🏳️‍⚧️ trans rights are human rights 🏳️‍⚧️
Theme
◀
▶

What Palomar Health’s $3.1 Million Data-Breach Deal Would Actually Pay

Ransomware • Medical data • Proposed settlement

Hackers spent nearly two weeks inside the medical group’s network and accessed or acquired files containing patient information. The proposed deal puts a fixed price on resolving the resulting claims, but “conveniently” leaves the number of affected people undisclosed. Woaw very poggers.

Primary source: settlement agreementSan Diego Superior CourtCase No. 37-2024-00024339-CU-NP-CTL
Subject to court approval

TL;DR

  • Hackers accessed Arch Health Partners’ network from April 23 through May 5, 2024, and accessed or acquired files containing personal, financial, insurance, and health information.
  • Arch Health Partners, doing business as Palomar Health Medical Group, has agreed to a proposed $3.1 million class settlement without admitting liability or wrongdoing.
  • Eligible class members could claim up to $5,000 for documented losses or choose an estimated $60 alternate payment. They could also request two years of one-bureau credit monitoring.
  • Payments can rise or fall depending on the number and value of valid claims. Administration expenses, court-approved legal fees, service awards, and monitoring costs also come from the fund.
  • The agreement does not disclose how many people were affected, how many experienced actual financial loss, or whether the stolen information was misused.
  • Anyone who remains in the class would release breach-related claims even if that person submits no valid claim and receives nothing.

The headline number is $3.1 million. The amount that would reach affected individuals depends on facts the agreement does not yet supply: class size, claims, fees, costs, and court approval.

Transparency notice: This article relies on the supplied settlement agreement. That document records the intrusion, the proposed relief, and the parties’ positions, but it is not a forensic report or a judicial finding of negligence. The plaintiffs alleged unlawful exposure of private information. Palomar Health Medical Group denies fault and liability. The settlement remains contingent on court approval.

For nearly two weeks in spring 2024, hackers had unauthorized access to the computer network of Arch Health Partners, the nonprofit healthcare organization that operates as Palomar Health Medical Group. According to the settlement agreement, they accessed or acquired files containing private information before deploying ransomware that encrypted parts of the system.

The exposed categories potentially reached well beyond names and addresses. Depending on the individual, the files included medical histories, diagnoses, prescriptions, Social Security numbers, insurance identifiers, payment-card information, passwords, or other credentials.

The organization detected the activity on May 5, 2024, after finding a ransom note and encrypted systems. Patients received email notices on or about May 21 and June 12, 2024. The agreement also records a written notice mailed on or about October 15, 2025.

The Facts

Clarissa Castro filed suit on May 28, 2024, alleging unlawful exposure of her information and the information of similarly situated people. Similar cases followed. Five named plaintiffs eventually proceeded in one amended class action against Arch Health Partners, doing business as Palomar Health Medical Group.

The parties reached the material terms of a classwide settlement during private mediation on July 30, 2025. Before mediation, the defendant privately gave plaintiffs’ lawyers information about the incident’s nature and cause, the number and geographic location of victims, and the kinds of information potentially accessed. Those figures and findings do not appear in the agreement supplied for this article.

$3.1MProposed all-cash settlement fund before fees, costs, awards, monitoring, and claims
$5,000Maximum documented-loss claim per eligible class member
$60Estimated alternate cash payment, subject to a proportional increase or decrease
2 yearsOne-bureau credit monitoring offered in addition to either cash option
April 23–May 5, 2024

Hackers accessed the medical group’s network without authorization and accessed or acquired files containing private information.

May 5, 2024

The organization detected a ransom note and encrypted systems, then began containment and investigation.

May 21 and June 12, 2024

The defendant provided email notices to patients on or about these dates.

May 28, 2024

Clarissa Castro filed the first complaint described in the settlement.

September 16, 2024

The plaintiffs filed an amended class-action complaint after counsel consolidated their litigation efforts.

July 30, 2025

The parties agreed to material settlement terms after a full-day mediation.

October 15, 2025

The agreement says written notice was mailed on or about this date.

What Was Taken From the Network

The agreement says the precise information varied by person. It does not say every affected individual had every listed category exposed.

Identity and contact data

Names, addresses, dates of birth, email addresses, and Social Security numbers.

Medical information

Medical histories, disability and diagnostic information, treatments, prescriptions, physicians, and medical-record numbers.

Insurance information

Health-insurance information, subscriber numbers, and group or plan numbers.

Financial and login data

Credit or debit card numbers, security codes or PINs, expiration dates, email-and-password combinations, and usernames and passwords.

The settlement class would include all individuals whose private information was accessed, acquired, disclosed, or compromised in the incident. It excludes the defendant’s directors, officers and agents, government entities, and the assigned judge, the judge’s immediate family, and court staff.

The agreement identifies what kinds of information were compromised. It does not disclose how many people were in the affected population.

What the Incident Meant for Affected People

The documented consequence is unauthorized access to or acquisition of files containing sensitive information. The settlement also records encryption of the organization’s systems. It does not establish that every listed data element was taken for every person.

Nor does the agreement establish that affected people experienced identity theft, fraudulent charges, medical-identity misuse, interrupted care, or other specific downstream harm. The availability of reimbursement for documented losses creates a process for people who say they incurred incident-related expenses; it is not proof that such losses occurred throughout the class.

The notice sequence is also part of the record. Email notices went out in May and June 2024, while written notice was mailed in October 2025. The agreement does not explain the difference between those dates or identify how many people received each form of notice.

