A settlement has resolved one of the largest healthcare data breach lawsuits still working through the U.S. court system. The HIPAA Journal reported on September 3, 2026 that Managed Care of North America, Inc. (MCNA) has agreed to a multi-million-dollar settlement fund closing out class action litigation tied to a 2023 ransomware attack that hit close to 8.9 million people. The deal caps a three-year legal fight that started with 25 separate lawsuits and ended with a single consolidated case in the Southern District of Florida.
For a security and IT audience, the case is a useful checkpoint on how long healthcare breach litigation actually takes to resolve, what a “multi-million-dollar” settlement really pays out per person, and why insurers and dental benefit administrators remain a soft target for ransomware crews. The numbers involved, the timeline of the litigation, and the terms of the payout all say something about where healthcare cybersecurity liability is heading in 2026.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What happened: the 2023 MCNA ransomware attack, recapped
MCNA is a major dental benefits administrator, best known for managing government-sponsored dental coverage tied to state Medicaid programs and the Children’s Health Insurance Program (CHIP). Its subsidiaries include MCNA Dental, MCNA Insurance Company, and Healthplex, Inc. Because of that role, MCNA’s systems held an outsized volume of sensitive records belonging to children and low-income households enrolled in public dental benefit plans.
According to The HIPAA Journal, MCNA identified the cybersecurity incident on March 6, 2023. The subsequent forensic investigation determined that an unauthorized third party had been inside MCNA’s network from February 22, 2023 through March 7, 2023, when the intrusion was used to deploy ransomware and encrypt files. Before the encryption stage, the attackers exfiltrated a large volume of data. The LockBit ransomware group was identified as the actor behind the attack, and when MCNA did not pay the ransom, LockBit published the stolen files.
The compromised data set, per The HIPAA Journal’s reporting, included names, addresses, phone numbers, email addresses, birth dates, Social Security numbers, driver’s license numbers, government-issued ID numbers, health insurance information, Medicare and Medicaid ID numbers, group plan names and numbers, and details about the dental and orthodontic care patients received. That combination, Social Security numbers plus health insurance identifiers plus care details, is exactly the profile that fuels long-term identity theft and medical fraud, not just a one-time credit card replacement.
MCNA began notifying affected individuals on May 26, 2023, roughly two and a half months after the intrusion was first identified. The investigation ultimately confirmed the breach affected 8,923,662 individuals, a figure that puts it among the largest healthcare-sector breaches disclosed in the past several years.
From 25 lawsuits to one consolidated case
A breach of this scale almost guarantees a wave of class action filings, and MCNA’s case followed that pattern quickly. The first lawsuit was filed on June 5, 2023, just over a week after notification letters went out. By the time the dust settled, MCNA and its subsidiaries had been named in 25 separate putative class action complaints across multiple jurisdictions.
Because the complaints were, in The HIPAA Journal’s words, “materially and substantively identical” with overlapping legal theories, they were consolidated into a single action in the U.S. District Court for the Southern District of Florida. The consolidated case proceeded under the caption Crowe, et al., v. Managed Care of North America, Inc., et al., and the plaintiffs asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, violations of state consumer protection statutes, and requests for declaratory and injunctive relief.
MCNA denied wrongdoing and moved to dismiss the amended complaint. That motion was denied in part and granted in part by the court, and the case survived into discovery. Two rounds of court-appointed mediation reportedly failed to produce a deal before the parties finally reached settlement terms after extensive additional negotiations. That arc, filing to failed mediation to eventual settlement, took a little over three years, which tracks with how long large-scale healthcare breach MDLs typically run before resolution.
Inside the settlement: what MCNA is actually paying
The settlement notice, as detailed by The HIPAA Journal, describes a multi-million-dollar fund with several capped components rather than one lump payout to the entire class. MCNA has agreed to cover attorneys’ fees up to $6,400,000, litigation expenses up to $1,313,000, and settlement administration costs up to $2,000,000. Notably, the total value of the settlement, meaning the full cash-plus-benefits figure, has not been made public.
