CClaimWatch

Privacy class action settlements

Class action settlements over privacy violations — website tracking, pixels, wiretapping, biometric data, and unauthorized data sharing.

Privacy settlements by the numbers

385
Settlements tracked
24
Accepting claims now
347 closed
$2.5M
Median settlement fund
from the 99 of 385 that disclose one
$510.9M
Combined funds
largest $59.5M

A settlement fund is the total a defendant agreed to pay, not what any one claimant receives — most funds are divided among everyone who files. Settlements are negotiated agreements, and defendants typically deny wrongdoing rather than being found liable.

How big are privacy settlements?

The 99 settlements in this category that publish a fund, grouped by size. Most cluster low and a few are very large — which is why the headline figure above is a median rather than an average.

Settlement fund sizes for Privacy settlements, by band, across 99 settlements that disclose a fund
Fund sizeSettlementsShare
Under $1M
2424%
$1M – $5M
5152%
$5M – $25M
2020%
$25M – $100M
44%
$100M and up
00%

A fund is the total a defendant agreed to pay, not an individual payout.

Get new claim opportunities by email

Free alerts for new settlements and deadlines. Unsubscribe anytime.

Show

Accepting claims now

August 29, 2026privacy

Call-On-Doc Pixel Settlement

Call-On-Doc used third-party tracking technologies called "tracking pixels" on its web pages. Plaintiffs alleged this use violated certain California laws. Call-On-Doc denies wrongdoing, and the parties agreed to settle to avoid litigation costs and uncertainty.

August 31, 2026No proof neededprivacy

FitOn VPPA Settlement

FitOn allegedly disclosed its subscribers' personally identifiable information to third parties without consent and in violation of the Video Privacy Protection Act (VPPA). The defendant denies it violated any law.

Up to $10

September 1, 2026privacy

Serviceaide Data Breach Settlement

Serviceaide, Inc. experienced unauthorized access to its computer systems and network between September 19, 2024, and November 5, 2024, which exposed the private information of current and former patients of Catholic Health. The lawsuit alleges negligence, breach of implied contract, unjust enrichment, and invasion of privacy. The defendant denies all wrongdoing.

September 3, 2026privacy

Labcorp Data Breach Settlement

Labcorp allegedly suffered a data breach involving customer diagnostic services information through American Medical Collection Agency. The company has agreed to settle for $35 million related to this alleged security breach.

September 3, 2026data breach

MOVEit Data Breach Settlement - GRIPA

In May 2023, Greater Rochester Independent Practice Association suffered a data breach involving MOVEit Transfer file transfer software. The breach exposed personally identifiable information and protected healthcare information of individuals, including names, dates of birth, Social Security numbers, health information, and insurance details. GRIPA is settling claims related to this breach, though litigation against Progress Software Corporation (the MOVEit software licensor) continues.

$100–$12,500

September 3, 2026privacy

Okanogan Behavioral Healthcare Data Breach Settlement

Okanogan Behavioral Healthcare (OBHC) experienced an unauthorized data incident discovered in May 2024 that exposed sensitive patient information including names, addresses, dates of birth, Social Security numbers, driver's license numbers, identification numbers, and medical and health insurance information. OBHC denies any wrongdoing.

$50–$5,350

September 3, 2026data breach

Omni Healthcare Data Breach Settlement

In January 2024, an unauthorized third party conducted a cyberattack on Omni Healthcare's network and accessed certain files containing personal and medical information. The accessed files may have contained names, dates of birth, medical information, Social Security numbers, health insurance information, and financial account information. Omni Healthcare denies wrongdoing, and the parties agreed to settle to avoid the costs and uncertainties of continued litigation.

September 5, 2026No proof neededprivacy

Banner Health Data Breach Settlement

Banner Health allegedly disclosed patients' personally identifiable information and protected health information to third parties including Meta (Facebook) and Google through tracking technologies on its website and patient portal. This allegedly violated patients' privacy rights and applicable laws. Banner denies all wrongdoing.

