Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Palomar Health Data Breach Settlement: Up to $5,000 Available for Impacted San Diego Patients

Arch Health Partners, doing business as Palomar Health Medical Group, has agreed to pay $3.1 million to settle a class action lawsuit over an extensive cybersecurity incident that compromised patient information.

large-field-of-ripe-wheat-under-the-open-sky-on-a-2025-02-12-05-09-11-utc 1

If you received care or accessed services through Palomar Health Medical Group and had your personal or protected health data exposed between April 23 and May 5, 2024, you may be eligible to submit a claim for a cash payment or credit protection services.

What Happened in the Palomar Health Data Breach Incident?

The litigation, titled Castro et al. v. Arch Health Partners, Inc. (Case No. 37-2024-00024339-CU-NP-CTL), was brought forward after unauthorized actors breached the computer systems of Palomar Health Medical Group. According to court filings, cybercriminals accessed and copied sensitive digital records continuously from late April through early May 2024.

Plaintiffs in the class action alleged that the healthcare network—which operates hospitals, medical clinics, outpatient facilities, urgent care centers, and laboratories across northern San Diego County—failed to implement reasonable cybersecurity safeguards, properly encrypt patient databases, or adequately dispose of outdated personal data. While Palomar Health Medical Group agreed to the $3.1 million settlement to end the litigation, the organization denies all claims of negligence and wrongdoing.

What Patient Data Was Exposed in the Breach?

The cyberattack compromised a wide variety of personal, financial, and highly sensitive health records. Depending on the patient’s history with the medical network, the exposed information may include:

  • Full names, home addresses, dates of birth, and contact information

  • Social Security numbers and driver’s license details

  • Financial account numbers, credit or debit card data, and online login credentials

  • Health insurance policy details, member IDs, and billing records

  • Comprehensive medical histories, diagnoses, test results, treatment information, and physician records

When private medical files and identity numbers fall into unauthorized hands, victims face an ongoing threat of identity theft, fraudulent insurance claims, and financial exploitation.

Who Is Eligible to Receive Money or Benefits From the Settlement?

You may be eligible to file a claim as a settlement class member if you reside in the United States and received a notice stating that your personal details or protected health information were accessed, acquired, or compromised during the Palomar Health Medical Group data incident between April 23, 2024, and May 5, 2024.

The class covers individuals who received care through Palomar Health Medical Group or its affiliated entities, including Graybill Medical Group and Pacific Accountable Care in inland North San Diego County.

How Much Money Can Class Members Receive From the Settlement?

The $3.1 million settlement fund provides three distinct avenues of relief for verified class members, allowing affected individuals to select options that best meet their situation:

  • Documented Out-of-Pocket Losses (Up to $5,000): Class members who experienced financial harm due to the incident can claim up to $5,000 in reimbursement. Eligible expenses include unreimbursed bank fees, identity theft losses, credit monitoring purchases, professional fees, or time spent addressing identity compromise. Supporting documentation, such as receipts, bank statements, or correspondence, must be included with the claim.

  • Alternative Flat Cash Payment (Estimated $60): Class members who do not have documented financial losses or prefer not to submit proof can choose a flat cash payout estimated at $60. The final amount may be adjusted on a pro-rata basis depending on the total number of claims submitted.

  • Credit Monitoring and Identity Protection: In addition to cash payments, all class members can enroll in two years of free single-bureau credit monitoring services. This benefit includes dark web scanning, identity theft insurance, and dedicated fraud restoration assistance.

Understanding Your Digital Privacy Rights Under Health Data Laws

Federal frameworks like the Health Insurance Portability and Accountability Act (HIPAA), alongside state privacy laws such as the California Confidentiality of Medical Information Act (CMIA), mandate that medical providers maintain strict technical safeguards to secure patient information. Patients entrust healthcare networks with some of their most private details under the reasonable expectation that the data will be protected against cyber threats.

When a healthcare provider experiences a security breakdown that exposes sensitive medical history alongside financial identifiers, affected consumers have the legal right to seek compensation for the resulting risks and burdens. Class action lawsuits allow everyday people to come together, demand accountability from large medical systems, and secure resources to monitor and protect their credit.

Key Deadlines and Instructions to File Your Claim

To participate in the settlement and receive your financial payout or credit monitoring benefits, you must meet the court-established timelines:

  • October 22, 2026 – Claim Submission Deadline: Your claim form must be submitted online by 11:59 p.m. Eastern Time or postmarked by mail no later than October 22, 2026. This is the only way to obtain a cash payment or credit monitoring code.

  • October 22, 2026 – Opt-Out and Exclusion Deadline: If you wish to exclude yourself from the settlement class to maintain your right to sue Palomar Health Medical Group independently, your written request for exclusion must be postmarked by this date.

  • October 22, 2026 – Objection Deadline: If you intend to object to the fairness or terms of the settlement while remaining in the class, your written objection must be filed with the court and sent to counsel by this date.

  • November 6, 2026 – Final Approval Hearing: The court will hold a hearing to decide whether to grant final approval to the $3.1 million deal. Payments and credit monitoring codes will be distributed after the court enters final approval and any potential legal appeals are resolved.

To complete your claim form online, visit the official court-approved website at PHMGDataSettlement.com. You will need the Class Member ID and Confirmation Code printed on the notice you received by mail or email. If you cannot locate your notice, you can still complete a claim form directly on the settlement site.

Cyberattacks on healthcare providers put your most sensitive personal information at risk, but taking action can help safeguard your identity and ensure you receive the compensation you deserve. If your information was compromised in the Palomar Health Medical Group data breach, do not let the filing deadline pass without taking action.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
The Time for Action is Now!
Mass Arbitrations
Active Data Breaches
Date of Breach: December 22, 2025 to January 3, 2026 (discovered December 28, 2025)
Date of Breach: Estimated August 31, 2026 (unconfirmed by the company); first publicly reported September 17, 2026
Date of Breach: Unauthorized access: on or around September 17, 2026 (claimed by ransomware group Akira)
Latest News