Subscribe To Our Newsletter
Eligible class members can claim up to $2,500 for documented out-of-pocket losses, reimbursement for lost time (up to 3 hours at $15 per hour), and 2 years of CyEx Medical Shield Complete monitoring.
Summit Medical Group, a major healthcare provider network based in Tennessee, has agreed to a class action settlement to resolve allegations that it failed to protect the personal and health records of current and former patients and employees during a September 2024 data breach. If your confidential information was involved in this security incident, you may be eligible to submit a claim for cash compensation and free medical identity monitoring tools before upcoming court deadlines.
The lawsuit, Harris, et al. v. Summit Medical Group, PLLC, filed in Tennessee state court, alleged that the healthcare network omitted reasonable technical and administrative cybersecurity measures, leaving sensitive medical databases vulnerable to cybercriminals. Approximately 464,000 individuals across the United States were affected by the breach and received official notices from the organization.
In September 2024, cybercriminals gained unauthorized access to internal computer networks operated by Summit Medical Group, PLLC. The intrusion allowed bad actors to view and potentially exfiltrate confidential files stored on company servers.
After discovering the unauthorized access, Summit Medical Group conducted an investigation and determined that internal databases holding protected health information and personal identifying details had been accessed without authorization. Affected individuals were subsequently mailed official data breach notices informing them that their files had been compromised.
Plaintiffs filed a class action lawsuit in July 2025, asserting that Summit Medical Group breached its legal obligation to safeguard consumer and employee data under federal and state privacy standards.
According to court filings, the September 2024 security breach exposed a wide range of sensitive health data and personal identifiers. The compromised information varied by individual but included:
Full names and residential contact information
Social Security numbers
Healthcare provider names and visited facilities
Dates of service, diagnosis details, and treatment records
Prescription histories and medication details
Health insurance policy numbers and claims data
When healthcare providers experience network intrusions of this magnitude, affected individuals face an ongoing risk of medical identity theft, falsified health insurance claims, and financial account exploitation.
The class action lawsuit claimed that Summit Medical Group failed to implement modern, industry-standard data protection safeguards. Plaintiffs argued that adequate firewalls, data encryption, access controls, and routine network monitoring could have prevented cybercriminals from breaching internal systems.
The litigation contended that victims were forced to spend valuable time and out-of-pocket funds securing their personal identities, placing credit freezes, and monitoring bank accounts for unauthorized charges.
Summit Medical Group denies all allegations of wrongdoing and maintains that its computer systems and administrative safeguards were appropriate. However, to avoid the delay, expense, and uncertainty of ongoing litigation, the provider agreed to a class action settlement to resolve all pending claims. The court granted preliminary approval to the settlement agreement on July 28, 2026.
If you are a member of the settlement class, you can submit a claim to receive financial reimbursement for documented losses, compensation for lost time, and enrollment in specialized identity monitoring services.
Class members who suffered documented financial losses resulting directly from the September 2024 breach can claim up to $2,500 in cash reimbursement. Eligible expenses incurred between September 2024 and November 4, 2026, include:
Unreimbursed financial losses stemming from identity theft or fraudulent bank activity.
Fees paid for credit monitoring services, credit reports, or credit freezes and unfreezes.
Costs associated with obtaining replacement government-issued identification cards.
Postage, notary services, and communication expenses incurred while resolving identity theft claims.
To receive out-of-pocket reimbursement, you must submit supporting documentation, such as bank statements, receipts, credit bureau alerts, or police reports verifying your financial losses.
Class members can file a claim to receive reimbursement for up to three hours of lost time spent addressing issues caused by the data breach, calculated at a rate of $15 per hour (up to $45 total). Eligible activities include changing compromised account passwords, researching the security incident, and investigating suspicious financial charges.
(Note: Should the total sum of all valid documented-loss and lost-time claims exceed a collective cap of $500,000, individual cash payouts will be reduced on a pro rata basis.)
All class members can elect to receive two years of CyEx Medical Shield Complete. This specialized identity defense service provides active monitoring for medical data exposure and medical identity theft insurance coverage.
Healthcare networks operate under strict legal frameworks, including federal regulations such as the Health Insurance Portability and Accountability Act (HIPAA) and state consumer privacy statutes. These laws mandate that organizations handling protected health information deploy administrative, physical, and technical safeguards to prevent unauthorized access.
When a healthcare provider collects sensitive items—such as Social Security numbers, treatment histories, and health insurance information—it assumes a duty to protect those files from cyber intrusions. Class action lawsuits allow everyday people to unite, hold large corporate entities accountable for security oversights, and seek recovery for their losses.
You may be eligible to participate in the settlement if you reside in the United States and your private information was potentially compromised during the September 2024 Summit Medical Group data breach, including all individuals who were mailed an official notice of the incident.
Court documents indicate that the settlement class encompasses approximately 464,000 people across the country.
If you received an official settlement notice postcard, it contains the unique Login ID and PIN required to access your pre-populated claim form online. If you need to check your eligibility, you can access the official settlement site at SummitMedicalDataSettlement.com.
To claim financial benefits or preserve your legal rights regarding this security incident, you must pay attention to several court-ordered deadlines:
| Event or Action | Deadline Date | What It Means for You |
| Claim Form Deadline | November 4, 2026 | Last day to submit your claim form online or postmark a paper claim form by mail. |
| Reimbursement Expense Period | November 4, 2026 | End date for incurring eligible out-of-pocket expenses tied to the breach. |
| Final Approval Hearing | November 19, 2026 | The court will hold a hearing to decide whether to grant final approval to the settlement terms. |
If you take no action, you will forfeit your right to claim cash reimbursement, lost-time compensation, or identity monitoring, and you will give up your right to sue Summit Medical Group independently regarding this incident. Compensation will be distributed only after the court grants final approval and any potential appeals are resolved.
Submitting a claim is simple and can be completed online before the November 4, 2026 deadline:
Visit the Official Settlement Website: Navigate to SummitMedicalDataSettlement.com.
Log In to Your Claim Form: Enter the unique Login ID and PIN located on the settlement notice postcard mailed to you.
Select Your Settlement Benefits: Indicate whether you are claiming reimbursement for documented out-of-pocket expenses (up to $2,500), compensation for lost time (up to 3 hours at $15/hour), and/or enrolling in two years of CyEx Medical Shield Complete monitoring.
Upload Proof (If Applicable): If requesting out-of-pocket expense reimbursement, upload digital copies or photos of receipts, credit bureau statements, or bank alerts documenting your losses.
Provide Payment Details: Choose how you wish to receive your cash payout, such as direct digital payment or a physical paper check.
Submit Your Form: Complete your digital submission before 11:59 p.m. on November 4, 2026, or ensure paper claim forms are postmarked by November 4, 2026.
Everyday people trust medical providers with their most sensitive health records and personal information. When cybersecurity oversights expose private data to bad actors, consumers should not have to carry the financial burden of identity protection alone.
Don’t stand alone. If your personal or medical records were exposed in the September 2024 Summit Medical Group security incident, exercise your rights and submit your claim before the November 4, 2026 deadline.
New cases and investigations, settlement deadlines, and news straight to your inbox.