Up to $20

September 8, 2026privacy

Allina Pixel Settlement

Allina Health System allegedly disclosed certain personal or health-related information to third parties. The defendant denies these allegations but agreed to settle the class action lawsuit.

September 8, 2026privacy

Lemonade Data Disclosure Settlement

Lemonade, Inc. and Lemonade Insurance Agency, LLC experienced an unauthorized data exposure involving their online insurance quote platform between April 2023 and September 18, 2024. Personal information such as driver's license numbers was compromised, and affected individuals were notified in April and June 2025.

September 9, 2026privacy

Pineland Community Service Board Data Breach Settlement

Pineland Community Service Board experienced a cybersecurity incident from November 2024 to January 2025 that resulted in potential unauthorized access to or acquisition of individuals' private information including names, dates of birth, Social Security numbers, medical billing information, and medical treatment information. The defendant denies any wrongdoing or liability, but agreed to settle to avoid the risk, cost, and time of continuing the lawsuits.

September 14, 2026privacy

Schuster Company Data Breach Settlement

Schuster Company experienced a January 2024 cybersecurity incident involving its computer systems where certain files containing personal information may have been accessed, including names, Social Security numbers, dates of birth, and driver's license numbers or state identification information. Schuster denies wrongdoing, but the parties agreed to settle to avoid the costs, risks, and uncertainties of continued litigation.

September 16, 2026data breach

Aspire Health Alliance Data Breach Settlement

Aspire Health Alliance experienced a targeted cyberattack on its computer systems in September 2023. Files containing private information including names, dates of birth, medical services dates, health insurance policy numbers, physician information, medical condition or treatment information, and Medicare/Medicaid numbers were potentially accessed. Aspire denies wrongdoing, but has agreed to settle the lawsuit to avoid costs, risks, and uncertainties of continued litigation.

Cash Payment A (documented losses) or Cash Payment B (pro rata cash) plus Medical Data Monitoring

September 18, 2026privacy

Naper Grove Vision Care Data Breach Settlement

Naper Grove Vision Care, P.C. experienced a targeted cyberattack on its computer systems in May 2025 (the "Data Incident") in which certain files containing private information were accessed. The files may have contained personal information such as names combined with Social Security numbers and other non-public personally identifiable information. Naper Grove denies wrongdoing.

September 19, 2026No proof neededdata breach

Columbus Regional Health Data Breach Settlement

Columbus Regional Health allegedly disclosed confidential personally identifiable information (PII) and protected health information (PHI) to third-party technologies without patient consent. The defendant denies all claims and maintains it did nothing wrong but agreed to the settlement to avoid litigation costs and uncertainties.

Up to $25.50

September 28, 2026data breach

Amy Crull v. University of St. Thomas Data Breach Settlement

University of St. Thomas experienced unauthorized access to its network between July 25, 2025 and August 12, 2025. Personal information including credit card numbers, bank account numbers, Social Security numbers, passports, licenses, work account login credentials, home addresses, email addresses, phone numbers, and other sensitive documents were potentially compromised. UST denies any wrongdoing.

$50–$5,100

September 28, 2026privacy

Atrium Health Pixel Technology Settlement

Atrium Health improperly used pixel technology in connection with its MyAtriumHealth and MyCarolinas patient portal accounts. The health system has agreed to settle a class action lawsuit over this use of tracking technology without admitting wrongdoing.

September 28, 2026No proof neededdata breach

Mount Sinai Data Breach Settlement

Mount Sinai Medical Center of Florida disclosed protected health information and personally identifying information of patients through tracking, analytics, and advertising technologies on its website and patient portal to third parties. The disclosure occurred between June 10, 2021 and September 18, 2025.

Up to $20

September 29, 2026privacy

Physicians' Primary Care Data Incident Settlement

Physicians' Primary Care of Southwest Florida experienced a targeted cyberattack on its computer systems in September 2024 that compromised personal information including names, Social Security numbers, and private health information. Physicians' Primary Care denies wrongdoing, but has agreed to settle the lawsuit to avoid further litigation costs and uncertainties.

