If your personal information was exposed in the ZOLL Medical data breach that occurred between January 22-24, 2023, you may be eligible for compensation up to $5,000 through a $3.5 million settlement fund. The class action lawsuit, Smith et al v ZOLL Medical Corporation (Case No. 1:23-cv-10575 in the United States District Court, District of Massachusetts), resolved charges that the medical device company failed to protect the sensitive data of over one million patients and customers. The settlement created two distinct compensation tracks depending on whether your Social Security number was compromised in the incident.
The breach affected 1,004,443 class members whose personal information—including names, addresses, phone numbers, and in some cases Social Security numbers—was potentially accessed during a three-day window in late January 2023. ZOLL Medical manufactures cardiac and emergency response devices used by hospitals, emergency responders, and patients worldwide, making this breach particularly significant given the sensitivity of health-related personal data. Eligibility for compensation depends primarily on which of the two settlement subclasses you fall into and what type of losses you can document. Understanding the specific criteria and claim requirements is essential if you want to recover any compensation from this settlement fund.
Table of Contents
- Who Is Eligible for the ZOLL Medical Data Breach Settlement?
- Understanding the Two Settlement Subclasses
- How Much Compensation Can You Receive?
- What Counts as Out-of-Pocket Losses?
- The Claims Process and Important Deadlines
- What Led to This Settlement?
- Your Rights and Next Steps
Who Is Eligible for the ZOLL Medical Data Breach Settlement?
Any individual whose personal information was compromised in the ZOLL data breach is considered a member of the settlement class. The settlement encompasses all 1,004,443 individuals whose data was potentially accessed between January 22-24, 2023, though not everyone faces the same compensation structure. To be a class member, you must have had personal information in ZOLL Medical’s systems at the time of the breach—this could include current customers, former patients, emergency responders who used ZOLL devices, or individuals who had contact with the company in any professional capacity.
The settlement divided class members into two subclasses based on one critical factor: whether your Social security number was exposed. The SSN Subclass includes individuals whose Social Security numbers were compromised, while the Non-SSN Subclass covers those whose other personal information was accessed but whose Social Security numbers remained secure. This distinction matters significantly because it affects both the compensation amounts available and the procedural requirements for filing a claim. For example, if you received notification from ZOLL indicating that your SSN was exposed, you would be placed in the SSN Subclass regardless of whether you suffered actual financial harm from the breach.
Understanding the Two Settlement Subclasses
The two-tier structure of this settlement recognizes that compromised Social Security numbers present a substantially greater risk of identity theft and fraud than other personal information alone. Class members in the SSN Subclass have access to different compensation mechanisms and potentially higher recovery opportunities compared to those in the Non-SSN Subclass. This classification was determined by ZOLL Medical’s own records and the notification letters sent to affected individuals shortly after the breach was discovered. Members of the SSN Subclass can claim compensation both for documented out-of-pocket losses they suffered and through an alternative claims process if they lack receipts or documentation.
The Non-SSN Subclass members, by contrast, may recover out-of-pocket losses only—they do not have access to the same flexible claims procedures available to those whose Social Security numbers were exposed. This important limitation means that Non-SSN Subclass members must provide concrete proof of any financial harm they experienced, such as credit monitoring charges or identity theft recovery expenses. One significant warning: the settlement cannot compensate for speculative or potential future identity theft. Even if you received a breach notification, you cannot claim compensation simply because you fear that your information might be misused. You must either show documented losses or, if you are in the SSN Subclass, use the alternative claims process available to that group.
How Much Compensation Can You Receive?
The settlement established a $3.5 million fund to compensate affected class members for documented financial losses related to the data breach. Individual compensation is capped at $5,000 per person for out-of-pocket losses, meaning that even if you can prove greater expenses, your recovery through this settlement will not exceed that amount. The total available pool is divided among all claimants who submit valid claims, so the actual payment per person may be reduced if claims exceed the fund’s capacity. The mechanics of fund distribution depend on the total number of valid claims received.
