real-time credit monitoring, medical identity monitoring, public record monitoring, dark web scanning, and identity theft insurance with no deductible. This could be claimed alongside a cash payment.
All cash payments were subject to pro rata adjustment, so the final amounts could rise or fall depending on how many valid claims came in. Class counsel sought roughly $842,000 in fees, about one-third of the net settlement fund, along with expenses and service awards for the named representatives. Octapharma also agreed to strengthen its cybersecurity going forward.
Key Dates
The claim filing deadline was November 14, 2025. Claims were submitted through a portal hosted by Verita Connect, accessed through OPIDataSettlement.com, using the claim ID and PIN printed on each class member’s notice. Judge Cogburn held the final approval hearing on December 4, 2025, with no publicly reported objections. The court terminated the case on December 23, 2025, and payments to approved claimants began going out in February 2026.
If you did not file a claim by the November 14, 2025 deadline, the claims window is closed and no further payments are available under this settlement.
How the Breach Happened
Octapharma Plasma detected suspicious activity on its IT systems on April 17, 2024. An investigation concluded that an unauthorized third party had accessed sensitive donor and employee information. The BlackSuit ransomware group, which security researchers have linked to a rebrand of the Royal ransomware gang, claimed responsibility and said it had exploited vulnerabilities in VMware systems to encrypt files and steal data. BlackSuit is known for double-extortion tactics, threatening to publish stolen data on a leak site if a ransom goes unpaid; as of late April 2024, Octapharma had not appeared on that leak site, though the group publicly claimed to hold the data.
The company temporarily shut down more than 190 plasma donation centers across 35 states while it restored critical systems. Octapharma reported the incident to the FBI and notified state regulators, including the attorneys general of California and Iowa. A joint threat bulletin from the American Hospital Association and Health-ISAC confirmed that sensitive donor information and protected health information had been stolen.
The Lawsuit
Bret Woodall filed the first class action complaint on April 26, 2024, nine days after Octapharma detected the intrusion. Additional suits followed and were consolidated as Woodall v. Octapharma Plasma, Inc., Case No. 3:24-cv-00424, in the Western District of North Carolina. The plaintiffs alleged that Octapharma failed to reasonably secure, monitor, and maintain the personal information it collected from donors and employees, and brought common law claims along with claims under consumer protection and data security statutes in California, Oregon, Illinois, and North Carolina.
Octapharma denied all claims and maintained there was no wrongdoing. According to the settlement agreement, the company agreed to settle to avoid the risks, uncertainty, and expense of continued litigation.