Attorney Advertising · Informational Only · Not Legal Advice · Editorial Policy

Geisinger Health Data Settlement Covers Patients Affected by Employee Data Access Incident

Patients whose information was taken in the November 2023 Geisinger data security incident are covered by a $5 million class action settlement that received final court approval on March 16, 2026. The settlement, formally titled In re Geisinger Health Data Security Incident Litigation, resolves claims against both Geisinger Health and its IT vendor Nuance Communications, a Microsoft subsidiary, after a former Nuance employee accessed Geisinger’s systems without authorization and downloaded records on more than 1.2 million patients of the Danville, Pennsylvania-based health system. The class covers 1,308,363 people.

Members were able to choose between a one-year credit monitoring and identity theft protection membership or reimbursement of documented out-of-pocket losses up to $5,000 per person. The claim deadline was March 18, 2026, and has now passed; according to class counsel Shub Johns & Holbrook LLP, payments are expected later in 2026, once any appeals of the final approval order are resolved. To take one concrete example of how this played out: a Geisinger patient who spent money on credit freezes, identity restoration services, or fraud-related losses traceable to the breach could submit documentation and claim up to $5,000 — a meaningfully higher individual cap than many health data settlements of similar size offer.

Table of Contents

What Happened in the Geisinger Employee Data Access Incident?

This was not a typical outside hacking case. According to reporting from Becker’s Hospital Review and the HIPAA Journal, Andre J. Burk — who also went by the name Max Vance — was a 46-year-old California man employed by Nuance Communications, which provided IT services to Geisinger. Nuance terminated him, and two days later, on November 29, 2023, he used his still-functional Nuance credentials to log into Geisinger’s systems and download data on more than 1.2 million patients.

Advertisement

The data exposed, per BankInfoSecurity, included names, dates of birth, addresses, phone numbers, medical record numbers, race, gender, admit/discharge codes, and abbreviations of the facilities where patients were treated. Notably absent from the reported list are Social Security numbers and financial account details, which distinguishes this incident from breaches like the 2015 Anthem hack, where Social Security numbers were taken. That said, the combination of medical record numbers with demographic details still creates real risk of medical identity theft and targeted phishing. The insider angle mattered legally. Plaintiffs argued that a terminated vendor employee retaining working access credentials for two days after firing reflected a failure of basic offboarding controls — which is why both Geisinger and Nuance, rather than Geisinger alone, are paying into the settlement fund.

How the $5 Million Settlement Fund Is Structured

The $5 million settlement fund is being paid jointly by Geisinger Health and Nuance Communications, as reported by TechTarget. Class members had two options: elect a one-year credit monitoring and identity theft protection membership, or file a claim for reimbursement of documented out-of-pocket losses up to $5,000 per member. The important limitation is documentation. The $5,000 cap is not an automatic payment — it applies only to losses a claimant could actually substantiate, such as receipts for credit monitoring purchases, bank records showing fraud losses, or evidence of time and expenses spent responding to identity theft.

Claimants without documentation were limited to the credit monitoring benefit. This is standard in data breach settlements, but it routinely surprises class members who expect a flat cash payment simply for having been affected. A second limitation worth understanding: with 1,308,363 class members sharing a $5 million fund — which also covers attorneys’ fees, administration costs, and service awards — the economics only work because most class members historically do not file claims. Those who did file stand to receive real value; those who missed the March 18, 2026 deadline have no further path to compensation under this settlement.

The Criminal Case Against the Former Nuance Employee

The civil settlement ran parallel to a federal criminal prosecution. According to Becker’s hospital Review, Vance pleaded guilty to one count of obtaining information from a protected computer without authorization, entering his plea on February 27. That charge falls under the Computer Fraud and Abuse Act, the federal statute most commonly used against insiders who exceed or retain access after their authorization ends.

The guilty plea is a specific example of how criminal and civil tracks interact in data breach litigation. A conviction or plea establishing that data was deliberately stolen — as opposed to briefly exposed by a misconfiguration — tends to strengthen civil plaintiffs’ standing arguments, because courts are more willing to find a concrete injury when records are known to be in a criminal’s hands. In cases where breached data is never shown to have been accessed by a bad actor, defendants often succeed in getting claims dismissed for lack of demonstrated harm. Here, the theft was undisputed.

