ConnectOnCall Will Pay $4.95 Million Over a Breach That Reached 914,138 Patients' After-Hours Calls — the No-Receipt Payment Tops Out at $75, You Do Not Need a Letter to File, and Claims Close November 2
ConnectOnCall was the after-hours answering service behind thousands of doctors' offices. Between February 16 and May 12, 2024, someone else was reading the messages. The settlement in In re ConnectOnCall.com Data Breach Litigation (E.D.N.Y., No. 2:24-cv-08790) puts $4,950,000 into a non-reversionary fund; class counsel will ask for up to $1,650,000 of it and the administrator estimates another $490,000 to run the claims process. Anyone in the U.S. whose information “may have been impacted” is in the class — no notice letter required — and the claim form asks only that you attest to having communicated after-hours with a healthcare provider at some point in the ten years ending May 12, 2024. Opt-out and objections close October 19; claims close November 2; the hearing is November 17 in Central Islip.
By Settlement Insight Data Desk ·
What an after-hours answering service knows about you
ConnectOnCall was not a hospital and most of the people in this class have never heard of it. The official settlement site describes it as “an after-hours on-call answering service used by healthcare providers in the United States” — the system that takes the call when you phone your doctor's office at 9 p.m., logs what you said, and routes it to whoever is on call. Its parent, Phreesia, Inc., the patient-intake software company, bought ConnectOnCall in October 2023.
According to the site, “On or about May 12, 2024, Defendants learned that an unknown threat actor gained access to the ConnectOnCall Platform between February 16, 2024, and May 12, 2024, and exfiltrated data within the ConnectOnCall Platform, including certain provider-patient communications.” That is just under three months of access. The notification letters did not go out until December 11, 2024 — seven months after discovery.
The number attached to the breach comes from the federal breach portal: ConnectOnCall reported it to the U.S. Department of Health and Human Services as affecting 914,138 individuals, per HIPAA Journal and BleepingComputer, which both cited the HHS listing. The data described in the breach notices, as summarized by HIPAA Journal, ran to names, phone numbers, dates of birth, medical record numbers, and details of health conditions, treatments and prescriptions, with Social Security numbers for a smaller subset. The settlement site itself is narrower and more careful — it says the exfiltrated data included “certain provider-patient communications” — and adds a sentence that matters for what follows: “The lawsuit does not allege that, because of the Data Incident, any individual's data was misused in any way.”
You are in the class if your data “may have been impacted” — and there is no letter test
Most breach settlements limit the class to people the company mailed a notice to. This one does not. The definition on the site is: “all living individuals residing in the United States whose Private Information may have been impacted in the Data Incident.” The only exclusions are the defendants' own directors, officers and employees, and the judges and court staff on the case.
The claim form fills that gap with an attestation instead of a lookup. To receive either cash payment, you must “attest under penalty of perjury to having communicated after-hours with a healthcare provider or their office between May 12, 2014, and May 12, 2024.” Ten years. The breach lasted three months; the attestation window is a decade. Neither the site nor the agreement explains the choice, but the practical effect is clear: most patients have no way of knowing whether their particular clinic used ConnectOnCall, and the form does not make them find out. If you left an after-hours message for a doctor at any point in that period and live in the United States, the form is open to you.
What the form does not ask for is the letter. If you received one in December 2024, keep it; it is useful for the documented-loss tier. If you did not, you are not disqualified.
Two cash tiers and a monitoring product — and the order they are paid in
There are three things on offer, and every claimant gets the first one.
Dark Web and Medical Data Monitoring. Two years, one bureau, through CyEx Medical Shield Complete: dark-web monitoring, medical-identity monitoring, real-time alerts, and “insurance coverage for up to $1,000,000 for medical identity theft.” The FAQ attaches a number to it — “an estimated value of $360.00 per two years per Settlement Class Member” — and the settlement agreement calls that figure an “estimated retail cost.” Neither document says what the fund actually pays per enrollment, and we are not going to guess.
Cash Payment A — Documented Losses, up to $5,000. For “actual, documented, and unreimbursed costs, expenses, losses, or charges incurred as a result of identity theft or identity fraud, falsified tax returns, or other possible misuse of your Private Information attributed to the Data Incident.” Documentation must be “not self-prepared.” Nothing already reimbursed — including through the monitoring offered with the original letters — counts. If the paperwork is rejected and not cured, the claim “will be converted to Cash Payment B.”
