Managed Care of North America, MCNA Insurance Company and Healthplex have agreed to settle a consolidated class action lawsuit over a 2023 data breach that exposed personal and health information belonging to nearly 9 mn people.
The settlement covers people notified that their private information was potentially compromised during unauthorized access to MCNA’s computer systems between Feb. 26 and March 7, 2023. The defendants deny the allegations and any wrongdoing, and the court has not determined that they violated the law.
Eligible class members can submit claims for up to $2,500 in documented out-of-pocket losses associated with the breach. Claims must be filed by Oct. 19, 2026, and losses already reimbursed from another source aren’t eligible for additional payment under the settlement.
Class members who don’t opt out will also receive two years of medical data monitoring, subject to enrollment and final court approval. A claim form isn’t required for this benefit.
The deadline to opt out or object to the settlement is also Oct. 19. People who remain in the class will give up their right to pursue separate claims covered by the settlement, even if they don’t seek reimbursement for out-of-pocket losses.
A final approval hearing is scheduled for Nov. 16, 2026. The court will decide whether to approve the agreement and consider attorneys’ fees and costs.
The lawsuit followed a breach discovered by MCNA in March 2023. According to notices issued after the incident, an unauthorized party accessed the company’s systems for more than a week and viewed or copied personal and protected health information.
The exposed data potentially included names, addresses, dates of birth, phone numbers and email addresses. Social Security numbers, driver’s license or other government-issued identification numbers, insurance information, medical records, treatment information, x-rays, photographs, medications, bills and claims data were also among the information potentially affected.
MCNA said the breach involved current and former patients, parents or guardians, guarantors, healthcare providers and employees. The company issued notifications on behalf of more than 100 corporations, insurance plans and state agencies connected to its services.
A filing with the Maine Attorney General’s office indicated that nearly 9 mn people were affected by the incident. MCNA is a dental insurer and benefits management company serving government-sponsored Medicaid and Children’s Health Insurance Program members.
The ransomware group LockBit later claimed responsibility for the attack and reportedly demanded a $10 mn ransom. The group subsequently published data it said had been taken from MCNA after the ransom wasn’t paid.
The consolidated lawsuit alleged that MCNA and the other defendants failed to adequately protect sensitive information before the breach. Those allegations remain disputed, and the settlement does not amount to an admission of liability.
Under the proposed agreement, the defendants have also undertaken measures intended to further secure their systems and protect private information. The settlement will not become final unless the court approves it at the November hearing.









