HomeDossiersM&D Capital Premier Billing: $1 million settlement in Jan 2026 resolving data...

M&D Capital Premier Billing: $1 million settlement in Jan 2026 resolving data breach and billing claims

The $1 Million Settlement Fund. M&D Capital Resolves 2023 Data Breach Litigation.

The $1 million settlement fund established by M&D Capital Premier Billing LLC and Island Ambulatory Surgery Center LLC marks the conclusion of litigation surrounding the July 2023 data breach. This financial resolution, finalized in the Supreme Court of New York, Queens County, addresses allegations of negligence and contract breach affecting approximately 284, 326 individuals. The settlement fund provides monetary compensation and credit monitoring services to patients whose Social Security numbers, medical histories, and financial data were exposed during the three-week unauthorized network intrusion.

Settlement Fund Allocation and Structure

The agreement establishes a non-reversionary Common Fund of $1, 000, 000. This capital pool covers all payments to class members, administrative expenses, legal fees, and service awards. M&D Capital Premier Billing structured the settlement to resolve the consolidated class action filed under Skolnick et al. v. M&D Capital Premier Billing, LLC, Index No. 706879/2024. The distribution protocol prioritizes direct payments to victims who suffered verifiable financial harm. The court-approved terms allocate the fund as follows:

Expense Category Allocation Amount Purpose
Class Benefit Fund ~$632, 000 (Estimated) Direct cash payments and credit monitoring for 284, 326 eligible class members.
Attorney Fees $350, 000 (Maximum) Legal representation costs for Class Counsel, capped at 35% of the total fund.
Service Awards $18, 000 $3, 000 payments to each of the six named plaintiffs (Skolnick, Dixon, Facon, Kashvili, Lee, Maloney).
Administration Variable Costs for notice distribution, claims processing, and website management (deducted from the fund).

Compensation Tiers for Victims

Class members must submit valid claims by January 27, 2026. The settlement offers two distinct recovery channels. Claimants may select only one option. Tier 1: Documented Loss Payment Victims can receive up to $5, 000 in reimbursement for out-of-pocket expenses directly linked to the data breach. Eligible costs include bank fees, communication charges, credit freezing costs, and professional fees incurred to remediate identity theft. Claimants must provide third-party documentation such as receipts, bank statements, or invoices. This tier also covers up to four hours of lost time, compensated at $25 per hour, if the time was spent dealing with the breach’s aftermath. Tier 2: Flat Cash Payment Alternatively, class members may elect a flat cash payment. The initial estimate for this payment is $75. This amount is subject to pro rata adjustment. If the total value of valid claims exceeds the net settlement fund, the $75 figure decrease. Conversely, if funds remain after all claims are paid, the amount per claimant increase.

“Defendants have entered into this Agreement to resolve all controversies and disputes… and to avoid the litigation costs and expenses. Defendants do not in any way acknowledge, admit to, or concede any of the allegations made in the Complaint.”
, Settlement Agreement, Skolnick v. M&D Capital Premier Billing

The 2023 Network Intrusion

The litigation from a cyberattack that compromised M&D Capital’s network between June 20, 2023, and July 8, 2023. Forensic investigations revealed that unauthorized actors maintained access to the system for 19 days. The breach exposed sensitive Protected Health Information (PHI) and Personally Identifiable Information (PII) including: * Patient Identity: Full names, addresses, and dates of birth. * Medical Records: Diagnosis codes, medication lists, and treatment histories. * Financial Data: Social Security numbers, health insurance policy numbers, and billing information. M&D Capital Premier Billing did not problem notifications to affected individuals until March 18, 2024, nearly nine months after the initial discovery. This delay became a central point of contention in the subsequent lawsuits. Plaintiffs argued that the gap between discovery and notification exacerbated the risk of identity theft and financial fraud.

Litigation Timeline and Resolution

The legal process moved rapidly following the March 2024 notification. Plaintiff Jacqueline Skolnick filed the initial complaint on March 28, 2024. Five related class action lawsuits followed, which the court consolidated. * July 8, 2023: M&D Capital discovers suspicious network activity. * March 18, 2024: Data breach notices mailed to 284, 326 individuals. * March 28, 2024: class action lawsuit filed in Queens County Supreme Court. * October 8, 2025: Court grants Preliminary Approval of the $1 million settlement. * January 27, 2026: Deadline for class members to file claims. * February 11, 2026: Scheduled Final Approval Hearing. The settlement agreement mandates that M&D Capital Premier Billing implement enhanced data security measures. These non-monetary terms require the defendant to upgrade network monitoring tools and conduct regular cybersecurity audits to prevent future incursions. The $1 million payment resolves all claims against both M&D Capital and the co-defendant, Island Ambulatory Surgery Center, releasing them from further liability regarding this specific incident.

284,326 Patient Records. The Verified Scope of the July 2023 Exfiltration.

The $1 Million Settlement Fund. M&D Capital Resolves 2023 Data Breach Litigation.
The $1 Million Settlement Fund. M&D Capital Resolves 2023 Data Breach Litigation.
The forensic investigation into the M&D Capital Premier Billing network intrusion confirmed a precise window of unauthorized access spanning 19 days, from June 20, 2023, to July 8, 2023. During this period, cyber actors successfully exfiltrated a database containing the sensitive personal and protected health information (PHI) of 284, 326 individuals. The breach did not expose static demographic details; it compromised the complete administrative and clinical profiles of patients served by Island Ambulatory Surgery Center and other client entities.

Forensic Timeline of the Intrusion

Network logs analyzed by third-party cybersecurity specialists established that the initial penetration occurred on June 20, 2023. The threat actors maintained persistence within the M&D Capital infrastructure for nearly three weeks before suspicious activity triggered internal alerts on July 8, 2023. This dwell time allowed for the systematic lateral movement across servers and the unencumbered extraction of unencrypted files. The gap between the breach containment in July 2023 and the commencement of patient notifications on March 18, 2024, spanned over eight months. This delay left victims unaware that their financial and medical identities were compromised, preventing them from taking defensive measures such as freezing credit or auditing medical benefit statements during a serious window of vulnerability.

Inventory of Compromised Data Fields

The exfiltrated dataset contained a high-density combination of identifiers that facilitates sophisticated medical identity theft. Unlike standard financial breaches, this incident exposed the “full cover” of patient data required for fraudulent billing and insurance schemes.

Verified Data Categories Exfiltrated (July 2023)
Data Category Specific Data Points Exposed Risk Implication
Personal Identifiers Full names, residential addresses, dates of birth. Foundational data used to fabricate synthetic identities.
Federal ID Social Security Numbers (SSNs). Enables opening of new credit lines and tax fraud.
Financial Data Account numbers, credit/debit card numbers. Direct theft of funds and unauthorized transaction processing.
Medical Billing CPT codes, billing amounts, dates of service, provider names. Allows for the generation of phantom medical claims.
Clinical Records Diagnoses, medication lists, treatment histories. Used to bypass insurance fraud filters by mimicking real patient history.
Insurance Data Policy numbers, group IDs, subscriber information. Facilitates policy hijacking and fraudulent benefit exhaustion.

