CPAP Medical Supplies' Data Breach Settlement Says “Up to $5,000” — but There Is No Cash Without Receipts: Documented Losses Only, Capped at $500,000 for 90,133 People. Claims Close November 26, 2026.
Does this affect you?
AI Legal Assistant · free · answers in seconds · general information, not legal advice
Brett Conner v. CPAP Medical Supplies and Services, Inc., Case No. CACE-26-011830, Circuit Court of the Seventeenth Judicial Circuit in and for Broward County, Florida, Judge Michele Towbin Singer. CPAP Medical Supplies and Services, Inc. — in the settlement agreement's words a seller of durable medical equipment and supplies “with a focus on sleep apnea therapy” — had its network breached between December 13 and December 21, 2024, and began mailing breach letters on or about August 15, 2025; the HHS Office for Civil Rights portal lists 90,133 people affected. Judge Singer granted preliminary approval on July 29, 2026. The CPAP Medical Supplies data breach settlement pays cash only against proof: up to $5,000 per person for documented out-of-pocket losses, with a $500,000 ceiling for everyone combined, plus two years of CyEx Medical Shield Complete monitoring for any class member who claims it. There is no flat, no-proof payment. Claims close November 26, 2026 at CPAPDataIncidentSettlement.com, run by Simpluris; opt-outs and objections are due October 30, 2026, and the final approval hearing is December 1, 2026, by Zoom. This is not the Philips CPAP recall.
By Settlement Insight Data Desk ·

The short answer: receipts or nothing — plus two years of monitoring
If a letter from CPAP Medical Supplies and Services told you in or after August 2025 that your information may have been involved in its December 2024 cyberattack, you are almost certainly in this settlement. The class is “All living individuals residing in the United States who were sent notice by Defendant that their Private Information may have been impacted in the Data Incident.” The settlement notices went out on August 28, 2026 — by email where CPAP had an address on file, by postcard otherwise.
What you can get is narrower than the “up to $5,000” in the headlines. The notice offers exactly two benefits. The first is a Cash Payment for Documented Losses: “If you incurred actual, documented out-of-pocket losses due to the Data Incident, you can get back up to $5,000.00.” The losses must fall between December 13, 2024 and November 26, 2026, and you have to prove them. The second is two years of CyEx Medical Shield Complete, a medical-identity monitoring service any class member can claim. There is no third option — no flat “alternate cash” payment for people without receipts, no payment for lost time, no pro rata share of a settlement fund. If the breach cost you nothing out of pocket, the monitoring is the whole benefit, and you still have to file a claim to get it.
The claim deadline for both is November 26, 2026. As of September 30, 2026 the court has not decided whether to approve the deal; the final approval hearing is on December 1, 2026, and the notice says payments come only “if the Court grants final approval, and after any appeals are resolved.”
Who CPAP Medical is — and why this is not the Philips CPAP settlement
The name invites confusion, so first what this case is not. The CPAP settlements most people have heard of involve Philips Respironics, which recalled CPAP, BiPAP and ventilator devices over a sound-abatement foam that could break down. Those cases ran through federal multidistrict litigation in the Western District of Pennsylvania, and their registration deadlines have passed; we follow where those payments stand on our CPAP settlement checks page. Nothing in the settlement described here concerns a defective machine, and a Philips claim does not make you a member of this class — or the other way round.
CPAP Medical Supplies and Services, Inc. is a supplier, not a device maker. The settlement agreement says it is “in the business of selling durable medical equipment and supplies with a focus on sleep apnea therapy” and holds information on “current and former patients and employees.” The HHS breach portal lists it as a Florida healthcare provider; ClassAction.org describes it as offering “sleep therapy services and CPAP supplies to military members and their families.”
The incident, in the agreement's words: “In late December 2024, Defendant became aware it was the victim of a cybersecurity incident that took place between December 13, 2024, and December 21, 2024,” in which “an unauthorized third party infiltrated its computer network.” The notice lists what the files may have contained: “names; physical addresses; email addresses; telephone numbers; Social Security numbers; drivers’ license numbers; health insurance information; medical histories; treatment plans; and financial information.” Letters followed about eight months later, “On or about August 15, 2025.” ClassAction.org, summarizing CPAP's online breach notice, reports that it was confirmed by June 27, 2025 that the systems held identifiable health and personal data.
