Elixir Medical Corporation Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Elixir Medical
Active investigation Data breach · Healthcare Notices mailed Sep 4, 2026

Received a July 2026 breach notice from Elixir Medical?

Dapeer Law, P.A. is investigating a potential class action against Elixir Medical Corporation, a Milpitas, California medical device company, on behalf of current and former employees, consultants, beneficiaries, and dependents whose personal information may have been exposed in the July 2026 cyber incident.

Submit your claim See what to do No fee unless we recover for you
Breach window
July 20 to 21, 2026
Unauthorized network access
Notification delay
About 6 weeks
Files identified Aug 2026, notices Sep 2026
Credit monitoring
Offered
Experian IdentityWorks Credit (Experian)
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Elixir Medical dated July 2026.
  • Your letter offered enrollment in complimentary Experian IdentityWorks Credit monitoring (Experian).
  • You provided personal, financial, or medical information to Elixir Medical in connection with employment, consulting work, or benefits coverage, including as a beneficiary or dependent.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

According to a notice filed with the California Attorney General, an unauthorized party gained access to Elixir Medical Corporation's computer network on July 20 and July 21, 2026. Elixir Medical says it responded to the activity, secured its environment, and retained third-party cybersecurity specialists to investigate what happened and what information was involved. Law enforcement was also notified.

The company reports that on August 11, 2026 it identified the files that were at risk in the incident. Those files were human-resources records, and the notice states they contained names and Social Security numbers, and, depending on what an individual had provided to Elixir Medical's HR function, may also have contained driver's license numbers, credit or debit card numbers, direct deposit bank account information, and medical information. Notification letters were mailed and the incident was reported to the California Attorney General on September 4, 2026, roughly six weeks after the at-risk files were identified.

Because the affected records were HR files, the exposure pattern here is unusual in one respect: a single file set may combine a Social Security number, a bank account used for direct deposit, a payment card, and medical information for the same person. That combination is what identity thieves need to open credit, redirect a paycheck, or file a fraudulent tax return, and medical information held by an employer can carry separate privacy obligations. Elixir Medical is offering complimentary Experian IdentityWorks Credit monitoring to notice recipients, and Dapeer Law is evaluating whether the company's data security practices and the timing of its notifications support claims on behalf of affected individuals.

HR file exposure Social Security numbers Direct deposit information California Attorney General Medical device industry
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter contains the Experian enrollment code and the activation deadline, and it is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free Experian IdentityWorks Credit monitoring

Enroll in the Experian IdentityWorks Credit monitoring offered in your letter before the activation deadline printed on it. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide.

Because direct deposit bank account information may have been involved, also review your payroll deposits and bank statements, and consider asking your bank to flag the account for unusual activity.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

July 20 to 21, 2026 Passed
Unauthorized access to Elixir Medical's computer network
July 2026 Passed
Activity contained, cybersecurity specialists retained, law enforcement notified
August 11, 2026 Passed
HR files containing personal information identified as at risk
September 4, 2026 Passed
Notice reported to the California Attorney General, letters mailed
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines,

If your paycheck was redirected, a payment card was used without authorization, or a fraudulent tax return was filed in your name, document the amounts and keep every statement and letter. Out-of-pocket losses and the time you spent resolving them are often the strongest part of an individual claim.

or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring the company to implement stronger data security practices for the human-resources information it holds on employees, consultants, beneficiaries, and dependents.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Elixir Medical. What should I do? +

Keep your notice letter, then enroll in the complimentary Experian IdentityWorks Credit monitoring using the code in the letter before the activation deadline. Because the files may have included Social Security numbers and direct deposit bank account information, also request your free credit reports, watch your payroll deposits and bank statements, and consider a fraud alert or a credit freeze with all three bureaus. If medical information was involved, review any explanation-of-benefits statements for services you did not receive. A free consultation with a data breach attorney will tell you whether you may have a claim.

Am I eligible to join a class action against Elixir Medical? +

If you received a notice letter from Elixir Medical about this incident, you are likely within the affected group. Eligibility for a class action typically turns on your state of residence, which categories of your information were involved, and whether you have documented losses or fraud you can trace to the breach. Dapeer Law reviews notice letters at no cost to assess these factors.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The notice states that the affected human-resources files contained names and Social Security numbers, and that they may also have contained driver's license numbers, credit or debit card numbers, direct deposit bank account information, and medical information, depending on what each person had provided to Elixir Medical. Your individual letter should identify which categories applied to you, so check it closely and keep it.

Did Elixir Medical offer free credit monitoring? +

Yes. Elixir Medical is offering complimentary access to Experian IdentityWorks Credit, which monitors for misuse of personal information and includes identity theft resolution support. The enrollment code, the membership length, and the activation deadline appear in the mailed letter. Enrolling does not waive your right to pursue a legal claim.

How many people were affected by the Elixir Medical breach? +

Elixir Medical has not publicly disclosed the total number of affected individuals in its California Attorney General filing. That figure often becomes available later through other state regulators or in litigation. This page will be updated as more is known.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

The sample notice was filed with the California Attorney General and is available from the state's data breach notification portal at oag.ca.gov. The Sources section below links directly to the filed PDF. If you cannot locate your own letter, Dapeer Law can help you obtain a copy of the notice during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Elixir Medical Corporation, Experian, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with California Attorney General on September 4, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Bimbo Bakeries USA Data Breach Lawsuit Investigation

Next
Next

Stokke LLC Data Breach Lawsuit Investigation