Cash Payment B — Alternate Cash, “a maximum amount of $75.” No documentation; the ten-year attestation is the whole requirement. This is the tier almost everyone will use.
Then the sentence that governs both: “In the event the amount of Valid Claims exhausts the Settlement Fund, the amount of the Cash Payments will be reduced pro rata accordingly.” The administrator pays in a fixed order — “(1) Dark Web and Medical Data Monitoring; (2) Cash Payment A – Documented Losses; and (3) Cash Payment B – Alternate Cash.” Monitoring is funded first, documented losses second, and the $75 tier gets what is left. The $75 is a ceiling, not a promise.
The arithmetic: $4.95 million gross, and what comes out before anyone is paid
The fund is $4,950,000, and the preliminary approval order describes it as “non-reversionary” — nothing goes back to ConnectOnCall or Phreesia. But it pays for everything: in the FAQ's words, “(a) all Valid Claims for Dark Web and Medical Data Monitoring and for Cash Payments; (b) all Settlement Administration Costs; and (c) any Court-awarded attorneys' fees, costs, and Service Awards.”
The known deductions: class counsel “will file a motion asking the Court to award attorneys' fees not to exceed $1,650,000, plus reimbursement of reasonable costs” — one-third of the fund. Administration is “estimated to be $490,000” and “could be lower or higher.” Service awards are “up to $2,500 each” for the class representatives. Take the fee request and the administration estimate at face value and roughly $2.8 million remains for monitoring and cash, before litigation costs are reimbursed.
Against that sits a class the government counted at 914,138. If even one in twenty of them files for the $75, the cash tier alone would be $3.4 million — more than what is left. That is why the pro rata clause exists, and why the honest description of Cash Payment B is “up to $75, and probably less if the claim rate is high.” The number of claims filed is the only variable that matters, and nobody will know it until after November 2.
Separately from the fund, the defendants will hand class counsel a written attestation about security measures taken since the breach, with a cost estimate. The FAQ is explicit that “The costs of these measures are the responsibility of the Defendants and will not in any way reduce the Settlement Fund.”
October 19, November 2, November 17 — and what “effective” means here
Monday, October 19, 2026 is the deadline to opt out (postmarked, signed personally, mailed to the administrator at P.O. Box 4274, Portland, OR 97208-4274 — no email, no phone, no group opt-outs) and to object (filed with the court and mailed to class counsel, defense counsel and the administrator by the same date). The objection requirements are long, and include a five-year history of any prior class-action objections by your lawyer or your lawyer's firm; the site notes that counsel “may conduct limited discovery on any objector.”
Monday, November 2, 2026 is the claim deadline — online, or mailed and postmarked by that date. From today that is 64 days.
Tuesday, November 17, 2026 at 10:00 a.m. ET is the final approval hearing, before Judge Sanket J. Bulsara at the U.S. District Court for the Eastern District of New York, 100 Federal Plaza, Central Islip. Preliminary approval was signed on July 27, 2026.
Payment timing runs off the settlement's “Effective Date,” and the agreement defines it two ways: “5 days after the entry of the Final Approval Order and Judgment, provided there are no objections” — or, if anyone objects, five days after the appeal period runs out or any appeal is resolved. The administrator then has 45 days to distribute benefits. With no objections and approval on November 17, that points to early 2027; a single objection with an appeal pushes it out by months. The FAQ's own line is the standard one: “It may take time for the Settlement to be approved and become final. Please be patient.”
Three breach settlements this week, three different ways the money works
ConnectOnCall is one of three healthcare-adjacent breach settlements with open claim windows that we read this week, and they pay in three different ways. ConnectOnCall's $75 is a maximum from a fixed fund, paid after monitoring and documented losses. Central Maine Healthcare's $50 is a pro rata estimate that the site says can go up as well as down. YES Communities' $50 is a fixed amount with no fund at all — the company pays each valid claim separately, so no claimant dilutes another.
The pattern is one we documented in August across six settlements: the headline number on a breach settlement is the documented-loss cap, and the number most people actually receive is the no-proof tier, which is set by the claim rate. For ConnectOnCall the cap is $5,000, the no-proof ceiling is $75, and the 914,138 figure is the reason to treat the $75 as the top of a range rather than the bottom.
One thing this settlement does better than most: the monitoring is medical-identity monitoring with a $1 million policy, which is the right product for a breach of clinical messages rather than credit-card numbers. It is also the thing the fund pays for first.
