The Somnia data breach settlement is a $2.425 million class action resolution covering more than 450,000 patients whose personal and medical information was exposed when unauthorized actors accessed Somnia Inc.’s systems on or about July 11, 2022. The U.S. District Court for the Southern District of New York granted final approval in Chabak, et al. v. Somnia Inc., et al. (No. 7:22-cv-09341-PMH) on April 28, 2025, and payments to approved claimants were scheduled to go out by the second week of June 2025.
What Happened in the Breach
On or about July 11, 2022, intruders accessed Somnia’s systems and compromised data belonging to patients who had received anesthesiology services through practices Somnia manages. The exposed information included names, dates of birth, Social Security numbers, driver’s license numbers, financial account information, health insurance policy numbers, medical record numbers, Medicaid and Medicare IDs, and personal health information.
Somnia manages anesthesia practices across more than nine states, and the affected group spans dozens of them, from Resource Anesthesiology Associates locations in New York, New Jersey, and California to smaller regional groups such as Hazleton Anesthesia Services, Grayling Anesthesia Associates, and Anesthesia Associates of El Paso. Somnia has not admitted wrongdoing.
Who Was Eligible
The settlement class covers all U.S. residents whose personal information was compromised in the July 11, 2022 incident. In practical terms, that means patients treated by any Somnia-managed practice, in states including New York, New Jersey, California, Maryland, Ohio, Pennsylvania, Indiana, Virginia, Connecticut, Missouri, Michigan, New Mexico, North Carolina, Washington, Kentucky, Massachusetts, and Texas.
Defendants, their corporate affiliates, officers and directors, the presiding judge and his family, and anyone who timely opted out were excluded. The deadline to opt out or object was December 2, 2024, and the claim filing deadline was January 2, 2025. Those windows have closed; late claims are not accepted.
What Claimants Could Recover
Class members who filed a valid, timely claim were eligible for two kinds of payment out of the settlement fund.
The first was reimbursement of out-of-pocket losses up to $2,500. Documented, unreimbursed expenses traceable to the breach qualified, including identity theft costs, bank fees, credit monitoring purchases, credit freeze fees, costs to replace government-issued IDs, and professional fees for identity theft assistance. Lost time could be claimed at $20 per hour, up to 20 documented hours ($400 maximum), or up to 5 self-certified hours ($100 maximum) where the claimant could document fraud but not the specific time spent. Bank statements, receipts, and correspondence from financial institutions were the kind of documentation required.
The second was a default pro rata cash payment available to every participating class member, including those who also claimed out-of-pocket losses. California residents received three shares of the remaining fund; non-California residents received one share. The dollar value per share depended on participation rates and the total paid on documented-loss claims. All amounts were subject to pro rata reduction if approved claims exceeded the fund balance after fees, expenses, and service awards.
The $2,425,000 fund covers all class member payments together with attorneys’ fees and expenses and service awards. The court awarded $1,000,000 in attorneys’ fees, $50,295 in litigation expenses, and $1,000 service awards to each of the nine named plaintiffs.
When Payments Go Out
Following final approval on April 28, 2025, the administrator was scheduled to issue payments to approved claimants by the second week of June 2025. The settlement notice cautioned that no distribution could occur until final approval became effective and any appeals were resolved.
The Allegations Behind the Settlement
Lead plaintiff Irene Chabak filed the initial complaint on October 31, 2022, and the court consolidated six related cases in January 2023. The amended complaint named Somnia Inc. along with five affiliated practice entities: Anesthesia Services of San Joaquin P.C., Palm Springs Anesthesia Services P.C., Resource Anesthesiology Associates of IL P.C., Resource Anesthesiology Association of NM Inc., and Anesthesia Associates of El Paso, P.A.
Plaintiffs asserted negligence, negligence per se, breach of confidence, and unjust enrichment, along with California-specific claims under the Confidentiality of Medical Information Act and the Consumer Legal Remedies Act. The original complaint alleged that Somnia “intentionally, willfully, recklessly or negligently” failed to secure its data systems and owed duties under HIPAA, industry standards, and its own representations to patients. Plaintiffs also alleged that breach notification letters were delayed and “extremely vague,” and that Somnia used local practice names in its notices in a way that obscured the responsible entity. The complaint invoked the Federal Trade Commission Act, arguing that inadequate data security amounted to an unfair act or practice, and asserted that Somnia failed to use intrusion detection systems or monitor for suspicious activity.