Check Your Claims
← Legal News / Data Privacy

Palomar Health Data Breach Settlement: Claims Due October 22

A proposed $3.1 million Palomar Health Medical Group settlement offers cash and credit-monitoring benefits to people affected by a 2024 network intrusion.

By Class Action Pulse Staff · Published

Reported from primary sources · Verified against official filings and settlement records.

People whose private information was compromised in Palomar Health Medical Group's April-May 2024 data incident may be eligible to claim benefits from a proposed $3.1 million class action settlement. The settlement offers two years of credit monitoring and a choice between reimbursement of up to $5,000 for documented losses or an alternative cash payment currently estimated at $60.

Claims must be submitted online or postmarked by October 22, 2026. The deadline to opt out or object is earlier, on October 7, 2026. Palomar Health Medical Group denies wrongdoing, and the court has not granted final approval.

Key facts

  • Case: Castro et al. v. Arch Health Partners Inc. d/b/a Palomar Health Medical Group, No. 37-2024-00024339-CU-NP-CTL
  • Court: Superior Court of California, County of San Diego
  • Who may be included: Individuals whose private information was accessed, acquired, disclosed, or compromised in the data incident involving Palomar Health Medical Group systems from April 23 through May 5, 2024
  • Settlement fund: $3.1 million
  • Cash choices: Up to $5,000 for documented losses or an estimated $60 alternative payment
  • Additional benefit: Two years of one-bureau credit monitoring, available with either cash choice or by itself
  • Opt-out and objection deadline: October 7, 2026
  • Claim deadline: October 22, 2026
  • Final approval hearing: November 6, 2026, at 10:30 a.m. Pacific Time
  • Current status: Proposed settlement with preliminary approval

In this article

What happened

Palomar Health Medical Group says it identified suspicious activity on certain systems on May 5, 2024. Its official incident notice states that an unauthorized actor had access to certain files in its network from April 23 through May 5 and may have copied those files.

The medical group says it launched an investigation, reviewed potentially affected files, and worked to identify the people whose information appeared in them. According to its notice, that review was completed on September 4, 2025. The notice says the organization was not aware of actual or attempted misuse of information connected to the incident when it issued the notice.

A lawsuit followed, alleging that Palomar Health Medical Group was legally responsible for the incident and resulting risks or losses. The parties negotiated a settlement rather than continue through trial. On July 17, 2026, Judge Loren Freestone granted preliminary approval, provisionally certified a settlement class, appointed Angeion Group as administrator, and set a final approval hearing.

What changed The court-authorized claims process is open. A valid claim is required for any cash or monitoring benefit, but benefits will not be issued unless the settlement receives final approval and becomes effective.

Who Palomar Health Medical Group is

The defendant is Arch Health Partners Inc., doing business as Palomar Health Medical Group. Its patient-facing website describes a medical group whose physicians and other providers deliver outpatient healthcare services. The data at issue came from systems used in that healthcare setting.

Palomar's incident notice says it was acting for itself, Graybill Medical Group Inc., and Pacific Accountable Care LLC when notifying affected individuals. Those names are relevant because a recipient may recognize a physician group or affiliated organization rather than the precise defendant name printed in the lawsuit. The court-authorized class definition, however, controls settlement eligibility.

This case concerns the confidentiality and security of information held in medical-group systems. It is separate from a different 2026 Palomar notice involving a third-party business associate. The settlement notice expressly ties this case to the incident that occurred between April 23 and May 5, 2024.

What information may have been involved

Palomar Health Medical Group's official incident notice says the categories varied by person. They may have included names, addresses, dates of birth, Social Security numbers, driver's license or other government identification numbers, passport information, financial-account or payment-card information, and health savings account information.

The notice also lists medical histories, diagnostic and treatment information, biometric data, medical record numbers, Medicare or Medicaid identifiers, patient account numbers, health insurance information, email addresses, and account credentials. The presence of a category in the notice does not mean every category was involved for every person.

The settlement uses the term Private Information for information connected to the incident and covered by the litigation. The best individualized evidence is the notice sent to the affected person and the administrator's records. Readers should not assume that every patient or every person affiliated with the medical group is included.