Specific Entities and Client Impact

While M&D Capital Premier Billing served as the central node for the breach, the downstream impact radiated to its provider clients. The primary entity named in the settlement, Island Ambulatory Surgery Center LLC, relied on M&D for revenue pattern management, meaning their patient roster comprised of the affected 284, 326 records. The investigation also implicated data related to affiliated corporate entities, including ASC Strategic Services LLC and Drachman Katz LLP. The interconnected nature of these organizations meant that data was not siloed; once the threat actors breached the M&D perimeter, they accessed a repository that aggregated sensitive billing data from multiple sources. This aggregation created a single point of failure where a vendor-level breach resulted in a multi-provider mass casualty event for patient privacy.

The Mechanics of the “Billing Claims” Exposure

The “billing claims” aspect of the settlement refers specifically to the exposure of proprietary medical billing information. This data subset is particularly valuable on the dark web because it includes the Current Procedural Terminology (CPT) codes and International Classification of Diseases (ICD) codes linked to specific patients. Criminals use this data to construct “phantom billing” scams. By possessing a patient’s valid name, insurance policy number, and a history of legitimate procedures (e. g., a previous knee surgery), fraudsters can submit realistic-looking claims for follow-up care or related equipment that was never provided. The breach at M&D Capital provided the exact blueprint, diagnosis codes, treatment dates, and provider identities, needed to bypass the fraud detection algorithms used by major insurers and Medicare.

Regulatory and Notification Metrics

The breach was formally reported to the U. S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) as a hacking/IT incident. The verified count of 284, 326 victims places this event among the significant vendor-associated breaches of 2023 in the New York region.

“The forensic investigation confirmed that an unauthorized third party gained access to its network on June 20, 2023, and maintained access until July 8, 2023. During those three weeks, protected health information provided by its covered entity clients may have been viewed or acquired.”

The notification letters sent in March 2024 confirmed that the exposure was not theoretical. The forensic review could not rule out the exfiltration of specific files, leading to the conclusion that the entire identified dataset was at risk. Consequently, the settlement defines the class not by confirmed fraud, by the presence of their data on the compromised server during the 19-day window of unauthorized access.

Settlement Class Definition

The settlement agreement finalized in the Supreme Court of New York, Queens County, defines the “Settlement Class” strictly by the data audit. Any individual who received a “Notice of Data Breach” letter from M&D Capital Premier Billing dated on or around March 18, 2024, is automatically included. This creates a closed class of 284, 326 verified members who are eligible to claim the $75 cash payment or up to $5, 000 in documented loss reimbursement, regardless of whether they have yet experienced direct financial loss. The court’s approval of this class definition validates the severity of the risk posed by the specific combination of medical and financial data lost in this incident.

Social Security and Diagnoses. The High Sensitivity of Exposed Medical Data.

The exposure of sensitive health and personal identifiers in the M&D Capital Premier Billing breach represents a “golden record” event in cybersecurity terms. Unlike standard retail breaches that compromise cancellable credit card numbers, the July 2023 intrusion granted cybercriminals access to the permanent biological and bureaucratic identities of 284, 326 individuals. The specific combination of Social Security numbers (SSNs) and clinical treatment data creates a vulnerability profile that financial restitution alone cannot easily repair.

The Anatomy of the Exposed “Golden Record”

The term “golden record” refers to a complete profile that allows a criminal to fully assume a victim’s identity. In the case of M&D Capital Premier Billing, the compromised server contained the three pillars required for total identity usurpation: government identification, financial routing data, and medical history. According to the class action filings in the Supreme Court of New York, Queens County, the unauthorized access from June 20, 2023, to July 8, 2023. During this nineteen-day window, threat actors had unimpeded access to unencrypted files containing: * Patient Demographics: Full names, physical addresses, and dates of birth. * Government Identifiers: Social Security numbers. * Financial Data: Health insurance policy numbers, member IDs, and patient account numbers. * Clinical Data: Medical diagnoses, treatment records, medication lists, and procedural billing codes (CPT/ICD). This dataset allows for “fullz” sales on the dark web, packages of data that include everything needed to open lines of credit, file fraudulent tax returns, or, most dangerously, obtain medical care under a victim’s name.

The Specific Danger of Exposed Diagnoses

The inclusion of “diagnosis, medication, and treatments” in the exposed data elevates the severity of this breach beyond simple financial fraud. M&D Capital Premier Billing, acting as a business associate for providers like Island Ambulatory Surgery Center, processed specific billing codes that reveal the intimate health status of patients. Exposure of this clinical data carries two distinct risks: extortion and medical identity theft. 1. Extortion and Privacy Medical records frequently contain sensitive information regarding chronic conditions, mental health treatments, or elective surgeries. In the hands of bad actors, this information becomes use. While no public reports currently confirm that M&D data has been used for direct extortion, the chance remains a lifetime liability for victims. Unlike a password, a patient cannot change their medical history. A diagnosis of cancer, HIV, or a mental health disorder recorded in 2023 remains a fact of that patient’s life in 2026 and beyond. 2. The Mechanics of Medical Identity Theft The most immediate operational risk for the 284, 326 victims is the use of their data to obtain fraudulent healthcare services. With a valid name, SSN, and insurance policy number, a criminal can: * Procure Prescription Drugs: Thieves use stolen identities to fill prescriptions for controlled substances, such as opioids, which are then resold. * Schedule Elective Procedures: Criminals may undergo surgeries or treatments using the victim’s insurance coverage. * File Phantom Claims: Organized crime rings use the valid patient data to bill insurers for procedures that never happened, cashing out the reimbursements while the victim is left with the “Explanation of Benefits” statement months later.

The “Killware” Risk: Corrupted Medical Files

The most insidious threat posed by the M&D Capital breach is the chance corruption of legitimate medical records. When an imposter uses a victim’s identity to receive care, the medical details of the thief, blood type, allergies, chronic conditions, become commingled with the victim’s official health record. For example, if an imposter with Type A blood undergoes surgery using the identity of a victim with Type O blood, that erroneous blood type data may be permanently entered into the victim’s digital health file. In a future emergency, such as a car accident where the victim is unconscious, a doctor relying on that corrupted record could administer a fatal transfusion. This category of risk, frequently termed “killware” in cybersecurity analysis, transforms a data privacy problem into a patient safety emergency.

