A federal judge in New York has cleared the way toward final approval of a $4.95 million settlement covering anyone in the United States whose private information may have been exposed when ConnectOnCall, an after-hours on-call answering service used by doctors’ offices and medical practices nationwide, suffered a data breach in 2024. A class member with documented losses can file for up to $5,000, while someone who qualifies but has no receipts to show can still collect a flat cash payment capped at $75. The settlement carries an unusual second path: a person who never received, opened or kept the mailed notice can still file a claim, because the administrator built a separate form for exactly that situation.
ConnectOnCall’s After-Hours Line and What It Exposed
ConnectOnCall operated as a third-party on-call answering service, connecting patients who called after normal office hours with the healthcare providers who used its platform. According to the court-authorized settlement notice, an unknown threat actor gained access to the ConnectOnCall Platform between February 16, 2024, and May 12, 2024, and exfiltrated data that included provider-patient communications along with other private information belonging to patients of the practices that relied on the service. ConnectOnCall did not begin notifying the people it believed were affected until December 11, 2024, several months after it learned of the intrusion. The resulting case, In re ConnectOnCall.com Data Breach Litigation, Case No. 2:24-cv-08790, names ConnectOnCall.com, LLC and Phreesia, Inc. as defendants and is pending before the Honorable Sanket J. Bulsara of the U.S. District Court for the Eastern District of New York. Neither company has admitted wrongdoing, and the court has not ruled on the underlying claims of negligence and invasion of privacy; the settlement resolves the case without a trial.
Free settlements tracker: Open settlements have claim deadlines, and fake settlement sites copy real ones. See the current list with the free tracker.
How to File Without the Notice’s Unique ID and PIN
Most class-action settlements require a claimant to enter a Unique ID and PIN printed on the notice mailed or emailed to them, and ConnectOnCall’s settlement site works the same way for anyone who still has that notice — a 10-character code paired with a 4-digit PIN, according to the claim-submission instructions posted by Epiq, the court-appointed administrator. But a person can belong to the Settlement Class without ever seeing that notice: mail gets forwarded incorrectly, notice emails land in spam folders, and some patients whose provider used ConnectOnCall never had a current address on file with that provider. For that situation, the administrator built a separate intake path. On the no-ID claim form, a class member instead types in their own name, address and contact information, then attests under penalty of perjury to having communicated after-hours with a healthcare provider or its office at some point between May 12, 2014, and May 12, 2024 — the qualifying fact the settlement substitutes for a printed code. That sworn attestation, not the mailed notice, is what establishes the claim.
What a Valid Claim Actually Pays
The settlement fund totals $4,950,000, and it must cover monitoring benefits, cash payments and settlement administration costs — estimated at roughly $490,000 — before money reaches individual claimants, according to the FAQ page the administrator publishes for the case. A class member with documented losses tied to the breach, such as identity theft, falsified tax returns or other misuse of their information, can file for Cash Payment A, reimbursed up to $5,000, but only with supporting documentation that is not self-prepared. A class member without documented losses can instead choose Cash Payment B, an alternate cash payment with a maximum of $75. That $75 ceiling is not guaranteed: the notice states the fund pays monitoring benefits first, Cash Payment A claims second and Cash Payment B claims last, and if approved claims exceed what remains in the fund at that point, the alternate cash payment is reduced pro rata. Either option can be paired with two years of Dark Web and Medical Data Monitoring through CyEx Medical Shield Complete, which the notice values at $360 and which includes up to $1,000,000 in medical identity-theft insurance coverage.
The Court Dates That Still Have to Happen
Claims must be submitted online or postmarked by November 2, 2026. Anyone who wants to keep the right to sue ConnectOnCall and Phreesia separately over the same data has to opt out by October 19, 2026, the same date by which a written objection to the deal must be filed. Judge Bulsara has scheduled a Final Approval Hearing for November 17, 2026, at the federal courthouse in Central Islip, New York, where he will decide whether the settlement is fair and rule on class counsel’s request for attorneys’ fees of up to $1,650,000 plus service awards of up to $2,500 for each of the named plaintiffs. No benefit — cash, monitoring or otherwise — goes out to anyone unless and until that approval is granted and becomes final.
Why Exposed Medical Data Feeds Medicare Fraud
The lawsuit does not allege that anyone’s information from the ConnectOnCall breach was actually misused, but the category of data involved — provider-patient communications tied to patients’ after-hours medical contacts — is exactly the material that fuels medical identity theft and Medicare billing fraud on a national scale. The Justice Department’s 2025 National Health Care Fraud Takedown announced criminal charges connected to more than $14.6 billion in alleged fraud, including an operation prosecutors called Gold Rush, in which a criminal network is accused of submitting $10.6 billion in fraudulent Medicare claims for durable medical equipment by exploiting the stolen identities and confidential medical information of more than one million Americans. “The scale of today’s Takedown is unprecedented, and so is the harm we’re confronting,” said Acting Inspector General Juliet T. Hodgkins of the Department of Health and Human Services’ Office of Inspector General, whose agents investigated the scheme alongside the FBI. HHS-OIG describes the underlying harm in more personal terms: a stranger using a patient’s name, Social Security number or Medicare number to bill for care never delivered, with the potential to corrupt the victim’s own medical record in the process. The two years of medical-identity monitoring built into the ConnectOnCall settlement, paid for out of its $4.95 million fund, is aimed at that specific risk for the people whose after-hours medical contacts sat inside the breached platform.
Data Breach Claims Without a Notice Letter
The ConnectOnCall settlement’s no-ID claim form solves one narrow problem: a class member who lost or never received a mailed notice. Most open settlements carry no equivalent blank-claim option, so a missed or misplaced notice there usually means a missed deadline and a forfeited claim. Reading a notice correctly — the deadline, the eligibility rule, which payment tier applies — is what separates a completed claim from one that never gets filed.
The Settlement & Refund Recovery System is a 36-page guide covering the four-date rule for reading a settlement notice and a step-by-step filing walkthrough for claims that arrive without the notice’s identifying codes.
See the four-date rule and the filing walkthrough in The Settlement & Refund Recovery System.
This article was researched and drafted with the assistance of AI and reviewed by an editor.



