Asheville Arthritis Data Breach Settlement
This settlement is closed to new claims — the deadline was January 26, 2026. You can still see what it was about and follow the case in court below. Looking for money you can still claim? Browse open settlements →
What happened
In May 2024, Asheville Arthritis and Osteoporosis Center experienced a data breach that compromised private and personally identifying information of roughly 58,000 patients. The stolen information included names, addresses, dates of birth, phone numbers, Social Security numbers, and medical information such as medical notes, lab results, diagnoses, and health insurance details. The defendant disputes the claims and denies wrongdoing.
Do you qualify?
Anyone whose private and personally identifying information was compromised in the data incident affecting Asheville Arthritis and Osteoporosis Center's systems between May 22, 2024 and January 26, 2026.
How to file
The claim deadline was January 26, 2026, and claim forms are no longer being accepted. Settlement payments were already issued on June 12, 2026. If you believe you qualify and have not received payment, contact the settlement administrator.
Common questions
- How much does the Asheville Arthritis Data Breach Settlement pay?
- The total settlement fund is $500,000. Actual amounts depend on how many valid claims are filed — most settlements divide a fixed fund pro rata, so a higher claim rate means a smaller individual check. An "up to" figure is a cap, not a guarantee.
- What is the claim deadline for the Asheville Arthritis Data Breach Settlement?
- This settlement is closed to new claims — the deadline was January 26, 2026. Once a claim deadline passes you generally forfeit your share, even if you qualified.
- Is the Asheville Arthritis Data Breach Settlement notice real, or a scam?
- Claims are filed at arthritisdatabreach.com. Filing a class action claim is always free — no legitimate settlement charges you to claim, and no administrator will ask for payment, a gift card, or your full Social Security number by email or text. If a notice asks for any of those, it is not from the administrator. When in doubt, ignore the link you were sent and go to the official settlement website directly.
- When will payments from the Asheville Arthritis Data Breach Settlement be sent?
- Class action payouts typically take 12 to 24 months after the claim deadline, and longer if the settlement is appealed. The final approval hearing for this case is set for April 13, 2026; no payments can be issued before a settlement receives final approval.
New to class actions?
This summary was generated from public settlement documents and may contain errors. Confirm eligibility, deadlines, and payment terms on the official settlement website before filing. ClaimWatch is not a law firm and this is not legal advice. Filing a claim is free.
More privacy settlements
View all →Berman & Rabin Data Breach Settlement
Berman & Rabin, P.A. experienced a cyberattack on its computer systems in July 2024 (the "Data Incident"). Certain files containing private information were potentially accessed, including names, Social Security numbers, drivers' license numbers, financial information, medical information, and health insurance information. Berman & Rabin denies any wrongdoing, but the parties agreed to settle to avoid costs and risks of continued litigation.
Call-On-Doc Pixel Settlement
Call-On-Doc used third-party tracking technologies called "tracking pixels" on its web pages. Plaintiffs alleged this use violated certain California laws. Call-On-Doc denies wrongdoing, and the parties agreed to settle to avoid litigation costs and uncertainty.
FitOn VPPA Settlement
FitOn allegedly disclosed its subscribers' personally identifiable information to third parties without consent and in violation of the Video Privacy Protection Act (VPPA). The defendant denies it violated any law.
Up to $10
Serviceaide Data Breach Settlement
Serviceaide, Inc. experienced unauthorized access to its computer systems and network between September 19, 2024, and November 5, 2024, which exposed the private information of current and former patients of Catholic Health. The lawsuit alleges negligence, breach of implied contract, unjust enrichment, and invasion of privacy. The defendant denies all wrongdoing.