Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Susan B. Allen Memorial Hospital Agrees to Class Action Settlement Following July 2025 Patient Data Breach

Susan B. Allen Memorial Hospital has agreed to a class action settlement following a July 2025 data breach that exposed the sensitive personal and medical records of over 12,000 patients.

large-field-of-ripe-wheat-under-the-open-sky-on-a-2025-02-12-05-09-11-utc 1

Susan B. Allen Memorial Hospital has agreed to resolve a class action lawsuit alleging the Kansas-based healthcare provider failed to protect private medical and personal information during a targeted cyberattack in July 2025.

The security incident affected more than 12,000 patients and individuals whose sensitive health records, full names, dates of birth, billing information, and medical treatment details were stored on company network systems.

Under the terms of the court-approved class action agreement, affected individuals can file a claim to receive up to $100 in combined cash benefits along with two full years of medical identity protection. If you received a written data breach notification letter from Susan B. Allen Memorial Hospital, you may be eligible to claim compensation before upcoming court deadlines.

What Happened During the July 2025 Cyberattack on Susan B. Allen Memorial Hospital?

In July 2025, unauthorized bad actors breached internal computer networks at Susan B. Allen Memorial Hospital, accessing files that contained confidential patient and administrative records.

According to court filings in In Re: Susan B. Allen Data Security Litigation (Case No. BU-2025-CV-000185), cybercriminals gained access to files containing sensitive personal and health information.

The compromised information included a wide range of sensitive patient details:

  • Full names and dates of birth

  • Health insurance information and billing records

  • Medical treatment details and healthcare histories

Following an internal investigation, notifications were sent to impacted individuals informing them that their confidential files had been accessed. Plaintiffs subsequently filed a class action lawsuit in the District Court of Butler County, Kansas, arguing that the hospital failed to implement modern cybersecurity defenses to prevent foreseeable cyber intrusions.

What Allegations Were Raised in the Healthcare Data Incident Lawsuit?

The lawsuit alleged that Susan B. Allen Memorial Hospital failed to uphold basic privacy standards and failed to maintain adequate technical safeguards needed to defend patient systems against unauthorized access.

Key legal claims raised by the plaintiffs included:

  • Failure to Secure Patient Records: Failing to implement encryption and network firewalls necessary to safeguard protected health information.

  • Increased Vulnerability to Medical Fraud: Exposing patients to medical identity theft, falsified insurance claims, and unauthorized financial transactions.

  • Inconvenience and Preventable Expenses: Forcing victims to dedicate time and personal funds toward account monitoring, fraud investigations, and password resets.

Susan B. Allen Memorial Hospital denies all allegations of wrongdoing and maintains that its IT infrastructure was reasonable. However, to avoid the delay, expense, and uncertainty of protracted trial proceedings, the hospital agreed to establish a class action settlement structure to compensate affected patients.

What Benefits and Cash Payments Can You Claim From the Settlement?

The settlement structure allows class members to claim both identity protection services and cash reimbursements, subject to a combined total cash cap of $100.00.

1. Two Years of CyEx Medical Shield Complete Monitoring

All eligible class members can enroll in two years of complimentary CyEx Medical Shield Complete services. This specialized medical identity monitoring package includes:

  • $1 million in medical identity theft insurance coverage

  • Monitoring for Healthcare Insurance ID and Medical Record Number (MRN) exposure

  • Real-time alerts for unauthorized Health Savings Account (HSA) spending

  • Dedicated access to fraud resolution agents to assist with identity recovery

2. Cash Reimbursement for Attested Lost Time (Up to $100)

If you spent time addressing the fallout of the security incident—such as researching the breach, monitoring bank statements, changing passwords, or freezing credit accounts—you can claim $25 per hour for up to four hours (maximum $100.00). No receipts are required for this claim; you only need to provide a brief written description of how your time was spent.

3. Reimbursement for Out-of-Pocket Expenses (Up to $100)

If you incurred actual out-of-pocket costs related to the breach between July 14, 2025, and November 12, 2026, you can submit a claim for cash reimbursement. Covered expenses include credit report fees, credit freeze costs, replacement ID fees, postage, and unreimbursed fraud losses. Supporting proof, such as bank statements or receipts, is required.

Note: An aggregate cap of $100.00 applies across both cash payout options combined. A claimant cannot receive $100 for time and an additional $100 for out-of-pocket losses; the total cash payout per person is capped at $100.00.

