Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Bayhealth Medical Center Reaches $2.5 Million Class Action Settlement Following 2024 Data Breach

Bayhealth Medical Center agreed to a $2.5M class action settlement following a 2024 data breach exposing patient records. See if you qualify for cash payouts up to $5,000.

large-field-of-ripe-wheat-under-the-open-sky-on-a-2025-02-12-05-09-11-utc 1

If you received care at Bayhealth Medical Center or received a security notice regarding your personal information, you may be eligible to receive cash compensation and free identity protection services.

Bayhealth Medical Center has agreed to establish a $2.5 million settlement fund to resolve a class action lawsuit alleging the Delaware-based healthcare network failed to adequately protect patient data during a cyberattack discovered in July 2024. The breach potentially exposed sensitive medical records, health insurance details, and Social Security numbers belonging to nearly half a million people.

While Bayhealth denies any wrongdoing, the healthcare provider agreed to the monetary settlement to resolve the claims and avoid the risks and ongoing costs of trial.

What Happened in the Bayhealth Medical Center Cyberattack?

In late July 2024, unauthorized third parties breached Bayhealth Medical Center’s computer network, accessing and copying sensitive files without authorization between July 27 and July 31, 2024. Reports indicated that the Rhysida ransomware group claimed responsibility for intruding into the system and acquiring patient files.

The compromised files contained highly sensitive personal details, including patient names, contact information, Social Security numbers, health insurance details, and private medical treatment records.

Following the incident, affected individuals filed a class action lawsuit asserting that Bayhealth failed to implement reasonable and industry-standard cybersecurity safeguards to protect patient data. The lawsuit alleged that had Bayhealth maintained proper administrative, physical, and technical security measures, the unauthorized access could have been prevented.

What Does the $2.5 Million Bayhealth Settlement Provide?

The $2.5 million settlement fund establishes monetary reimbursement and ongoing protection for all nationwide residents whose personal information was exposed in the July 2024 breach. Eligible class members have two primary choices for monetary recovery, in addition to medical data monitoring services:

  • Documented Out-of-Pocket Reimbursements (Up to $5,000): Class members who experienced financial losses directly tied to the breach can claim up to $5,000. Reimbursable expenses include fraudulent charges, credit monitoring or identity theft protection fees, fees for freezing or unfreezing credit reports, and administrative costs such as postage or notary fees.

  • Pro-Rated Cash Payout (Approximately $60): Class members who did not incur documented out-of-pocket expenses can elect to receive a single cash payment instead. The baseline estimate is roughly $60, though the final payout may increase or decrease on a pro-rata basis depending on the total number of valid claims submitted and remaining funds after administrative fees and legal costs.

  • Two Years of Free Medical Data Monitoring: Regardless of whether you submit a claim for cash reimbursement or the flat cash payment, all eligible class members can enroll in two years of free medical data monitoring services to help detect potential identity theft or unauthorized use of health records.

Legal Rights and Data Privacy Protections under Federal and State Law

Healthcare providers hold a legal duty under both state common law and federal statutory frameworks to safeguard patient privacy. Lawsuits surrounding medical data breaches often involve core federal standards:

  • Health Insurance Portability and Accountability Act (HIPAA): Requires healthcare organizations to maintain strict administrative, physical, and technical safeguards to preserve the confidentiality and security of Protected Health Information (PHI).

  • Federal Trade Commission Act (FTC Act): Prohibits unfair or deceptive business practices, enforcing that companies must provide reasonable cybersecurity protection for sensitive consumer data.

Under these standards, consumers whose protected health information is compromised maintain rights to hold corporations accountable for security failures and recover damages for the resulting risks of identity theft and financial fraud.

Who Is Eligible to Participate in the Bayhealth Settlement?

You may be eligible to participate in the settlement if you meet the following criteria:

  • You reside in the United States.

  • Your personal information or protected health information was compromised in the Bayhealth Medical Center data breach discovered in July 2024.

  • You received a formal data breach notification letter or notice from Bayhealth regarding the security incident.

Court documents indicate that the settlement covers approximately 496,261 individuals nationwide.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
The Time for Action is Now!
Mass Arbitrations
Active Data Breaches
Date of Breach: Reported July 31, 2026
Date of Breach: Reported July 31, 2026
Date of Breach: Reported July 31, 2026
Latest News