The Data Behind This Story
- Settlement fund
- $4,950,000, non-reversionary — pays all benefits, administration costs, attorneys' fees and service awards
- Case
- In re ConnectOnCall.com Data Breach Litigation, No. 2:24-cv-08790, U.S. District Court for the Eastern District of New York, Judge Sanket J. Bulsara; defendants ConnectOnCall.com, LLC and Phreesia, Inc.
- The breach
- Unauthorized access to the ConnectOnCall after-hours answering platform February 16 – May 12, 2024, with exfiltration of provider-patient communications; discovered May 12, 2024; letters mailed December 11, 2024
- People affected
- 914,138, as reported to the U.S. Department of Health and Human Services (per HIPAA Journal and BleepingComputer citing the HHS breach listing)
- Who is in the class
- All living U.S. residents whose private information may have been impacted — no notice letter required; claimants attest to an after-hours communication with a healthcare provider between May 12, 2014 and May 12, 2024
- Monitoring
- Two years of CyEx Medical Shield Complete (dark-web and medical-identity monitoring, alerts, up to $1,000,000 medical identity theft insurance); estimated retail value $360 per person
- Cash Payment A
- Up to $5,000 for documented, unreimbursed losses attributed to the breach (documentation must not be self-prepared)
- Cash Payment B
- Up to $75 with no documentation — reduced pro rata if valid claims exhaust the fund; paid after monitoring and documented losses
- Fees and costs
- Attorneys' fees requested: not to exceed $1,650,000 plus costs; administration estimated at $490,000; service awards up to $2,500 per class representative — all from the fund
- Opt-out / objection deadline
- Monday, October 19, 2026 (opt-out postmarked; objection filed and mailed)
- Claim deadline
- Monday, November 2, 2026 — online or postmarked
- Final approval hearing
- Tuesday, November 17, 2026 at 10:00 a.m. ET, 100 Federal Plaza, Central Islip, NY (preliminary approval July 27, 2026)
- Payment timing
- Within 45 days after the Effective Date — 5 days after final approval if there are no objections, otherwise after the appeal period or any appeal
- Administrator / official site
- Epiq — connectoncallsettlement.com; 1-877-313-8735; P.O. Box 4274, Portland, OR 97208-4274
- Source: connectoncallsettlement.com — official court-authorized settlement website administered by Epiq (primary source; the site returns HTTP 403 to plain fetchers, so the Home, FAQ and Documents pages were rendered in a browser on August 30, 2026 and saved; footer stamp ‘Updated: 8/25/2026 4:02:53 PM’): case number and judge; description of ConnectOnCall and the incident dates; the class definition and exclusions; the $4,950,000 fund and what it pays; the $490,000 administration estimate; the monitoring product and its $360 estimated value; Cash Payment A and B terms, the ten-year attestation and the pro rata clause and distribution order; the $1,650,000 fee cap and $2,500 service awards; all deadlines and the hearing; administrator contact details
- Source: Preliminary Approval Order, In re ConnectOnCall.com Data Breach Litigation, No. 2:24-cv-08790 (E.D.N.Y.), signed by Judge Sanket J. Bulsara and dated July 27, 2026 — downloaded from the settlement website's Documents page: the ‘non-reversionary $4,950,000’ fund language, the hearing date and time, and the claim deadline set at 15 days before the hearing
- Source: Amended Settlement Agreement (Dkt. 58-1), In re ConnectOnCall.com Data Breach Litigation — downloaded from the settlement website: the definition of ‘Effective Date’ (¶39), the ‘estimated retail cost of $360.00 per two years’ for the monitoring, the 45-day distribution deadline after the Effective Date (¶107), and the attestation window of May 12, 2014 to May 12, 2024
- Source: HIPAA Journal, ‘ConnectOnCall Announces 914K-Record Data Breach’ (hipaajournal.com/connectoncall-data-breach) — the 914,138 figure as reported to HHS, the May 15, 2024 Phreesia notice, the December 11, 2024 letters, Phreesia's October 2023 acquisition, and the data types listed in the breach notices; secondary source, used only for facts not on the settlement site
- Source: BleepingComputer, December 16, 2024, ‘ConnectOnCall breach exposes health data of over 910,000 patients’ — corroborates the 914,138 HHS figure and the October 2023 acquisition; secondary source
- Source: settlementinsight.com/news/six-breach-settlements-48-hours-2500-headline-10-dollars — our own August 12 analysis of no-proof payment tiers, used only for the comparison in the final section
- Source: claimdepot.com — consulted for discovery only; every figure and date above was taken from the official administrator site and the court documents posted there
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.