Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Mental Health Association Agrees to Settlement Over 2024 Cyberattack Exposing Sensitive Patient Data

If you received care or services from the Mental Health Association, Inc. or had your personal details stored on its network, your sensitive information may have been exposed in a targeted 2024 cyberattack.

large-field-of-ripe-wheat-under-the-open-sky-on-a-2025-02-12-05-09-11-utc 1

The Massachusetts-based nonprofit community organization has agreed to a class action settlement to resolve allegations that it failed to adequately protect patient and client records from unauthorized access.

The security incident exposed private personal and medical details for approximately 12,633 people. The class action lawsuit claimed that the Mental Health Association did not maintain reasonable cybersecurity measures to shield sensitive files from bad actors. To resolve the litigation, the organization established a settlement fund offering free credit monitoring, reimbursement for out-of-pocket expenses, payment for lost time, or a hassle-free cash payout for affected individuals.

Court documents indicate that the agreement received preliminary court approval on July 24, 2026. Affected consumers now have a limited window to file a claim and secure their settlement benefits before upcoming legal deadlines.

What Happened During the Mental Health Association Data Breach?

The class action lawsuit stems from a targeted cyberattack that occurred on or around November 28, 2024. According to court filings, unauthorized actors managed to breach the Mental Health Association’s computer systems and access confidential files containing sensitive personal, financial, and medical information.

The lawsuit alleged that the organization failed to implement basic cybersecurity protections, deploy adequate encryption, or properly train staff to prevent unauthorized system access. As a result, cybercriminals were able to compromise private data that individuals entrusted to the healthcare provider.

The Mental Health Association has not admitted any wrongdoing or liability, but agreed to the financial settlement to resolve the lawsuit and avoid the expense, delay, and uncertainty of an extended trial.

What Private Information Was Exposed in the 2024 Cyberattack?

Data breaches involving medical and mental health facilities are particularly concerning because they often expose deeply sensitive medical histories alongside standard personal identifiers. The lawsuit alleged that the compromised files contained a combination of the following confidential information:

  • Full names and residential addresses

  • Social Security numbers

  • Medical diagnoses and health condition details

  • Prescription medication details and history

  • Medical record numbers and clinical notes

When cybercriminals acquire this type of combined medical and personal data, affected individuals face elevated risks of identity theft, medical fraud, financial exploitation, and targeted phishing attempts.

Who Is Eligible to Receive Payouts and Free Credit Monitoring?

You may be eligible to participate in the settlement if you received a notice informing you that your private information was accessed or potentially compromised during the Mental Health Association cyberattack on or around November 28, 2024.

The court-approved class includes all individuals living in the United States whose personal, financial, or health data was accessible in the breach. Approximately 12,633 individuals have been identified as eligible class members.

If you are unsure whether you are included, you can check your eligibility by locating the official settlement notice sent by mail or email, which contains a unique login ID and PIN for the online claim portal.

What Settlement Benefits and Cash Payments Can You Claim?

The settlement structure provides several options so that affected consumers can choose the remedy that best fits their situation. Eligible class members can choose between itemized loss reimbursements or a direct cash payment, in addition to free identity protection tools.

Option 1: Reimbursement for Documented Out-of-Pocket Losses

If you spent money dealing with the fallout of the data breach, you can submit a claim for up to $5,000 in reimbursement for out-of-pocket expenses incurred between November 28, 2024, and November 19, 2026. Covered expenses include:

  • Unreimbursed losses resulting from identity theft or fraud.

  • Fees paid for credit reports, credit monitoring, or credit freezes and unfreezes.

  • Costs associated with replacing government-issued identification cards.

  • Miscellaneous administrative expenses like postage, notary fees, or long-distance phone calls.

Class members filing for documented losses must provide supporting documentation, such as bank statements, receipts, or police reports.

Option 2: Payment for Lost Time

If you spent time resolving identity theft issues or protecting your accounts after receiving notice of the breach, you can claim compensation for lost time. You can receive $25 per hour for up to three hours (for a maximum of $75).

This payment covers time spent changing passwords, monitoring credit accounts, contacting financial institutions, or researching the security incident. Time payment claims can be combined with out-of-pocket loss claims.

Option 3: Direct Cash Payment (No Proof Required)

If you did not incur out-of-pocket costs or prefer a simple option without gathering receipts, you can select a flat cash payment of $40. No supporting documentation or proof of expense is required to claim this benefit.

Note: All cash payment amounts may be adjusted proportionally (pro rata) if the total value of approved claims exceeds the $300,000 settlement threshold.

Option 4: Three Years of Free Credit Monitoring

Every class member—regardless of whether they select documented losses, lost time, or a flat cash payout—is eligible to enroll in three years of free credit monitoring through CyEx Identity Defense Complete. This service includes dark web scanning, public records monitoring, real-time credit alerts, and $1 million in identity theft insurance.

Understanding Health Data Privacy Laws and Corporate Accountability

Healthcare providers and community organizations have a strict duty under federal and state law to protect sensitive patient information. Laws such as the Health Insurance Portability and Accountability Act (HIPAA), alongside state data privacy and consumer protection statutes, establish safeguards to ensure that personal health information remains confidential.

When organizations fail to maintain adequate technical safeguards, plaintiffs can file class action lawsuits alleging negligence, breach of implied contract, and violations of state privacy laws. These legal actions hold corporations and non-profits accountable, ensuring they upgrade their security protocols and compensate consumers for the risks imposed on them.

By participating in class action settlements, everyday people send a clear message to organizations that safeguarding sensitive personal and medical data must be a top priority.

How to File Your Claim Before the November 2026 Deadline

To receive any financial compensation or credit monitoring services under this settlement, you must take action before the court-enforced deadline.

Key Deadlines to Remember:

  • Claim Filing Deadline: November 19, 2026 (Claims must be submitted online or postmarked by this date).

  • Final Approval Hearing: December 15, 2026 (The court will review the settlement to decide whether to grant final approval).

Steps to Submit Your Claim:

  1. Locate Your Notice: Find the official settlement notice sent to you via mail or email. Locate your unique Login ID and PIN.

  2. Visit the Official Portal: Go directly to the court-approved settlement website at MHADataSettlement.com.

  3. Complete the Claim Form: Enter your Login ID and PIN, select your preferred benefit (flat cash payout or documented loss reimbursement), and choose whether to enroll in the free three-year credit monitoring service.

  4. Attach Documentation (If Applicable): If claiming out-of-pocket expenses, upload digital copies of your receipts or bank statements.

  5. Submit by Mail (Alternative): If you prefer not to submit online, you can download a PDF version of the claim form from the official website, print it, fill it out, and mail it to the settlement administrator before November 19, 2026.

Benefits will be distributed after the court grants final approval during the December 15, 2026 hearing and after any potential legal appeals are resolved.

Take Action to Protect Your Information and Rights Today

Data breaches can disrupt your life and leave your private health information vulnerable to bad actors for years. You don’t stand alone when dealing with the aftermath of a corporate or institutional security failure. Everyday people deserve accountability and fair compensation when their sensitive data is exposed.

If you received notice of the Mental Health Association data breach, make sure to submit your claim at MHADataSettlement.com before the November 19, 2026 deadline.

If you suspect your information was compromised in a different healthcare or corporate data breach and want to explore your legal options, connect with an experienced consumer protection attorney.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
The Time for Action is Now!
Mass Arbitrations
Active Data Breaches
Date of Breach: Reported to the Vermont Attorney General in September 2026; underlying incident reported mid-2026
Date of Breach: Reported to the Vermont Attorney General in September 2026
Date of Breach: Reported September 2026; not yet confirmed by the company
Latest News