For the roughly 8.9 million class members, there are two main benefit tracks:
- Documented loss reimbursement: class members can submit a claim for documented, unreimbursed losses tied to the breach, up to $2,500 per person. However, the total pool for these claims is capped at $250,000. If valid claims exceed that cap, payouts are reduced and paid on a pro-rata basis. There is no flat alternative cash payment for people without documented losses.
- Medical data monitoring: every class member is eligible to enroll in two years of medical data monitoring service, listed at a retail value of $179.40 per year, which includes a $1 million identity-theft reimbursement policy. Enrollment requires a unique activation code, not a claim form.
Do the math on that loss-reimbursement pool: $250,000 split across a class of nearly 8.9 million people is a rounding error per person if even a small fraction of the class files a claim. In practice, most class members will get value from the monitoring benefit rather than a meaningful cash payment, since documented, unreimbursed out-of-pocket losses are historically claimed by only a small percentage of eligible class members in breach settlements of this size.
MCNA also agreed to non-monetary terms: the company committed to updating its business practices and implementing additional security measures aimed at reducing the risk of a repeat incident, without admitting liability or wrongdoing as part of the deal.
Key dates: what class members need to know
The settlement has moved past the negotiation stage and now has concrete deadlines attached, which is a meaningful shift from where the case stood earlier in the summer. The table below lays out the current schedule as reported.
| Milestone | Date / Detail |
|---|---|
| Unauthorized network access begins | February 22, 2023 |
| Incident identified by MCNA | March 6, 2023 |
| Ransomware deployed, access ends | March 7, 2023 |
| Notification letters sent | May 26, 2023 |
| First class action lawsuit filed | June 5, 2023 |
| Total putative class actions filed | 25 lawsuits, consolidated into one |
| Individuals affected | 8,923,662 |
| Deadline to object, opt out, or file a claim | October 19, 2026 |
| Final fairness hearing | November 16, 2026 |
Class members should watch for direct notification, which The HIPAA Journal says will go out within 30 days of the court’s preliminary approval order, since the notice will include claim instructions and the activation code needed for the medical data monitoring benefit. Nothing is final until the November 16 fairness hearing, where the judge decides whether to formally approve the settlement, including the attorneys’ fee award.
Why MCNA was a target: dental benefits as a soft underbelly
Dental and vision benefit administrators sit in an odd spot in the healthcare security conversation. They handle the same category of protected health information (PHI) as hospitals and insurers, Social Security numbers, Medicaid IDs, treatment records, but they typically operate with smaller security budgets and less regulatory scrutiny than a hospital system or a major health plan. MCNA specifically administers government-sponsored dental benefits, meaning its records skew toward children and lower-income households enrolled through Medicaid and CHIP, populations with comparatively little ability to monitor their own credit or catch fraud early.
LockBit’s involvement fits a pattern security researchers have flagged repeatedly: ransomware groups increasingly treat data exfiltration as the primary leverage point, not just file encryption. Even organizations that can restore from backups and avoid paying a ransom still face the class action and regulatory fallout of a data leak once a “pay or we publish” threat is carried out. MCNA’s case shows that fallout playing out over more than three years, well past the point where most headlines have moved on, a pattern also visible in the broader tally of data breaches topping 471 million victims in H1 2026.
Inside LockBit’s playbook: why exfiltrate before encrypting
LockBit’s approach in the MCNA case followed the FBI Internet Crime Complaint Center‘s well-documented “double extortion” pattern, which has become standard among major ransomware operations: gain network access, quietly exfiltrate as much sensitive data as possible, then deploy the encryption payload only once the theft is complete. That sequencing matters because it means backups alone are not a defense. Even an organization that restores every encrypted file from backup within hours still has to deal with the fact that a copy of its most sensitive records is sitting with the attackers, and possibly on a leak site if the ransom goes unpaid.
In MCNA’s case, the window between initial access on February 22, 2023 and the ransomware deployment on March 7, 2023 gave the attackers roughly two weeks inside the network, enough time to map out where the most valuable records lived and pull them out before triggering the encryption event that would alert the security team. That two-week dwell time is not unusual for ransomware intrusions and is part of why network segmentation and early intrusion detection remain such a heavily emphasized control in healthcare-sector security guidance, and why the economics of groups like LockBit are worth understanding in the context of how the broader ransomware economy actually works.