Understanding Patient Rights Under Healthcare Privacy Laws

Federal standards such as the Health Insurance Portability and Accountability Act (HIPAA) alongside state consumer privacy codes require healthcare organizations to implement administrative and technical security measures to safeguard protected health information.

Medical records are among the most sensitive data points an individual possesses. Unlike a credit card number that can be canceled and reissued, a medical record number or health history cannot be changed once exposed.

When hospital systems fall short of cybersecurity standards, patient safety and financial security are compromised. Class action lawsuits allow everyday citizens to join together, demand accountability from healthcare institutions, and recover compensation for security lapses.

Who Is Eligible to File a Settlement Claim?

You may be eligible to participate as a class member if you reside in the United States and received a written or electronic notice from Susan B. Allen Memorial Hospital stating that your personal or health information was potentially compromised during the July 2025 data incident.

The settlement class encompasses over 12,000 patients and individuals whose details were maintained on affected hospital servers.

If you need to verify whether you are on the class list or need help requesting your Notice credentials, you can reach the official settlement administrator:

  • Settlement Website: SBAMHDataSettlement.com

  • Administrator: SBAMH Data Incident Settlement, c/o Settlement Administrator, P.O. Box 25226, Santa Ana, CA 92799-9958

  • Toll-Free Phone: 833-421-7273

  • Email: info@SBAMHDataSettlement.com

Critical Deadlines and Court Approval Hearing Dates

To receive compensation or protect your legal rights regarding this security incident, you must pay close attention to several court-ordered deadlines:

Deadline / Event Date What It Means
Exclusion (Opt-Out) Deadline October 13, 2026 Last day to opt out of the settlement if you want to keep your right to sue the hospital independently.
Objection Deadline October 13, 2026 Last day to submit written comments or objections regarding the terms of the settlement to the court.
Claim Form Deadline November 12, 2026 Last day to submit a claim form online, by email, or postmarked by mail.
Final Approval Hearing December 7, 2026 The court will hold a hearing via Zoom to determine whether to grant final approval to the settlement.

If you take no action, you will forfeit your right to claim cash compensation or medical identity monitoring, and you will give up your right to participate in future legal actions against Susan B. Allen Memorial Hospital regarding this breach.

Step-by-Step Instructions on How to Submit Your Claim

Filing your claim is simple and can be completed online or by mail before the November 12, 2026 deadline:

  1. Access the Portal: Visit the official site at SBAMHDataSettlement.com.

  2. Log In: Enter the Login ID and PIN located on the notice mailed or emailed to you. If you misplaced your notice, use the site contact options to request your details from the administrator.

  3. Select Your Benefits: Choose to enroll in the two years of CyEx Medical Shield Complete monitoring. Indicate whether you are claiming cash for attested time, out-of-pocket losses, or both.

  4. Detail Your Time Spent: If claiming time, briefly describe the tasks you completed (e.g., changing passwords, reviewing credit reports) and select the number of hours (up to 4 hours at $25/hour).

  5. Attach Receipts (If Claiming Out-of-Pocket Expenses): Upload documentation, such as bank statements, receipts, or credit bureau notices, showing expenses caused by the incident.

  6. Select Payment Method: Choose how you wish to receive cash funds—via PayPal, virtual prepaid card, or paper check.

  7. Submit Before Deadline: Complete your digital submission online by 11:59 p.m. on November 12, 2026, or ensure paper forms are postmarked by November 12, 2026.

Hold Healthcare Institutions Accountable: Claim Your Benefits

Everyday people trust medical providers with their private health records and personal details. When security vulnerabilities expose sensitive patient files to cybercriminals, consumers shouldn’t have to carry the burden of identity defense on their own.

Don’t stand alone. If your information was compromised in the July 2025 Susan B. Allen Memorial Hospital security incident, take a few minutes to submit your claim before the November 12, 2026 deadline.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
The Time for Action is Now!
Mass Arbitrations
Active Data Breaches
Date of Breach: Not yet publicly disclosed. The incident was reported to the Texas and Vermont Attorneys General on September 9, 2026.
Date of Breach: Alleged attack reported September 7, 2026 (unconfirmed by company)
Date of Breach: Notification letters mailed August 27, 2026; disclosed to Massachusetts OCABR September 1, 2026 (exact breach date not disclosed)
Latest News