September 30, 2026data breach

ApolloMD Data Breach Settlement

A data security incident at ApolloMD on or around May 22, 2025, may have allowed an unauthorized third party to access files containing private information of patients treated by ApolloMD's affiliated physicians and practices. ApolloMD denies these claims and maintains it did nothing wrong.

October 1, 2026data breach

Healthcare Services Group Data Breach Settlement

Healthcare Services Group, Inc. suffered a cybersecurity data breach on or around September 27, 2024, which exposed employee personally identifiable information including names, Social Security numbers, driver's license numbers, state identification numbers, financial account details, full access credentials, and medical and health insurance information. HCSG denies any wrongdoing.

Up to $5,000

October 5, 2026data breach

Total Vision Data Breach Settlement

Total Vision experienced a data security incident on October 30, 2020, in which patient and customer information was compromised. Plaintiffs claim Total Vision did not adequately protect personal information, though Total Vision denies any wrongdoing.

Up to $1,000

October 15, 2026No proof neededprivacy

Period Tracker Data Privacy Settlement (Flo, Google, Flurry)

Between November 2016 and February 2019, the Flo period and ovulation tracker app allegedly incorporated code from third-party software development kits (from Flurry, Meta, and Google) through which user information related to menstruation and pregnancy was allegedly shared without proper legal authorization. Google agreed to pay $48 million, Flo agreed to pay $8 million, and Flurry agreed to pay $3.5 million to settle. All defendants deny wrongdoing and assert they did nothing wrong.

Not stated

October 22, 2026data breach

Lands' End Data Breach Settlement

Lands' End experienced a data security incident in December 2024 that compromised personal information on a portion of its computer systems. Certain files containing information such as names, dates of birth, Social Security numbers, driver's license/passport information, and in some cases medical information were accessed. Lands' End denies wrongdoing, and the parties agreed to settle to avoid litigation costs and uncertainties.

Privacy cases in litigation

Filed and being fought in court. These are allegations — there is no settlement, no claim form and no payout yet.

In litigation · filed August 20, 2026privacy

Pandiscia v. Twitch Interactive Class Action

A proposed class action has been filed against Twitch Interactive, Inc. in federal court. While specific allegations are not detailed in the available docket entries, the case appears to concern claims that could affect Twitch users or account holders. The nature of the lawsuit will become clearer upon review of the full complaint.

In litigation · filed August 19, 2026privacy

Aarons v. NextRoll Data Privacy Class Action

A proposed class action against NextRoll, Inc. apparently concerning privacy or data-related claims affecting consumers or users of the company's services or platforms. Without access to the complaint details, the specific allegations cannot be determined from the docket information provided.

In litigation · filed August 18, 2026privacy

Doe v. X.AI Corp.

A proposed class action has been filed against X.AI Corp. and related entities by multiple plaintiffs using pseudonyms (John Doe I and Jane Does). The nature of suit code suggests statutory claims, and the use of anonymized plaintiff names indicates the case may involve sensitive personal matters such as privacy violations, data breaches, or similar concerns affecting ordinary individuals.

In litigation · filed August 10, 2026privacy

Wright v. McCormick & Company Data Breach Class Action

This proposed class action alleges that McCormick & Company, Inc. engaged in fraud or violations of truth-in-lending laws. Based on the nature of suit code, the complaint apparently concerns alleged misrepresentations or deceptive practices that may have affected consumer transactions or data handling by the defendant.

In litigation · filed August 3, 2026privacy

Kennedy v. PowerSchool Group Class Action

A proposed class action has been filed against PowerSchool Group LLC, a company that provides student information and school management software to educational institutions. The complaint alleges unspecified claims that could plausibly affect students, parents, or other individuals whose data is processed through PowerSchool's systems. The specific allegations cannot be determined from the docket caption and initial filing information alone.

In litigation · filed July 31, 2026data breach

Cada v. Amazon.com Data Breach Class Action

This proposed class action alleges that Amazon.com, Inc. failed to adequately protect consumer personal data, resulting in unauthorized access or breach. The complaint seeks relief on behalf of affected consumers and is being pursued by a well-known class-action attorney.