Information varied by person The official list describes possible data categories. It does not establish that every listed identifier, medical record, or financial detail was compromised for every class member.

What the lawsuit alleges

The plaintiffs allege Palomar Health Medical Group is liable for the data incident and asserted multiple legal claims. The public settlement notice summarizes those claims at a high level rather than presenting a court finding that a particular security practice violated a particular law.

Palomar denies the claims, wrongdoing, and liability. The settlement notice states that the agreement is a resolution of disputed claims, not an admission or an indication that the company violated the law. The court did not decide in favor of either side before preliminary approval.

A data breach settlement can provide benefits without resolving every disputed fact about how an intrusion occurred or whether a defendant legally caused each alleged loss. Here, the agreement creates a common fund and claim rules while preserving the defendant's denial. Claimants must still show that they fit the class definition and meet the requirements for the benefit they select.

Who may be included

The settlement class includes individuals whose private information was accessed, acquired, disclosed, or compromised in connection with the Palomar Health Medical Group cybersecurity incident between April 23 and May 5, 2024. The notice says settlement class members were sent notice by mail.

Receipt of the settlement notice is therefore a strong practical indicator of inclusion. People who are uncertain can contact the administrator through PHMGDataSettlement.com or by calling 1-844-440-4203. The administrator, not this article, decides whether a claim is valid.

Excluded groups include directors, officers, and agents of the defendant or its subsidiaries and affiliates; governmental entities; and the assigned judge, the judge's immediate family, and court staff. A person who properly opts out is also no longer part of the settlement class.

An opt-out allows a person to preserve the ability to pursue separate claims covered by the release, subject to applicable law, but that person cannot receive settlement benefits. Someone who remains in the class will be bound by the final judgment and release if the settlement becomes final, even if that person files no claim.

Notice-based records matter The settlement is not open to every Palomar patient. The class is limited to people whose private information was compromised in the defined 2024 incident.

What benefits are available

The $3.1 million fund pays valid class-member benefits as well as administration expenses and any attorneys' fees, costs, or service awards approved by the court. Claimants may select one cash option and may also request the monitoring benefit.

Up to $5,000 for documented losses

Cash Payment A reimburses reasonable, documented losses related to the incident, up to $5,000 per settlement class member. The claimant must attest under penalty of perjury that the losses occurred and provide reasonable supporting documentation.

The notice describes the benefit as reimbursement. It does not promise $5,000 to everyone. The administrator will review the amount, documentation, connection to the incident, and whether another source already reimbursed the expense.

An estimated $60 alternative payment

Cash Payment B is an alternative cash option for people who do not seek documented-loss reimbursement. The official notice estimates this payment at $60, but the final amount will be determined only after all claims are received and evaluated.

The estimate may change because the same fund must cover valid benefits and court-approved expenses. A claimant cannot receive both documented-loss reimbursement and the alternative cash payment.

Two years of credit monitoring

Class members may request two years of credit monitoring with one credit bureau. The monitoring benefit may be claimed by itself or in addition to either cash choice.

Credit monitoring watches for changes in a credit file. It is different from a credit freeze, which restricts a credit bureau from releasing a consumer's report without authorization. The settlement benefit does not establish that identity theft occurred.

Benefits can be combined only in one way A claimant may choose documented-loss reimbursement or alternative cash, not both. Two years of credit monitoring may be added to either cash choice or claimed alone.

What proof is required

For documented losses, the claimant must select Cash Payment A, attest that the losses are related to the incident, and provide reasonable documentation. The notice describes documentation generated at the time of the expense or loss as important support.

Examples can include statements, invoices, receipts, or other records showing the amount and why it relates to the incident. A bare statement of a loss may not be enough. The administrator may request more information while reviewing a claim.

The alternative cash option does not require proof of a specific financial loss, but the claimant must still establish class membership and complete a valid claim form. Credit monitoring likewise requires a claim even though it is not conditioned on showing a completed identity-theft loss.

How to file a claim

Claims can be submitted through the court-authorized website, PHMGDataSettlement.com. The site also provides a printable claim form and the formal notice. Online claims must be completed by October 22, 2026. Mailed claims must be postmarked by that date.

