483,126 People in a Catholic Health Database Left Open for 47 Days, and a Claim Window That Closed Three Days Ago. The Hearing Is Still Twelve Days Away.
Nancy Balzer, et al., v. Serviceaide, Inc., Index No. 625615/2025, Supreme Court of New York, Nassau County, before Hon. Lisa A. Cairo. The claim deadline was September 1, 2026; we checked the Kroll claim portal on September 4 and it returns “Deadline Passed.” A widely read roundup still lists the case under September 2026 — the deadline fell on the first day of that month. Two things are worth reading anyway: the investigation found no evidence anything was copied but could not rule it out, while this same case’s own settlement papers speak of unlawful access — and the final approval hearing on September 16 is still ahead.
By Settlement Insight Data Desk ·

The deadline, checked rather than calculated
The court's own schedule set the claim deadline at September 1, 2026 — fifteen days before the final approval hearing. On September 4 we opened the Kroll claim portal and it answered: “Deadline Passed — The deadline for this form has passed.” The settlement website still shows September 1 with no extension banner.
That matters because the case still appears in a September 2026 roundup of open settlements. The deadline fell on the first day of the month. Anyone arriving through that route in the next four weeks will find a closed form.
The opt-out and objection deadlines both passed on August 17. What is still ahead is the final approval hearing on September 16, 2026 at 10:00 a.m. ET, at 100 Supreme Court Drive in Mineola — and the website warns the date can move without notice. Anyone who filed in time is waiting on that hearing: payment follows final approval and the expiry of any appeals, not the claim deadline.
What the letter says, and what the settlement papers say
This is the part most coverage gets backwards. Serviceaide ran an Elasticsearch database for its customer Catholic Health, the non-profit hospital network in Buffalo. On November 15, 2024 it learned that “certain information within its Catholic Health Elasticsearch database was inadvertently made publicly available.” The exposure window ran from September 19 to November 5, 2024 — 47 days.
And then the sentence that should be quoted whenever this case is described: “the investigation did not identify any evidence that information was copied, but we are unable to rule out this type of activity.” The settlement papers describe it differently. The official settlement website calls the case one “regarding unauthorized access to the Defendant’s computer systems and network”, the short notice inside the agreement says “a third party unlawfully accessed their computer systems and network”, and a trade publication writes that forensics “confirmed” unauthorised access. That is a contradiction inside one and the same case, and we are not going to resolve it for you.
The scale is not in doubt. The federal breach portal lists 483,126 individuals and describes the exposure as “names, Social Security numbers, addresses, diagnoses/conditions, lab results, medications, and other treatment information.” The letters went out on May 9, 2025, not quite six months after Serviceaide learned of it — the data review had only finished on March 20, 2025.
Catholic Health is not a defendant. Serviceaide is the IT service provider; the hospital network is its customer, and the federal portal lists Serviceaide itself as the business associate. The notification letters came from Serviceaide c/o Cyberscout, headed “Notice of Security Incident.” If you were a Catholic Health patient, this is still your case — but the money comes from the vendor.
Eleven federal cases, dropped and refiled in a state court
The procedural history is unusual enough to record. Eleven separate class actions were filed in the Northern District of California in 2025; ten were consolidated on July 22, and a consolidated complaint followed on August 21. Serviceaide moved to dismiss on September 22, the plaintiffs opposed on October 6 — and the motion was never decided.
Instead, after settlement talks in October and November 2025, the plaintiffs voluntarily dismissed the entire federal case and filed a new one in Nassau County, New York, dropping the California unfair-competition count along the way. Dismissing and refiling in state court is a legitimate and common route to settlement approval, and it is why the consolidated California proceedings end in nothing. One further case, Mendez v. Serviceaide in the Western District of New York, is not listed in the settlement at all, and what became of it we do not know.
Fifteen named plaintiffs appear in the state caption. Preliminary approval came on May 21, 2026.
What it paid — and two things it did not include
The fund is $1,800,000 and is explicitly non-reversionary: “'Settlement Fund' means the non-reversionary $1,800,000.00 in cash.” Nothing goes back to Serviceaide.
- Cash Payment A: up to $5,000 for documented losses “as a result of fraud and/or identity theft related to the Data Incident”
- Cash Payment B: an estimated $50, pro rata, no documentation — but you may take A or B, not both
- Claims for A that fail on documentation and are not cured are automatically converted into B, which is a genuinely claimant-friendly clause and rarer than it should be
- Fees requested: up to one third of the fund, $600,000, plus costs. Service awards requested: up to $2,500 for each of fifteen class representatives, $37,500 in total — nothing is awarded until the hearing
Two absences are worth naming, because both are common in breach settlements and both are missing here. There is no lost-time payment — no attested hours at $25, nothing. And the settlement grants no credit monitoring: the only monitoring in this story is the twelve months of Cyberscout that Serviceaide offered in the May 2025 letter, which had to be activated within 90 days of that letter and therefore closed around August 7, 2025 — over a year ago. Inside the settlement, credit monitoring appears in two roles: as an expense you could have claimed under Cash Payment A, and as a deduction — the agreement excludes anything already covered “in connection with the credit monitoring and identity theft protection product offered as part of the notification letter.”
