MCNA Settles Class Action After Breach Exposed Data of 8.9 Million Patients
Dental benefits administrator agrees to provide monitoring and reimbursement following a 2023 cyberattack.
Managed Care of North America (MCNA) has agreed to a class action settlement following a 2023 cyberattack that compromised the sensitive data of millions. The agreement resolves claims that the third-party dental benefits administrator failed to maintain reasonable cybersecurity measures to protect consumer information.
The breach occurred between February 26 and March 7, 2023, affecting approximately 8.9 million patients and families. According to court documents from the federal class action Crowe v. Managed Care of North America (No. 0:23-cv-61065-AHS), the exposed data included names, addresses, birth dates, and Social Security numbers. Additionally, the leak compromised driver's license numbers, health insurance information, Medicaid and Medicare IDs, and specific dental and orthodontic care records.
Settlement Terms and Deadlines
Under the terms of the settlement, eligible class members can receive two years of free medical data monitoring services. For those who suffered direct financial harm, the settlement provides reimbursement for documented out-of-pocket losses related to identity theft or fraud, with a maximum payout of $2,500 per person. However, the total cash fund available for these documented losses is capped at $250,000.
Affected individuals must submit a valid claim form by October 19, 2026, which also serves as the deadline for exclusions or objections. The court is scheduled to hold a final approval hearing for the settlement on November 16, 2026.
Industry Implications
This case underscores the critical vulnerability of third-party healthcare administrators who manage massive repositories of personally identifiable information (PII) and protected health information (PHI). MCNA operates as a manager for oral health coverage contracts for Medicare beneficiaries, state Medicaid agencies, and children's health insurance programs.
Because the breach targeted populations that are often more vulnerable—specifically low-income individuals and the elderly—the risk of long-term medical fraud and identity theft is significantly elevated. The inclusion of both Social Security numbers and government health IDs provides bad actors with a comprehensive toolkit for fraudulent activity, highlighting a systemic risk in how outsourced healthcare administration handles sensitive data.
What to Watch
As the case moves toward its final approval hearing in late 2026, the primary focus remains on the adequacy of the $250,000 reimbursement cap relative to the 8.9 million people affected. While the medical monitoring provides a preventative layer, the limited cash fund suggests that only a small fraction of those with actual financial losses will be fully reimbursed. Observers will be watching to see if the court finds this distribution equitable given the scale of the exposure.