Modoc Medical Center Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Modoc Medical Center
Active investigation Data breach · Healthcare Notices mailed Sep 22, 2026

Received a January 2026 breach notice from Modoc Medical Center?

Dapeer Law, P.A. is investigating a potential class action against Modoc Medical Center, a critical access hospital in Alturas, California, on behalf of patients whose personal information may have been exposed in the January 2026 cyber incident.

Submit your claim → See what to do No fee unless we recover for you
Breach window
January 19 to 27, 2026
Unauthorized access and file downloads
Notification delay
About 8 months
Discovered January 2026, notices September 2026
Credit monitoring
12 or 24 months
Through Experian IdentityWorks
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Modoc Medical Center dated January 2026.
  • Your letter offered enrollment in free Experian IdentityWorks credit monitoring and identity restoration services.
  • You had personal information held by Modoc Medical Center in its capacity as a hospital and healthcare provider, for example as a current or former patient.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility →
Background

What happened

According to a notice filed with the California Attorney General, Modoc Medical Center discovered suspicious activity on January 27, 2026 involving a limited number of its systems. The hospital reports that it took steps to secure its network and engaged independent cybersecurity specialists to investigate. That investigation determined that an unknown actor accessed certain Modoc systems and downloaded certain files between January 19 and January 27, 2026.

Modoc Medical Center reports that it then conducted a detailed review of the downloaded files to identify the information involved and the individuals to whom it related. Notice of the incident was reported to the California Attorney General on or about September 22, 2026, and letters are being sent to affected individuals. The hospital states that it reported the event to federal law enforcement and appropriate government regulators, and it is offering complimentary credit monitoring and identity restoration services through Experian IdentityWorks. The gap between the January 2026 discovery and the September 2026 notices, roughly eight months, is one of the questions our investigation is examining.

The public notice confirms that names were involved and indicates that additional data elements vary by individual and are listed in each person's letter. Because the files were held by a hospital, the information involved may include patient or medical details, which can carry heightened sensitivity and may be subject to protections under state law and federal health privacy rules. Affected individuals should review their letter closely to confirm which categories of their information were included.

Healthcare Data Breach Unauthorized File Download Patient Information California Attorney General Experian IdentityWorks
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter contains the activation code for Experian IdentityWorks and is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free Experian credit monitoring

Enroll in the Experian IdentityWorks credit monitoring and identity restoration services offered in your letter, using the activation code printed there, before the stated deadline. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide.Because the incident involved a hospital, also review the Explanation of Benefits statements from your health insurer and any medical bills for services you did not receive.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim →
Timeline

Breach timeline

January 19 to 27, 2026 Passed
Unknown actor accesses Modoc Medical Center systems and downloads files
January 27, 2026 Passed
Suspicious activity discovered and systems secured
January to September 2026 Passed
Forensic investigation and detailed review of the downloaded files
September 22, 2026 Passed
Notice reported to the California Attorney General, letters sent to affected individuals
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Modoc Medical Center to implement stronger data security practices going forward.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Modoc Medical Center. What should I do? +

Keep your notice letter, enroll in the complimentary Experian IdentityWorks credit monitoring using the activation code in the letter, and review your bank, credit card, and medical statements, as well as health insurance Explanation of Benefits statements, for unfamiliar activity. Consider obtaining your free credit reports and placing a fraud alert or security freeze with the three major credit bureaus, and contact a data breach attorney to understand your options.

Am I eligible to join a class action against Modoc Medical Center? +

If you received a notice letter from Modoc Medical Center about this incident, you may be eligible. Factors that affect eligibility include confirmation that your information was in the downloaded files, your state of residence, the categories of your data involved, and whether you experienced any economic or emotional harm. A free case review can clarify your options.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The public notice confirms that names were involved and states that other data elements vary by individual. Because the files were held by a hospital, they may have included patient or medical information, but the public filing does not itemize specific categories. Your individual letter lists the specific categories of your information, so review it closely and keep it.

Did Modoc Medical Center offer free credit monitoring? +

Yes. Modoc Medical Center is offering complimentary credit monitoring and identity restoration services through Experian IdentityWorks, for a term of either 12 or 24 months as stated in each letter, along with an activation code and enrollment deadline. Accepting this service does not waive your right to pursue legal action.

How many people were affected by the Modoc Medical Center breach? +

Modoc Medical Center has not publicly disclosed the total number of individuals affected in its California Attorney General filing. We will update this page as more becomes known.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

The notice was filed with the California Attorney General and can be downloaded from that office's data breach notification portal. Dapeer Law can also help you obtain a copy of the notice during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Modoc Medical Center, Experian, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with California Attorney General on September 22, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Seyfarth Shaw Data Breach Lawsuit Investigation

Next
Next

5Star Life Insurance Company Data Breach Lawsuit Investigation