Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Equinox Inc. Reaches Class Action Data Breach Settle ment: How to Claim Your Cash Payout and Credit Monitoring

A proposed class action settlement has been reached in New York state court (McHugh v. Equinox, Inc. and Carter v. Equinox, Inc.) resolving claims against Equinox, Inc. stemming from an April 2024 security incident.

large-field-of-ripe-wheat-under-the-open-sky-on-a-2025-02-12-05-09-11-utc 1

Equinox Inc. has agreed to a class action settlement following an April 2024 data breach that exposed sensitive personal, medical, and financial information belonging to consumers across the United States. If you received a breach notification letter from Equinox informing you that your personal records were involved in the incident, you may be eligible to submit a claim for cash compensation and free credit protection services before the October 23, 2026 filing deadline.

What Happened During the April 2024 Equinox Data Breach?

The settlement resolves consolidated class action litigation pending in the Supreme Court of the State of New York, Albany County (McHugh v. Equinox, Inc., Index No. 911677-24, and Carter v. Equinox, Inc., Index No. 901198-25). According to court filings, Equinox detected suspicious network activity on or around April 29, 2024.

A subsequent investigation revealed that cybercriminals gained unauthorized access to Equinox’s internal systems and acquired files containing highly sensitive customer and patient records. Following the discovery, Equinox retained cybersecurity experts, notified law enforcement authorities, and mailed formal data breach notification letters to affected individuals.

Plaintiffs filed class action lawsuits alleging that Equinox failed to implement reasonable cybersecurity safeguards to protect consumer data from foreseeable cyberattacks. The lawsuits further claimed that the exposure of private records created an ongoing, heightened risk of identity theft, fraud, and unauthorized financial transactions for impacted individuals.

What Personal Information Was Exposed in the Cyber Incident?

Data breaches involving medical and financial infrastructure carry serious long-term risks for consumers because compromised health insurance and identity records cannot easily be changed like a compromised credit card number.

Court notices confirm that the unauthorized access exposed a broad range of sensitive personal identification and health details, including:

  • Basic Identity Information: Full names, physical addresses, and dates of birth.

  • Government Identifiers: Social Security numbers and driver’s license numbers.

  • Health & Medical Records: Health insurance details, medical treatment and diagnosis information, medication-related records, provider names, and medical record numbers (MRN) or patient IDs.

  • Financial Details: Personal financial account information associated with customer profiles.

Equinox denies all claims of legal liability and maintains that it did nothing wrong. No court has found Equinox guilty of any legal violation. However, to avoid the high costs, distractions, and prolonged uncertainty of litigation, Equinox agreed to settle the claims with affected consumers.

Settlement Benefits: Cash Reimbursements and Free Credit Monitoring

Under the terms of the settlement agreement, eligible consumers who submit a timely and valid claim form can select from multiple forms of financial relief and identity protection benefits.

The settlement structure allows class members to claim the following remedies:

  • Documented Out-of-Pocket Loss Reimbursement: Class members can claim up to $5,000 for verified, unreimbursed financial losses directly linked to the data breach. Covered expenses include bank fees, fraudulent charges, credit monitoring costs incurred independently, professional fees, and administrative expenses related to identity recovery.

  • Pro Rata Cash Payment: In addition to or instead of documented loss claims, class members can request an estimated $100 cash payment. The exact final payout may be adjusted upward or downward on a pro rata basis depending on the total number of valid claims submitted.

  • Three Years of Free Credit Monitoring: Class members can enroll in three years of one-bureau credit monitoring services. This benefit includes dark web monitoring, up to $1 million in identity theft insurance coverage, and fully managed identity restoration services.

Class Counsel will ask the court to approve attorneys’ fees not to exceed $228,333.33 (one-third of the overall fund value), plus out-of-pocket litigation expenses, alongside representative service awards of up to $2,500 for each named plaintiff.

How Data Privacy Laws Protect Consumers from Corporate Cyber Risks

State data privacy statutes and common law negligence principles require organizations that collect private records to maintain safeguards commensurate with the sensitivity of that information. When companies collect Social Security numbers and medical histories, consumers trust them to maintain strong cybersecurity protections.

When data security measures fall short, consumers bear the burden of monitoring bank accounts, responding to fraudulent inquiries, and repairing damaged credit profiles. Class action settlements help rebalance this burden by requiring companies to fund credit monitoring services and reimburse consumers for out-of-pocket identity theft expenses.

Through class action litigation, everyday people can join together to ensure that corporate entities invest in proper data security protocols. This settlement holds Equinox accountable while providing direct compensation to people whose private records were exposed.

Who Qualifies for the Equinox Data Breach Class Action Settlement?

You don’t need to guess whether your personal information was exposed in the April 2024 incident. Eligibility is clear and straightforward based on formal notice.

You may be eligible to receive settlement benefits if you meet the following criteria:

  • Geographic Requirement: You are a living individual currently residing in the United States.

  • Breach Notice: You were sent a formal data breach notice letter directly from Equinox indicating that your personal information may have been impacted in the April 29, 2024 data incident.

If you received a notice letter in the mail or via email from Equinox or the settlement administrator, you are automatically included as a class member and have the legal right to submit a claim.

Key Deadlines and How to Submit Your Claim Before Time Runs Out

If you are a class member, you must take active steps before the upcoming court deadlines to protect your rights or claim cash benefits:

  • Submit a Claim Form (Deadline: October 23, 2026): To receive a pro rata cash payment, loss reimbursement, or credit monitoring, you must submit a claim online at the official settlement website or postmark a paper claim form by October 23, 2026.

  • Exclude Yourself (Deadline: September 23, 2026): If you want to keep your right to sue Equinox individually regarding these claims, you must submit a written request for exclusion postmarked by September 23, 2026. You will not receive settlement benefits if you exclude yourself.

  • Object to the Settlement (Deadline: September 23, 2026): If you do not exclude yourself, you can write to the court explaining why you object to the settlement terms by September 23, 2026.

  • Final Approval Hearing (November 12, 2026): The Supreme Court of the State of New York, Albany County, will hold a final fairness hearing on November 12, 2026, at 11:00 a.m. to decide whether to grant final approval to the settlement.

You do not need to still physically own or possess the iPhone to participate, provided you can verify your purchase during the qualifying period.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
The Time for Action is Now!
Mass Arbitrations
Active Data Breaches
Date of Breach: Reported to Vermont AG on July 25, 2026 (specific breach date not publicly disclosed)
Date of Breach: February 18, 2026 (discovered)
Date of Breach: Breach occurred in March 2026; publicly disclosed and added to breach-monitoring databases in July 2026
Latest News