Concord Orthopaedics Professional Association has agreed to a settlement to resolve consolidated class action litigation arising from a November 2024 cybersecurity incident that involved unauthorized access to the personal and protected health information (PHI) of 72,815 individuals.
Incident Overview
Concord Orthopaedics Professional Association, based in New Hampshire, identified unauthorized access to its computer network on November 21, 2024. The network contained personal data and PHI, including names, birth dates, appointment details, medical insurance information, Social Security numbers, and driver’s license numbers or state ID numbers. The organization began notifying affected individuals on March 25, 2025.
Litigation Background
The first lawsuit related to the incident was filed on April 1, 2025, by Kattie Montambeault in the Merrimack County Superior Court for the State of New Hampshire. Four additional class action complaints were filed following the initial case. These actions were consolidated as a Montambeault, et al. v. Concord Orthopaedics Professional Association lawsuit in the Superior Court of Hillsborough County, New Hampshire. The consolidated complaint includes 12 individuals acting as class representatives.
The claims in the litigation alleged that Concord Orthopaedics did not implement reasonable and appropriate cybersecurity measures to protect sensitive information stored on its systems. The complaint states that this failure resulted in unauthorized access to the sensitive data of the plaintiffs and other class members.
Settlement Terms
Concord Orthopaedics agreed to resolve the claims through a settlement that does not include any admission of wrongdoing, fault, or liability. The court had already given preliminary approval of the settlement, and class counsel along with the class representatives have indicated that the terms are fair.
The settlement provides several forms of relief to class members. All eligible individuals are entitled to one year of medical data monitoring services. Class members may also submit claims for reimbursement of documented, unreimbursed losses related to the data breach, with a maximum reimbursement of $3,000 per individual.
Compensation is also available for time spent resolving issues associated with the incident. Class members may claim reimbursement for up to four hours of lost time at a rate of $25 per hour, with a maximum payment of $100.
An alternative compensation option is available in the form of a one-time cash payment estimated at $50. The final amount may vary depending on the number of valid claims submitted. Individuals who submit claims for lost time are not eligible to receive the one-time cash payment.
Key Deadlines and Court Proceedings
The deadline for class members to object to the settlement or request exclusion is May 26, 2026. Claims must be submitted by July 8, 2026. A final fairness hearing is scheduled for June 23, 2026.
Data Exposure Scope
The potential HIPAA violation incident involved access to multiple categories of personal data and PHI maintained by the organization. The affected dataset included identifiers and healthcare-related information stored within the compromised network environment. The number of impacted individuals is reported as 72,815.
Image credit: LimeSky, AdobeStock / logo©ConcordOrthopaedics