If fewer people claim compensation than anticipated, each claimant’s award may be higher. Conversely, if a large number of claims are filed, the available per-person amount could be lower than the $5,000 cap. For instance, if $3.5 million is divided among 700 claimants who each claimed $5,000 in losses, each person would receive the full $5,000. But if 1,500 claimants each claimed $5,000, the fund would be insufficient and payments would need to be pro-rated, meaning everyone would receive a smaller percentage of their claimed amount.
What Counts as Out-of-Pocket Losses?
Out-of-pocket losses eligible for compensation under this settlement include documented expenses you incurred as a direct result of the data breach. Credit monitoring services purchased after the breach, identity theft recovery services, costs associated with placing fraud alerts or credit freezes, and expenses related to resolving fraudulent charges or accounts opened in your name all qualify. Documentation is essential—you will need receipts, credit card statements, or other proof of payment to substantiate your claim. The settlement process recognizes that not all financial harms are easy to document. If you are in the SSN Subclass, you have the option of claiming a reasonable estimate of losses without requiring receipts for every single expense.
This alternative process acknowledges that some costs may be difficult to fully document, such as time spent dealing with identity theft or certain professional fees. However, Non-SSN Subclass members do not have this flexibility and must provide evidence of actual expenses. One important distinction: the settlement reimburses only out-of-pocket expenses that you actually paid from your own funds. It does not compensate for time spent resolving the breach, emotional distress, or other non-monetary harms, even though these burdens are genuine. If a credit card company or your insurance covered monitoring expenses, you generally cannot claim reimbursement for costs that someone else paid on your behalf.
The Claims Process and Important Deadlines
Filing a claim requires completing a claim form and submitting it along with appropriate documentation by the settlement’s deadline. The claims administrator will process each submission and determine whether it meets the settlement’s criteria. If your claim is approved, you will receive compensation from the settlement fund. If it is denied, you typically have a right to object or request a review, though the specific procedures depend on the exact terms of your settlement notice. Deadlines are critical in settlement claims—missing them can result in permanent loss of your right to compensation. You should have received a notice from the settlement administrator with specific deadline information, claim form instructions, and the address or website for submission.
If you did not receive a notice but believe you may be affected by the breach, contact the settlement administrator directly using information from official ZOLL Medical communications or the court case documentation. Do not rely on third-party websites for deadline information, as they may contain errors or outdated information. A significant caveat: the settlement claims process is not automatic. The burden is on you to file a claim and provide supporting documentation. If you simply wait for a check to arrive without submitting a claim form, you will not receive any compensation, even if you are clearly a class member. The settlement does not make payments to individuals who have not submitted valid claims by the deadline.
What Led to This Settlement?
ZOLL Medical’s data systems were compromised between January 22-24, 2023, exposing personal information stored in the company’s databases. The company serves the emergency medical response and cardiac care markets globally, handling sensitive health information as part of its normal business operations. Following discovery of the breach, ZOLL notified affected individuals and regulators of the incident and its scope.
The resulting class action lawsuit alleged that ZOLL Medical failed to implement adequate security measures to protect the personal data in its systems. Rather than proceed to trial, the company agreed to the $3.5 million settlement to resolve the claims against it. Notably, a related legal proceeding involving an IT company allegedly responsible for some aspect of the breach resulted in that company’s liability being cleared by the First Circuit Court, leaving ZOLL Medical to bear the financial responsibility for the settlement.
Your Rights and Next Steps
You have the right to receive fair compensation if you suffered documented financial losses from the ZOLL Medical data breach and you submit a timely, valid claim. The settlement process is designed to streamline compensation rather than require individual lawsuits. Filing a claim requires only that you complete the claim form accurately and provide appropriate documentation—you do not need to hire an attorney or navigate court proceedings yourself, though you may consult with legal counsel if you wish.
If you received a breach notification from ZOLL Medical or the settlement administrator, follow the instructions provided carefully. Gather documentation of any expenses you incurred related to the breach—credit monitoring charges, identity theft service costs, or expenses from resolving fraudulent activity. Submit your claim well before the deadline using the exact method specified in your notice. Keep copies of everything you submit and retain a record of your claim submission date and confirmation number for your records.