One oddity in the paperwork, which we note without resolving: the agreement names class counsel in one paragraph as Jeff Ostrow, Raina Borrelli, Gary M. Klinger and Scott Cole, and in a later paragraph names two entirely different lawyers. One of the two passages is almost certainly boilerplate carried over from another settlement. We are not going to guess which.
The Data Behind This Story
- Case
- Nancy Balzer, et al., v. Serviceaide, Inc., Index No. 625615/2025
- Court
- Supreme Court of the State of New York, County of Nassau
- Judge
- Hon. Lisa A. Cairo, J.S.C.
- Defendant
- Serviceaide, Inc., Santa Clara, CA — the IT vendor. Catholic Health of Buffalo is its customer and is not a party
- People affected
- 483,126 (federal breach portal)
- Exposure window
- September 19 – November 5, 2024 — 47 days publicly reachable
- Cause
- A database inadvertently made publicly available. The investigation found no evidence anything was copied
- Notified
- May 9, 2025
- Fund
- $1,800,000, non-reversionary
- Benefits
- Up to $5,000 documented, or about $50 pro rata without proof — one or the other
- Lost-time payment
- None
- Credit monitoring in the settlement
- None. The 12 months of Cyberscout came with the 2025 letter and closed around August 7, 2025
- CLAIM DEADLINE
- September 1, 2026 — passed; the portal returns “Deadline Passed”
- Opt-out / objection
- August 17, 2026 — passed
- Final approval hearing
- September 16, 2026, 10:00 a.m. ET, Mineola, NY — may change without notice
- Administrator
- Kroll Settlement Administration, (833) 930-1176
- Source: Settlement Agreement in Balzer v. Serviceaide, Inc., read September 4, 2026 — the fifteen-plaintiff caption, the identification of Catholic Health as Serviceaide's customer (¶ 2), the procedural history of the eleven Northern District of California cases, their consolidation on July 22, 2025, the August 21, 2025 consolidated complaint, the September 22, 2025 motion to dismiss and the voluntary dismissal and refiling in Nassau County (¶¶ 6–12), the class counsel definition (¶ 25) and the conflicting later paragraph, the administrator (¶ 59), the non-reversionary $1,800,000 fund (¶ 64), the $5,000 documented-loss and estimated $50 alternate payments (¶¶ 18–19 and Section V), the automatic conversion of failed Cash Payment A claims, the fee request of up to $600,000 (¶ 101) and the fifteen $2,500 service awards (¶ 100). A full-text search of the 3,602-line agreement for “lost time,” “attested time,” “time spent,” “hourly” and “per hour” returned zero hits, with “credit monitoring” as the control term returning hits in the same pass.
- Source: Preliminary Approval Order, NYSCEF Doc. No. 25, received May 21, 2026 — the caption and index number, the signature “/s/ Hon. Lisa A. Cairo, J.S.C.” dated the 21st day of May 2026, and the schedule at ¶ 21 fixing notice completion for July 17, 2026, the final approval and fee motion for August 3, 2026, opt-out and objection for August 17, 2026, the claim deadline fifteen days before the hearing, and the hearing itself for September 16, 2026 at 10:00 a.m. ET.
- Source: Official settlement website serviceaidedatasettlement.com and the Kroll claim portal at forms.ksacms.com, both read September 4, 2026 — the posted deadlines matching the court's schedule, the absence of any extension notice, and the claim form itself returning “Deadline Passed — The deadline for this form has passed.”
- Source: Serviceaide notification letter dated May 9, 2025 — the November 15, 2024 discovery, the September 19 to November 5, 2024 exposure window, the sentence “the investigation did not identify any evidence that information was copied, but we are unable to rule out this type of activity,” the March 20, 2025 completion of the data review, the data categories, and the twelve months of Cyberscout monitoring with a 90-day activation window.
- Source: HHS Office for Civil Rights breach portal, Archive tab, entity search “Serviceaide,” read September 4, 2026 — 483,126 individuals affected, Serviceaide listed as a business associate, and the official description of the exposure. The control check was that the same search on the “Under Investigation” tab returns nothing while the Archive tab returns the record.
- Source: Barclay v. Serviceaide, Inc., No. 5:25-cv-04278 (N.D. Cal.), complaint via CourtListener — the corporate details of the defendant and the 47-day characterisation of the exposure window at ¶ 39.
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.