Privacy class action settlements
Class action settlements over privacy violations — website tracking, pixels, wiretapping, biometric data, and unauthorized data sharing.
Privacy settlements by the numbers
A settlement fund is the total a defendant agreed to pay, not what any one claimant receives — most funds are divided among everyone who files. Settlements are negotiated agreements, and defendants typically deny wrongdoing rather than being found liable.
The 99 settlements in this category that publish a fund, grouped by size. Most cluster low and a few are very large — which is why the headline figure above is a median rather than an average.
| Fund size | Settlements | Share | |
|---|---|---|---|
| Under $1M | 24 | 24% | |
| $1M – $5M | 51 | 52% | |
| $5M – $25M | 20 | 20% | |
| $25M – $100M | 4 | 4% | |
| $100M and up | 0 | 0% |
A fund is the total a defendant agreed to pay, not an individual payout.
Get new claim opportunities by email
Free alerts for new settlements and deadlines. Unsubscribe anytime.
Accepting claims now
Call-On-Doc Pixel Settlement
Call-On-Doc used third-party tracking technologies called "tracking pixels" on its web pages. Plaintiffs alleged this use violated certain California laws. Call-On-Doc denies wrongdoing, and the parties agreed to settle to avoid litigation costs and uncertainty.
FitOn VPPA Settlement
FitOn allegedly disclosed its subscribers' personally identifiable information to third parties without consent and in violation of the Video Privacy Protection Act (VPPA). The defendant denies it violated any law.
Up to $10
Serviceaide Data Breach Settlement
Serviceaide, Inc. experienced unauthorized access to its computer systems and network between September 19, 2024, and November 5, 2024, which exposed the private information of current and former patients of Catholic Health. The lawsuit alleges negligence, breach of implied contract, unjust enrichment, and invasion of privacy. The defendant denies all wrongdoing.
Labcorp Data Breach Settlement
Labcorp allegedly suffered a data breach involving customer diagnostic services information through American Medical Collection Agency. The company has agreed to settle for $35 million related to this alleged security breach.
MOVEit Data Breach Settlement - GRIPA
In May 2023, Greater Rochester Independent Practice Association suffered a data breach involving MOVEit Transfer file transfer software. The breach exposed personally identifiable information and protected healthcare information of individuals, including names, dates of birth, Social Security numbers, health information, and insurance details. GRIPA is settling claims related to this breach, though litigation against Progress Software Corporation (the MOVEit software licensor) continues.
$100–$12,500
Okanogan Behavioral Healthcare Data Breach Settlement
Okanogan Behavioral Healthcare (OBHC) experienced an unauthorized data incident discovered in May 2024 that exposed sensitive patient information including names, addresses, dates of birth, Social Security numbers, driver's license numbers, identification numbers, and medical and health insurance information. OBHC denies any wrongdoing.
$50–$5,350
Omni Healthcare Data Breach Settlement
In January 2024, an unauthorized third party conducted a cyberattack on Omni Healthcare's network and accessed certain files containing personal and medical information. The accessed files may have contained names, dates of birth, medical information, Social Security numbers, health insurance information, and financial account information. Omni Healthcare denies wrongdoing, and the parties agreed to settle to avoid the costs and uncertainties of continued litigation.
Banner Health Data Breach Settlement
Banner Health allegedly disclosed patients' personally identifiable information and protected health information to third parties including Meta (Facebook) and Google through tracking technologies on its website and patient portal. This allegedly violated patients' privacy rights and applicable laws. Banner denies all wrongdoing.
Up to $20
Allina Pixel Settlement
Allina Health System allegedly disclosed certain personal or health-related information to third parties. The defendant denies these allegations but agreed to settle the class action lawsuit.
Lemonade Data Disclosure Settlement
Lemonade, Inc. and Lemonade Insurance Agency, LLC experienced an unauthorized data exposure involving their online insurance quote platform between April 2023 and September 18, 2024. Personal information such as driver's license numbers was compromised, and affected individuals were notified in April and June 2025.
Pineland Community Service Board Data Breach Settlement
Pineland Community Service Board experienced a cybersecurity incident from November 2024 to January 2025 that resulted in potential unauthorized access to or acquisition of individuals' private information including names, dates of birth, Social Security numbers, medical billing information, and medical treatment information. The defendant denies any wrongdoing or liability, but agreed to settle to avoid the risk, cost, and time of continuing the lawsuits.
