Serviceaide Agrees to $1.8 Million Settlement in Litigation Related to Catholic Health Data Breach
Serviceaide, Inc. has agreed to establish a $1.8 million settlement fund to resolve consolidated litigation related to a 2024 data breach that affected approximately 483,000 patients of its client, Catholic Health, while denying the allegations and denying any wrongdoing.
Settlement Agreement
The settlement resolves consolidated class action litigation arising from a cybersecurity incident involving Serviceaide. The company provides AI-powered solutions intended to support productivity and service delivery. Catholic Health hired Serviceaide for services that allowed patient data access.
Under the settlement, Serviceaide will establish a settlement fund totaling $1,800,000. The settlement provides for deductions from the fund for attorneys’ fees and expenditures, settlement management and notification expenses, and service awards for the 15 class representatives. The remaining funds will be available for valid claims submitted by eligible class members.
Serviceaide denies the allegations asserted in the litigation and denies liability. The company also disputes the claims and contentions presented in the lawsuit. Court filings included a motion to dismiss by Serviceaide and an opposition filed by the plaintiffs. The parties later negotiated a settlement that has been finalized.
Data Breach Details
Serviceaide identified unauthorized access to its systems on or around November 15, 2024. A forensic investigation determined that an unauthorized third party had access to the company’s network from September 19, 2024, through November 5, 2024.
Serviceaide determined that a database containing records associated with approximately 483,000 Catholic Health patients was potentially accessed or obtained during the incident.
The HIPAA-covered information contained in the affected database included names, birth dates, Social Security numbers, medical or health information, treatment details, medical insurance information, and email usernames together with accompanying passwords.
Affected individuals received notification of the incident on May 9, 2025.
Litigation
Serviceaode faced eleven class action lawsuits in connection with the data breach. The cases were consolidated as Nancy Balzer, et al., v. Serviceaide, Inc. in the Supreme Court of the State of New York, County of Nassau.
The consolidated complaint alleges that the data breach could have been prevented and attributes the incident to negligence by the defendant. The lawsuit includes claims for negligence, unjust enrichment, breach of implied contract, invasion of privacy, violations of California’s Unfair Competition Law, California Business and Professions Code Sections 17200 and following, and declaratory judgment.
Serviceaide disputes those allegations and denies that it engaged in wrongdoing.
Settlement Benefits
Eligible class members have two claim options under the settlement.
One option permits reimbursement for documented, unreimbursed losses associated with fraud or identity theft resulting from the incident, together with other qualifying losses, up to a maximum of $5,000 for each class member.
The second option allows eligible class members to submit a claim for a cash payment estimated to be approximately $50. Those payments will be distributed on a pro rata basis after payment of approved claims for documented losses.
Settlement Deadlines
The deadline for submitting a claim is September 1, 2026. The deadline to object to the settlement or request exclusion from the settlement is August 17, 2026. The final fairness hearing is scheduled for September 16, 2026.