This article provides an in-depth, SEO-optimized overview of the Henderson v. Reventics Settlement, covering what the case is about, the parties involved, the settlement terms, eligibility and claims process, timelines and key deadlines, implications for affected individuals and organizations, and practical tips. If you or someone you know may have been impacted, this guide will help you understand what the settlement means and what actions you may need to take.

1. What is the case?
The case formally titled Henderson, et al. v. Reventics, LLC, et al. was filed in the District Court for the State of Colorado, Case No. 1:23-cv-00586. Here’s what happened:
- On December 15, 2022, the defendant Reventics, LLC (together with OMH Healthedge Holdings, Inc. (d/b/a Omega Healthcare)) discovered a data security incident in which an unauthorized user accessed and encrypted portions of its network.
- The plaintiffs allege that Reventics failed to adequately safeguard sensitive protected health information (PHI) and personally identifiable information (PII) of over 250,000 individuals—including names, dates of birth, Social Security numbers, driver’s license numbers, medical record numbers, etc.
- According to the complaint, Reventics allegedly did not notify affected individuals until February 2023, despite discovering the intrusion earlier.
- The case raised claims under data-breach, negligence, and privacy theories—arguing that the defendants violated industry standards and applicable regulation (including potential HIPAA obligations) by failing to protect PHI/PII.
In short: this was a class-action style lawsuit alleging that a large healthcare-software provider failed to protect sensitive consumer data, and as a result individuals were exposed to risk of harm.
2. Key settlement terms
After litigation, the parties reached a settlement (pending court approval) known as the Henderson v. Reventics Settlement. Some of the key terms:
- The defendants agreed to create a Settlement Fund of US $8,150,000.
- Class members (i.e., individuals whose PHI/PII was potentially compromised) may be eligible to claim:
- Reimbursement for documented losses up to $5,000, or
- A flat cash payment of $100 (subject to pro rata adjustment based on number of valid claims).
- The Fund also covers administration costs, notice costs, attorneys’ fees, service awards, and court-approved expenses.
- The defendants explicitly deny any wrongdoing or violation of law, but chose to settle to avoid further litigation and risk.
These are the headline terms. Below, we’ll break down eligibility, timelines, and what this means for individuals.
3. Who is eligible — Settlement Class & criteria
To determine if you might qualify under the Henderson v. Reventics Settlement, here is how eligibility is defined:
Settlement Class Definition
You are a Class Member if:
- Your protected health information (PHI) and/or personally identifiable information (PII) was potentially involved in the December 2022 Data Security Incident at Reventics.
- You received a notice from Reventics (or the defendants) beginning in February 2023, informing you of the incident.
Types of information at issue
The complaint identifies that the compromised data included full names, addresses, dates of birth, Social Security numbers, patient medical record numbers, account numbers, driver’s license/government ID numbers, health plan names/IDs, clinical data including diagnoses, prescription medications, and billing codes.
Important nuance
- Simply having data accessed may not on its own guarantee eligibility for the maximum reimbursement — documentation may be required.
- There is a choice: either claim documented loss (with proof) up to $5,000 or accept the flat payment (typically $100 subject to adjustment) if you do not claim documented loss.
- If you do nothing, you will not receive a payment and you will give up any rights to further claims against the defendants for these particular claims under the settlement.
4. Timeline & Important Deadlines
Understanding the key dates is critical if you may be eligible:
| Event | Date |
|---|---|
| Deadline to submit a Claim Form | July 25, 2025 (extended from June 21, 2025) |
| Deadline to exclude yourself (opt-out) or to object to the settlement | Same: July 25, 2025. (Originally June 21, 2025) |
| Final Fairness Hearing (Court will decide whether to approve settlement) | August 14, 2025 at 8:30 a.m. MT in Arapahoe County, Colorado. |
Points to note:
- If you miss the claim submission deadline, you become ineligible for payment under the settlement.
- If you exclude yourself, you forgo payment under the settlement but retain the right to pursue your own lawsuit (if applicable) separate from this class action.
- Objecting means you remain a class member and eligible for benefits (if you submit a claim) but you’ve raised an objection to some aspect of the settlement for the court to consider.
- The settlement is pending approval; if the court rejects it, terms may change.
5. How to file a claim — What you need to do
If you’re eligible and want to participate, here are the steps and what to gather:
Steps to file a claim
- Visit the settlement website: www.reventicsdatasettlement.com (administrator: CPT Group, Inc.) for Claim Form and instructions.