Schuster Company Data Breach Settlement
Schuster Company experienced a January 2024 cybersecurity incident involving its computer systems where certain files containing personal information may have been accessed, including names, Social Security numbers, dates of birth, and driver's license numbers or state identification information. Schuster denies wrongdoing, but the parties agreed to settle to avoid the costs, risks, and uncertainties of continued litigation.
Aspire Health Alliance Data Breach Settlement
Aspire Health Alliance experienced a targeted cyberattack on its computer systems in September 2023. Files containing private information including names, dates of birth, medical services dates, health insurance policy numbers, physician information, medical condition or treatment information, and Medicare/Medicaid numbers were potentially accessed. Aspire denies wrongdoing, but has agreed to settle the lawsuit to avoid costs, risks, and uncertainties of continued litigation.
Cash Payment A (documented losses) or Cash Payment B (pro rata cash) plus Medical Data Monitoring
Naper Grove Vision Care Data Breach Settlement
Naper Grove Vision Care, P.C. experienced a targeted cyberattack on its computer systems in May 2025 (the "Data Incident") in which certain files containing private information were accessed. The files may have contained personal information such as names combined with Social Security numbers and other non-public personally identifiable information. Naper Grove denies wrongdoing.
Columbus Regional Health Data Breach Settlement
Columbus Regional Health allegedly disclosed confidential personally identifiable information (PII) and protected health information (PHI) to third-party technologies without patient consent. The defendant denies all claims and maintains it did nothing wrong but agreed to the settlement to avoid litigation costs and uncertainties.
Up to $25.50
Amy Crull v. University of St. Thomas Data Breach Settlement
University of St. Thomas experienced unauthorized access to its network between July 25, 2025 and August 12, 2025. Personal information including credit card numbers, bank account numbers, Social Security numbers, passports, licenses, work account login credentials, home addresses, email addresses, phone numbers, and other sensitive documents were potentially compromised. UST denies any wrongdoing.
$50–$5,100
Atrium Health Pixel Technology Settlement
Atrium Health improperly used pixel technology in connection with its MyAtriumHealth and MyCarolinas patient portal accounts. The health system has agreed to settle a class action lawsuit over this use of tracking technology without admitting wrongdoing.
Mount Sinai Data Breach Settlement
Mount Sinai Medical Center of Florida disclosed protected health information and personally identifying information of patients through tracking, analytics, and advertising technologies on its website and patient portal to third parties. The disclosure occurred between June 10, 2021 and September 18, 2025.
Up to $20
Physicians' Primary Care Data Incident Settlement
Physicians' Primary Care of Southwest Florida experienced a targeted cyberattack on its computer systems in September 2024 that compromised personal information including names, Social Security numbers, and private health information. Physicians' Primary Care denies wrongdoing, but has agreed to settle the lawsuit to avoid further litigation costs and uncertainties.
ApolloMD Data Breach Settlement
A data security incident at ApolloMD on or around May 22, 2025, may have allowed an unauthorized third party to access files containing private information of patients treated by ApolloMD's affiliated physicians and practices. ApolloMD denies these claims and maintains it did nothing wrong.
Healthcare Services Group Data Breach Settlement
Healthcare Services Group, Inc. suffered a cybersecurity data breach on or around September 27, 2024, which exposed employee personally identifiable information including names, Social Security numbers, driver's license numbers, state identification numbers, financial account details, full access credentials, and medical and health insurance information. HCSG denies any wrongdoing.
Up to $5,000
Total Vision Data Breach Settlement
Total Vision experienced a data security incident on October 30, 2020, in which patient and customer information was compromised. Plaintiffs claim Total Vision did not adequately protect personal information, though Total Vision denies any wrongdoing.
Up to $1,000
Period Tracker Data Privacy Settlement (Flo, Google, Flurry)
Between November 2016 and February 2019, the Flo period and ovulation tracker app allegedly incorporated code from third-party software development kits (from Flurry, Meta, and Google) through which user information related to menstruation and pregnancy was allegedly shared without proper legal authorization. Google agreed to pay $48 million, Flo agreed to pay $8 million, and Flurry agreed to pay $3.5 million to settle. All defendants deny wrongdoing and assert they did nothing wrong.