How many people: the agreement says “nearly 90,000.” The HHS Office for Civil Rights breach portal, which we searched on September 30, 2026, lists CPAP Medical Supplies and Services Inc., Florida, 90,133 individuals affected, submitted 08/15/2025, a “Hacking/IT Incident” involving a “Network Server” — on the portal's list of breaches currently under investigation. ClassAction.org reports the same 90,133 from CPAP's filing with the Maine Attorney General; that filing was not publicly viewable when we tried to open it.
The $5,000 is a ceiling: what counts as a loss, what counts as proof, and the $500,000 cap
The cash benefit reimburses money you actually spent or lost because of the breach. The notice gives four examples: “losses because of identity theft or fraud”; “fees for credit reports, credit monitoring, or freezing and unfreezing your credit”; “cost to replace your IDs”; and “postage to contact banks by mail.” The proof has to come from someone other than you: “You need to send proof, like bank statements or receipts, to show how much you spent or lost. You can also send notes or papers you made yourself to explain or support other proof, but those notes or papers alone are not enough to make a valid claim.” Anything already reimbursed cannot be claimed again — the agreement names, as one example, compensation through the identity-protection and credit-monitoring services CPAP offered in its 2025 letter.
One wrinkle is worth knowing before you file. The agreement words the benefit more narrowly than the notice. Paragraph 61 says a claimant elects the payment “attesting under penalty of perjury to being the victim of fraud and/or identity theft and incurring documenting losses,” and the claim form's checkbox reads “documented losses due to identity theft or fraud.” The notice, the FAQ and the claim form's own benefit summary, however, list credit-report and credit-freeze fees as covered without that condition. Whether a fee paid purely as a precaution will be accepted is for the administrator to decide. What is not a gray area: the attestation is made under penalty of perjury, so it should describe only what actually happened to you.
Then the cap: “There will be a maximum of $500,000.00 payable by the Defendant for this benefit. In the event the total dollar amount of all Valid Claims for this benefit exceed that amount, Settlement Class Members’ distribution amounts will be reduced pro rata.” By our arithmetic, $500,000 pays the full $5,000 to exactly 100 people — about one in every 900 of the 90,133 notified. Smaller claims leave room for more claimants; if approved claims add up to more than $500,000, every one of them shrinks by the same percentage. The agreement also gives CPAP a way out: it may terminate the deal “if more than 100 Valid Claims for Cash Payments for Documented Losses are received and the total amount claimed for such Valid Claims equals or exceeds $500,000.00,” or if more than 250 class members opt out.
Cash is paid the way you choose on the claim form: PayPal, Venmo, Zelle, a virtual prepaid card, or a physical check mailed to your address.
Two years of medical-identity monitoring — and a $60,000 line in the agreement
Every class member who files can check a box for two years of CyEx Medical Shield Complete, with or without a cash claim. Per the notice, it “comes with $1 million of medical identity theft insurance” and monitors for “healthcare insurance ID exposure,” “Medical Record Number (MRN) exposure” and “unauthorized Health Savings Account (HSA) spending,” with a fraud resolution agent if something looks wrong. The agreement adds: “The monitoring will be with one credit bureau and the service will include $1,000,000.00 of identity theft insurance with no deductible.” Given what the files may have held — health insurance information, medical histories, treatment plans — this is the benefit most of the class can actually use. Monitoring codes are activated 45 days after the settlement’s Effective Date.
One sentence in the agreement deserves a closer look. Paragraph 62: “The maximum Defendant will pay for Settlement Administration Costs and Medical Data Monitoring shall be $60,000.00.” That one figure has to cover the administrator's work — the emails and postcards, the website, the toll-free line, the claim review — and the monitoring for everyone who enrolls. By our arithmetic it comes to about 67 cents per notified person. The agreement does not say what happens if enrollments push the combined cost past $60,000, and we have not seen a per-person price for the product. The notice itself contains no such limit: “All Class Members are eligible to claim two years of CyEx Medical Shield Complete.”
October 30, November 26, December 1: how to claim, opt out or object
To claim — deadline November 26, 2026. The online form at CPAPDataIncidentSettlement.com asks for the “LoginID and PIN” printed on your notice; if you cannot find them, the administrator asks you to email info@CPAPDataIncidentSettlement.com “by providing your full name and mailing address.” You can also download the paper claim form and mail it, or email a scan of it with your documents. One claim per person. The deadline wording differs slightly between documents: the notice and the website say a mailed form must be “postmarked no later than November 26, 2026,” while the paper form itself says forms must be mailed “so that they are received by the Settlement Administrator no later than November 26, 2026.” Filing online, or mailing well ahead of the date, avoids the question.