- Provide your CPT ID and Passcode (if you received notice) to identify yourself as a potential Class Member.
- Decide whether you want to claim documented losses (and provide supporting proof) or take the flat payment option.
- Submit the Claim Form online or via mail by July 25, 2025.
- If you claim documented losses, attach required receipts, invoices, bank/credit statements, police reports or other documentation showing out-of-pocket losses related to the breach.
What documents to gather
- Receipts or invoices showing you spent money as a result of the breach (e.g., credit monitoring, identity theft remediation).
- Bank or credit card statements showing unauthorized charges or unreimbursed fraudulent activity (if you’re claiming it).
- Any letters of notification you received from Reventics, LLC regarding the incident (often includes your CPT ID/passcode).
- Your mailing address, email, phone number, and other identifying info as required.
Important caveats
- All claims are subject to verification. If you fail to submit required documentation, your claim may be denied or delayed.
- If you choose the flat payment option ($100), you are forgoing claims for documented losses.
- The $100 payment is subject to “pro rata adjustment,” meaning if many people claim, the amount may go down.
Read too : Dan McKeon Nebraska: How an Agricultural Heritage Shapes His Legislative Agenda
6. Legal implications & what this means for individuals and organizations
For individuals (Class Members)
- If you receive the notice, submitting the claim is your only way to receive a payment under this settlement.
- By staying in the class (not excluding yourself), you give up the right to file a separate lawsuit on the same claims against the defendants once the settlement is finalized.
- Even if you don’t feel you suffered actual identity theft or visible misuse of data, you may still choose to claim the flat payment option.
- But: Just because you were notified doesn’t guarantee significant monetary recovery — the flat payment is modest, and the documented loss route requires proof and may still be subject to limitations.
For organizations (data-controllers/healthcare entities/software providers)
- The case underscores the legal risks around data breaches involving PHI/PII, particularly in healthcare and software service industries.
- Even if a defendant settles without admitting liability, the publicity and costs (administration, legal, notice) can be significant.
- Entities should ensure they have robust cybersecurity, timely breach detection and notification, and clear incident response plans.
- If you are a vendor or a business partner in the healthcare space, this case illustrates the possibility of class litigation in the U.S. when networks and vendor systems are compromised.
Legal standing & precedent:
It’s worth noting that while the settlement has been reached, in parallel the defendants succeeded at a motion to dismiss stage: In September 2024, the U.S. District Court for the District of Colorado granted Reventics’ and Omega’s motion to dismiss on Article III standing grounds—finding plaintiffs had not alleged concrete injury traceable to the breach.
This decision shows that even when a breach occurs, establishing class action standing can be challenging—though settlement may be reached regardless.
7. Pros & cons of participating in the settlement
Pros
- A relatively easy claims process (especially with the flat payment option) for individuals whose data was involved.
- Avoids the cost, delay and uncertainty of joining a separate lawsuit.
- Provides some monetary compensation for those impacted (even if modest).
- Gives closure: once settlement is approved and claim paid, you typically cannot be sued further for the same matter.
Cons / Things to watch
- The flat payment ($100) is modest and may be diluted by pro rata adjustment depending on number of claims.
- The documented loss route may require substantial effort (gathering proof) and may still not guarantee full recovery.
- If you exclude yourself, you forgo payments under the settlement but retain the option to sue—but suing independently can be costly and uncertain.
- If you do nothing, you will not receive any payment and lose your ability to participate in the settlement benefits.
- Settlements like this generally do not guarantee that your data was misused or will be misused—but rather compensate for risk and remediation.
8. Frequently Asked Questions (FAQs)
Q: What if I received a notice from Reventics but lost the CPT ID or passcode?
A: Visit the settlement website (or contact the administrator, CPT Group) to see if there is a way to recover your CPT ID/passcode. Without it you may still file but the administrator will need to verify your membership eligibility.
Q: Can I claim both documented losses and the flat payment?
A: No. The settlement offers either the documented losses route (up to $5,000) OR the flat payment of $100 (subject to adjustment). You choose one path.
Q: What if I exclude myself from the settlement?
A: If you exclude yourself, you won’t receive any payment under this settlement, but you retain the right to pursue a separate lawsuit against Reventics (and/or the other defendants) for the same breach — if you choose to and if the statute of limitations permits.
Q: Will my claim payment definitely be $100?
A: Not necessarily. The $100 flat payment is “subject to a pro rata adjustment” depending on how many valid claims are submitted and how much of the settlement fund remains after deductions of fees, administration, etc.
