Capital Health $4.5M Data Breach Settlement Gets Final Approval; Payments Next

Capital Health $4.5 Million Data Breach Settlement Gets Final Approval; Payments Come Next
On July 14, 2026, a federal judge granted final approval to a $4.5 million class-action settlement over Capital Health's 2023 ransomware data breach. The claim-filing window has already closed; approved payments and three years of credit monitoring follow once any appeals resolve.
Information last verified on July 20, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This article addresses the federal court settlement in Graycar v. Capital Health Systems. It is general information about that case, not a claims portal and not legal advice. For steps anyone can take after a breach, see what to do after a data breach.
What Happened
The U.S. District Court for the District of New Jersey granted final approval to the Capital Health data breach settlement on July 14, 2026, at a final-approval hearing held before U.S. Magistrate Judge Justin T. Quinn in Bruce Graycar, et al. v. Capital Health Systems, Inc. (No. 3:23-cv-23234-MAS-JTQ, before District Judge Michael A. Shipp). The settlement creates a $4.5 million fund to resolve claims arising from a 2023 cyberattack on the New Jersey and Pennsylvania healthcare provider.
According to the litigation, Capital Health identified unauthorized activity on or around November 26, 2023, and a forensic investigation confirmed a criminal cyber actor had access to its network between November 11 and November 26, 2023, deploying ransomware to encrypt files. The exposed data included names, dates of birth, Social Security numbers, contact information, and clinical information. Under the approved terms, a class member could claim up to $5,000 for documented out-of-pocket losses, or a $100 alternative cash payment, and all class members were eligible for three years of credit monitoring. The court had set April 6, 2026 as the deadline to submit a claim.

What the Law Actually Says
A data breach class-action settlement does not become payable the day the parties sign it. A court must grant preliminary approval, notice must go to the class, class members must file claims by a set deadline, and then the court holds a final-approval hearing to decide the settlement is fair, reasonable, and adequate. Here, preliminary approval came in November 2025, the claim deadline fell on April 6, 2026, and final approval was entered on July 14, 2026.
Final approval is the milestone that unlocks distribution, but it is not the same as a check in hand. The settlement provides that payments begin only after approval is final and any appeals are resolved, which can add weeks or months. For anyone whose data was involved but who did not file by the April deadline, no benefit is available from this fund. Healthcare-provider ransomware settlements now recur often enough that readers may find it useful to compare similar matters, such as the Esse Health data breach settlement and the Onsite Mammography settlement.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Two things about this settlement are worth a reader's attention, and neither is the headline dollar figure. First, the gap between the fund and the class. A $4.5 million fund spread across a large healthcare class, after fees and the cost of credit monitoring, generally means individual cash payments land far below the $5,000 documented-loss ceiling. The realistic outcome for most claimants is a modest pro-rata payment, and the $100 alternative payment exists precisely because documented five-figure losses are rare.
Second, the timing trap. The claim deadline (April 2026) fell months before final approval (July 2026), a common structure that routinely confuses people who first hear about a settlement after it is approved. By the time a settlement makes news for being approved, the chance to file is often already gone. That is a recurring pattern worth internalizing: the moment to act on a breach settlement is when notice arrives, not when a headline announces approval.
How This Affects You
If you already filed a valid claim in this case, the practical takeaway is patience: distribution follows final approval and the resolution of any appeals, and the administrator, not this website, controls timing. If you received notice but did not file by April 6, 2026, no payment is available here. Either way, the protective steps after any breach do not depend on a settlement at all. Placing a free credit freeze with the three major bureaus blocks new-account fraud at no cost, and it is available to anyone regardless of whether a settlement ever pays. Be wary of any site that asks for a Social Security number or a fee to "claim" this settlement; the court-approved administrator does not operate that way.
This is general legal information, not legal advice. It covers the Graycar v. Capital Health Systems settlement and reflects sources verified on July 20, 2026. Laws and settlement timelines change; consult a lawyer licensed in your jurisdiction about your specific situation.
Related articles
- What to do after a data breach
- How to freeze your credit after a data breach
- Esse Health data breach settlement
- Onsite Mammography data breach settlement
Last updated: 2026-07-20. This is a developing story; details verified as of 2026-07-20.
Frequently Asked Questions
Can I still file a claim in the Capital Health settlement?
No. The court set April 6, 2026 as the deadline to submit a claim, and that date has passed. Final approval on July 14, 2026 does not reopen the claims window.
How much will class members receive?
The settlement allows up to $5,000 for documented losses or an estimated $100 alternative cash payment, plus three years of credit monitoring. Because a $4.5 million fund is shared across the class after fees, most claimants realistically receive a modest pro-rata amount rather than the maximum.
When will payments go out?
The settlement provides that distribution begins only after final approval is entered and any appeals are resolved. No specific payment date is guaranteed; the court-appointed administrator controls timing.
Is Recording Law running this settlement?
No. Recording Law is not the administrator, the court, or a claims processor. We report on the case. Confirm every detail on the official court-approved settlement website before acting.
What should I do if my data was in the Capital Health breach?
A free credit freeze with the three major credit bureaus is the first step and works whether or not a settlement pays. Monitor your accounts and be cautious of any site charging a fee or requesting your Social Security number to claim a settlement.
Sources and References
- Bruce Graycar, et al. v. Capital Health Systems, Inc., official settlement website (D.N.J.), documents and final-approval information(capitalhealthdatabreachsettlement.com)
- Class notice: Capital Health data incident settlement (long-form notice)(classaction.org)
- Capital Health to pay $4.5M in LockBit breach settlement(bankinfosecurity.com)
- Capital Health Data Breach Litigation, Frequently Asked Questions (official court-approved settlement website): final-approval status, benefits, claim deadline, and payment timing(capitalhealthdatabreachsettlement.com)