Elixir Medical Corporation Data Breach Lawsuit Investigation
Received a July 2026 breach notice from Elixir Medical?
Dapeer Law, P.A. is investigating a potential class action against Elixir Medical Corporation, a Milpitas, California medical device company, on behalf of current and former employees, consultants, beneficiaries, and dependents whose personal information may have been exposed in the July 2026 cyber incident.
Who may qualify
You may be eligible to participate in a class action if any of the following applies:
- You received a data breach notification letter from Elixir Medical dated July 2026.
- Your letter offered enrollment in complimentary Experian IdentityWorks Credit monitoring (Experian).
- You provided personal, financial, or medical information to Elixir Medical in connection with employment, consulting work, or benefits coverage, including as a beneficiary or dependent.
- No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
- Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.
Not sure if you qualify?
Send us your notice, we'll confirm your eligibility at no cost.
What happened
According to a notice filed with the California Attorney General, an unauthorized party gained access to Elixir Medical Corporation's computer network on July 20 and July 21, 2026. Elixir Medical says it responded to the activity, secured its environment, and retained third-party cybersecurity specialists to investigate what happened and what information was involved. Law enforcement was also notified.
The company reports that on August 11, 2026 it identified the files that were at risk in the incident. Those files were human-resources records, and the notice states they contained names and Social Security numbers, and, depending on what an individual had provided to Elixir Medical's HR function, may also have contained driver's license numbers, credit or debit card numbers, direct deposit bank account information, and medical information. Notification letters were mailed and the incident was reported to the California Attorney General on September 4, 2026, roughly six weeks after the at-risk files were identified.
Because the affected records were HR files, the exposure pattern here is unusual in one respect: a single file set may combine a Social Security number, a bank account used for direct deposit, a payment card, and medical information for the same person. That combination is what identity thieves need to open credit, redirect a paycheck, or file a fraudulent tax return, and medical information held by an employer can carry separate privacy obligations. Elixir Medical is offering complimentary Experian IdentityWorks Credit monitoring to notice recipients, and Dapeer Law is evaluating whether the company's data security practices and the timing of its notifications support claims on behalf of affected individuals.
What to do if you received a letter
Keep your notice letter
Do not discard it. Your letter contains the Experian enrollment code and the activation deadline, and it is important evidence if you decide to participate in a lawsuit.
Enroll in the free Experian IdentityWorks Credit monitoring
Enroll in the Experian IdentityWorks Credit monitoring offered in your letter before the activation deadline printed on it. Accepting this benefit does not waive your right to pursue legal action.
Place a fraud alert or credit freeze
Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide.
Because direct deposit bank account information may have been involved, also review your payroll deposits and bank statements, and consider asking your bank to flag the account for unusual activity.
Speak with a data breach attorney
Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options, and advise whether you may be eligible to join a class action.
Submit your notice for a free review
Two minutes online. A licensed attorney reviews every submission.
Breach timeline
Compensation you may be entitled to
Out-of-pocket expenses
Credit freezes, identity restoration services, and other costs incurred responding to the breach.
Time spent monitoring
Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.
Identity theft & fraud losses
Unreimbursed funds stolen from accounts, unauthorized credit lines,
If your paycheck was redirected, a payment card was used without authorization, or a fraudulent tax return was filed in your name, document the amounts and keep every statement and letter. Out-of-pocket losses and the time you spent resolving them are often the strongest part of an individual claim.
or tax refund fraud tied to the breach.Statutory damages
Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.
Injunctive relief
Court orders requiring the company to implement stronger data security practices for the human-resources information it holds on employees, consultants, beneficiaries, and dependents.
Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.
Common questions
I received a data breach letter from Elixir Medical. What should I do? +
Keep your notice letter, then enroll in the complimentary Experian IdentityWorks Credit monitoring using the code in the letter before the activation deadline. Because the files may have included Social Security numbers and direct deposit bank account information, also request your free credit reports, watch your payroll deposits and bank statements, and consider a fraud alert or a credit freeze with all three bureaus. If medical information was involved, review any explanation-of-benefits statements for services you did not receive. A free consultation with a data breach attorney will tell you whether you may have a claim.
Am I eligible to join a class action against Elixir Medical? +
If you received a notice letter from Elixir Medical about this incident, you are likely within the affected group. Eligibility for a class action typically turns on your state of residence, which categories of your information were involved, and whether you have documented losses or fraud you can trace to the breach. Dapeer Law reviews notice letters at no cost to assess these factors.
How much money could I receive from a class action lawsuit? +
Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.
What personal information was exposed in the breach? +
The notice states that the affected human-resources files contained names and Social Security numbers, and that they may also have contained driver's license numbers, credit or debit card numbers, direct deposit bank account information, and medical information, depending on what each person had provided to Elixir Medical. Your individual letter should identify which categories applied to you, so check it closely and keep it.
Did Elixir Medical offer free credit monitoring? +
Yes. Elixir Medical is offering complimentary access to Experian IdentityWorks Credit, which monitors for misuse of personal information and includes identity theft resolution support. The enrollment code, the membership length, and the activation deadline appear in the mailed letter. Enrolling does not waive your right to pursue a legal claim.
How many people were affected by the Elixir Medical breach? +
Elixir Medical has not publicly disclosed the total number of affected individuals in its California Attorney General filing. That figure often becomes available later through other state regulators or in litigation. This page will be updated as more is known.
Is there a deadline to take legal action? +
Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.
How do I get a copy of the official breach notice? +
The sample notice was filed with the California Attorney General and is available from the state's data breach notification portal at oag.ca.gov. The Sources section below links directly to the filed PDF. If you cannot locate your own letter, Dapeer Law can help you obtain a copy of the notice during a free consultation.
Sources & references
- Official breach notice filing · California Attorney General, Elixir Medical Corporation breach notification (PDF)
- Company · Elixir Medical Corporation (elixirmedical.com)
- Credit bureau freezes · Equifax · Experian · TransUnion
- Free weekly credit reports · AnnualCreditReport.com
- Identity theft recovery guide · FTC IdentityTheft.gov
Don't let the deadline decide for you. Submit your claim today.
You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.