MOVEit Data Breach Settlement - GRIPA
$100–$12,500
What happened
In May 2023, Greater Rochester Independent Practice Association suffered a data breach involving MOVEit Transfer file transfer software. The breach exposed personally identifiable information and protected healthcare information of individuals, including names, dates of birth, Social Security numbers, health information, and insurance details. GRIPA is settling claims related to this breach, though litigation against Progress Software Corporation (the MOVEit software licensor) continues.
Do you qualify?
You qualify if you received notice from Greater Rochester Independent Practice Association that your Personally Identifiable Information and/or Protected Healthcare Information was potentially compromised in the MOVEit Data Breach.
How to file
Complete and submit a Claim Form by September 3, 2026, either online using your Claimant ID and PIN or by mailing a paper form postmarked by that date. You will need the Claimant ID and PIN provided on your notice.
Common questions
- How much does the MOVEit Data Breach Settlement - GRIPA pay?
- Estimated payout: $100–$12,500. The total settlement fund is $2.1M. Actual amounts depend on how many valid claims are filed — most settlements divide a fixed fund pro rata, so a higher claim rate means a smaller individual check. An "up to" figure is a cap, not a guarantee.
- What is the claim deadline for the MOVEit Data Breach Settlement - GRIPA?
- The claim deadline is September 3, 2026. Filing is free and is done on the official settlement website at moveitsettlementgripa.com.
- Do I need proof of purchase for the MOVEit Data Breach Settlement - GRIPA?
- Yes. This settlement asks for documentation supporting your claim — a receipt, an account record, or the notice you were sent. Check the official settlement website for exactly which documents are accepted.
- Is the MOVEit Data Breach Settlement - GRIPA notice real, or a scam?
- Settlement Administrator (not named on page) is the settlement administrator for this case. Claims are filed at moveitsettlementgripa.com. Filing a class action claim is always free — no legitimate settlement charges you to claim, and no administrator will ask for payment, a gift card, or your full Social Security number by email or text. If a notice asks for any of those, it is not from the administrator. When in doubt, ignore the link you were sent and go to the official settlement website directly.
- How long until I get paid from the MOVEit Data Breach Settlement - GRIPA?
- Class action payouts typically take 12 to 24 months after the claim deadline, and longer if the settlement is appealed. The final approval hearing for this case is set for September 3, 2026; no payments can be issued before a settlement receives final approval.
- What happens if I do nothing?
- You receive no payment, and in most class actions you also give up the right to sue Greater Rochester Independent Practice Association (GRIPA) separately over these same claims. To keep that right you must opt out (exclude yourself) by August 4, 2026.
New to class actions?
This summary was generated from public settlement documents and may contain errors. Confirm eligibility, deadlines, and payment terms on the official settlement website before filing. ClaimWatch is not a law firm and this is not legal advice. Filing a claim is free.
More data breach settlements
View all →FMC Services Data Breach Settlement
FMC Services, LLC experienced a data incident on or about July 26, 2022, in which an unauthorized third party compromised personally identifiable information and personal health information of class members. The company denies that any information had been acquired.
Urban One Data Breach Settlement
Urban One's computer systems were targeted in a cyberattack in March 2025, resulting in unauthorized access to files containing personal information such as identifying information or information that could be used to identify, locate, or contact individuals. Urban One denies any wrongdoing.
Kaplan v. Crimson Wine Group Data Breach Settlement
Crimson Wine Group, Ltd. suffered a targeted cyberattack on its computer systems in or about June 2024. Certain files containing private information were accessed, potentially including names, Social Security numbers, and financial account information. The company denies wrongdoing.
Serviceaide Data Breach Settlement
Serviceaide, Inc. experienced unauthorized access to its computer systems and network between September 19, 2024, and November 5, 2024, which exposed the private information of current and former patients of Catholic Health. The lawsuit alleges negligence, breach of implied contract, unjust enrichment, and invasion of privacy. The defendant denies all wrongdoing.