Medusind Data Breach Settlement: $5 Million, Approved and Paid Out
Questions about this case?
AI Legal Assistant · free · answers in seconds · general information, not legal advice
The Medusind data breach settlement is finished for new claimants. Medusind, a Miami medical and dental billing company, agreed to pay $5 million over a December 2023 hack. A federal judge granted final approval on January 26, 2026. The claim deadline was December 29, 2025, and approved claimants began receiving payments on April 10, 2026. As of October 2026 there is no form to file and no new deadline.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened in the Medusind Data Breach
Medusind handles billing, coding and revenue-cycle work for doctors and dentists — it says it serves over 6000 healthcare providers from 12 locations in the US and India. Most people in this case never dealt with Medusind directly; their provider did.
On or around December 29, 2023, Medusind identified unauthorized access to its network and found evidence that files had been copied out. The exposed fields varied by person and included names, contact details, dates of birth, health insurance and billing information, payment card or bank details, medical history, and government ID numbers such as Social Security, driver’s license and passport numbers.
Notice letters went out in January 2025 — more than a year after detection. The lawsuits allege Medusind failed to use reasonable safeguards and took too long to warn people. Medusind denies any fault or liability.
Case Details
Eight separate complaints were consolidated into Owings v. Medusind, Inc., No. 1:25-cv-20117-RAR, in the U.S. District Court for the Southern District of Florida, before Judge Rodolfo A. Ruiz II. The lead case was filed on January 9, 2025. The parties settled after a mediation on June 10, 2025, with no admission of wrongdoing. The official settlement site is MedusindDataIncidentSettlement.com.
Status: Approved, Claims Closed, Payments Issued
If you did not file by December 29, 2025, you cannot file now. If you filed and have not been paid, contact the administrator directly (details below) — not a third-party site.
Who Was in the Settlement Class
The class covered people living in the United States who received a notice from Medusind saying their information may have been affected by the December 2023 incident. People who lived in California on December 29, 2023 could claim an extra statutory payment.
How many people? Medusind’s January 2025 filing with the Maine Attorney General reported at least 360,934 individuals. A later file review, reported by HIPAA Journal in September 2025, put the figure at more than 701,000. The class was defined by the notice letter, not by either number.
Claims required the unique ID (and, online, the PIN) printed on the settlement notice.
What the Settlement Paid
Documented losses: up to $5,000 for unreimbursed fraud, identity-theft, credit-freeze and similar costs, with proof.
Alternate cash: a pro rata payment estimated at about $100.
California award: an additional payment estimated at about $100.
Everyone in the class could also claim two years of credit monitoring. Final per-person amounts depended on the number of valid claims and were not published in the sources we could read. Medusind also agreed to security improvements. Compare typical outcomes with our data breach settlement calculator.
How cases like this one end
Our copy of the federal courts’ own case database covers 123,245 other contract casesclosed in U.S. federal district courts between 2015 and 2025, 5.8% of them filed as class actions:
- 30.9% ended in a settlement recorded by the court. Another 20.2% were dismissed voluntarily, which often follows a private settlement — so the real settlement share sits between 30.9% and 51.1%.
- 7.6% were decided on a motion before any trial.
- 1 in 71 reached a trial (1.4%), after a median of 29.3 months.
- Median time from filing to the end of the case: 7.6 months.
- Only 7,369 of them (6%) record a money award at all; the median of those is $402,000.
These are base rates for this type of case (federal other contract cases) — not a prediction about this lawsuit, and not legal advice. Source: Federal Judicial Center, Integrated Database (civil), analysed by Settlement Insight. Cases heard in state courts are not included.
Medusind Data Breach Timeline
- 1
December 29, 2023 — Intrusion Detected
Medusind identifies unauthorized access to its network the same day it happens, takes systems offline and later finds that files were copied.
- 2
January 2025 — Notices and First Lawsuits
Letters reach at least 360,934 people per the Maine filing, with two years of Kroll credit monitoring. The lead federal case is filed in Miami on January 9, 2025.
- 3
June 10, 2025 — Mediation Produces a Deal
Eight consolidated cases settle in mediation for $5 million. Medusind admits no wrongdoing. The class is later put at more than 701,000 people.
- 4
December 2025 — Deadlines Close
Opt-outs and objections were due December 14, 2025. Claims were due December 29, 2025.
- 5
January 26, 2026 — Final Approval
Judge Rodolfo A. Ruiz II approves the settlement. Only five class members opted out.
- 6
April 10, 2026 — Payments Begin
The administrator starts paying approved claimants by check or digital payment. As of October 2026 no new claim period exists.
Three Things to Watch For
With the money already flowing, the fakes shift from “file a claim” to “collect your payment”:
“Late Medusind claims still accepted”
The claim deadline was December 29, 2025 and the court approved the deal in January 2026. A site or ad offering to file a Medusind claim now is collecting your data, not filing anything.
“Your settlement payment is on hold” messages
Texts or emails asking you to confirm your bank login, card number or Social Security number to release a Medusind payment are phishing. The real administrator writes from P.O. Box 3236, Portland, OR 97208-3236 and can be reached at 888-885-6687 — check any message against those details yourself.
Paid “unclaimed funds” recovery offers
If you filed and your check never arrived, the administrator will reissue it for free. Anyone charging a fee or a percentage to “locate” your Medusind money is selling something you can get at no cost.
Medusind Data Breach — Questions People Actually Ask
Is there a Medusind data breach settlement?
Yes. Medusind agreed to pay $5 million to settle Owings v. Medusind, Inc., No. 1:25-cv-20117-RAR (S.D. Fla.). The court granted final approval on January 26, 2026, and payments to approved claimants began on April 10, 2026.
Can I still file a claim?
No. The claim deadline was December 29, 2025. Late claims are not part of the approved settlement, and no second claim period has been announced as of October 2026.
Who is Medusind and why did it have my information?
Medusind is a Miami-based billing and practice-management company for medical and dental offices. If your doctor or dentist outsourced billing to it, your identity, insurance and treatment details passed through its systems.
How much did the settlement pay each person?
Claimants could get up to $5,000 for documented losses, or an alternate cash payment estimated at about $100, plus an extra amount estimated at about $100 for California residents. The estimates were pro rata, so actual checks depended on how many valid claims were filed.
I filed a claim but have not been paid. What do I do?
Contact the Medusind Data Incident Settlement Administrator at 888-885-6687 or P.O. Box 3236, Portland, OR 97208-3236, with the unique ID from your notice. Check your spam folder if you chose a digital payment.
How many people were affected by the Medusind data breach?
Medusind’s January 2025 report to the Maine Attorney General listed at least 360,934 people. A later review reported by HIPAA Journal put the number at more than 701,000.
Is the Medusind breach letter I got real?
The genuine January 2025 letters described the December 29, 2023 incident and offered two years of credit monitoring through Kroll. Any message today asking for your Social Security number or bank login to “release” a payment is not from the administrator.
What is worth doing now?
Freeze your credit at all three bureaus — free and reversible. Because medical and insurance data were exposed, read your explanation-of-benefits statements for care you never received. If you have new fraud, the settlement can no longer cover it, so report it to the FTC at IdentityTheft.gov.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
Data Breach Settlement Calculator
Estimate what a data breach class member typically receives
Open Class Action Settlements
Settlements still accepting claims, with deadlines
TriZetto Data Breach Lawsuit
Another billing-vendor breach, now MDL 3185, no settlement yet
Settlement Payout Calculator
How fees and claim rates shrink a per-person payment