Comparative Risk Analysis: Financial vs. Medical Data Breach
Risk Factor Financial Breach (Credit Card) Medical Breach (M&D Capital Case)
Remediation Speed Hours to Days (Cancel card) Months to Years (Audit health records)
Direct Cost to Victim $0 (Fraud protection) Avg. $13, 500 (Uncovered bills/legal fees)
Dark Web Value $1, $5 per record $250, $1, 000 per record
Primary Risk Monetary loss Misdiagnosis, Wrong Treatment, extortion
Lifespan of Risk Short-term (until card expires) Permanent (SSN/History cannot change)

The Role of Social Security Numbers

The inclusion of Social Security numbers in the M&D Capital breach acts as the “skeleton key” that unlocks the full chance of the stolen medical data. In the United States healthcare system, the SSN is frequently used as a unique patient identifier to link records across provider networks. By possessing the SSN, a threat actor can bypass identity verification used by hospitals and insurers. A criminal presenting at an emergency room with a valid name, DOB, and SSN is rarely challenged further. The Skolnick complaint highlighted this specific negligence, arguing that M&D Capital failed to encrypt these specific fields adequately, leaving them readable to the intruders who maintained access to the network for nearly three weeks.

Settlement Provisions for High-Sensitivity Data

The $1 million settlement fund finalized in January 2026 explicitly acknowledges the high sensitivity of this data through its allocation of “Medical Monitoring” services. While standard data breach settlements offer credit monitoring to watch for financial fraud, the M&D agreement includes a specialized provision for medical monitoring. This service, provided by CyEx, is designed to alert victims to changes in their medical credit reports, a specialized credit file that tracks medical debt and insurance inquiries. This is a direct response to the exposure of diagnostic and treatment data. The settlement allows class members to claim this benefit for two years, a recognition that the risk of medical identity theft has a longer incubation period than simple credit card fraud.

The Long-Tail Consequences

The 284, 326 individuals affected by the M&D Capital breach face a “long-tail” risk profile. Financial breaches show immediate indicators of fraud. Medical data breaches frequently remain dormant for years. A criminal may hold the data until the victim’s insurance policy renews, or sell the data to a secondary broker who specializes in long-term insurance fraud. The January 2026 settlement claims deadline marks the legal conclusion of the case, for the victims, the vigilance required is indefinite. The exposure of a mental health diagnosis or a history of substance abuse treatment can resurface years later in employment background checks or life insurance underwritings if the data is publicly leaked or sold to data brokers.

Regulatory Context and Negligence Allegations

The plaintiffs in the Skolnick and Dixon actions argued that M&D Capital’s failure to segregate and encrypt this sensitive data constituted a breach of implied contract. Patients provide their intimate health details to medical providers like Island Ambulatory Surgery Center with the understanding that this information is protected by HIPAA standards. When that data is passed to a third-party billing vendor like M&D, the patient loses visibility into how their data is secured. The breach revealed that M&D Capital’s network segmentation was insufficient to prevent lateral movement. Once the attackers gained entry on June 20, 2023, they were able to locate and exfiltrate files containing the most sensitive combination of data points available in the healthcare ecosystem. The settlement resolves these allegations without an admission of wrongdoing, the structure of the payout, prioritizing those with documented losses, confirms that the exposure caused tangible harm to the victim class.

The load of “Clean-Up”

For the victims of the M&D Capital breach, “cleaning up” a compromised medical identity is a bureaucratic nightmare. Unlike disputing a credit card charge, removing a fraudulent appendectomy from a medical record requires proving a negative, that the patient did not have the procedure. This frequently involves obtaining affidavits from physicians, undergoing physical exams to prove surgical scars do not exist, and navigating the complex appeals processes of health insurance companies. The $1 million settlement provides a method for reimbursement of these efforts (up to $5, 000 per claim for documented losses), it cannot compensate for the time and stress involved in scrubbing a medical history. The exposure of diagnosis codes means that every future doctor’s visit carries a shadow of doubt: is the chart accurate, or is it polluted by the data theft of July 2023?

“The theft of a credit card is a nuisance. The theft of a medical history is a permanent corruption of the victim’s biological truth.”

This distinction drives the urgency behind the January 2026 settlement. The court’s approval of the fund reflects the reality that M&D Capital Premier Billing did not just lose numbers; they lost the private medical narratives of over a quarter-million New Yorkers. The settlement closes the legal chapter, the data remains out in the wild, a permanent digital scar for the patients of Island Ambulatory Surgery Center.

Island Ambulatory Surgery Center. The Co-Defendant Role in the Queens County Lawsuit.

284,326 Patient Records. The Verified Scope of the July 2023 Exfiltration.
284,326 Patient Records. The Verified Scope of the July 2023 Exfiltration.
The $1 million settlement finalized in January 2026 resolves the consolidated class action litigation against M&D Capital Premier Billing LLC and its co-defendant, Island Ambulatory Surgery Center LLC (IASC). While M&D Capital served as the central billing vendor where the breach originated, IASC’s inclusion as a named co-defendant in the Supreme Court of New York, Queens County (Index No. 706879/2024) highlights the serious legal exposure medical providers face when their third-party vendors mishandle patient data.

The Co-Defendant: Island Ambulatory Surgery Center Profile

Island Ambulatory Surgery Center, located in Brooklyn, New York, operates as a multi-specialty facility providing outpatient surgical services. The center specializes in disciplines requiring sensitive patient disclosures, including pain management, orthopedics, podiatry, and urology. As a direct healthcare provider, IASC collected high-risk Protected Health Information (PHI) from patients before transmitting it to M&D Capital for billing and coding purposes. In the litigation Skolnick et al. v. M&D Capital Premier Billing LLC and Island Ambulatory Surgery Center LLC, plaintiffs argued that IASC bore a direct responsibility to vet and monitor its vendors. The inclusion of IASC as a primary co-defendant, rather than a passive victim of M&D’s security failure, signals a shift in plaintiff strategy. Attorneys successfully argued that the duty to protect patient data is non-delegable, meaning a hospital or surgery center cannot absolve itself of liability simply by outsourcing data processing to a third party.

Chronology of the Breach at IASC

The timeline of the breach reveals a significant gap between the vendor’s discovery and the provider’s awareness, a gap that became a focal point of the negligence claims.

Verified Timeline of Events: Island Ambulatory Surgery Center
Date Event Details
July 8, 2023 Vendor Discovery M&D Capital detects unauthorized activity on its network.
July 31, 2023 Provider Detection IASC detects “unusual activity” disrupting its own systems, indicating the breach may have moved laterally or affected connected portals.
Feb 7, 2024 Forensic Confirmation IASC confirms specific patient files were accessed and acquired by the unauthorized actor.
March 29, 2024 Litigation Filed Plaintiff Jacqueline Skolnick files the initial class action complaint in Queens County Supreme Court.
April 5, 2024 Provider Notification IASC begins mailing notification letters to approximately 7, 900 directly affected patients, nearly nine months after the initial intrusion.
Jan 27, 2026 Settlement Deadline Final date for IASC patients to submit claims for the $1 million settlement fund.