Not stated
Lands' End Data Breach Settlement
Lands' End experienced a data security incident in December 2024 that compromised personal information on a portion of its computer systems. Certain files containing information such as names, dates of birth, Social Security numbers, driver's license/passport information, and in some cases medical information were accessed. Lands' End denies wrongdoing, and the parties agreed to settle to avoid litigation costs and uncertainties.
Privacy cases in litigation
Filed and being fought in court. These are allegations — there is no settlement, no claim form and no payout yet.
Pandiscia v. Twitch Interactive Class Action
A proposed class action has been filed against Twitch Interactive, Inc. in federal court. While specific allegations are not detailed in the available docket entries, the case appears to concern claims that could affect Twitch users or account holders. The nature of the lawsuit will become clearer upon review of the full complaint.
Aarons v. NextRoll Data Privacy Class Action
A proposed class action against NextRoll, Inc. apparently concerning privacy or data-related claims affecting consumers or users of the company's services or platforms. Without access to the complaint details, the specific allegations cannot be determined from the docket information provided.
Doe v. X.AI Corp.
A proposed class action has been filed against X.AI Corp. and related entities by multiple plaintiffs using pseudonyms (John Doe I and Jane Does). The nature of suit code suggests statutory claims, and the use of anonymized plaintiff names indicates the case may involve sensitive personal matters such as privacy violations, data breaches, or similar concerns affecting ordinary individuals.
Wright v. McCormick & Company Data Breach Class Action
This proposed class action alleges that McCormick & Company, Inc. engaged in fraud or violations of truth-in-lending laws. Based on the nature of suit code, the complaint apparently concerns alleged misrepresentations or deceptive practices that may have affected consumer transactions or data handling by the defendant.
Kennedy v. PowerSchool Group Class Action
A proposed class action has been filed against PowerSchool Group LLC, a company that provides student information and school management software to educational institutions. The complaint alleges unspecified claims that could plausibly affect students, parents, or other individuals whose data is processed through PowerSchool's systems. The specific allegations cannot be determined from the docket caption and initial filing information alone.
Cada v. Amazon.com Data Breach Class Action
This proposed class action alleges that Amazon.com, Inc. failed to adequately protect consumer personal data, resulting in unauthorized access or breach. The complaint seeks relief on behalf of affected consumers and is being pursued by a well-known class-action attorney.
Yellow Corporation Data Breach Class Action
A proposed class action has been filed in bankruptcy court alleging that Yellow Corporation and related entities suffered a data breach affecting ordinary people. The complaint, brought by individual named plaintiffs, seeks recovery of money and property, injunctive relief, and declaratory judgment related to the alleged unauthorized access to personal information.
Funk v. Collectors Universe Data Breach Class Action
A proposed class action against Collectors Universe, Inc. and Collectors Holdings, Inc. alleges racketeering and corrupt practices under RICO. Based on the nature of suit code and filing structure, the case apparently concerns alleged misconduct affecting consumers, though the specific allegations are not detailed in the available docket metadata.
Sanchez v. Exact Sciences Corporation Class Action
A proposed class action has been filed against Exact Sciences Corporation, a company known for genetic testing and cancer screening products. Based on the docket entry, the complaint alleges claims characterized as "Other" personal injury matters, though the specific allegations are not detailed in the available docket metadata. Ordinary consumers who may have purchased or used Exact Sciences' products or services could plausibly be class members if the claims involve product defects, privacy violations, or similar consumer-facing issues.
Hayes v. Welldynerx Data Breach Class Action
A proposed class action filed by Rochelle Hayes against Welldynerx, LLC, apparently concerning a contractual or consumer-related dispute. Based on the case caption and nature of suit, the lawsuit likely involves allegations affecting ordinary consumers or account holders, though the specific claims cannot be determined from the docket entry alone.
Adger Volunteer Fire Department v. 3M Company and Others - PFOA/PFOS Firefighting Gear Class Action
A proposed class action by Adger Volunteer Fire Department against multiple manufacturers of firefighting apparel and equipment, apparently alleging personal injury and product liability claims. The case likely concerns alleged exposure to harmful substances such as PFOA/PFOS (per- and polyfluoroalkyl substances) used in firefighting gear. Firefighters and fire departments are seeking damages for alleged injuries related to the use of these products.
