Patients hit by the Onsite Mammography breach have until mid-August to file for payment

woman wearing blue dress

Patients affected by a medical-data incident have only a few days left to turn a breach notice into a settlement claim. The official Onsite Mammography administrator lists August 11 as the deadline. Available benefits include a pro rata cash payment, reimbursement for documented losses and monitoring designed for both credit and medical information.

The incident reached one employee email account

The court-supervised settlement site says an unauthorized third party gained access to one Onsite Mammography employee’s email account around October 2024. Files in that account may have included patients’ personally identifiable information and protected health information.

The class generally consists of U.S. residents whose private information may have been affected. Onsite denies wrongdoing and liability but agreed to settle on a classwide basis. The case is Clarkson et al. v. Onsite Mammography, LLC, doing business as Onsite Women’s Health, in federal court in Massachusetts.


Free retirement updates: Miss an enrollment or claim deadline and it may be gone. Our free Retirement Shield newsletter keeps readers ahead of the ones that matter. Get the free newsletter.

Cash and documented losses are separate benefits

The proposed $2.525 million settlement provides up to $5,000 for actual, documented and unreimbursed losses connected to the incident, according to the administrator’s frequently asked questions. Eligible expenses must have occurred on or after October 2024, and the claim needs records plus a description when the connection is not obvious.

A claimant may also request a pro rata cash payment. Its size is not guaranteed because the remaining fund is divided after administration, taxes, legal awards, documented-loss claims and monitoring costs. The phrase “file for payment” therefore means filing for an available settlement benefit, not that every patient will receive the same check.

Medical identity risk extends beyond a credit report

Health information can be used to impersonate a patient, seek care, submit insurance claims or make a scam message unusually convincing. A credit-monitoring alert may catch a new loan but not a false medical claim. That is why the settlement’s monitoring option includes medical or health-care data features rather than relying only on ordinary bureau activity.

Patients should review insurer explanations of benefits for unfamiliar providers, dates or services and ask the insurer how to dispute an error. Portal passwords should be unique, and multifactor authentication should be enabled where available. A false entry in a medical record can affect care as well as money, so it should be raised with the provider’s privacy or records office promptly.

The notice and claim confirmation belong in the records file

A person seeking documented reimbursement should organize receipts, bank or card statements, credit-report charges, professional fees and correspondence showing why the cost followed the incident. Reimbursed expenses should not be claimed again. A brief timeline can make the relationship easier for the administrator to evaluate.

The official notice or claim identifier should be kept with the final submission. Claimants should save a PDF or screenshot of the completed form and confirmation number. If a third-party site demands money to file, requests a full bank login or creates a different deadline, stop and return to the administrator domain.

August 11 is the action date

Online forms must be submitted and mailed forms postmarked by August 11 under the administrator’s instructions. The opt-out and objection deadlines have already passed, and the fairness hearing is scheduled for September 9. Payment timing depends on approval and processing after that hearing.

The short runway makes eligibility and proof more important than estimating the eventual cash amount. The administrator explicitly identifies the only official site and warns that other pages may contain incorrect information. Patients with an Onsite notice should use those remaining days to choose the appropriate benefit, attach the available records and lock in a dated confirmation before the portal closes.

A health-data breach can create targeted impersonation

A criminal who knows the name of a medical provider, an appointment type or a recent screening can make a false billing or insurance call sound credible. Patients should not confirm birth dates, policy numbers or one-time codes in response to an inbound message. Calling the provider or insurer through a known number tests whether the request is real without rewarding the caller’s urgency.

Medical-data monitoring does not replace careful review of statements. An explanation of benefits can reveal a claim even when the patient owes nothing, and a portal can show an unfamiliar appointment before a paper notice arrives. Disputes should be documented with the insurer and provider so an incorrect diagnosis, medication or procedure does not remain in the clinical record.

The court record defines the available rights.

The administrator’s court-documents page contains the settlement papers and approval filings behind the summary. Class membership is tied to information that may have been affected, not a requirement that identity theft already occurred. That is why a pro rata cash option and monitoring are available alongside documented-loss reimbursement.

Someone claiming up to $5,000, however, needs actual unreimbursed costs tied to the incident. The maximum should not be entered as an estimate of future harm. Separating preventive benefits from experienced loss keeps the form accurate and reduces the chance that an otherwise valid claim is delayed by unsupported figures.

This article was researched and drafted with AI assistance and reviewed against the linked primary sources.

More Financial Reading

Social Security and Medicare change every year, and nobody sends you a memo. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.