Legal Theory: Vendor Risk and Vicarious Liability

The plaintiffs’ complaint, consolidated under Index No. 706879/2024, leveraged the delay between the July 2023 breach and the April 2024 notification to substantiate claims of negligence. Under New York General Business Law (GBL) § 899-aa and the Health Insurance Portability and Accountability Act (HIPAA), covered entities must notify victims “without unreasonable delay.” The nine-month lag exposed IASC to allegations that it absence adequate incident response or failed to maintain sufficient oversight of its business associate, M&D Capital. The lawsuit accused IASC of: 1. Negligent Selection of Vendor: Failing to ensure M&D Capital employed strong cybersecurity measures before sharing sensitive patient data. 2. Breach of Implied Contract: Violating the privacy pledge made to patients in the center’s Notice of Privacy Practices. 3. Unjust Enrichment: Retaining payments for medical services while failing to use a portion of those funds to secure the associated data. Defense counsel for IASC maintained that the surgery center was a victim of a sophisticated cyberattack targeting its vendor. yet, the settlement agreement bypasses these defenses, binding both M&D and IASC to the $1 million payout without an admission of wrongdoing. This “no-admission” clause allows IASC to resolve the liability without conceding that its vendor management practices were legally deficient.

Specific Data Exposure Risks for IASC Patients

The data compromised in the IASC subset of the breach was particularly sensitive due to the nature of the surgeries performed. Unlike a standard credit card breach, the exposed files included: * Medical Diagnosis Codes: Specific ICD-10 codes revealing chronic conditions, pain management treatments, and urological problem. * Treatment Histories: Dates of surgeries and specific procedures performed at the Brooklyn facility. * Health Insurance Information: Policy numbers and coverage details that could be used for medical identity theft. * Social Security Numbers: Full SSNs were exposed for of the class, necessitating the credit monitoring component of the settlement. The exposure of urology and pain management records carries a heightened risk of extortion or “doxing,” adding weight to the plaintiffs’ claims for emotional distress damages. The settlement allocates up to $5, 000 per class member for documented losses, a figure that acknowledges the chance severity of medical identity theft where erroneous entries in a victim’s health record could lead to mistreatment.

Settlement Mechanics for the Co-Defendant

In the final settlement structure, IASC and M&D Capital are treated as a single “Released Party” entity regarding liability. The $1, 000, 000 fund is a joint obligation, covering the claims of all 284, 326 class members, including the 7, 900 specifically attributed to IASC. For IASC patients, this consolidation is advantageous. If IASC had been sued separately with a smaller class of 7, 900, the administrative costs might have consumed a larger percentage of any chance recovery. By grouping the IASC patients into the larger M&D class, the administrative overhead is amortized, chance leaving more funds available for valid claims. The settlement stipulates that IASC patients are eligible for the same two tiers of compensation as M&D’s direct clients: * Tier 1 (Documented Losses): Reimbursement for out-of-pocket expenses, professional fees, and lost time (calculated at $25/hour) up to $5, 000. * Tier 2 (Flat Payment): A pro-rata cash payment, estimated at $75, for those who cannot document specific financial harm attest to the breach of their privacy.

for Medical Vendor Management

The resolution of Skolnick v. M&D Capital serves as a clear warning to ambulatory surgery centers and small medical practices. The $1 million settlement demonstrates that providers can and be held financially accountable for the security failures of their billing partners. IASC’s involvement illustrates the “chain of trust” vulnerability in modern healthcare. While the surgery center focused on patient care, its administrative backend, outsourced to M&D, became the vector for a massive privacy violation. The legal costs incurred by IASC in defending the Queens County action, combined with its contribution to the settlement fund, likely exceed the cost of years of enhanced vendor auditing. Future contracts between surgery centers and billing vendors likely see stricter indemnification clauses and requirements for real-time breach detection integration. The nine-month delay in IASC’s notification process suggests a absence of technical integration with M&D’s systems, a gap that prevented the provider from knowing its own data was compromised until long after the initial intrusion.

Consolidation of Claims

The Queens County litigation did not start as a single case. Following the March 2024 notifications, at least five separate class action lawsuits were filed against M&D and its clients. These were consolidated into the Skolnick action (Index No. 706879/2024). This consolidation prevented IASC from fighting a multi-front legal war, streamlining the process into a single negotiation that yielded the January 2026 settlement. The court’s preliminary approval in October 2025 and the final claim deadline in January 2026 mark the end of this specific legal chapter for IASC. yet, the reputational damage to the Brooklyn facility remains a lingering concern, as the breach notification letters sent to patients explicitly named the surgery center as the source of the leaked data, regardless of the vendor’s underlying fault.

Tier A Compensation. The Strict Documentation Requirements for $5,000 Payouts.

Tier A Compensation: The Strict Documentation Requirements for $5, 000 Payouts

The settlement agreement in Jacqueline Skolnick, et al. v. M&D Capital Premier Billing, LLC establishes two distinct tiers of monetary relief. While the “Cash Payment B” option offers a flat, estimated payment of $75 without requiring proof of loss, the “Cash Payment A” category allows class members to claim up to $5, 000. This higher tier is reserved for individuals who suffered verifiable, out-of-pocket financial losses directly attributable to the July 2023 data breach. Accessing these funds requires navigating a rigorous audit process administered by Epiq Global, where the load of proof rests entirely on the claimant.

The “More Likely Than Not” Causation Standard

To qualify for Tier A reimbursement, a claimant must demonstrate that their financial loss was “more likely than not” a result of the Data Incident discovered on July 8, 2023. This legal standard, known as the “fairly traceable” requirement, serves as the primary filter for the Settlement Administrator. Losses that occurred prior to July 2023 are automatically disqualified. also, expenses that cannot be reasonably linked to the exposure of specific data points, such as Social Security numbers, medical diagnosis codes, or financial information, face rejection. The Settlement Administrator reviews claims to ensure they meet three specific criteria: 1. Timing: The loss occurred on or after July 8, 2023. 2. Nature: The loss involves actual financial expenditure or liability, not speculative damages or future risks. 3. Nexus: The loss connects reasonably to the type of data exposed (e. g., a fraudulent credit card charge links to exposed financial data; a falsified tax return links to an exposed SSN).

Eligible Expenses and Documentation

The settlement agreement explicitly defines “Documented Losses” as unreimbursed expenses. Class members cannot claim costs that were already refunded by a bank, credit card issuer, or insurance provider. This “anti-double-dipping” provision requires claimants to prove the fraud occurred, that they permanently lost money fighting it. The following table outlines the specific categories of eligible expenses and the documentation required to substantiate them.