In litigation · filed July 30, 2026data breach

Yellow Corporation Data Breach Class Action

A proposed class action has been filed in bankruptcy court alleging that Yellow Corporation and related entities suffered a data breach affecting ordinary people. The complaint, brought by individual named plaintiffs, seeks recovery of money and property, injunctive relief, and declaratory judgment related to the alleged unauthorized access to personal information.

In litigation · filed July 28, 2026data breach

Funk v. Collectors Universe Data Breach Class Action

A proposed class action against Collectors Universe, Inc. and Collectors Holdings, Inc. alleges racketeering and corrupt practices under RICO. Based on the nature of suit code and filing structure, the case apparently concerns alleged misconduct affecting consumers, though the specific allegations are not detailed in the available docket metadata.

In litigation · filed July 23, 2026privacy

Sanchez v. Exact Sciences Corporation Class Action

A proposed class action has been filed against Exact Sciences Corporation, a company known for genetic testing and cancer screening products. Based on the docket entry, the complaint alleges claims characterized as "Other" personal injury matters, though the specific allegations are not detailed in the available docket metadata. Ordinary consumers who may have purchased or used Exact Sciences' products or services could plausibly be class members if the claims involve product defects, privacy violations, or similar consumer-facing issues.

In litigation · filed July 22, 2026privacy

Hayes v. Welldynerx Data Breach Class Action

A proposed class action filed by Rochelle Hayes against Welldynerx, LLC, apparently concerning a contractual or consumer-related dispute. Based on the case caption and nature of suit, the lawsuit likely involves allegations affecting ordinary consumers or account holders, though the specific claims cannot be determined from the docket entry alone.

In litigation · filed July 21, 2026consumer products

Adger Volunteer Fire Department v. 3M Company and Others - PFOA/PFOS Firefighting Gear Class Action

A proposed class action by Adger Volunteer Fire Department against multiple manufacturers of firefighting apparel and equipment, apparently alleging personal injury and product liability claims. The case likely concerns alleged exposure to harmful substances such as PFOA/PFOS (per- and polyfluoroalkyl substances) used in firefighting gear. Firefighters and fire departments are seeking damages for alleged injuries related to the use of these products.

In litigation · filed July 20, 2026privacy

Pearson v. Google LLC Class Action

A proposed class action has been filed against Google LLC in the Northern District of California. The complaint alleges unspecified claims under statutory law, with the nature of suit classified as 'Other Statutory Actions.' Without access to the complaint's substantive allegations, the specific claims cannot be determined from the docket entry alone, though the case is brought as a class action by named plaintiffs Corinne Pearson and Melenie Crutcher.

Closed to new claims

Past the filing deadline — kept so you can look up what a case was about and what it paid.

Claims closed · August 27, 2026data breach

Berman & Rabin Data Breach Settlement

Berman & Rabin, P.A. experienced a cyberattack on its computer systems in July 2024 (the "Data Incident"). Certain files containing private information were potentially accessed, including names, Social Security numbers, drivers' license numbers, financial information, medical information, and health insurance information. Berman & Rabin denies any wrongdoing, but the parties agreed to settle to avoid costs and risks of continued litigation.

Claims closed · August 26, 2026privacy

Backchecked Data Breach Settlement

Backchecked, LLC suffered a targeted cyberattack on its computer systems in September 2024. Files containing private information including names, addresses, dates of birth, Social Security numbers, and driver's license numbers may have been accessed. Backchecked denies any wrongdoing.

Claims closed · August 26, 2026data breach

Hillcrest Convalescent Center Data Breach Settlement

Hillcrest Convalescent Center, Inc. experienced a cyberattack on its computer systems in June 2024 that may have resulted in unauthorized access to and acquisition of sensitive personal information including names, addresses, financial account information, dates of birth, driver's license numbers, Social Security numbers, government ID numbers, medical treatment records, health insurance information, and provider information. Hillcrest denies wrongdoing and the court has not decided the merits; the parties settled to avoid litigation costs and uncertainties.

