Check Your Claims
← Settlements/Data Privacy

Family Medical Associates of Raleigh data breach investigation

FMAR reports unauthorized access and downloaded information in April 2026. Attorneys are seeking affected people for evaluation, but no settlement payment is available.

Updated October 6, 2026

Company under investigation
Family Medical Associates of Raleigh, PA (investigation subject; no filed case verified)
Status
Under investigation
Potential compensation
No verified settlement or payment
How to join
Request attorney evaluation; no verified claim deadline
Case type
Attorney investigation
Check if you qualify →

Overview

Company role
Raleigh family-medicine practice
Reported access
April 18–20, 2026
Action available
Request attorney evaluation; no settlement

Family Medical Associates of Raleigh, PA, or FMAR, reports that an unauthorized actor accessed its computer systems and downloaded certain information between April 18 and April 20, 2026. Attorneys are now seeking affected people while investigating whether to file a class action. No filed class complaint, court-certified class or cash settlement was verified for this listing.

The company-authored updated notice is the evidence for the incident. The separate attorney page establishes recruitment. Neither proves legal wrongdoing or guarantees that a particular reader's information was exposed. That distinction matters before treating an inquiry as a claim for money.

Who the parties are

FMAR is a family-medicine practice in Raleigh, North Carolina. Its website describes primary health care for patients of all ages, appointments, medical advice and patient-portal communications. Patients interact with the practice for care and related administration. The incident concerns information stored in the practice's computer systems, not a verified defect in a medication or a medical-treatment claim.

ClassAction.org publishes legal-case information and a recruitment page about this incident. That page discloses that submitted information is forwarded to Bryson Harris Suciu & DeMay PLLC, the law firm sponsoring the investigation. The firm seeks information to assess possible litigation; it is not identified as a settlement administrator or court-appointed class counsel in the reviewed record.

No named plaintiff, court, case number or settlement administrator was verified. FMAR is the organization under investigation, not a defendant established by a complaint reviewed for this article. Unnamed data-security professionals and law enforcement assisted its response, according to the practice; their identities and specific findings are not supplied.

What happened

The notice separates the access period from discovery and public notification. These are different events, not interchangeable descriptions of when the incident occurred.

  • April 18–20, 2026. FMAR says an unauthorized actor accessed its systems and downloaded certain information during this period.
  • May 7, 2026. The practice became aware of suspicious activity. It says it investigated, reset credentials, isolated affected systems, communicated with law enforcement and engaged security and privacy professionals.
  • July 2, 2026. FMAR says it first posted a website notification so potentially affected people could learn about the situation and protective steps.
  • October 5, 2026. ClassAction.org published the attorney-recruitment page. That publication is not a lawsuit filing date.

The updated notice says FMAR worked continuously after discovery to identify potentially impacted information. It does not provide a confirmed total affected population or the date on which every individual notice was sent. Those gaps are not filled with an estimate.

What each side says

FMAR acknowledges unauthorized access and downloading. It also says that, at the time of the reviewed notice, there was no evidence that information had been misused for identity theft or fraud in connection with the incident. This is its stated assessment, not a finding that exposure created no risk.

The practice says it added security-monitoring tools, enhanced multi-factor authentication and reinforced administrative and technical safeguards. Multi-factor authentication requires more than one verification step to access an account. These statements describe the company's response; they do not independently establish that its security was adequate before or after the incident.

The recruiting attorneys are investigating a possible class action. Their page describes possible compensation and security changes if litigation is filed and successful. Those are conditional possibilities, not damages already awarded. No complaint-specific allegations, legal defenses, admission of liability or response to a filed case were verified.

What the court has and has not decided

No court ruling was verified in the reviewed investigation record. There is no established settlement approval, class certification or judicial finding of negligence for this listing. Class certification is a court decision allowing identified representatives to pursue claims for a defined group. Attorney recruitment alone does not produce that decision.

A company incident notice also does not establish that all legal requirements for a lawsuit have been met. A lawyer would need to examine the facts, potentially applicable law and evidence of an individual's involvement before advising on a claim.

Who may qualify

  • Connection to the incident. Attorneys seek people whose information was exposed or who reasonably believe they were affected, including notice recipients. Merely visiting the practice does not establish exposure.
  • Individual records matter. The company lists general data categories, not a finding that every category applied to every person. Retain any personal notice and ask FMAR what information may have been involved.
  • Investigation, not a certified class. No verified class definition, geographic exclusion list, settlement claim form or court-approved compensation criteria are available in the reviewed record. A lawyer must evaluate an individual inquiry.

The recruitment page seeks people whose information was exposed, including notice recipients and people who otherwise believe they were affected. This is an invitation to evaluation, not a judicial eligibility definition. No verified date-of-treatment cutoff, state-specific exclusion or requirement to prove identity theft is imposed by a settlement here.

FMAR's notice lists general categories in the affected systems. These include names, addresses, contact information, dates of birth, demographic information, biometric and genetic data, financial account numbers without access information, and Social Security or taxpayer identification numbers. Biometric information relates to physical characteristics used to identify a person; genetic information concerns inherited biological characteristics. The notice does not specify which such records applied to each recipient.