How This Settlement Compares to Other Health Data Breach Settlements

At roughly $3.82 per class member in gross fund terms ($5 million across 1,308,363 people), the Geisinger settlement sits in the typical range for healthcare breach cases of this size. What sets it apart is the responsible-party structure: because the breach originated with a vendor’s former employee, Nuance — the business associate — shares the cost with Geisinger, the covered entity. In many hospital breach settlements, the health system bears the full amount even when a third-party vendor was the point of failure.

The tradeoff class members faced was the classic one in these settlements: take the credit monitoring benefit, which has a retail value often exceeding $100 but requires no paperwork, or pursue documented losses up to $5,000, which pays more but demands proof. For most people with no demonstrable fraud losses, the monitoring election was the rational choice. For anyone who actually experienced identity theft traceable to the breach, the reimbursement track was clearly superior — and the $5,000 individual cap is more generous than the $2,500 caps seen in some comparable cases.

What Class Members Should Watch for During the Payment Phase

Final approval was granted on March 16, 2026, by Chief Judge Matthew Brann of the U.S. District Court for the Middle District of Pennsylvania, but approval does not mean immediate checks. Class counsel at Shub Johns & Holbrook LLP has indicated payments are expected later in 2026, after the window for appeals of the final approval order closes and any appeals that are filed get resolved. A single objector’s appeal can delay distribution by months or longer, which is a structural feature of class actions that claimants have no control over.

📨 Get Free Mass Tort Guides Alerts

Free · No spam · Unsubscribe anytime

A warning that applies to every large settlement in its payment phase: this is prime season for scams. Fraudsters monitor settlement news and contact class members claiming they need a “processing fee,” bank login credentials, or a Social Security number to release payment. The legitimate settlement administrator, reachable through the official site at geisingerdatasettlement.com, will never charge a fee to deliver a settlement benefit. Anyone contacted by phone or email demanding payment or sensitive credentials in connection with this settlement should treat it as fraudulent.

Why Vendor Offboarding Failures Keep Causing Health Data Breaches

The Geisinger incident is a textbook illustration of third-party access risk in healthcare. A health system’s security is only as strong as its vendors’ account lifecycle management — here, credentials belonging to an employee Nuance had already terminated still worked against Geisinger’s systems two days later. HIPAA’s business associate framework anticipates exactly this arrangement: Nuance, as a business associate handling patient data on Geisinger’s behalf, carried its own compliance obligations, which is part of why it appears alongside Geisinger as a settling defendant.

The Court and Counsel Behind the Settlement

The case was litigated in the U.S. District Court for the Middle District of Pennsylvania — the federal district covering Geisinger’s Danville headquarters — with Chief Judge Matthew Brann presiding over both preliminary and final approval.

Shub Johns & Holbrook LLP served among class counsel and has been the primary public source for post-approval updates, including the guidance that distributions are expected later in 2026. The official settlement website, geisingerdatasettlement.com, remains the authoritative channel for administrator contact information and status updates during the payment phase.

Frequently Asked Questions

Who is covered by the Geisinger data settlement?

The class includes 1,308,363 Geisinger patients whose information was downloaded in the November 29, 2023 unauthorized access incident involving a former Nuance Communications employee.

How much can class members receive?

Members could elect one year of credit monitoring and identity theft protection, or claim reimbursement of documented out-of-pocket losses up to $5,000 per person.

Can I still file a claim?

No. The claim deadline was March 18, 2026, and has passed. Only members who filed timely claims will receive benefits.

When will payments go out?

Class counsel expects distributions later in 2026, after any appeals of the March 16, 2026 final approval order are resolved.

What data was exposed?

Names, dates of birth, addresses, phone numbers, medical record numbers, race, gender, admit/discharge codes, and facility name abbreviations. Social Security numbers were not among the reported data elements.

What happened to the person responsible?

Andre J. Burk (a.k.a. Max Vance) pleaded guilty on February 27 to one federal count of obtaining information from a protected computer without authorization.


You Might Also Like

Browse every open class action settlement at OpenClassActions. Enter free giveaways and sweepstakes at Giveaway Goose. Forgot the name of a movie? Identify it at FindThisMovie. Caring for someone with dementia? Find practical guides at HelpDementia. Watching prices and your paycheck? Follow the numbers at Inflation Money.