A class action lawsuit was filed against ConnectOnCall.com, LLC and Phreesia, Inc. after a cybersecurity incident exposed private messages between patients and their healthcare providers. ConnectOnCall was an after-hours on-call answering service — the system that handled your call when you phoned your doctor's office outside normal hours.
The lawsuit says an unknown attacker had access to the ConnectOnCall platform between February 16, 2024 and May 12, 2024, and copied data out of it, including certain provider-patient communications. The companies began notifying people who may have been affected on December 11, 2024.
Several near-identical lawsuits were filed. The court combined them on February 22, 2025 into one case, In re ConnectOnCall.com Data Breach Litigation, Case No. 2:24-cv-08790, in the United States District Court for the Eastern District of New York, before Judge Sanket J. Bulsara. On June 26, 2025 the court appointed five firms to run the case for the class: Kopelowitz Ostrow, Milberg, Morgan & Morgan, Lynch Carpenter, and Sultzer & Lipari.
The legal claims include negligence, negligence per se, breach of a third-party beneficiary contract, invasion of privacy, unjust enrichment, and a request for a declaratory judgment. The defendants deny doing anything wrong, and no court has decided that any law was broken. Both sides agreed to settle rather than keep litigating.
The companies agreed to pay $4,950,000 into a settlement fund. The fund is non-reversionary, which means none of it goes back to the companies — whatever the court approves is spent on class member benefits, administration, attorneys' fees, and awards to the people who brought the case.
The settlement class is every living person living in the United States whose private information may have been caught up in the incident. There is nothing to buy and nothing to return; what matters is whether your information was on the platform.
Everyone with a valid claim can get two years of dark web and medical data monitoring through CyEx Medical Shield Complete, which watches for your information turning up where it should not, sends real-time alerts, and carries up to $1,000,000 of insurance against medical identity theft. The settlement values that service at about $360 per person. Alongside it, you choose one of two cash options, described below.
The companies also agreed to give the class's lawyers a written statement, before the settlement is finalized, describing the security measures they put in place after the incident and what those measures cost. That spending is the companies' own and does not come out of the fund.
Claims must be filed by October 31, 2026. The court will decide whether to approve the settlement at a hearing on November 17, 2026.
There are two cash options, and you pick one. Cash Payment A covers documented losses: real, out-of-pocket, unreimbursed costs you can show came from identity theft, identity fraud, a falsified tax return, or other misuse of your information tied to this incident. It pays up to $5,000, and it requires supporting paperwork you did not write yourself — receipts, account statements, notices, a police report. Cash Payment B is the alternate cash payment, a flat share of the fund up to $75, and it asks for no documentation at all.
If more valid claims come in than the fund can cover, the cash payments shrink proportionally. The settlement pays out in a set order when that happens: the monitoring service first, then Cash Payment A, then Cash Payment B. A Cash Payment A claim that is rejected, or that arrives without workable documentation, is converted to Cash Payment B rather than thrown out.
Nothing is paid until the settlement is final. The court holds its approval hearing on November 17, 2026, and the settlement becomes effective five days after the court's final order if nobody objects — longer if there are objections or an appeal. The settlement administrator then has 45 days to send out benefits.
Anything left in the fund after claims, costs, fees, and awards goes to two privacy non-profits the parties have proposed: the International Association of Privacy Professionals and the Future of Privacy Forum. It does not return to the companies.
You are in the settlement class if you are a living person living in the United States and your private information may have been affected by the ConnectOnCall data incident. There is no purchase to prove and no minimum loss.
The one thing every claim has to swear to is easy to miss: you must declare, under penalty of perjury, that you communicated after-hours with a healthcare provider or their office between May 12, 2014 and May 12, 2024. That ten-year window is far wider than the four months the attacker was inside the system, so most people who used an after-hours line in that decade can make the declaration honestly.
A small group is excluded: directors, officers, and employees of the companies, and the judges on the case, their immediate families, and court staff. Anyone who asks to be excluded from the settlement gives up all benefits.
An unknown attacker copied data from the ConnectOnCall platform, including certain provider-patient communications — the messages taken when you called your doctor's office after hours. The lawsuit does not claim anyone's data has been misused.
The attacker had access between February 16 and May 12, 2024, but the sworn declaration covers after-hours contact with a provider between May 12, 2014 and May 12, 2024. The wider window reflects how long communications sat on the platform.
No. The claim form has a box for it and it helps the administrator match your record faster, but the settlement class is defined by whether your information may have been affected, not by whether you can find the letter.
No. Cash Payment A and Cash Payment B are alternatives — you elect one. Everyone with a valid claim can take the dark web and medical data monitoring in addition to whichever cash option they choose.
Paperwork you did not prepare yourself: receipts, notices, account statements showing unauthorized charges, bank fees, credit freeze payments, a police report, or an IRS letter about a falsified return. A self-written list of losses is not enough.
It converts to Cash Payment B rather than being thrown out. If you cannot supply workable documentation and do not fix the claim, you still receive the alternate cash payment of up to $75.
Yes. If valid claims exhaust the fund, cash payments are reduced proportionally. The administrator funds the monitoring service first, then Cash Payment A, then Cash Payment B — so the alternate cash payment absorbs any shortfall.
Class counsel will ask the court for attorneys' fees of no more than $1,650,000 plus costs — a third of the fund. They will also ask for $2,500 for each of the five people who brought the case. The court can award less.
Leftover funds go to two privacy non-profits the parties proposed: the International Association of Privacy Professionals and the Future of Privacy Forum. The fund is non-reversionary, so nothing goes back to the companies.
Ninety days from the day it is issued. After that the check is void and the money becomes residual funds — you forfeit it. Watch your mail in the weeks after the settlement becomes final.
Last updated