Upstream Rehabilitation Data Breach Class Action: A data breach at Upstream Rehabilitation in January 2023 revealed sensitive personal and medical information about tens of thousands of individuals from the United States. The unauthorized hacking by cybercriminals into this information revealed the loopholes in safeguarding data in the health industry. With intense public outcry and a class action lawsuit, upstream agreed to a $4.3 million class action settlement that attempts to indemnify the victims as well as protect against future violations.
If your data were compromised in this hack, you might have been eligible to receive many benefits, including compensation for losses in the way of cash, free credit monitoring, or identity theft restoration service. Understanding how these settlements work, who is qualified, and what to do is significant—especially during a period where cyber attacks are increasing.
This comprehensive guide explains the terms of the Upstream Rehabilitation Data Breach Class Action Settlement, outlines the compensation scheme, provides a step-by-step guide to claims, and offers tips on how to protect your personal data in the future.
Upstream Rehabilitation Data Breach Class Action
Feature | Details |
---|---|
Settlement Amount | $4.3 million |
Breach Period | January 24–31 and February 3–9, 2023 |
Eligible Parties | Individuals whose data was compromised during the breach |
Claim Deadline | January 30, 2025 (now passed) |
Reimbursement Amount | Up to $5,000 for documented losses |
Estimated Cash Payment | Minimum $50 (pro rata) for those without documented losses |
Credit Monitoring Offered | 3 years of free financial account monitoring |
Official Settlement Website | UpstreamDataSettlement.com |

The Upstream Rehabilitation Data Breach Class Action Settlement is a significant consumer data protection and corporate accountability innovation. With its $4.3 million fund, it rewarded actual harm due to data breaches—financial, emotional, or both.
Despite the deadline having been missed, the case provides salient lessons: control your own digital identity, be mindful of your rights as a class-action suit participant, and be continually proactive in cybersecurity defense.
Understand the Upstream Data Breach
Upstream Rehabilitation is one of the leading providers of outpatient physical therapy care in the U.S., owning a chain of clinics through brands such as BenchMark Physical Therapy, Drayer Physical Therapy Institute, and SERC Physical Therapy. Hackers broke into their systems between January 24 and February 9, 2023, and accessed unauthorized confidential information.
Data that was breached includes:
- Full names
- Social Security numbers
- Dates of birth
- Health insurance policy numbers
- Clinical and diagnostic information
- Billing and claims records
This kind of data can be used for identity theft, insurance scams, or phishing attacks, leaving victims exposed to long-term financial and reputational harm. Upstream took further cybersecurity precautions after internal probes and government alert, and entered into a settlement to conclude lawful claims.
Who Qualifies For The Upstream Rehabilitation Data Breach Class Action Settlement?
To be considered part of the settlement class, you must have received a breach notification letter from Upstream Rehabilitation or one of its affiliates. This letter would confirm that your personally identifiable information (PII) or protected health information (PHI) was exposed.
Significantly, even if you weren’t directly harmed—such as by identity theft or financial loss—you could still be entitled to compensation. The settlement was designed not only to give benefits to those with quantifiable damages, but also as a preventive measure to all who were impacted.
This expanded inclusion reflects the increasing realization that data exposure poses hidden threats, even where there is no direct financial consequence.
What Compensation Is Available?
The settlement fund was used to pay for three types of relief:
1. Reimbursement for Documented Losses (Up to $5,000)
If you suffered financial losses or out-of-pocket costs as a result of the breach, you may recover up to $5,000. Acceptable documentation includes:
- Bank or credit card statements of fraudulent transactions
- Invoices from professionals who have helped with identity recovery
- Receipts for services such as credit monitoring or security freezes
- Affidavits detailing efforts made to prevent damages
These payments are intended to assist in the restoration of your financial position after suffering fraud, inconvenience, or emotional distress as a result of the breach.
2. Pro Rata Cash Payments (Est. $50 or More)
You may receive a cash payment even if you didn’t suffer a direct loss. These payments were made on a pro rata basis, so the actual payout was based on the number of valid claims received.
This allowance acknowledges the disruption and stress of knowing your personal information is in the wrong hands. Experts estimated payments of at least $50, although some recipients may get more.

3. Three Years of Free Credit Monitoring
Every class member qualified for three years of free financial monitoring, including:
- Daily tracking of credit reports
- Identity restoration services
- Fraud alerts
- Access to money management tools
For most, this alone is worth hundreds of dollars and provides continued protection from long-term abuse of personal information.
How to Claim Your Upstream Rehabilitation Data Breach Class Action Payment Settlement
While the claim deadline (January 30, 2025) has now expired, knowing the process is useful for future reference or comparable cases.
Upstream Rehabilitation Data Breach Class Action Guide:
1. Go to the Official Settlement Website
Go to UpstreamDataSettlement.com to obtain claim forms and FAQs.
2. Select Your Reward
Determine if you want to claim reimbursement, a basic cash payment, or the credit monitoring product.
3. Get Paperwork Ready
In case you were seeking monetary losses, be ready with bank statements, receipts, or affidavits substantiating your claim.
5. Make Your Claim

Fill in the form and submit it online or by mail on or before the deadline specified. Alternatively, you can also upload documents electronically.
Watch for Progress
After you submit, check the status from time to time. The settlement administrator will usually send you confirmation emails or mail notifications of approval and payment schedules.
What If You Missed the Deadline?
As of April 1, 2025, the deadline for submitting new claims has passed. If you did not submit before the deadline, you are no longer eligible to claim compensation.
There are, however, a few things you can do:
- Check Claim Status: If you submitted a claim earlier, visit the settlement website to track progress.
- Contact the Administrator: If you believe your data was affected but you never received notification, reach out for clarification or verification.
- Use Preventive Tools: Even if you missed the claim, consider signing up independently for credit monitoring or freezing your credit reports to safeguard against future fraud.
Why This Settlement Matters
The Upstream violation is just one instance of an unsettling trend. In 2023 alone, according to the U.S. Department of Health and Human Services, data breaches of healthcare data hit over 88 million Americans, and the industry is being targeted repeatedly as a result of the substantial worth of medical records on the black market.
For healthcare professionals, the settlement serves as an alarm to boost cybersecurity measures, staff training, and encryption practices. For consumers, it’s a reminder to review credit reports regularly, employ good passwords, and be careful when receiving emails that ask for personal details.
FAQs:
What is the Upstream Rehabilitation data breach settlement about?
It compensates patients whose personal and medical information was exposed during a cyberattack in early 2023.
How much can I get from the settlement?
Qualified claimants could receive up to $5,000 for proven financial losses or an estimated $50+ in cash if they had no documented losses.
Can I still file a claim?
No. The final deadline to submit a claim was January 30, 2025.
What if I didn’t suffer financial loss?
You were still eligible to receive a cash payment or access to three years of professional credit monitoring.