Patients of Esse Health, a St. Louis physician group, can claim a flat $50 cash payment from a data-breach settlement without submitting any proof of loss, but the window closes August 4, 2026. The payout stems from a $2,525,000 settlement over an April 2025 cyberattack that exposed personal and medical information for hundreds of thousands of people the practice served. The $50 is an estimate rather than a guarantee, and eligible patients can also enroll in two years of identity-protection coverage at no cost — a combination worth understanding before the deadline passes.
What the Esse Health settlement pays
The settlement offers class members a one-time pro-rata cash payment expected to be about $50, with no requirement to document any out-of-pocket loss — an unusually low barrier compared with settlements that demand receipts. The figure can rise or fall depending on how many valid claims are filed, so a heavier response would shrink each check and a lighter one would enlarge it. Separately, every class member may enroll in two years of medical identity-protection services that include a $1 million identity-theft insurance policy, a benefit the practice funds outside the cash fund.
The money comes from a $2,525,000 fund that also covers attorneys’ fees, administration and notice costs, and service awards for the eight class representatives, with whatever remains paying the flat cash benefit, according to the settlement’s long-form notice. Eligibility runs to the people whose information was involved in the breach and who received notice; the class is not open to the general public, and only those actually affected by the incident can claim.
The pairing of cash and monitoring is deliberate. Data-breach settlements increasingly separate a modest, no-proof cash payment — designed to be easy to claim — from a longer-term protection benefit that addresses the real risk, which is fraud committed with stolen identity data. Choosing both is generally the fuller use of what the settlement provides, since the two benefits cover different problems.
Free retirement updates: Every year, billions in settlements and unclaimed money go unclaimed. The free Retirement Shield newsletter sends the real ones, with deadlines, a couple times a week. Get the free newsletter.
The April 2025 breach behind the payout
Esse Health detected the cyberattack on April 21, 2025, and a forensic investigation confirmed that intruders accessed names, addresses, birth dates, health information, and health-insurance details, with roughly 5,000 people also having Social Security numbers exposed. The scope was reported inconsistently across agencies — one federal filing listed about 23,671 patients and a state notification cited 263,601 — but the consolidated lawsuit put the total affected at approximately 521,167 individuals.
The litigation, brought as Clausner v. American Multispecialty Group and consolidated in a St. Louis court, alleged the practice failed to implement reasonable cybersecurity safeguards and could have prevented the breach. Esse Health denies any wrongdoing or liability and agreed to settle to avoid the cost and risk of continued litigation, a standard resolution that lets both sides close the matter without a trial verdict.
Physician-group breaches like this one are especially sensitive because the stolen files combine financial identifiers with medical records, a mix that is harder to undo than a leaked password. A Social Security number cannot be reset, and health-insurance details can be used to obtain care or file false claims under a victim’s name, which is why the settlement bundles years of monitoring rather than a one-time payment alone.
How to claim before August 4 and what else to weigh
Class members must submit a claim by August 4, 2026, the day after a final fairness hearing scheduled for August 3 at which the court decides whether to approve the deal, the settlement terms show. The deadline to object to or opt out of the settlement was July 5, 2026, and has passed, so the remaining decision for most affected patients is simply whether to file for the cash, the identity protection, or both.
For older patients in particular, the identity-protection enrollment can be the more valuable half of the offer, because exposed Social Security numbers and health-insurance details fuel medical-identity fraud that can surface years after a breach. As with any settlement, no legitimate administrator charges a fee to release a $50 payment, and requests for bank passwords or upfront costs signal a scam rather than a real claim.
Patients unsure whether they are covered can start with the notice itself. The settlement administrator mailed or emailed direct notice to affected individuals, and that notice carries the claim instructions and any identifier needed to file; anyone who believes they were a patient during the breach but did not receive a notice can still reach the administrator through the official settlement channels before the deadline. Filing takes only minutes, and selecting both the cash payment and the two-year monitoring at the same time avoids having to return to the process later.
What remains, now that the objection window has closed, is a short, practical decision rather than a legal one. The settlement will not fully compensate anyone for the permanent exposure of a Social Security number, and the roughly $50 reflects that limit, but the claim costs nothing to file and the monitoring addresses the exposure that outlasts the check. After August 4, both benefits disappear for anyone who has not acted.
This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.
More Financial Reading