Patients swept into the McKenzie Health System data breach can now choose between a flat $50 payment with no paperwork or reimbursement of up to $4,000 for documented losses, but both options close on August 24, 2026. The settlement resolves a class action over an April 2025 cyberattack on the Michigan hospital system, formally captioned as the McKenzie Memorial Hospital data breach litigation. For older patients whose Social Security numbers and medical records were exposed, the deadline and the two payment tracks are the practical details worth acting on, alongside a warning about the impostors who trail every settlement of this kind.
What the breach exposed and the case behind it
The lawsuit stems from a data-security incident that McKenzie Health System disclosed after unauthorized access to its network in April 2025. Breaches at hospital systems are especially damaging because the exposed files can combine names, dates of birth, Social Security numbers, and medical or insurance information, the exact bundle identity thieves use to open accounts or file fraudulent claims. The settlement does not require the hospital to admit wrongdoing; it resolves the claims while compensating the affected patients.
The incident placed McKenzie among a long run of health-care breaches that have made medical providers a leading target for cybercriminals. For a rural hospital system, a single intrusion can touch a large share of the surrounding community, including retirees who rely on the system for care and whose records stretch back years. That breadth is part of why courts approve settlements paying every affected patient rather than only those who can prove a loss.
According to a summary of the agreement, the settlement covers people whose private information was potentially compromised in the incident and who received notice of it. A final fairness hearing is scheduled for October 6, 2026, when the court will decide whether to grant final approval, but the claim window itself closes well before that date. Waiting for the hearing is not a reason to delay a claim.
Free retirement updates: Every year, billions in settlements and unclaimed money go unclaimed. The free Retirement Shield newsletter sends the real ones, with deadlines, a couple times a week. Get the free newsletter.
The $50 and $4,000 options and who qualifies
Eligible class members can elect a straightforward $50 cash payment that requires no documentation, a route built for patients who have not tracked specific costs. The alternative reimburses up to $4,000 in documented out-of-pocket losses tied to the breach, covering expenses such as fraud losses, credit-monitoring fees, and the cost of freezing or unfreezing credit incurred between April 14, 2025 and August 24, 2026. That path requires proof, such as bank statements or receipts.
The choice between the two options usually comes down to records. A patient who noticed fraudulent charges, paid for a credit freeze, or spent hours untangling a misused identity may recover far more through the documented-loss track than the flat payment provides. A patient with no traceable costs generally does better taking the guaranteed $50 rather than assembling paperwork for expenses that never occurred.
Patients who never received a mailed notice are not automatically excluded. Anyone who was a McKenzie Health System patient around the time of the breach can contact the settlement administrator to confirm whether their information was part of the exposed data and request the identifiers needed to file. Because breached hospital records often resurface months or even years later in identity-theft attempts, patients who have seen no misuse yet still have reason to lock in the free credit monitoring while the window remains open.
Beyond the cash, class members may claim two years of credit monitoring that includes identity-theft protection and $1 million in identity-theft insurance. The official settlement website is where valid claims are filed, either online using the login ID and PIN printed on a mailed notice or by downloading and mailing the claim form. The administrator can be reached by phone for patients who no longer have their notice.
The impostor claim that shadows every settlement
Legitimate settlements attract a second wave of fraud, and this one is no exception. Scammers monitor public claim deadlines and then call or email potential class members claiming they must pay a fee, confirm a Social Security number, or provide bank login details to “release” a settlement payment. No genuine settlement administrator asks for an upfront fee, and filing a real claim never requires handing over account passwords.
Time is the practical enemy here. The August 24 deadline applies to submitting the claim, not to when the money arrives, and payments typically follow only after the October approval hearing and any appeal period. Filing early avoids the common trap of a mailed notice going into a drawer and resurfacing after the window has already closed.
The safest path is to start only from the court-approved website or the number on the official notice, and to treat any unsolicited message about the settlement as suspect. Patients worried about how the underlying breach may affect them can build a recovery plan and place free fraud alerts through the government’s identity-theft recovery site and review the standard steps to take after a data breach. The money in this settlement is real and claimable, but only through the door the court actually opened, and only until August 24.
This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.
More Financial Reading