Claims closed · August 26, 2026privacy

KYB Americas Corporation Data Incident Settlement

In February 2025, KYB Americas Corporation experienced a targeted data security incident on its computer systems. Certain files containing personal information were potentially accessed. KYB denies doing anything wrong, and the court has not decided who is right.

Claims closed · August 24, 2026data breach

McKenzie Memorial Hospital Data Breach Settlement

McKenzie Memorial Hospital suffered a targeted cyberattack on its computer systems in April 2025 that compromised certain files containing private information such as names, addresses, dates of birth, Social Security numbers, patient account numbers, medical record numbers, and treatment information. McKenzie denies wrongdoing, and the parties agreed to settle to avoid the costs and risks of continuing litigation.

Claims closed · August 21, 2026privacy

Valladolid v. Memorial Health Services - Meta Pixel Data Privacy Settlement

Memorial Health Services disclosed patients' personally identifiable information to third parties through the Meta Pixel and other tracking, analytics, and advertising technologies without consent in violation of the California Invasion of Privacy Act. The defendant denies all claims and maintains it did nothing wrong but agreed to the settlement to avoid ongoing litigation expenses and uncertainties.

Claims closed · August 20, 2026privacy

Wyssta Services, Inc. Data Privacy Settlement

Wyssta Services allegedly violated the Electronic Communications Privacy Act and Illinois Eavesdropping Statute by installing and implementing advertising and analytics tracking technologies, such as cookies and pixels, on the Delta Dental member portal (my.deltadentalcoversme.com) without users' knowledge or consent. The defendant denies all allegations and liability.

Claims closed · August 19, 2026No proof neededdata breach

Compex Legal Services Data Breach Settlement

An unauthorized user gained access to Compex Legal Services' systems in a cyber incident that was discovered in April 2024. The incident impacted personally identifiable information (PII) and protected health information (PHI) of class members. Compex has agreed to settle the claims without admitting wrongdoing.

Paid $100–$5,200

Claims closed · August 19, 2026privacy

Legends Hospitality Data Breach Settlement

Legends Hospitality suffered targeted cyberattacks on its computer systems in November 2024, December 2024, and January 2025. Certain files containing Private Information including names, dates of birth, Social Security numbers, driver's license numbers, government ID numbers, financial information, medical information, and health insurance information were accessed. Legends Hospitality denies wrongdoing, and the parties agreed to settle to avoid the costs and risks of continued litigation.

Claims closed · August 19, 2026data breach

Mt. Baker Imaging Data Security Incident Settlement

Mt. Baker Imaging and Northwest Radiologists experienced a ransomware attack between January 20-25, 2025, in which cybercriminals accessed and stole personally identifiable information and protected health information belonging to approximately 340,184 people. Plaintiffs allege the companies failed to implement adequate data security safeguards, though Defendants deny wrongdoing but agreed to settle to avoid litigation costs and uncertainty.

Paid Up to $5,000

Claims closed · August 19, 2026data breach

WaterStreet Company Data Breach Settlement

WaterStreet Company experienced a data breach on March 17, 2025, resulting in unauthorized access to files containing private information including names, taxpayer identification numbers, bank account information, and Social Security numbers. WaterStreet denies wrongdoing, but has agreed to settle the lawsuit to avoid further costs and risks.

Claims closed · August 18, 2026data breach

Ciuni & Panichi Data Breach Settlement

Ciuni & Panichi, Inc. experienced a data breach in November 2024 when unauthorized individuals accessed a database containing personal information including names, Social Security numbers, and dates of birth. The defendant denies wrongdoing, but a settlement has been reached to compromise and end the lawsuit.

Paid $125–$5,000

Claims closed · August 18, 2026data breach

Datavant Data Security Incident Settlement

A phishing email attack allowed unauthorized access to a company email account at Ciox Health, LLC d/b/a Datavant Group between May 8, 2024 and May 9, 2024, potentially exposing certain personal information. The defendant denies any wrongdoing.

