People affected by the FMC Services, LLC data breach that occurred on July 26, 2022, face a closing window to file claims for roughly $75 in basic compensation or up to $5,000 for documented losses. The deadline is August 31, and the breach was serious enough to trigger federal and state reporting requirements. With the claims period now in its final months, anyone who received a notification letter from FMC Services needs to act before the cutoff or forfeit any potential payout.
Why the August 31 claims deadline forces a decision now
The breach at FMC Services was not a minor incident quietly handled behind closed doors. Federal law requires covered healthcare entities to report any exposure of unsecured protected health information to the Secretary of Health and Human Services when 500 or more individuals are affected. The federal breach portal tracks exactly these large-scale incidents, and FMC’s breach met that threshold. That filing confirms the scope was significant enough to warrant public accountability and formal notice to regulators.
The practical question for affected customers is straightforward: file a claim before August 31 or walk away from any recovery. The number of people who actually submit claims will likely track closely with how many individuals were listed in the federal breach report, not with how much attention the story received in the press. Most breach victims learn about their eligibility through direct notification letters, not news articles. That means the real driver of claim volume is the size of the affected population recorded in government databases, and the clock is running out for those individuals to respond.
Because the settlement payments are tied to the number of valid claims, waiting until after the deadline is not an option. Once the claims period closes, the administrator will typically begin validating submissions, calculating individual payouts, and distributing funds. Anyone who ignores the August 31 date will almost certainly be excluded from that process, regardless of how clearly they were notified in 2022.
Federal and state records confirm the FMC breach scope
Two separate government records anchor the key facts. The California Department of Justice lists the breach date as Tuesday, July 26, 2022, and hosts the sample notification letter that FMC Services sent to affected individuals. That state filing provides the clearest public record of what consumers were told and when, including the description of the compromised data and the offer of credit monitoring.
On the federal side, the U.S. Department of Health and Human Services maintains the breach portal where covered entities must disclose incidents affecting 500 or more people. Oversight of these privacy incidents is handled by the agency’s civil rights arm, which is detailed on the Office for Civil Rights page. Both the state report and the federal listing confirm that FMC followed the required reporting steps, but neither government source publishes the specific settlement terms, per-person payment amounts, or claim-form instructions.
This gap matters. Consumers who search for their breach notification on official government websites will find confirmation that the incident happened and that it was reported properly. They will not, however, find the dollar figures or filing instructions on those pages. The roughly $75 basic payment and the $5,000 ceiling for documented losses come from the settlement process itself, not from the regulatory filings. Affected individuals should refer to the actual claim form or settlement notice they received by mail or email for step-by-step instructions tailored to this case.
Open questions about payout mechanics and verification
Several details about the FMC settlement remain outside the public government record. No primary source among the federal or state filings specifies the total settlement fund, the exact per-person payout formula, or how losses must be documented to qualify for the higher $5,000 tier. The claims administrator’s contact information and the verification process for out-of-pocket expenses are similarly absent from the official breach portal entries, which focus on compliance rather than compensation.
In practice, most data breach settlements require claimants seeking reimbursement for documented losses to provide copies of receipts, bank or credit card statements, invoices, or other written proof tying the expense to the incident. There is usually also a sworn statement that the losses were not reimbursed by another source, such as a bank or insurer. While the precise rules for the FMC settlement are not laid out in the state or federal reports, affected individuals can expect the claim form itself to spell out what qualifies and what does not.
Given those unknowns, the safest course for anyone who received an FMC Services notification in 2022 is to locate the original settlement notice, read the detailed instructions, and submit a claim before August 31 even if they are unsure whether they will qualify for the higher reimbursement tier. Failing to file guarantees no payment at all, while submitting a timely claim preserves the opportunity to receive at least the basic cash amount and potentially more if eligible losses can be documented. For breach victims, the remaining weeks before the deadline are the final chance to turn a regulatory disclosure into actual financial relief.
Free tool for readers: It’s free, takes about five minutes, and there’s no sign-up to see your result: get your free Retirement Safety Score — a 0–100 number plus a few personalized steps for making your money last.