Expense Category Eligible Line Items Required Documentation (Strict)
Financial Fraud Costs Unreimbursed bank fees, overdraft charges, late fees, credit card fraud charges. Bank or credit card statements with the specific fraudulent transactions highlighted. Letters from financial institutions denying reimbursement.
Identity Theft Protection Costs for purchasing credit monitoring services, identity theft insurance, or credit reports. Invoices or receipts showing the date of purchase (post-July 2023) and the price paid. Subscription renewal notices are insufficient without proof of payment.
Communication Costs Long-distance phone charges, cell phone minutes, data overage charges. Phone bills specifically detailing charges by the minute or by the gigabyte. Flat-rate unlimited plans are generally excluded unless a specific overage fee was incurred due to breach-related calls.
Travel and Logistics Gasoline for local travel (e. g., to police stations or banks), postage, notary fees. Receipts for gas/postage dated to the time of the dispute resolution efforts. A concurrent log or narrative explaining the purpose of the travel (e. g., “Trip to Chase Bank to file fraud affidavit”).
Professional Fees Legal fees, accountant fees for refiling tax returns. Invoices from the attorney or accountant detailing the services rendered specifically for remediation of the data breach problem.

The Telecommunications Loophole

A serious limitation in the settlement terms involves reimbursement for communication costs. The agreement specifies that cell phone charges are eligible only if they are “charged by the minute,” and data charges are eligible only if “charged based on the amount of data used.” In the current US telecommunications market, where the vast majority of consumers use unlimited voice and data plans, this requirement disqualifies most claims for time spent on the phone with banks or credit bureaus. Unless a claimant can produce a bill showing a specific surcharge for exceeding a plan’s limits directly due to breach-related activities, these expenses be rejected. This clause protects the settlement fund from absorbing the “sunk costs” of monthly utility bills that the claimant would have paid regardless of the breach.

The Audit and Cure Process

Epiq Global, acting as the Settlement Administrator, holds the authority to determine the validity of each claim. If a Tier A claim is submitted with insufficient documentation, for example, a credit card statement that shows a charge does not prove it was fraudulent, the claim is not immediately rejected. Instead, the Administrator initiates a “cure period.” The claimant receives a notification detailing the deficiency and is granted a specific window ( 30 days) to provide the missing evidence. Failure to respond or provide adequate proof during this cure period results in the reclassification of the claim. The request for $5, 000 is denied, and the claim is automatically downgraded to “Cash Payment B,” the flat payment estimated at $75.

Pro Rata Reductions and Fund Depletion

The $5, 000 figure represents a cap, not a guaranteed payout. The settlement operates under a “Common Fund” model, where the $1, 000, 000 total liability covers all valid claims, administrative costs, and legal fees (up to $350, 000). If the total value of valid Tier A claims and Tier B claims exceeds the Net Settlement Fund, payments be reduced on a pro rata basis. This means that even a claimant with perfect documentation for $4, 000 in losses might receive significantly less if the breach affects a high volume of victims who all submit valid claims. Conversely, if participation is low, payments could theoretically increase, though the settlement terms frequently cap the upside to prevent windfalls.

Exclusion of “Self-Attested” Time

Unlike data breach settlements that allow claimants to self-certify “lost time” (e. g., claiming 5 hours at $25/hour for calling banks) without third-party proof, the M&D Capital Premier Billing settlement places a premium on documented third-party expenses for Tier A. The “Cash Payment B” option serves as the catch-all for undocumented harm, including lost time and general inconvenience. Claimants attempting to bill the fund for their own time under Tier A without external receipts find those line items disallowed.

Strategic Filing Considerations

For the 284, 326 individuals notified of the breach, the choice between Tier A and Tier B involves a risk-reward calculation. Tier A offers a higher chance payout requires the disclosure of sensitive financial documents to the Settlement Administrator and carries the risk of a downgrade. Tier B offers a guaranteed (albeit variable) check with minimal friction. The deadline for submitting these proofs is January 27, 2026. Documents must be uploaded via the settlement portal at MDDataSettlement. com or mailed to the Portland, Oregon PO Box managed by Epiq. Postmarks after this date result in the total forfeiture of the claim, regardless of the validity of the loss.

Tier B Cash Payments. The Pro Rata Dilution Risk for the $75 Flat Fee.

Social Security and Diagnoses. The High Sensitivity of Exposed Medical Data.
Social Security and Diagnoses. The High Sensitivity of Exposed Medical Data.

The Mechanics of the “Alternative Cash Payment”

The settlement agreement in Skolnick, et al. v. M&D Capital Premier Billing LLC establishes a bifurcated compensation structure designed to categorize class members based on the severity of their injury. While “Cash Payment A” offers reimbursement up to $5, 000 for documented losses, requiring receipts, bank statements, and proof of fraud, the vast majority of the 284, 326 affected individuals are expected to fall into “Cash Payment B.” This tier, marketed in settlement notices as a “Flat Cash” payment, offers an estimated $75 to any class member who attests to the exposure of their data without providing third-party documentation of financial harm. The appeal of Tier B is its low barrier to entry; it functions as a strict liability payout for the exposure of sensitive medical and personal data, including Social Security numbers and diagnosis codes.

yet, the $75 figure represents a theoretical ceiling rather than a guaranteed payout. The settlement operates on a “claims-made” basis within a non-reversionary Common Fund capped strictly at $1, 000, 000. This fixed cap creates a zero-sum financial environment where every dollar allocated to administrative overhead, legal fees, or service awards directly reduces the capital available for claimant distribution. Unlike “claims-paid” settlements where the defendant agrees to pay a fixed amount per valid claim regardless of the total volume, the M&D Capital agreement limits the defendant’s total liability to the single million-dollar payment. Consequently, the “Flat Cash” amount is entirely dependent on the “Net Settlement Fund”, the residual amount remaining after all priority deductions are satisfied.

The Waterfall of Deductions

To understand the precarious nature of the Tier B payment, one must examine the priority of payments dictated by the settlement terms. The $1, 000, 000 fund is not reserved exclusively for patient compensation. Before a single dollar is distributed to a class member, the fund must satisfy three primary categories of expenses:

Estimated Settlement Fund Allocation (Pre-Distribution)
Expense Category Estimated Amount Impact on Fund
Total Settlement Fund $1, 000, 000 100%
Attorneys’ Fees (Max Request) $350, 000 -35. 0%
Service Awards (6 Representatives) $18, 000 -1. 8%
Administration Costs (Epiq Global) $150, 000, $200, 000 (Est.) -15. 0% to -20. 0%
Net Settlement Fund (Available for Claims) ~$432, 000, $482, 000 ~43%, 48%

The request for attorneys’ fees is capped at 35% of the fund, or $350, 000. also, the six class representatives, Jacqueline Skolnick, Ashley Dixon, Candice Facon, Benjamin Kashvili, Youn Lee, and Jillian Maloney, are eligible for service awards totaling up to $18, 000 ($3, 000 each). The most variable and chance damaging deduction is the cost of settlement administration. Epiq Global, the appointed administrator, is responsible for managing the notice program for nearly 285, 000 individuals. Even with a heavy reliance on email notices, the costs for postage, website hosting (MDDataSettlement. com), call center operations, and claims processing frequently exceed $150, 000 in class actions of this size. If administration costs reach $200, 000, the Net Settlement Fund available for actual victims shrinks to approximately $432, 000, less than half of the headline settlement figure.

