A Paylogix data breach may have affected thousands of people, a new class action lawsuit claims

Texan Sarah Smith filed a class action lawsuit against Paylogix LLC, a New York insurance technology company, in the U.S. District Court for the Eastern District of New York on Aug. 28, 2026.

The complaint alleges cybercriminals accessed Paylogix's network in November 2025 and copied files holding Social Security numbers, dates of birth and medical information, and that the company did not notify people for roughly nine months.

Who is Paylogix?

Paylogix runs enrollment, billing, premium collection and administration systems for voluntary employee benefits, which are the supplemental health and life insurance policies workers sign up for through their jobs.

Smith works for Memorial Hermann Health System, which the lawsuit claims uses the Paylogix portal to enroll and administer those benefits. She says she provided her personal information as a condition of receiving the benefits.

How the breach allegedly unfolded

The Paylogix data breach occurred between Nov. 13-Nov. 18, 2025. During that window, cybercriminals infiltrated the company's computer network and copied files belonging to Smith and potentially thousands of others, the proposed class action alleges.

The ransomware group Akira claimed responsibility on or about Jan. 15, 2026, posting on its dark web leak site that it would upload 185 gigabytes of corporate data, including "complete information about 130 employees including SSNs, passports, DLs and so on," according to the lawsuit. Akira reportedly later leaked all of the data.

The stolen data reportedly included:

  • Names
  • Social Security numbers
  • Dates of birth
  • Driver's license numbers
  • Financial account details
  • Medical records

Paylogix did not begin notifying affected individuals until on or about Aug. 14, 2026, roughly 270 days after the breach began and seven months after Akira's post, the lawsuit says. It confirmed the exposed information included names and Social Security numbers.

The class action lawsuit against Paylogix claims the company did not follow minimum standards under the National Institute of Standards and Technology Cybersecurity Framework Version 2.0 and the Center for Internet Security's Critical Security Controls and failed to meet Health Insurance Portability and Accountability Act of 1996 rules for protecting electronic health information.

The legal claims

Smith brings four claims against Paylogix along with a fifth count asking for court oversight:

  • Negligence, the failure to use reasonable care in protecting information the company collected
  • Negligence per se, a theory treating violation of a public-protection law as automatic fault, pled here under the Federal Trade Commission Act's ban on unfair business practices
  • Unjust enrichment, a theory that applies when a company profits unfairly at someone else's expense
  • Breach of implied contract, the unwritten promise to secure data workers hand over to receive benefits
  • Declaratory and injunctive relief, a request that the court call the security inadequate and order improvements

The lawsuit seeks damages, restitution, prejudgment interest and a court order requiring Paylogix to improve its security.

What this means for impacted workers

The proposed class covers everyone in the United States whose personal or health information the breach exposed, including all those who received a notice.

As of this writing, there is no settlement and no claims process.