OneTouchPoint data breach settlement offers up to $5,600 per claimant


A class action settlement over a 2022 data breach at OneTouchPoint, a printing and mailing services vendor, offers affected individuals up to $5,600 in compensation, according to an announcement published September 7, 2026. The settlement resolves a lawsuit alleging the company failed to adequately protect private information exposed in an April 2022 ransomware attack.

OneTouchPoint discovered the breach on April 28, 2022, when encrypted files were found on its computer systems. A forensic investigation determined that unauthorized actors had accessed servers beginning April 27, 2022. The breach ultimately affected more than 2.6 million individuals whose information was stored by the company for healthcare providers, health insurance companies, and other clients.

The settlement creates two classes of eligible claimants. Monetary class members—individuals whose information the investigation confirmed was compromised—can pursue several compensation options. These include up to $500 for documented out-of-pocket expenses such as bank fees, credit report costs, or identity theft insurance premiums; up to $5,000 for extraordinary monetary losses directly caused by the breach, such as professional fees for credit repair; and up to $100 for time spent responding to the breach at $25 per hour. Claimants who do not submit a losses or time claim can receive a flat $75 alternative payment. All class members also have the option to receive two years of single-bureau credit monitoring with at least $1 million in fraud protection.

A computer screen displaying a data security warning or breach notification alert, with a lock icon and red warning indicators visible, representing cybersecurity breach aftermath.

Injunctive relief class members—individuals who received a breach notice but whose information was not confirmed compromised—are not eligible to submit monetary claims but will benefit from OneTouchPoint’s cybersecurity enhancements for at least five years as part of the settlement.

The settlement fund will cover administration costs, up to $1.5 million in attorneys’ fees and litigation costs, $1,000 service awards to class representatives, credit monitoring expenses, and payments to approved claimants. The company also agreed to invest approximately $2 million in security improvements.

A calendar or deadline reminder graphic showing November dates, symbolizing the approaching claim deadline for settlement participants.

OneTouchPoint denies any wrongdoing but agreed to the settlement to avoid the cost and uncertainty of continued litigation. The company initially reported the breach as affecting 1.1 million individuals, but the number grew to over 2.6 million as more affected organizations submitted breach reports to regulators.

Class members must submit claims by November 16, 2026. The court will hold a final approval hearing on November 18, 2026. The settlement administrator will issue payments to approved claimants after claim processing is complete or within 60 days of final approval, whichever is later. Claimants can receive payments via Zelle, PayPal, Venmo, a virtual prepaid card, or paper check.

Sources

  • Claim Depot — Settlement details, compensation tiers, claim deadlines, and settlement fund breakdown
  • HIPAA Journal — Breach victim count of 2.65 million individuals and initial discovery date
  • Class Action — April 2022 breach date and affected entity details
  • SecurityWeek — OneTouchPoint business description as printing and mailing services vendor

Give your feedback

Be the first to rate this post
or leave a detailed review



ECIKS.org is an independent media. Support us by adding us to your Google News favorites:

Post a comment

Publish a comment