Claims closed · August 18, 2026data breach

Mason v. Wright Brothers Construction Company Data Breach Settlement

Wright Brothers Construction Company suffered a targeted cyberattack on its computer systems in April 2024 in which certain files containing private information, including names and Social Security numbers, were accessed. The defendant denies wrongdoing.

Claims closed · August 17, 2026privacy

Alta Resources Corp. Data Breach Settlement

A targeted cyberattack on Alta Resources Corp.'s computer systems occurred in November 2023, which compromised files containing private information including names, Social Security numbers, financial account information, taxpayer identification numbers, government-issued identification, and health insurance/medical information. Alta denies wrongdoing, but has agreed to settle the lawsuit to avoid litigation costs and risks.

Claims closed · August 17, 2026No proof neededdata breach

Bradford Health Data Incident Settlement

Bradford Health Partners, LLC and Bradford Health Services, LLC experienced a cybersecurity incident in November 2023 that resulted in unauthorized access to or acquisition of customers' private information, including names, dates of birth, identification numbers, Social Security numbers, medical information, health insurance information, and financial information. The company has agreed to pay $900,000 and implement additional security measures to resolve the class action lawsuit.

Paid $150–$5,000

Claims closed · August 17, 2026data breach

EMM Loans Data Breach Settlement

EMM Loans was the target of a cyberattack on its computer systems in February 2024. The attack resulted in unauthorized access to files containing personal information including names, Social Security numbers, driver's license numbers, and passport numbers. EMM Loans denies it did anything wrong.

Claims closed · August 17, 2026data breach

GeoLogics Corporation Data Breach Settlement

GeoLogics Corporation experienced a targeted cyberattack on its computer systems in December 2023 that compromised private information. Files containing personal data such as names, addresses, phone numbers, dates of birth, photo identification, driver's licenses, and Social Security numbers were accessed. GeoLogics denies wrongdoing, and the court has not decided the merits of the case.

Claims closed · August 16, 2026privacy

Williams v. Duke University Health System Settlement

Duke University Health System allegedly used a tracking tool on its website that may have led to the disclosure of personal or health-related information to a vendor when users visited the website. Duke denies any wrongdoing and the court has not ruled that it did anything wrong.

Paid Pro rata share of the Net Settlement Fund

Claims closed · August 14, 2026No proof neededprivacy

St. Joseph Hospital MyChart Data Breach Settlement

St. Joseph Hospital of Nashua allegedly unlawfully collected, used, and disclosed personally identifiable information and protected health information of persons who used its MyChart patient portal account. The hospital denies these allegations and admits no wrongdoing.

Paid Up to $50

Claims closed · August 12, 2026data breach

Deanco Healthcare Data Breach Settlement

On May 1, 2023, Deanco Healthcare experienced a cybersecurity attack that compromised its IT network. The threat actor accessed database files containing customers' addresses, dates of birth, Social Security numbers, driver's license numbers, financial account information, health insurance details, and clinical information. Deanco agreed to settle without admitting wrongdoing.

Paid $100–$5,000

Claims closed · August 11, 2026privacy

Onsite Mammography Data Breach Settlement

In October 2024, an unauthorized third party gained access to one Onsite Mammography employee's email account, exposing certain files that may have contained settlement class members' personally identifiable information (PII) and protected health information (PHI). The defendant denies any wrongdoing but has agreed to settle the lawsuit on a classwide basis.

Claims closed · August 8, 2026privacy

LCPtracker Data Breach Settlement

LCPtracker, Inc. experienced a targeted cyberattack on its computer systems in August 2024 that resulted in unauthorized access to files containing private information, including names and Social Security numbers. LCPtracker denies wrongdoing, but has agreed to settle the lawsuit to avoid the costs, risks, and uncertainties of continued litigation.

Claims closed · August 7, 2026No proof neededprivacy

Motility Data Breach Settlement

Motility Software Solutions suffered a cybersecurity incident in August 2025 that resulted in potential unauthorized access to or acquisition of personal information including names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, and driver's license numbers. The company has agreed to settle the litigation without admitting wrongdoing.

Paid $75–$5,000

All past settlements →