The Medical Monitoring Drain

A serious and frequently overlooked provision in the Skolnick agreement further threatens the cash payments. The settlement allows class members to claim two years of “CyEx” medical monitoring services. Crucially, the cost of these services is deducted from the Net Settlement Fund before cash payments are calculated. The settlement terms explicitly state that funds are distributed ” for payment of Medical Monitoring and then for Cash Payments.”

This structure introduces a significant variable. If the negotiated rate for CyEx monitoring is, for example, $10 per enrollee, and 5% of the class (14, 216 individuals) selects this benefit, the cost to the fund would be $142, 160. In this scenario, the remaining capital for cash payments would plummet from ~$432, 000 to ~$290, 000. This method prioritizes credit and medical monitoring services over direct cash compensation, meaning high enrollment in the monitoring benefit directly cannibalizes the funds available for the $75 Tier B checks.

Pro Rata Dilution Scenarios

The “pro rata” clause is the mathematical method that adjusts the $75 payment based on participation rates. If the total value of valid claims exceeds the Net Settlement Fund, all payments are reduced proportionally. Given the class size of 284, 326, the participation rate required to trigger dilution is exceptionally low. The following analysis assumes a Net Settlement Fund of $400, 000 (after fees, awards, admin costs, and a modest monitoring uptake).

The 2% Threshold:
If just 2% of the class submits a valid claim for Tier B (5, 687 claims), the total demand on the fund would be $426, 525 (5, 687 × $75). This amount already exceeds the estimated available capital of $400, 000. Under this conservative participation scenario, the $75 payment would immediately dilute to approximately $70. 33.

While a 2% claim rate is standard for consumer class actions, data breach settlements involving sensitive medical information frequently see higher engagement due to the perceived risk of identity theft. If the participation rate rises to 5%, a reasonable expectation given the direct notice campaign, the math becomes punitive.

At a 5% claim rate (14, 216 claims), the theoretical demand for Tier B payments hits $1, 066, 200. This figure is higher than the entire gross settlement fund, let alone the net amount available. With only ~$400, 000 actually available for distribution, the pro rata reduction would slash the payment to approximately $28. 13 per person. In a high-participation scenario of 10%, the payment would collapse to roughly $14. 00. This creates a paradox: the more successful the notice campaign is in reaching victims, the less valuable the individual compensation becomes.

Comparison to Industry Standards

The M&D Capital settlement structure mirrors a broader trend in healthcare data breach litigation, where “claims-made” caps shield defendants from open-ended liability. For comparison, the Solara Medical Supplies settlement ($9. 76 million fund for 114, 000 people) provided a much higher per-capita buffer. In that case, the ratio of funds to class members was approximately $85 per person gross. In the M&D Capital case, the ratio is $3. 51 per person gross ($1, 000, 000 ÷ 284, 326). This highlights the extreme leanness of the M&D Capital settlement. The $75 Tier B estimate appears to be based on an assumption of near-zero participation (less than 1. 5%), which is an optimistic projection for the defense a risky proposition for class members expecting meaningful compensation.

The “Claims Made” Reality for Tier A

Tier A claimants (Documented Losses up to $5, 000) are not immune to this dilution. The settlement does not segregate funds for Tier A and Tier B; they draw from the same pool. If a small number of victims submit valid claims for significant financial damages, for instance, 50 people claiming the full $5, 000 for identity theft recovery costs, that $250, 000 withdrawal would devastate the remaining pool for Tier B claimants. Conversely, if the Tier B pool is diluted, the settlement administrator may also apply pro rata reductions to Tier A payments, depending on the specific language regarding “equitable distribution” in the final approval order., yet, flat fee payments bear the brunt of the reduction to preserve the integrity of reimbursed documented losses.

The January 2026 Deadline

The claims deadline of January 27, 2026, serves as the final cutoff for this mathematical determination. Until the Settlement Administrator, Epiq Global, tallies the final count of valid claims, the $75 figure remains speculative. Class members filing in late 2025 or January 2026 do so with no guarantee of the final amount. The Final Approval Hearing, scheduled for February 11, 2026, before Justice Joseph J. Risi in Queens County Supreme Court, be the venue where the final participation numbers are revealed. Historically, settlement administrators do not announce the pro rata adjustment until after the final approval is granted and all appeals are exhausted, meaning claimants may not know the actual value of their check until mid-to-late 2026.

The structure of the M&D Capital settlement places the financial risk of the breach entirely on the class members. By capping the fund at $1 million while facing a class of nearly 300, 000, the defendants have fixed their costs. The variable becomes the compensation received by the victims. If the breach caused widespread alarm leading to a 10% claim rate, the “penalty” for the defendants remains $1 million, the “remedy” for the victims evaporates into nominal payments. This show the importance of the “Net Settlement Fund” definition over the headline “Gross Settlement Fund” number in evaluating the true value of the resolution.

January 27, 2026. The Hard Deadline for Class Member Claim Submissions.

The January 27, 2026, cutoff served as the final barrier for the 284, 326 class members eligible to extract compensation from the $1 million settlement fund established by M&D Capital Premier Billing LLC and Island Ambulatory Surgery Center LLC. This date, mandated by the Supreme Court of New York, Queens County (Index No. 706879/2024), marked the absolute cessation of claim intake for the data breach discovered in July 2023.

Submission Mechanics and Administrator

The court-appointed Settlement Administrator, Epiq Global, enforced a strict 11: 59 PM Pacific Standard Time cutoff for online submissions via the official portal, MDDataSettlement. com. For physical mail, the “mailbox rule” applied, requiring envelopes to bear a postmark no later than January 27, 2026. Packets received after this date without the requisite postmark were categorized as late and subject to rejection during the final accounting phase. Class members were required to utilize a Unique ID and PIN, provided in the Notice of Data Breach initially distributed on November 7, 2025, to validate their identity. The administration process bifurcated claims into two distinct categories, each with specific evidentiary load:

  • Cash Payment A (Documented Losses): Claimants seeking up to $5, 000 in reimbursement were required to upload or attach third-party documentation. Valid proofs included bank statements showing reversal fees, telephone bills detailing specific calls related to the breach, or credit monitoring invoices dated after July 8, 2023.
  • Cash Payment B (Flat Payment): Individuals absence specific documentation could elect a flat cash payment, estimated at $75. This amount remains subject to pro rata adjustment based on the total volume of valid claims filed by the January deadline.

serious Settlement Milestones

The January 27 deadline did not exist in isolation functioned as the final step in a rigid procedural timeline. The window for “active participation” (filing a claim) closed six weeks after the deadline for “passive resistance” (opting out).

