June 29, 2026: A federal judge granted final approval to a $5.3 million class-action settlement resolving claims against long-term care pharmacy giant PharMerica over a March 2023 cyberattack that exposed personal data on roughly 5.8 million patients, according to McKnight's Senior Living and court records in Lurry v. PharMerica Corporation.
What happened in the 2023 breach
PharMerica—one of the largest U.S. pharmacy service providers, operating more than 180 long-term care pharmacies nationwide—disclosed unauthorized access in March 2023. The Money Message ransomware group claimed responsibility, posting screenshots of customer tables and leaking stolen files that included highly sensitive health and identity data.
Per TechCrunch and subsequent litigation filings, compromised information included:
- Names, addresses, and birth dates
- Social Security numbers
- Medicare and Medicaid numbers
- Medication and clinical information
- Health insurance details
Money Message claimed to have exfiltrated terabytes of data and published portions on its leak site. Multiple individual lawsuits followed; courts consolidated them into a single nationwide class action in the U.S. District Court for the Western District of Kentucky, Louisville Division.
From litigation to settlement
Plaintiffs alleged PharMerica failed to safeguard patient data. PharMerica denied liability but engaged in formal mediation in August 2025, producing the proposed settlement agreement.
Key procedural milestones:
- January 12, 2026: Judge Rebecca Grady Jennings granted preliminary approval of the $5.275 million fund (McKnight's, HIPAA Journal).
- February 10, 2026: Settlement notices began mailing to affected individuals per court schedule.
- April 27, 2026: Deadline for class members to submit claims.
- May 12, 2026: Final fairness hearing held.
- June 29, 2026: Court entered final approval (CourtListener docket).
What the settlement pays for
McKnight's reported the approved deal creates two benefit structures:
Settlement fund (~$5.3 million)
The primary fund covers:
- Attorney fees: roughly $3.5 million owed to plaintiffs' counsel, with PharMerica contributing beyond the fund amount
- Litigation costs: about $88,000
- Class representative awards: $43,500 to each of six named plaintiffs
- Administration and data-mining costs to identify class membership
Class member benefits
Eligible individuals may receive:
- Documented out-of-pocket losses reimbursed up to $10,000 per class member (identity theft, fraud, or breach-related expenses with documentation)
- One year of Kroll Complete Monitoring on a claims-made basis—credit monitoring, dark web monitoring, payday loan monitoring, fraud consultation, identity theft restoration, $1 million identity theft insurance, and credit score reporting per settlement terms cited by trade press
- A pro rata cash payment whose amount depends on total valid claims submitted
Beyond monetary relief, PharMerica agreed to change business practices related to information security to better protect personal data stored on its systems—a standard injunctive component in large healthcare breach settlements.
Who is in the class
The consolidated complaint covers individuals whose personal information was compromised in the March 2023 incident and who received direct notice from PharMerica. If you received a settlement notice or were notified by PharMerica about the breach, review the official notice and administrator instructions—not third-party "claim helper" sites that may charge fees.
The formal settlement notice is published at classaction.org. Claim deadlines and payout timing follow the court-approved schedule administered by the settlement claims processor.
Why this matters for senior living and healthcare
PharMerica serves assisted living, skilled nursing, hospice, home infusion, behavioral health, and oncology pharmacy markets—making this one of the highest-profile long-term care pharmacy breaches of the ransomware era. The 5.8 million patient count ranks among the largest healthcare data incidents tied to a single pharmacy services vendor.
The settlement illustrates how multi-year breach litigation often resolves: preliminary approval, notice period, claims window, fairness hearing, then final approval—while separate regulatory scrutiny (HIPAA, state AG notifications) may continue on parallel tracks.
Action items if you were affected
- Locate your settlement notice if you received PharMerica breach notification in 2023–2024; verify instructions on the official administrator site linked in court documents.
- Submit documented losses if you incurred fraud, credit freezes, or professional identity-restoration costs tied to the breach—keep receipts and bank statements.
- Enroll in offered monitoring through the settlement channel rather than paying for duplicate commercial services.
- Freeze or monitor credit if SSN exposure creates ongoing fraud risk—especially for patients whose Medicare/Medicaid identifiers were involved.
- Be alert to phishing citing real medication or facility names; criminals repurpose breach data in targeted healthcare scams.
Canonical BreachHistory record
BreachHistory tracks the underlying 2023 Money Message ransomware incident separately from this 2026 settlement milestone: PharMerica 2023 breach — 5.8M patients.
Sources: McKnight's Senior Living, HIPAA Journal, TechCrunch, CourtListener, settlement notice (PDF).