Catholic Health patients exposed in a 2024 data breach can claim about $50 in cash, or up to $5,000 for losses, before September 1.

RDNE Stock project/Pexels

Nearly half a million people whose medical and personal information ran through Catholic Health, the large hospital system based in Buffalo, New York, are now eligible for a payment from a class-action settlement over a data breach in the fall of 2024. The deal offers two paths: a flat cash payment of roughly $50 that requires no paperwork, or reimbursement of up to $5,000 for anyone who can document money lost because of the breach. For older patients, whose exposed health and identity records can be exploited quietly for years, the detail that matters most is the calendar. Every claim has to be filed by September 1, 2026.

How the breach happened, and who is covered

The exposure did not originate inside the hospital’s own walls. It happened at Serviceaide, a technology vendor that handled data on Catholic Health’s behalf, when an unauthorized party reached its systems over a stretch of roughly seven weeks, from September 19 to November 5, 2024. The resulting agreement, valued at about $1.8 million, resolves the claims on behalf of an estimated 480,000 people without Serviceaide admitting any wrongdoing. In general, anyone who received a notice that their information was caught up in the incident falls within the class.

The core terms, including who qualifies and how to file, are laid out on the court-approved administrator’s official settlement site. That page is the authoritative place to confirm eligibility, review the two payment options, and submit a claim, and it is the only site a class member needs in order to collect. Everything about the deal, from the payment amounts to the deadline, traces back to the terms posted there.


Free for readers: Miss an enrollment or claim deadline and it’s gone. The free Retirement Shield newsletter keeps readers ahead of the ones that matter. Get the free newsletter.

Two ways to collect, and the trade-off between them

The settlement sets out two mutually exclusive options. The first is a flat cash payment, reported at about $50, that asks for no documentation and suits anyone who was notified but cannot point to a specific loss. The second is reimbursement of up to $5,000 for documented out-of-pocket costs tied to the breach. A claimant chooses one or the other, not both, and an independent summary of the Serviceaide settlement lays out how each option is calculated.

The larger reimbursement is built for people who can show real money spent, such as fraudulent charges, bank fees, the cost of a credit freeze, or hours spent untangling identity theft, and gathering statements and receipts before filing strengthens that kind of claim. Both amounts can be adjusted on a pro-rata basis depending on how many valid claims arrive, so the final figures may drift from the headline numbers. Filing costs nothing in either case, and no one should pay a company that offers to submit a claim in exchange for a share of the payout.

Filing is straightforward in either case. The settlement site offers an online form and a mail option, and it asks for the identifying details needed to match a claimant to the affected records, typically a notice number or class-member code printed on the breach letter. Anyone who no longer has that letter can still use the site to check whether their records fall within the class, and the administrator’s contact information is posted there for questions. Choosing an option and submitting before the deadline is all that the process requires, with nothing to buy and no fee to pay.

Why a breach from 2024 still carries real risk

Stolen personal data does not lose its value when a breach fades from the headlines. Names, dates of birth, contact details, and in many health-sector incidents Social Security numbers, insurance identifiers, and medical records can be bought, resold, and reused by criminals for years. That long tail is exactly why a settlement arriving well after the original incident still delivers something concrete, and why the protection wrapped around it can matter as much as the cash. Anyone who suspects their identity has already been misused can build a free, step-by-step recovery plan through the Federal Trade Commission’s IdentityTheft.gov, the government’s official reporting and recovery service.

Health-sector breaches carry a distinct danger beyond ordinary financial fraud. When medical and insurance identifiers are exposed, criminals can commit medical identity theft, using another person’s coverage to obtain care or prescriptions, which can corrupt a victim’s medical file and generate bills for services never received. Unwinding that is harder than reversing a fraudulent credit-card charge, and it is a particular risk for older adults who use their Medicare and insurance numbers frequently. Reviewing insurance statements and explanation-of-benefits notices for care that never happened is a sensible companion to watching a credit report.

For older adults especially, a data breach is a slow-burning threat rather than a single event, because a compromised Social Security number can surface in a fraudulent account opening long after the fact. A free credit freeze is the strongest routine defense. Placing one with each of the three nationwide credit bureaus blocks criminals from opening new accounts in a victim’s name, and the FTC’s guidance on credit freezes and fraud alerts explains how to set one up and lift it when needed. Taking that step alongside a settlement claim turns a one-time payout into lasting protection.

The deadline, and the trap hidden inside it

The settlement still needs final sign-off from the court, with an approval hearing scheduled for September 16, 2026. The claim deadline comes first, on September 1, 2026, and that gap is where people lose money. A claim can feel safe to postpone because the case is not yet final, yet the right to file closes more than two weeks before the judge weighs in, and a claim submitted after September 1 will not be paid no matter how the approval turns out. As of late July 2026, the window remains open.

What an eligible patient should do now

The practical path is short. Anyone who received a breach notice from Catholic Health or Serviceaide should confirm eligibility on the official settlement site, decide between the no-proof cash payment and the documented-loss reimbursement, and file before the September 1 cutoff. Those who kept their notification letter will move faster, since it typically carries a class-member code used to match a person to the affected records. As with any publicized payout, impostors follow the money, so a call or email demanding a fee or bank login to process a claim is a warning sign, not a step in the real process. Checking the record and filing on time is the difference between collecting and letting a rare chance at compensation slip away.


Free for readers: Every year, billions in settlements and unclaimed money go unclaimed. The free Retirement Shield newsletter sends the real ones — with deadlines — a couple times a week. Get the newsletter free.

This article was researched and drafted with AI assistance and reviewed against the linked primary sources.

Social Security and Medicare change every year, and nobody sends you a memo. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.