Pearson v. Google LLC Class Action
A proposed class action has been filed against Google LLC in the Northern District of California. The complaint alleges unspecified claims under statutory law, with the nature of suit classified as 'Other Statutory Actions.' Without access to the complaint's substantive allegations, the specific claims cannot be determined from the docket entry alone, though the case is brought as a class action by named plaintiffs Corinne Pearson and Melenie Crutcher.
Closed to new claims
Past the filing deadline — kept so you can look up what a case was about and what it paid.
Berman & Rabin Data Breach Settlement
Berman & Rabin, P.A. experienced a cyberattack on its computer systems in July 2024 (the "Data Incident"). Certain files containing private information were potentially accessed, including names, Social Security numbers, drivers' license numbers, financial information, medical information, and health insurance information. Berman & Rabin denies any wrongdoing, but the parties agreed to settle to avoid costs and risks of continued litigation.
Backchecked Data Breach Settlement
Backchecked, LLC suffered a targeted cyberattack on its computer systems in September 2024. Files containing private information including names, addresses, dates of birth, Social Security numbers, and driver's license numbers may have been accessed. Backchecked denies any wrongdoing.
Hillcrest Convalescent Center Data Breach Settlement
Hillcrest Convalescent Center, Inc. experienced a cyberattack on its computer systems in June 2024 that may have resulted in unauthorized access to and acquisition of sensitive personal information including names, addresses, financial account information, dates of birth, driver's license numbers, Social Security numbers, government ID numbers, medical treatment records, health insurance information, and provider information. Hillcrest denies wrongdoing and the court has not decided the merits; the parties settled to avoid litigation costs and uncertainties.
KYB Americas Corporation Data Incident Settlement
In February 2025, KYB Americas Corporation experienced a targeted data security incident on its computer systems. Certain files containing personal information were potentially accessed. KYB denies doing anything wrong, and the court has not decided who is right.
McKenzie Memorial Hospital Data Breach Settlement
McKenzie Memorial Hospital suffered a targeted cyberattack on its computer systems in April 2025 that compromised certain files containing private information such as names, addresses, dates of birth, Social Security numbers, patient account numbers, medical record numbers, and treatment information. McKenzie denies wrongdoing, and the parties agreed to settle to avoid the costs and risks of continuing litigation.
Valladolid v. Memorial Health Services - Meta Pixel Data Privacy Settlement
Memorial Health Services disclosed patients' personally identifiable information to third parties through the Meta Pixel and other tracking, analytics, and advertising technologies without consent in violation of the California Invasion of Privacy Act. The defendant denies all claims and maintains it did nothing wrong but agreed to the settlement to avoid ongoing litigation expenses and uncertainties.
Wyssta Services, Inc. Data Privacy Settlement
Wyssta Services allegedly violated the Electronic Communications Privacy Act and Illinois Eavesdropping Statute by installing and implementing advertising and analytics tracking technologies, such as cookies and pixels, on the Delta Dental member portal (my.deltadentalcoversme.com) without users' knowledge or consent. The defendant denies all allegations and liability.
Compex Legal Services Data Breach Settlement
An unauthorized user gained access to Compex Legal Services' systems in a cyber incident that was discovered in April 2024. The incident impacted personally identifiable information (PII) and protected health information (PHI) of class members. Compex has agreed to settle the claims without admitting wrongdoing.
Paid $100–$5,200
Legends Hospitality Data Breach Settlement
Legends Hospitality suffered targeted cyberattacks on its computer systems in November 2024, December 2024, and January 2025. Certain files containing Private Information including names, dates of birth, Social Security numbers, driver's license numbers, government ID numbers, financial information, medical information, and health insurance information were accessed. Legends Hospitality denies wrongdoing, and the parties agreed to settle to avoid the costs and risks of continued litigation.
Mt. Baker Imaging Data Security Incident Settlement
Mt. Baker Imaging and Northwest Radiologists experienced a ransomware attack between January 20-25, 2025, in which cybercriminals accessed and stole personally identifiable information and protected health information belonging to approximately 340,184 people. Plaintiffs allege the companies failed to implement adequate data security safeguards, though Defendants deny wrongdoing but agreed to settle to avoid litigation costs and uncertainty.
Paid Up to $5,000
WaterStreet Company Data Breach Settlement
WaterStreet Company experienced a data breach on March 17, 2025, resulting in unauthorized access to files containing private information including names, taxpayer identification numbers, bank account information, and Social Security numbers. WaterStreet denies wrongdoing, but has agreed to settle the lawsuit to avoid further costs and risks.