The claim form asks the claimant to select one cash option and whether to request credit monitoring. A person seeking documented-loss reimbursement should attach the supporting records required by the form.

The separate October 7 deadline controls requests for exclusion and objections. Exclusion and objection have different legal effects. Exclusion removes the person from the settlement, while an objection asks the court to reject or change the proposed agreement. Anyone considering those options should read the full notice because this article does not provide legal advice.

Two deadlines control different actions October 7 is the opt-out and objection deadline. October 22 is the claim deadline. Filing by the later date does not preserve an earlier right that has expired.

Timeline and current status

  • April 23-May 5, 2024: Palomar says an unauthorized actor accessed certain network files and may have copied them.
  • May 5, 2024: Palomar identified suspicious activity and began investigating.
  • 2024: The lawsuit was filed in San Diego County Superior Court.
  • September 4, 2025: Palomar says it completed its file review and determined which individuals' information could have been affected.
  • July 17, 2026: The court preliminarily approved the settlement, provisionally certified the class, and appointed Angeion Group as administrator.
  • October 7, 2026: Deadline to opt out or object.
  • October 22, 2026: Claim deadline.
  • November 6, 2026: Final approval hearing scheduled for 10:30 a.m. Pacific Time.

The hearing date may change. The official settlement website is the controlling source for updates.

Evidence boundaries and unresolved issues

The company's notice says an unauthorized actor gained access to files and may have copied them. It also says Palomar was unaware of actual or attempted misuse connected to the incident when the notice was issued. Those statements do not rule out future misuse, but they also do not establish that misuse occurred.

The court has not found Palomar legally liable. Preliminary approval does not decide the merits. It permits notice and a claim process while the court considers whether the agreement is fair.

The alternative cash payment is only an estimate. The final amount and timing depend on claim volume, court-approved expenses, final approval, and any appeal. The $5,000 figure is a maximum for qualifying documented losses, not a standard payment.

The public notice does not support stating that every person had every listed data element exposed. Individual notices and administrator records are needed to understand what information was associated with a particular person.

What happens next

Class members who want benefits must file by October 22. People who want to opt out or object must act by October 7.

At the November 6 hearing, the court will consider final approval and requests for attorneys' fees and service awards. The preliminary order says any fee award will not exceed one-third of the gross settlement fund, but the court will determine the reasonable amount.

If the settlement becomes final, the administrator will evaluate claims and distribute approved benefits under the agreement. Appeals or other court orders could delay that process.

This article reports on the settlement and official records. It does not determine eligibility, promise payment, or recommend whether a person should claim, object, exclude themselves, freeze credit, or take another legal step.

Frequently asked questions

Who may qualify for the Palomar Health settlement?

Individuals whose private information was accessed, acquired, disclosed, or compromised in the Palomar Health Medical Group data incident from April 23 through May 5, 2024, may be included. Settlement class members were sent notice, subject to exclusions in the agreement.

What can class members claim?

A claimant may choose up to $5,000 in documented-loss reimbursement or an alternative cash payment estimated at $60. The claimant may also request two years of one-bureau credit monitoring.

Is the $60 payment guaranteed?

No. The official notice calls $60 an estimate. The final amount depends on the number and type of valid claims and other court-approved payments from the fund.

What is the claim deadline?

Online claims must be submitted and mailed claims postmarked by October 22, 2026. Opt-outs and objections are due October 7.

Has the settlement received final approval?

No. The court granted preliminary approval on July 17, 2026. A final approval hearing is scheduled for November 6, 2026, at 10:30 a.m. Pacific Time.

Free Eligibility Check

Do you qualify?

Check your eligibility and get help understanding your claim. It's free and takes under a minute.

Class Action Pulse is not a law firm and does not provide legal advice. Submitting this form does not create an attorney–client relationship. This is attorney advertising.

Class Action Pulse is a news and information service, not a law firm, and this article is general information — not legal advice. Eligibility, deadlines, and payouts are set by each settlement's official administrator and the courts; always verify the details through the official source before you file.

Join Our Email List

Never miss a claim you're owed

A short weekly briefing of new lawsuits and open settlements, with plain-English eligibility and the deadlines that matter. Free — unsubscribe anytime.