How the MCNA settlement compares to other 2026 healthcare breach payouts
Healthcare breach settlements have become a near-constant feature of 2026’s cybersecurity news cycle. The table below places the MCNA deal alongside other breach and settlement stories covered this year, using only the figures already reported for each case.
| Case | Individuals Affected | Settlement / Fine Detail |
|---|---|---|
| MCNA Dental / Healthplex (2023 breach) | 8,923,662 | Multi-million-dollar fund; fees capped at $6.4M, loss claims capped at $250,000 pool |
| Fidelity data breach settlement | Not specified in this article | $3.75M in combined fines reported |
| McKesson breach | Up to 284 million records claimed | $55M ransom demand reported; settlement not yet finalized |
| Aesto Health breach | 9.5 million patients | Breach disclosed 2026; litigation ongoing |
A settlement tracker logging the MCNA case alongside other active data breach settlements underscores a consistent theme: even breaches affecting many millions of people tend to settle for capped, relatively modest sums when spread across the entire class. Attorneys’ fees in these cases frequently rival or exceed the direct cash benefit pool available to consumers, a pattern that has drawn criticism from consumer advocates but remains standard in mass data breach litigation.
The regulatory backdrop: HHS OCR and state enforcement
Breaches of this size involving protected health information are required to be reported to the Department of Health and Human Services Office for Civil Rights (OCR), which maintains a public breach portal tracking incidents affecting 500 or more individuals. The MCNA incident, given its scale, would sit among the larger entries logged in that system for 2023. Beyond OCR, state attorneys general have become increasingly active in healthcare breach enforcement, often pursuing separate consumer-protection actions that run parallel to federal HIPAA obligations and private class action litigation.
The private settlement covered here resolves the consolidated class action, but it does not preclude separate regulatory action tied to the same underlying incident. Companies that settle class litigation over a breach can still face HHS OCR resolution agreements or state AG consent decrees addressing the same root-cause security failures.
What this means for enterprise security teams
For CISOs and IT leaders at healthcare-adjacent organizations, benefits administrators, third-party claims processors, and dental or vision networks included, the MCNA case is a reminder that liability exposure from a breach does not end when the incident response report is filed. It compounds for years through litigation, and the eventual settlement terms often include mandated security improvements as a condition of resolution, effectively giving courts and plaintiffs’ attorneys a say in an organization’s post-breach security posture.
The specific data fields exposed in the MCNA breach, Social Security numbers, government ID numbers, and Medicaid/Medicare identifiers alongside clinical details, also illustrate why segmenting and encrypting identity data separately from clinical records matters. A ransomware actor that only reaches treatment notes causes real harm, but one that also reaches SSNs and government ID numbers turns a HIPAA incident into a full identity-theft exposure event, which is exactly the combination that drove the class action claims here.
What affected individuals should do while the settlement moves through court
Individuals who received a breach notification letter from MCNA back in 2023 do not need to take action immediately, since claim forms and the medical data monitoring activation codes will only go out after the court grants preliminary approval and the notification process begins. In the meantime, security practitioners generally recommend that anyone whose Social Security number and government ID information were exposed in a breach of this type place a fraud alert or credit freeze with the major credit bureaus, monitor Medicaid and Medicare explanation-of-benefits statements for unfamiliar claims, and keep the original breach notification letter on file, since it may be needed to document eligibility when the claims process opens.
Because the settlement’s documented-loss reimbursement requires proof of an actual financial loss tied to the breach, individuals who experienced identity theft or fraudulent medical claims in the years since 2023 should keep records, such as bank statements, collection notices, or correspondence with the IRS about fraudulent tax filings, so they can support a claim once the filing window opens ahead of the October 19, 2026 deadline.
Predictions: where this heads next
- Court approval is likely but not guaranteed. Settlements that reach the fairness-hearing stage after multiple rounds of mediation are typically approved, but objections filed before the October 19, 2026 deadline could still alter fee awards or benefit terms before the November 16 hearing.