To opt out — deadline October 30, 2026. Only if you want to keep your own right to sue CPAP over the breach; if you opt out, you get nothing from the settlement. The request must name the case (Brett Conner v. CPAP Medical Supplies and Services, Inc., Case No. CACE-26-011830), give your full name, mailing address, telephone number and email address, carry your personal signature and the words “Request for Exclusion,” and go to CPAP Data Incident Settlement, ATTN: Exclusion Request, P.O. Box 25226, Santa Ana, CA 92799-9958.
To object — deadline October 30, 2026. Objections are filed with the Clerk of Court, 201 S.E. 6th Street, Fort Lauderdale, FL 33301, with copies to the administrator and to both sides' lawyers. The list of required contents is long: among other things, every class action objection you or your lawyer filed in the past five years, and “a statement confirming whether the objector and/or objector’s counsel utilized any form of artificial intelligence in preparation of the objection.” An objection missing any item is not valid, and “an attorney’s signature is not sufficient.”
The hearing — December 1, 2026. Judge Singer will hold the final approval hearing “at 8:30 a.m. Eastern Time, via Zoom”; the link and dial-in number are in FAQ 18 on the settlement website. Nobody has to attend. When money arrives depends on that hearing. The administrator “shall distribute Cash Payments no later than 45 days after the Effective Date.” If the judge approves on December 1 and there are no objections, the Effective Date is the next day, and by our arithmetic the outside date for cash payments would be January 16, 2027. With objections, the Effective Date moves at least 30 days out; an appeal pushes it further.
Is the notice real?
A notice is genuine if it matches these details. The court-approved administrator is Simpluris; the website is CPAPDataIncidentSettlement.com; the toll-free number, available 24/7 per the notice, is (833) 285-3011; the email is info@CPAPDataIncidentSettlement.com; the mailing address is CPAP Data Incident Settlement, c/o Settlement Administrator, P.O. Box 25226, Santa Ana, CA 92799-9958. The long-form notice carries “CaseID: 9642” in its footer and opens with: “A court has authorized this notice. This is not a solicitation from a lawyer. You are not being sued.”
A real notice gives you a LoginID and PIN for the claim site. The claim form collects your name, address, email, phone number and the account for your chosen payment method; it has no field for a Social Security number, and nothing in the notice, the claim form or the agreement asks you to pay anything to file. The notice says in capital letters: “DO NOT CONTACT THE COURT OR CLERK OF COURT REGARDING THIS SETTLEMENT” — questions go to the administrator. We explain how Simpluris notices and payments work on our Simpluris page.
How a federal lawsuit ended up in a Broward County courtroom
The case began in federal court. After the August 2025 letters, “four class-action complaints were filed in the United States District Court for the Middle District of Florida,” which were consolidated. CPAP moved to dismiss, and the court “denied the motion in part and granted it in part.” The parties then traded information informally and, after “a few weeks of arms-length negotiations,” agreed on terms on June 4, 2026. The agreement explains the change of courthouse: “During their settlement discussions the Parties determined that jurisdiction was proper in state court. Consequently, they dismissed the federal action and filed the Complaint in this Action” — which is why a December 2024 breach carries a 2026 Broward County case number. Judge Michele Towbin Singer signed the preliminary approval order on July 29, 2026.
There is no settlement fund. The agreement makes CPAP “solely responsible for the payment of all Settlement Class Member Benefits to Settlement Class Members, all Settlement Administration Costs, and any Court-approved attorneys’ fees, costs, and Service Awards.” Class counsel — Jeff Ostrow of Kopelowitz Ostrow P.A. and Mariya Weekes of Milberg PLLC — will ask for $400,000 in fees and costs, paid by CPAP on top of the claims, and a $1,000 service award for each of the eight class representatives. By our arithmetic the fee request equals 80 percent of the most that class members can receive in cash combined. The settlement does not depend on the fee request being granted. CPAP denies that it did anything wrong, and the court has not decided who is right. To compare what other breach settlements pay, see our data breach settlement calculator.