Potential health information includes treatment, service and discharge dates; lab results; diagnoses, procedures and medical history; medical-record numbers; physical or mental conditions; prescription information; treatment costs; and health-insurance or Medicare/Medicaid identifiers. Medicare and Medicaid are government health-coverage programs. The list describes possible information, not proof that every patient had every listed field downloaded.

What affected readers can do now

Keep the incident notice, relevant correspondence and a dated record of expenses or unusual account activity. FMAR encourages reviewing account statements, explanations of benefits and credit reports. An explanation of benefits is a health insurer's account of a processed medical claim, not necessarily a bill. Review it for services you do not recognize.

For incident questions, the company notice provides 888-619-1587, Monday through Friday, 9 a.m. to 9 p.m. Eastern, excluding major U.S. holidays. Ask what information may have been involved in your case rather than assuming the general data list applies to you.

If you seek legal evaluation, use the current recruitment page and read its sponsor and consent disclosures. It says initial contact costs nothing and creates no obligation to act. Any later representation or fee arrangement requires its own terms. A Class Action Pulse inquiry is separate from that firm's intake and does not itself file a case or preserve a filing deadline.

What you could receive

Potential legal action

No payment available now

The recruiting page describes possible recovery only if a case is filed and succeeds. No settlement fund, fixed award or compensation entitlement has been established.

Incident response

Information and protective steps

FMAR's notice provides an incident helpline and recommends reviewing statements, explanations of benefits and credit reports. The reviewed web notice does not specify a free monitoring enrollment offer.

No verified payment, settlement fund, cash option or court-approved benefit exists in the reviewed record. Possible litigation could seek relief, but its outcome, participating group and compensation would remain uncertain. There is no basis to advertise a per-person award.

The reviewed FMAR web notice supplies protective guidance and a help number. It does not specify a complimentary monitoring product, enrollment code or enrollment deadline. Do not assume an offer from another medical-practice breach applies here. If a personal letter gives additional terms, check that letter and confirm them with the practice.

Important dates and rights

There is no verified settlement claim, objection, exclusion or hearing deadline. April 18–20 describes access; May 7 describes discovery; July 2 describes the initial website notification. None is an instruction to submit a settlement claim.

Requesting contact does not make a reader a named plaintiff or class member. No settlement release was verified. A release is an agreement surrendering specified legal claims. Individual legal time limits may still matter, so a missing public settlement deadline should not be read as permission to wait indefinitely. Seek individual advice if preserving a claim is important.

Definitions

Protected health information means identifiable information about a person's health, treatment or related payment. Personally identifiable information means information that identifies, or can help identify, an individual. Unauthorized access means entry into systems without permission; downloading information is a further act the practice says occurred here. Exposure and later misuse are different questions.

An investigation is an effort to assess potential claims. A class action is a lawsuit in which representatives seek relief for a defined group. A settlement is an agreement resolving claims, often subject to court approval. This listing is at the investigation stage, not a verified settlement stage.

What happens next

Attorneys may evaluate notices, affected information and reported harms to decide whether litigation is appropriate. The public intake page does not establish that a case will be filed, that a court will authorize group proceedings or that money will be recovered. FMAR says it continues evaluating security practices.

The next useful evidence would be an individualized notice, a confirmed complaint or a court document identifying claims and procedural status. Until then, the practical actions are confirming personal involvement, reviewing records and requesting evaluation if desired.

Sources and evidence boundaries

The company-authored notice is available through a ClassAction.org mirror. FMAR's website supports its service description; the attorney page supports current recruitment and sponsor identity. The mirrored notice is not a regulator ruling, and the recruitment page is not a court docket. No affected-person total, filed complaint, recovery amount or settlement deadline was verified.

Class Action Pulse is not a law firm or settlement administrator, does not guarantee eligibility or payment, and provides legal information rather than individual legal advice. Consult the company materials and any later official court records for controlling information.

Frequently asked questions

Is there a Family Medical Associates of Raleigh settlement claim form?

No official cash settlement or settlement claim form was verified. The current attorney page seeks people for investigation and evaluation, not payment administration.

Was every patient's Social Security number exposed?

The company notice includes Social Security numbers among general categories that may have been impacted. It expressly says the categories may not apply to every potentially affected person.

Does submitting an inquiry make me a plaintiff?

No. An inquiry lets a legal representative evaluate your circumstances. It does not itself file a lawsuit, certify a class or establish that a firm represents you.

Has FMAR said identity theft occurred?

Its reviewed notice says there was then no evidence of misuse for identity theft or fraud in connection with the incident. That is the practice's reported assessment, not a guarantee about future activity or a court finding.

Sources

This is an attorney investigation, not an open settlement claim process. Class Action Pulse is not a law firm. An inquiry requests follow-up; it does not file a claim, guarantee a firm connection or establish representation.

Free Eligibility Check

Do you qualify?

Check your eligibility and get help understanding your claim. It's free and takes under a minute.

Class Action Pulse is not a law firm and does not provide legal advice. Submitting this form does not create an attorney–client relationship. This is attorney advertising.