- Claim rates for the cash pool will likely be low relative to the $250,000 cap. Based on typical participation rates in mass breach settlements, only a small share of the 8.9 million class members are expected to file documented-loss claims, meaning most value delivered will come through the medical monitoring benefit rather than direct payments.
- More benefits-administrator breaches should be expected. Given the sensitive data density and comparatively lighter security investment typical of dental, vision, and ancillary benefits processors, similar organizations remain attractive ransomware targets through the rest of 2026.
- Regulatory scrutiny of third-party administrators will likely increase. As more of these cases work through the courts, expect state attorneys general and HHS OCR to pay closer attention to benefits administrators specifically, rather than treating them as adjacent to core “healthcare provider” enforcement priorities.
- Settlement structures will keep separating cash caps from monitoring benefits. The MCNA structure, capped documented-loss reimbursement plus broader monitoring enrollment, has become the default template in healthcare breach settlements and is likely to persist because it limits defendants’ maximum cash exposure while still offering a tangible benefit to the full class.
The bigger picture on healthcare ransomware liability
The MCNA settlement lands in a year where healthcare and healthcare-adjacent breaches have repeatedly made headlines, from hospital systems to pharmacy benefit managers to, now, a dental benefits administrator serving Medicaid and CHIP populations. What ties these cases together is not just the scale of records exposed but how slowly the legal consequences play out relative to the speed of the original attack. LockBit’s intrusion into MCNA’s network took roughly two weeks from initial access to ransomware deployment. Resolving the resulting litigation took more than three years.
That mismatch, days to breach, years to resolve, is likely to remain the norm as long as mass data breach litigation continues to move through federal courts at its current pace. For organizations handling PHI and government-issued identifiers at scale, the practical takeaway is that the cost of a breach is not fully known until years after the notification letters go out, and it includes legal exposure that can run well beyond the initial incident response bill.
Frequently Asked Questions
What is the MCNA Dental data breach settlement?
It is a multi-million-dollar settlement resolving consolidated class action litigation against Managed Care of North America, Inc. (MCNA), MCNA Insurance Company, and Healthplex, Inc., stemming from a 2023 ransomware attack that affected 8,923,662 individuals, as reported by The HIPAA Journal.
How much money will each class member receive?
Class members can claim documented, unreimbursed losses up to $2,500 each, but the total pool for these claims is capped at $250,000 and paid pro rata if claims exceed that amount. All class members are also eligible for two years of medical data monitoring valued at $179.40 per year, including a $1 million identity-theft reimbursement policy.
What data was exposed in the MCNA breach?
According to The HIPAA Journal, exposed data included names, addresses, phone numbers, email addresses, birth dates, Social Security numbers, driver’s license numbers, government-issued ID numbers, health insurance information, Medicare/Medicaid ID numbers, group plan details, and dental and orthodontic treatment information.
Who was behind the MCNA ransomware attack?
The HIPAA Journal identified the LockBit ransomware group as responsible. The group gained unauthorized access to MCNA’s network on February 22, 2023, exfiltrated data, and deployed ransomware on March 7, 2023, after which it published the stolen files when a ransom was not paid.
When is the deadline to file a claim or opt out?
The deadline to object, opt out, or submit a claim is October 19, 2026. The court’s final fairness hearing on the settlement is scheduled for November 16, 2026.
Did MCNA admit wrongdoing in the settlement?
No. The settlement terms include no admission of liability or wrongdoing by MCNA or its co-defendants, which is standard in mass data breach class action settlements.
How does this compare to other 2026 healthcare data breach cases?
It is comparable in scale to other large healthcare breaches disclosed or litigated in 2026, including the Aesto Health breach affecting 9.5 million patients and the McKesson breach, though exact settlement values differ by case and several remain in earlier stages of litigation.
What should affected individuals do now?
Affected individuals should watch for a direct notification letter, expected within 30 days of the court’s preliminary approval order, which will include claim filing instructions and an activation code for the medical data monitoring benefit.
Click Here For The Original Source.