Ciuni & Panichi Data Breach Settlement
Ciuni & Panichi, Inc. experienced a data breach in November 2024 when unauthorized individuals accessed a database containing personal information including names, Social Security numbers, and dates of birth. The defendant denies wrongdoing, but a settlement has been reached to compromise and end the lawsuit.
Paid $125–$5,000
Datavant Data Security Incident Settlement
A phishing email attack allowed unauthorized access to a company email account at Ciox Health, LLC d/b/a Datavant Group between May 8, 2024 and May 9, 2024, potentially exposing certain personal information. The defendant denies any wrongdoing.
Mason v. Wright Brothers Construction Company Data Breach Settlement
Wright Brothers Construction Company suffered a targeted cyberattack on its computer systems in April 2024 in which certain files containing private information, including names and Social Security numbers, were accessed. The defendant denies wrongdoing.
Alta Resources Corp. Data Breach Settlement
A targeted cyberattack on Alta Resources Corp.'s computer systems occurred in November 2023, which compromised files containing private information including names, Social Security numbers, financial account information, taxpayer identification numbers, government-issued identification, and health insurance/medical information. Alta denies wrongdoing, but has agreed to settle the lawsuit to avoid litigation costs and risks.
Bradford Health Data Incident Settlement
Bradford Health Partners, LLC and Bradford Health Services, LLC experienced a cybersecurity incident in November 2023 that resulted in unauthorized access to or acquisition of customers' private information, including names, dates of birth, identification numbers, Social Security numbers, medical information, health insurance information, and financial information. The company has agreed to pay $900,000 and implement additional security measures to resolve the class action lawsuit.
Paid $150–$5,000
EMM Loans Data Breach Settlement
EMM Loans was the target of a cyberattack on its computer systems in February 2024. The attack resulted in unauthorized access to files containing personal information including names, Social Security numbers, driver's license numbers, and passport numbers. EMM Loans denies it did anything wrong.
GeoLogics Corporation Data Breach Settlement
GeoLogics Corporation experienced a targeted cyberattack on its computer systems in December 2023 that compromised private information. Files containing personal data such as names, addresses, phone numbers, dates of birth, photo identification, driver's licenses, and Social Security numbers were accessed. GeoLogics denies wrongdoing, and the court has not decided the merits of the case.
Williams v. Duke University Health System Settlement
Duke University Health System allegedly used a tracking tool on its website that may have led to the disclosure of personal or health-related information to a vendor when users visited the website. Duke denies any wrongdoing and the court has not ruled that it did anything wrong.
Paid Pro rata share of the Net Settlement Fund
St. Joseph Hospital MyChart Data Breach Settlement
St. Joseph Hospital of Nashua allegedly unlawfully collected, used, and disclosed personally identifiable information and protected health information of persons who used its MyChart patient portal account. The hospital denies these allegations and admits no wrongdoing.
Paid Up to $50
Deanco Healthcare Data Breach Settlement
On May 1, 2023, Deanco Healthcare experienced a cybersecurity attack that compromised its IT network. The threat actor accessed database files containing customers' addresses, dates of birth, Social Security numbers, driver's license numbers, financial account information, health insurance details, and clinical information. Deanco agreed to settle without admitting wrongdoing.
Paid $100–$5,000
Onsite Mammography Data Breach Settlement
In October 2024, an unauthorized third party gained access to one Onsite Mammography employee's email account, exposing certain files that may have contained settlement class members' personally identifiable information (PII) and protected health information (PHI). The defendant denies any wrongdoing but has agreed to settle the lawsuit on a classwide basis.
LCPtracker Data Breach Settlement
LCPtracker, Inc. experienced a targeted cyberattack on its computer systems in August 2024 that resulted in unauthorized access to files containing private information, including names and Social Security numbers. LCPtracker denies wrongdoing, but has agreed to settle the lawsuit to avoid the costs, risks, and uncertainties of continued litigation.
Motility Data Breach Settlement
Motility Software Solutions suffered a cybersecurity incident in August 2025 that resulted in potential unauthorized access to or acquisition of personal information including names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, and driver's license numbers. The company has agreed to settle the litigation without admitting wrongdoing.
Paid $75–$5,000