If the settlement is approved, affected people will face a practical choice. They may submit a claim, exclude themselves and preserve individual claims, or remain in the class without claiming a benefit. The last option still carries a legal consequence: their incident-related claims would be released.

How the $3.1 Million Fund Would Work

If the settlement takes effect, the defendant’s total payment obligation is capped at the $3.1 million fund. The agreement describes the fund as non-reversionary, meaning money left after the claims process would not ordinarily return to the company. Residual money would instead go to the Electronic Privacy Information Center, subject to court approval. If the settlement fails to become effective, however, remaining money would return to the defendant after outstanding administration costs are paid.

The full $3.1 million is not reserved for payments to affected people. The same pool would pay settlement administration, court-approved attorneys’ fees and costs, service awards for the five named plaintiffs, credit-monitoring services, and cash claims.

Administration, legal fees, costs, and service awards
Credit-monitoring claims
Documented-loss claims
Alternate cash claims
OptionWhat it providesConditions and limits
Documented lossesUp to $5,000 per class memberRequires reasonable records supporting incident-related expenses. Personal statements alone generally do not qualify as documentation.
Alternate cashEstimated payment of $60Paid instead of a documented-loss claim. The amount may increase or decrease according to the available net fund and valid claims.
Credit monitoringTwo years of one-bureau monitoring, dark-web monitoring, and $1 million in identity-fraud insuranceAvailable in addition to either cash option and paid from the settlement fund before cash claims.

A documented-loss claim that lacks adequate support and is not corrected would be treated as an alternate-cash claim. The settlement administrator would have final authority under the agreement to approve, reduce, or deny claims.

Class counsel plans to request attorneys’ fees of up to one-third of the settlement fund, plus reimbursement of costs. Counsel may also request service awards of no more than $2,500 for each named plaintiff. The court, not the parties, will determine what amounts are approved.

The Settlement’s Most Consequential Fine Print

The proposed release extends to known and unknown claims related to the incident. It covers Arch Health Partners and a broad group of related entities and people, including affiliates, successors, officers, employees, contractors, insurers, service providers, data processors, and others who could be alleged to share responsibility.

People who opt out by the court-approved deadline would receive no settlement benefit but would preserve their incident-related claims. Anyone who does not validly opt out would be bound even without filing a claim.

The proposed objection procedure is more demanding than a simple letter of disagreement. Objectors would have to provide their grounds and legal support, identify lawyers and potential witnesses, state whether they plan to attend the final hearing, and disclose class-action settlement objections made by them—and by their counsel or counsel’s firm—during the previous five years. The agreement also permits limited discovery of objectors or their lawyers. These procedures still require court approval.

Payment carries deadlines of its own. Class members would have 90 days to select a payment method, and paper checks would need to be cashed within 90 days after issuance. Undeliverable or unclaimed money would eventually become part of the residual fund.

What Palomar Says Changed

The defendant represents that it has implemented security enhancements since the incident at its own expense, separate from the settlement fund. The listed changes include endpoint detection and response tools, new backup-storage capabilities, and additional network monitoring.

The agreement supplies no technical specifications, implementation dates, independent audit results, or measurements of effectiveness. It also does not publicly identify the attack’s root cause or the safeguards in place before hackers entered the network. Those omissions prevent the settlement itself from establishing whether the new controls correct the weakness that enabled the intrusion.

Palomar entered the agreement to avoid the cost, uncertainty, disruption, and burden of continued litigation. It expressly denies the plaintiffs’ allegations and says the settlement is not an admission of fault. Plaintiffs’ counsel, for their part, say they believe the claims have merit but accepted the deal after weighing the risks and delay of continued litigation.

What the Court Still Must Decide

The document is a proposed settlement, not a liability judgment. It calls for the plaintiffs to seek preliminary approval from the San Diego County Superior Court. If the court grants that request, a notice and claims process would begin. The court would later consider final approval, requested legal fees and costs, service awards, objections, and whether the notice program satisfied due-process requirements.

Approval would mean the judge found the settlement fair, adequate, and reasonable. It would not mean the court found that Palomar negligently secured patient data, violated a particular law, or caused the losses alleged by class members. The agreement contains no such adjudication.

Class certification is similarly limited. Palomar agrees to certification only for settlement purposes. If final approval does not occur, that certification disappears and the company retains the right to oppose certification in renewed litigation.

What to Watch

  • San Diego County Superior Court: whether the court grants preliminary approval and accepts the proposed notice, claim, opt-out, and objection procedures.
  • Settlement administrator: the eventual notice will supply the website and deadlines that do not appear in the agreement.
  • Class counsel: the fee-and-cost application will show how much counsel seeks from the common fund and provide the court with a basis for evaluating the request.
  • Final-approval record: the administrator’s declaration is expected to report the number of claims, rejections, opt-outs, and objections. Those figures will make the settlement’s practical reach easier to assess.
  • Distribution: benefits are scheduled for no later than 75 days after final approval or 30 days after the settlement becomes effective, whichever is later.

The Number the Agreement Does Not Answer

The proposal sets a $3.1 million ceiling and describes several possible benefits. It does not reveal the affected population needed to judge that amount on a per-person basis. Until the notice program, fee request, and claims data enter the court record, the share of the fund that will reach affected people—and how thinly it may be divided—remains unresolved.

The source document for this investigation is attached below.

Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2229