M&D Capital Settlement: Procedural Timeline (2025-2026)
Date Action Item Requirement
November 7, 2025 Notice Commencement Direct mail and email notifications sent to 284, 326 identified class members.
December 13, 2025 Exclusion Deadline Last day to submit a written request to opt-out of the settlement class and retain individual suing rights.
December 13, 2025 Objection Deadline Final date to file a formal objection with the Queens County Supreme Court regarding settlement terms or legal fees.
January 27, 2026 Claim Filing Deadline Hard cutoff for all online Claim Forms and postmarked mail submissions.
February 11, 2026 Final Approval Hearing Court review of the settlement fairness, attorney fees (up to $350, 000), and service awards.

Documentation Standards for “Tier 1” Claims

For the subset of the class seeking the maximum $5, 000 reimbursement, the Settlement Administrator applied rigorous verification standards. The January 27 deadline required not just the submission of the form, the simultaneous provision of “Reasonable Documentation.” The settlement agreement defined acceptable evidence for these claims:

“Documentation must plausibly support that the claimed out-of-pocket expenses were actually incurred and are fairly traceable to the Data Incident. Self-prepared documents, such as handwritten notes or personal spreadsheets, are insufficient to meet this standard.”

Valid evidentiary submissions included: 1. Financial Records: Unreimbursed bank fees, overdraft charges, or late fees directly linked to fraud attempts post-July 2023. 2. Communication Logs: Phone bills documenting time spent resolving identity theft problem (compensated at a rate of $20-$25 per hour for lost time). 3. Credit Reports: Costs for purchasing credit reports or freezing/unfreezing credit files with Equifax, Experian, or TransUnion. 4. Professional Fees: Invoices from accountants or attorneys hired specifically to remediate identity theft caused by the M&D Capital breach.

Consequences of Inaction

Class members who failed to file a valid claim by the January 27, 2026, deadline forfeited all rights to monetary compensation from the $1, 000, 000 fund. also, because the Opt-Out deadline (December 13, 2025) had already passed, these individuals remained bound by the settlement’s release terms. They cannot sue M&D Capital Premier Billing or Island Ambulatory Surgery Center for the July 2023 data breach in the future, even though they received no payment. The settlement structure dictates that unclaimed funds do not revert to the defendants. Instead, if the total value of valid claims falls short of the net settlement fund, the surplus may be distributed to approved claimants (increasing the pro rata share) or directed to a cy pres recipient approved by the Court. Conversely, a high volume of claims filed by the January 27 cutoff dilute the estimated $75 flat payment, reducing it proportionally to ensure the fund covers all approved submissions.

Medical Monitoring Enrollment

Alongside monetary claims, January 27 also served as the deadline to enroll in the non-monetary benefit: two years of “CyEx” medical monitoring. This service includes single-bureau credit monitoring, dark web scanning, and $1 million in medical identity theft insurance. Unlike the cash payments, which required a choice between Tier 1 and Tier 2, the medical monitoring benefit was available to all valid claimants regardless of which cash option they selected. Failure to select this option on the Claim Form by the deadline resulted in a waiver of these protective services.

The 18 Day Intrusion Window. Forensic Analysis of the June to July Network Breach.

Island Ambulatory Surgery Center. The Co-Defendant Role in the Queens County Lawsuit.
Island Ambulatory Surgery Center. The Co-Defendant Role in the Queens County Lawsuit.
The $1 million settlement resolving the M&D Capital Premier Billing litigation hinges on a specific, catastrophic failure of network defense: an 18-day period of unauthorized access that went by internal security. Court documents and forensic reports filed with the Maine Attorney General confirm that the breach occurred between June 20, 2023, and July 8, 2023. During this window, threat actors navigated the servers of the New York-based medical billing firm, exfiltrating sensitive health and financial data belonging to 284, 326 individuals.

The 18-Day Dwell Time

In cybersecurity forensics, “dwell time” refers to the duration an attacker remains inside a network before detection. For M&D Capital, this period lasted exactly 18 days. The forensic investigation, conducted by third-party specialists, established that the initial intrusion vector was exploited on June 20, 2023. Unlike a “smash-and-grab” attack, the perpetrators maintained persistent access, allowing them to move laterally across the infrastructure. This extended window suggests the attackers had sufficient time to perform reconnaissance, map the network architecture, and identify the repositories containing high-value Protected Health Information (PHI). The breach was not identified until July 8, 2023, when M&D Capital’s IT administrators detected “suspicious activity” within the computer environment. By that time, the data extraction was likely complete. The failure to detect the intrusion for nearly three weeks became a central pillar of the class action lawsuit (Case No. 706879/2024), with plaintiffs arguing that standard intrusion detection systems (IDS) or endpoint detection and response (EDR) tools should have flagged the anomalous behavior earlier.

Forensic Timeline of the Breach

The following timeline reconstructs the sequence of events based on breach notification letters and settlement filings.

Date Event Forensic Detail
June 20, 2023 Initial Infiltration Unauthorized actor gains access to M&D Capital’s IT network.
June 20 , July 8, 2023 Lateral Movement & Exfiltration Actor accesses files containing SSNs, medical diagnosis codes, and billing info.
July 8, 2023 Detection & Lockdown M&D identifies suspicious activity; network is secured; third-party forensics engaged.
March 18, 2024 Public Notification Notification letters mailed to 284, 326 victims, eight months after detection.
January 27, 2026 Settlement Claim Deadline Final date for victims to file for the $1 million fund.

Data Exfiltration Specifics

The investigation confirmed that the attackers did not view the data likely acquired it. The compromised files contained a detailed profile of patients from clients like Island Ambulatory Surgery Center. The specific data elements exposed included: * Personal Identifiers: Full names, addresses, and dates of birth. * Financial Data: Social Security numbers and financial account information. * Medical Records: Medical billing details, insurance information, diagnosis codes, medication lists, and treatment histories. The combination of Social Security numbers and medical history creates a high risk of “medical identity theft,” where criminals use stolen credentials to obtain healthcare services or prescription drugs, chance corrupting the victim’s medical records. This specific risk factor drove the inclusion of “medical monitoring services” in the settlement terms, alongside standard credit monitoring.

The Notification Gap

A serious aspect of the forensic timeline is the eight-month gap between the discovery of the breach (July 8, 2023) and the notification of victims (March 18, 2024). While M&D Capital stated they were working with forensic specialists to determine the “nature and scope” of the activity during this period, the delay left victims unaware that their sensitive medical and financial data was compromised for nearly a year. State laws require notification “without unreasonable delay,” frequently defined as 30 to 60 days. The extended investigation period suggests the data environment was complex or unstructured, making it difficult for forensic teams to identify exactly which files were touched. This delay contributed to the legal pressure that resulted in the $1 million settlement fund, which allows class members to claim up to $5, 000 for documented losses incurred during the period they were left.

