Skip to main content

The Money Overview

Calibrated Healthcare breach victims get $21 to $29 automatically, or up to $5,175 with proof, by July 9

People affected by the Calibrated Healthcare, LLC data breach face a July 9 deadline to act on a settlement that offers automatic payments between $21 and $29 or documented claims reaching as high as $5,175. The breach itself dates back to February 2024, and state regulator filings confirm that the company reported the incident to the California Department of Justice. With the claims window closing fast, the size of any individual payout depends on whether victims simply wait for a default check or gather proof of out-of-pocket losses tied to the exposure of their personal health data.

Why the July 9 deadline changes the calculus for breach victims

Calibrated Healthcare, LLC reported two breach incident dates, February 25, 2024, and February 26, 2024, according to California breach records. Those filings were posted in late 2024, meaning months passed between the initial incident and public disclosure. That delay matters because affected individuals had limited time to monitor their accounts or freeze credit before the notification arrived, potentially increasing the window in which bad actors could misuse stolen data.

The settlement’s two-tier payout structure creates a clear choice. Victims who do nothing beyond confirming eligibility can expect a flat payment in the $21 to $29 range. Those who document specific harms, such as costs for credit monitoring, fees to replace identification, or time spent resolving fraudulent accounts, can claim up to $5,175. The disparity is steep enough that anyone with even modest documentation stands to collect several times the automatic amount, especially if they can show recurring expenses or multiple instances of fraud tied to the breach.

One open question is whether the size of the automatic tier reflects the volume of protected health information fields disclosed in each state’s breach notification rather than the raw number of people affected. Breach notices filed with different state attorneys general often list varying categories of exposed data, from names and dates of birth to diagnosis codes and insurance details. A notification listing more data fields could signal deeper exposure per person, which in turn could justify higher per-claimant payouts even if the total affected population is smaller. The available regulatory filings do not resolve this question directly, but the structure of the settlement tiers is consistent with a model that weights data sensitivity over headcount.

Regulator filings and federal reporting rules behind the settlement

The California DOJ breach list is one of the few public, searchable databases where consumers can verify that a company self-reported a data incident. Calibrated Healthcare, LLC appears in that registry with the two February 2024 incident dates and late-2024 posting dates. Separately, the federal HHS breach portal tracks HIPAA-related breaches affecting 500 or more individuals, creating a parallel paper trail for healthcare-specific incidents involving unsecured protected health information.

These two reporting channels serve different purposes. The California filing satisfies state consumer-protection law, while the federal portal enforces HIPAA’s notification requirements for covered entities and their business associates. When a healthcare company appears on both lists, it signals that regulators at two levels of government received formal notice of the incident. Neither database, however, publishes the exact number of affected individuals or a granular inventory of the data types exposed in the Calibrated Healthcare case, leaving consumers to infer risk from limited public descriptions.

State-level transparency tools provide some additional context. Through its broader OpenJustice platform, the California Department of Justice publishes a range of public safety and consumer-protection data that helps illustrate how frequently personal information is compromised and reported. While these aggregate resources do not name individual victims, they underscore why regulators push for timely breach notifications and why settlements like the one involving Calibrated Healthcare, LLC increasingly include compensation for both financial losses and time spent responding to an incident.

Gaps in the public record and what claimants should do first

Several details remain unclear from the available regulatory filings. The precise count of people whose records were compromised has not been disclosed, nor has a full breakdown of the specific data fields exposed for every individual. It is also not publicly documented how quickly Calibrated Healthcare, LLC notified all affected patients after confirming the breach, or how many of those individuals have since experienced identity theft, fraudulent billing, or other misuse of their information.

In the absence of complete public data, claimants should focus on what they can control before the July 9 deadline. The first step is to confirm that they received an official notice identifying them as part of the breach and to keep that letter or email with their records. Next, they should gather documentation of any costs that could plausibly be linked to the incident, such as receipts for credit monitoring, bank statements showing fraudulent charges later reversed, or correspondence with insurers about disputed medical bills.

Time spent dealing with the fallout may also be compensable under the settlement’s higher tier, so keeping a simple log of phone calls, letters, and account corrections can strengthen a claim. Even if a person has not yet seen clear evidence of fraud, proactively checking credit reports, reviewing medical benefit statements, and updating online account passwords can reduce the chance of future harm. For those who lack documentation or whose losses are minimal, accepting the automatic payment may still be worthwhile, but the closing claims window means that waiting passively carries the risk of leaving money on the table.


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.