The Data Behind This Story
- Case
- Brett Conner v. CPAP Medical Supplies and Services, Inc., Case No. CACE-26-011830
- Court
- Circuit Court, Seventeenth Judicial Circuit, Broward County, Florida — Judge Michele Towbin Singer; preliminary approval July 29, 2026; earlier federal cases (Middle District of Florida) dismissed after the June 4, 2026 agreement
- Defendant
- CPAP Medical Supplies and Services, Inc. — durable medical equipment and supplies, focus on sleep apnea therapy; Florida healthcare provider per HHS. Not Philips Respironics
- Incident
- Network intrusion December 13–21, 2024; letters from August 15, 2025; names, addresses, SSNs, driver's license numbers, health insurance information, medical histories, treatment plans, financial information
- Affected
- 90,133 per HHS OCR breach portal (submitted 08/15/2025, Hacking/IT Incident, Network Server; read September 30, 2026); “nearly 90,000” per the settlement agreement
- Class
- All living U.S. residents sent notice by CPAP that their Private Information may have been impacted in the Data Incident
- Cash
- Documented out-of-pocket losses December 13, 2024 – November 26, 2026, up to $5,000 each; the agreement requires a sworn statement that you were a victim of fraud or identity theft; third-party proof required; $500,000 total cap, pro rata above it; no flat or no-proof payment
- Monitoring
- Two years of CyEx Medical Shield Complete, $1 million medical identity theft insurance; administration and monitoring together capped at $60,000
- Deadlines
- Opt-out and objections October 30, 2026; claims November 26, 2026 (online, or mailed — see wording note); final approval hearing December 1, 2026, 8:30 a.m. ET via Zoom
- Payment
- PayPal, Venmo, Zelle, virtual prepaid card or check; no later than 45 days after the Effective Date — only after final approval and any appeals
- Fees and exit clauses
- Class counsel to request $400,000 in fees and costs; $1,000 per class representative (eight); paid by CPAP separately. CPAP may terminate with more than 250 opt-outs or more than 100 valid cash claims totaling $500,000 or more
- Administrator
- Simpluris — CPAPDataIncidentSettlement.com · (833) 285-3011 · info@CPAPDataIncidentSettlement.com · P.O. Box 25226, Santa Ana, CA 92799-9958
- Source: CPAPDataIncidentSettlement.com — home page, FAQ 1–21, Important Dates, Contact and claim-login pages, read September 30, 2026: case name and number, court, class definition, benefits, the $5,000 / $500,000 terms, all deadlines, LoginID and PIN requirement, Zoom hearing details, administrator contact, Simpluris as operator
- Source: Long Form Notice (Simpluris PDF, CaseID 9642), read September 30, 2026: data types, class definition and exclusions, cash and monitoring benefits, covered expenses and proof rules, fee and service-award requests, opt-out and objection requirements (including the artificial-intelligence statement), hearing date, payment timing, contact details
- Source: Claim Form (Simpluris PDF), read September 30, 2026: “received / postmarked” deadline wording, one claim per person, email submission, fields collected (no Social Security number), cash checkbox wording, payment options (PayPal, Venmo, Zelle, virtual prepaid card, check)
- Source: Settlement Agreement (PDF via the settlement website), read September 30, 2026: company description, incident dates, “nearly 90,000,” August 15, 2025 letters, four federal complaints in the Middle District of Florida, partial dismissal ruling, June 4, 2026 agreement and refiling in state court, ¶60 (CPAP pays everything), ¶61 (attestation, monitoring terms), ¶62 ($60,000 cap on administration and monitoring), ¶¶87–89 (payment timing, electronic payment), ¶101 (termination rights), ¶94 (not contingent on fees)
- Source: Order Granting Plaintiffs' Unopposed Motion for Preliminary Approval, Judge Michele Towbin Singer, July 29, 2026 (copy hosted by ClassAction.org, as the settlement site's document list loads by script), read September 30, 2026: judge, date, schedule rules
- Source: HHS Office for Civil Rights Breach Portal, “Cases Currently Under Investigation,” searched for “CPAP” on September 30, 2026: CPAP Medical Supplies and Services Inc., FL, Healthcare Provider, 90,133 individuals, submitted 08/15/2025, Hacking/IT Incident, Network Server
- Source: ClassAction.org newswire article of September 23, 2026 and its CPAP Medical breach page (updated September 23, 2026), read September 30, 2026: preliminary approval date, the company's military customer base, the June 27, 2025 confirmation and the 90,133 Maine Attorney General figure — cited as ClassAction.org's account; the Maine AG entry itself returned “Authentication Required” on September 30, 2026
- Source: Settlement Insight pages on the Philips Respironics CPAP litigation (/cpap-settlement-checks, /philips-cpap-lawsuit-calculator), read September 30, 2026: the distinction between the Philips foam recall and this breach case
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.