Subscribe To Our Newsletter
If you received care or services from the Mental Health Association, Inc. or had your personal details stored on its network, your sensitive information may have been exposed in a targeted 2024 cyberattack.
The Massachusetts-based nonprofit community organization has agreed to a class action settlement to resolve allegations that it failed to adequately protect patient and client records from unauthorized access.
The security incident exposed private personal and medical details for approximately 12,633 people. The class action lawsuit claimed that the Mental Health Association did not maintain reasonable cybersecurity measures to shield sensitive files from bad actors. To resolve the litigation, the organization established a settlement fund offering free credit monitoring, reimbursement for out-of-pocket expenses, payment for lost time, or a hassle-free cash payout for affected individuals.
Court documents indicate that the agreement received preliminary court approval on July 24, 2026. Affected consumers now have a limited window to file a claim and secure their settlement benefits before upcoming legal deadlines.
The class action lawsuit stems from a targeted cyberattack that occurred on or around November 28, 2024. According to court filings, unauthorized actors managed to breach the Mental Health Association’s computer systems and access confidential files containing sensitive personal, financial, and medical information.
The lawsuit alleged that the organization failed to implement basic cybersecurity protections, deploy adequate encryption, or properly train staff to prevent unauthorized system access. As a result, cybercriminals were able to compromise private data that individuals entrusted to the healthcare provider.
The Mental Health Association has not admitted any wrongdoing or liability, but agreed to the financial settlement to resolve the lawsuit and avoid the expense, delay, and uncertainty of an extended trial.
Data breaches involving medical and mental health facilities are particularly concerning because they often expose deeply sensitive medical histories alongside standard personal identifiers. The lawsuit alleged that the compromised files contained a combination of the following confidential information:
Full names and residential addresses
Social Security numbers
Medical diagnoses and health condition details
Prescription medication details and history
Medical record numbers and clinical notes
When cybercriminals acquire this type of combined medical and personal data, affected individuals face elevated risks of identity theft, medical fraud, financial exploitation, and targeted phishing attempts.
You may be eligible to participate in the settlement if you received a notice informing you that your private information was accessed or potentially compromised during the Mental Health Association cyberattack on or around November 28, 2024.
The court-approved class includes all individuals living in the United States whose personal, financial, or health data was accessible in the breach. Approximately 12,633 individuals have been identified as eligible class members.
If you are unsure whether you are included, you can check your eligibility by locating the official settlement notice sent by mail or email, which contains a unique login ID and PIN for the online claim portal.
The settlement structure provides several options so that affected consumers can choose the remedy that best fits their situation. Eligible class members can choose between itemized loss reimbursements or a direct cash payment, in addition to free identity protection tools.
If you spent money dealing with the fallout of the data breach, you can submit a claim for up to $5,000 in reimbursement for out-of-pocket expenses incurred between November 28, 2024, and November 19, 2026. Covered expenses include:
Unreimbursed losses resulting from identity theft or fraud.
Fees paid for credit reports, credit monitoring, or credit freezes and unfreezes.
Costs associated with replacing government-issued identification cards.
Miscellaneous administrative expenses like postage, notary fees, or long-distance phone calls.
Class members filing for documented losses must provide supporting documentation, such as bank statements, receipts, or police reports.
If you spent time resolving identity theft issues or protecting your accounts after receiving notice of the breach, you can claim compensation for lost time. You can receive $25 per hour for up to three hours (for a maximum of $75).
This payment covers time spent changing passwords, monitoring credit accounts, contacting financial institutions, or researching the security incident. Time payment claims can be combined with out-of-pocket loss claims.
If you did not incur out-of-pocket costs or prefer a simple option without gathering receipts, you can select a flat cash payment of $40. No supporting documentation or proof of expense is required to claim this benefit.
Note: All cash payment amounts may be adjusted proportionally (pro rata) if the total value of approved claims exceeds the $300,000 settlement threshold.
Every class member—regardless of whether they select documented losses, lost time, or a flat cash payout—is eligible to enroll in three years of free credit monitoring through CyEx Identity Defense Complete. This service includes dark web scanning, public records monitoring, real-time credit alerts, and $1 million in identity theft insurance.
Healthcare providers and community organizations have a strict duty under federal and state law to protect sensitive patient information. Laws such as the Health Insurance Portability and Accountability Act (HIPAA), alongside state data privacy and consumer protection statutes, establish safeguards to ensure that personal health information remains confidential.
When organizations fail to maintain adequate technical safeguards, plaintiffs can file class action lawsuits alleging negligence, breach of implied contract, and violations of state privacy laws. These legal actions hold corporations and non-profits accountable, ensuring they upgrade their security protocols and compensate consumers for the risks imposed on them.
By participating in class action settlements, everyday people send a clear message to organizations that safeguarding sensitive personal and medical data must be a top priority.
To receive any financial compensation or credit monitoring services under this settlement, you must take action before the court-enforced deadline.
Claim Filing Deadline: November 19, 2026 (Claims must be submitted online or postmarked by this date).
Final Approval Hearing: December 15, 2026 (The court will review the settlement to decide whether to grant final approval).
Locate Your Notice: Find the official settlement notice sent to you via mail or email. Locate your unique Login ID and PIN.
Visit the Official Portal: Go directly to the court-approved settlement website at MHADataSettlement.com.
Complete the Claim Form: Enter your Login ID and PIN, select your preferred benefit (flat cash payout or documented loss reimbursement), and choose whether to enroll in the free three-year credit monitoring service.
Attach Documentation (If Applicable): If claiming out-of-pocket expenses, upload digital copies of your receipts or bank statements.
Submit by Mail (Alternative): If you prefer not to submit online, you can download a PDF version of the claim form from the official website, print it, fill it out, and mail it to the settlement administrator before November 19, 2026.
Benefits will be distributed after the court grants final approval during the December 15, 2026 hearing and after any potential legal appeals are resolved.
Data breaches can disrupt your life and leave your private health information vulnerable to bad actors for years. You don’t stand alone when dealing with the aftermath of a corporate or institutional security failure. Everyday people deserve accountability and fair compensation when their sensitive data is exposed.
If you received notice of the Mental Health Association data breach, make sure to submit your claim at MHADataSettlement.com before the November 19, 2026 deadline.
If you suspect your information was compromised in a different healthcare or corporate data breach and want to explore your legal options, connect with an experienced consumer protection attorney.
New cases and investigations, settlement deadlines, and news straight to your inbox.