Q: What if I wasn’t notified but think I might have been affected?
A: If you did not receive notice, you might not be considered a Class Member eligible to file a claim. It depends on whether Reventics’ records identify you as someone impacted. On the website of the settlement administrator you can check eligibility and whether your data may have been included.
Q: How long until I receive payment after filing a claim?
A: Payments will issue only after the court grants final approval of the settlement, claims are verified, and processing is completed. Some notices suggest payments will be issued approximately 60 days after final approval.
9. Impact and lessons learned
For data-subjects / consumers
- Data breaches involving PHI/PII continue to be a major risk in healthcare and tech-service sectors.
- Even if you have not suffered identity theft yet, having your PHI/PII exposed increases lifetime risk; settlements like this recognize that risk.
- Keep documentation of any out-of-pocket expenses (credit monitoring, identity theft remediation, etc.) for potential claims.
- Keep track of notices and deadlines — missing a filing deadline could mean forfeiting your rights.
For businesses / service providers
- Vendor networks, software providers, and healthcare-service contracts need robust cybersecurity, prompt notification procedures, and clear contract terms covering breach responsibilities.
- Even when no admission of wrongdoing is made, the cost of settlement (administration, notice, legal fees) can be significant—so proactive prevention is often cheaper than reactive litigation.
- Entities may be vulnerable to class action aggregation even if each individual loss is small or speculative. The key risk is the potential for class-wide exposure and costly settlement or defense.
For the legal field
- The dismissal on standing grounds in this case (Henderson v. Reventics) demonstrates that courts are increasingly requiring plaintiffs to show concrete injury and traceability in data-breach class actions.
- However—even with motion to dismiss success for defendants—settlements may still be reached because of cost, risk, and exposure.
- This case highlights the tension between consumer-protection objectives (compensating individuals for data breach risk) and the legal requirement of injury in fact (for standing) in U.S. federal courts.
10. Key take-aways
- The Henderson v. Reventics Settlement offers affected individuals a choice: claim documented losses (up to $5,000) or accept a flat payment (around $100) for having their PHI/PII exposed.
- The settlement fund is approximately $8.15 million.
- Eligibility requires being notified of the December 2022 Reventics breach and your data being part of that incident.
- The claim deadline is July 25, 2025.
- Even if you do not believe you’ve suffered direct harm yet, you may still elect to submit a claim for the flat payment.
- This settlement does not amount to an admission of liability by Reventics or its affiliated entities — they deny wrongdoing.
- For businesses, the case underscores the importance of cybersecurity, rapid notification, and vendor risk management.
- For individuals, it underscores the importance of tracking data notices and acting within deadlines.
- Whether or not you pursue the documented loss route, you should retain any documentation of harm, expenses, or identity-theft remediation efforts.
- If you choose to exclude yourself from the settlement, you must initiate your own lawsuit (if you want to), but you lose the settlement benefits.
11. What to do right now (for eligible individuals)
- Check your records: Did you receive a notice from Reventics, LLC (or Omega) about a December 2022 data breach?
- Visit the settlement website: www.reventicsdatasettlement.com to review eligibility, download the Claim Form, and find FAQs.
- Collect documentation: If you plan to claim documented losses, gather your receipts, statements, letters, etc. If not, decide whether you will take the flat payment option.
- Submit your claim by July 25, 2025 (online or by mail) with your CPT ID/passcode (or follow instructions if you don’t have one).
- Monitor the status: After claim submission, stay alert for communications from the settlement administrator and payment timeline.
- Consider whether you should exclude yourself: If you believe you might want to pursue an independent lawsuit (rather than accept settlement) you must opt out by the deadline.
- Take protective steps: Regardless of whether you claim or not, consider credit monitoring, identity-theft protections, and monitor accounts for suspicious activity.
12. Conclusion
The Henderson v. Reventics Settlement illustrates how data-breach litigation in the healthcare and software space is evolving: large‐scale exposure of sensitive PHI/PII, class action risks, and settlements that offer compensation for risk and remediation rather than only for actual misuse. If you are an individual whose information was included in the breach, this may represent a small but meaningful benefit—but timing and documentation matter. For organizations, the case serves as a clear signal: robust cybersecurity and incident response are not optional—they’re a business imperative.
Important Disclaimer: This article is for informational purposes only and does not constitute legal advice. If you believe you are a Class Member in the Henderson v. Reventics settlement and you have questions about your rights, obligations, or whether to submit a claim or exclude yourself, you should consult with a qualified attorney.