Settlement

The January 2026 settlement closes the liability regarding this 18-day window. By establishing a non-reversionary fund, M&D Capital and Island Ambulatory Surgery Center acknowledge the severity of the exposure without admitting legal wrongdoing. The settlement structure, offering both flat cash payments (estimated at $75) and reimbursement for documented losses, directly addresses the financial risks created during the June-July 2023 intrusion.

“The forensic investigation confirmed that an unauthorized third party gained access to its network on June 20, 2023, and maintained access until July 8, 2023.” , M&D Capital Premier Billing Breach Notice

This admission places the breach squarely within a timeframe where active monitoring should have detected the anomaly. The resolution of this case highlights the financial consequences of dwell time; every day an attacker remains on a network increases the chance damages and the subsequent settlement value.

CyEx Medical Monitoring. The Two Year Identity Protection Clause for Victims.

The CyEx Mandate: Two-Year Surveillance Protocol

The settlement agreement finalized in the Supreme Court of New York, Queens County, distinguishes itself by offering a specific tier of protection tailored to the nature of the compromised data. Unlike standard breaches involving only credit card numbers, the M&D Capital Premier Billing incident exposed diagnostic codes, medical histories, and insurance policy numbers. To address this, the settlement establishes a 24-month subscription to CyEx Medical Monitoring for all valid claimants. This benefit functions as an additive claim; class members may select this service alongside the cash indemnity options (Payment A or B) without forfeiting their monetary eligibility.

The selection of CyEx (Cyber Experts) addresses the specific latency risks associated with medical identity theft. Financial fraud is detected within days via banking alerts, medical identity theft, where a criminal uses a victim’s insurance to obtain surgery or prescription drugs, can remain for years until the victim is denied coverage or receives a phantom bill. The CyEx package funded by the $1 million settlement includes active monitoring of Medical Record Numbers (MRN) and Health Insurance IDs, scanning for unauthorized usage that could pollute a patient’s legitimate medical history.

Service Specifications and Coverage Limits

The negotiated coverage extends beyond simple credit reporting. The CyEx protocol integrates dark web surveillance with specific medical data points. The cost of these subscriptions is deducted from the Net Settlement Fund before the pro-rata distribution of cash payments, making the participation rate a determining factor in the final cash amounts distributed to the class.

Verified CyEx Settlement Benefits (2025-2026)
Protection Component Scope of Service Coverage Limit
Duration Continuous monitoring from activation date 24 Months
Insurance Policy Reimbursement for stolen funds and remediation costs $1, 000, 000 (No Deductible)
Medical Scanning Surveillance of Medical Record Numbers (MRN) & Insurance IDs Global Dark Web & Payer Databases
Credit Watch Single-bureau credit file activity alerts 1 Bureau (Experian, Equifax, or TransUnion)
Fraud Resolution Access to U. S.-based restoration agents Unlimited Case Management

Enrollment Mechanics and Deadlines

Access to the CyEx service is not automatic. The 284, 326 class members identified in the M&D Capital records must affirmatively opt-in by submitting a valid claim form before the January 27, 2026, deadline. The settlement administrator, operating out of Portland, Oregon, requires claimants to utilize the Unique ID and PIN provided in the mailed notices to validate their eligibility. Failure to activate the code within the prescribed window results in the forfeiture of the monitoring benefit, although the release of claims against M&D Capital remains in force.

serious Latency Factor: Industry analysis indicates that medical identity theft resolution costs the average victim $13, 500 to resolve, compared to less than $500 for standard credit card fraud. The two-year window provided by CyEx is designed to the gap between the July 2023 breach and the chance sale of the data on the black market.

The inclusion of a $1, 000, 000 insurance policy with zero deductible is a significant provision. This policy covers out-of-pocket expenses incurred if a class member suffers identity theft during the coverage period. Eligible expenses include legal fees, lost wages (up to specific caps), and costs associated with re-filing insurance claims or correcting medical records. This insurance acts as a secondary of financial defense, sitting atop the settlement’s own expense reimbursement category (Cash Payment A), which covers losses incurred prior to the settlement’s finalization.

California Attorney General Reports. The March 2024 Regulatory Disclosure Trail.

Tier A Compensation. The Strict Documentation Requirements for $5,000 Payouts.
Tier A Compensation. The Strict Documentation Requirements for $5,000 Payouts.

The March 18, 2024 California Filing

The regulatory disclosure trail for the M&D Capital Premier Billing data breach formally began in earnest on March 18, 2024, when the company filed a mandatory data security incident report with the California Attorney General’s office. This filing, submitted eight months after the initial detection of the intrusion, provided the detailed public account of the cyberattack that compromised the sensitive medical and financial records of 284, 326 individuals. The document, accessible through the California Department of Justice’s breach portal, outlined the specific forensic findings that would later underpin the $1 million class action settlement finalized in January 2026. According to the report submitted to the California regulators, M&D Capital Premier Billing identified “suspicious activity” within its network environment on July 8, 2023. This detection triggered an immediate isolation of affected systems and the engagement of third-party forensic specialists. The investigation, yet, revealed that the unauthorized access had commenced weeks earlier. The forensic timeline disclosed to the Attorney General established that threat actors maintained a persistent presence in the network from June 20, 2023, until the breach was contained on July 8, 2023. During this 19-day window, the attackers successfully exfiltrated files containing high-value protected health information (PHI). The March 2024 disclosure was pivotal because it confirmed the specific data elements exposed, moving the incident from speculation to confirmed liability. The filing detailed that the compromised datasets included names, Social Security numbers, financial account information, dates of birth, and detailed medical histories. Specifically, the report noted the exposure of medical billing details, insurance information, medical diagnoses, medication records, and treatment histories. This level of granularity in the regulatory filing provided the factual basis for the subsequent negligence claims, as it demonstrated that the breach affected not just administrative data the core privacy of patient health records.

The Eight-Month Notification Gap

A serious component of the regulatory trail is the significant time lapse between the breach discovery in July 2023 and the regulatory notification in March 2024. While the forensic investigation concluded that the intrusion ended in July, the process of data mining, identifying exactly which individuals were affected and finding their contact information, consumed the subsequent months. In its correspondence with the California Attorney General, M&D Capital Premier Billing stated that it began notifying the “entities through which it obtained consumers’ information” in January 2024. This internal B2B notification phase preceded the public and regulatory disclosures by two months. This delay became a central point of contention in the litigation that followed. California Civil Code requires businesses to notify affected residents “in the most expedient time possible and without unreasonable delay.” The eight-month interval raised serious questions regarding compliance with these timeliness standards. The regulatory filings suggest that the complexity of the unstructured data involved, likely scanned medical documents or complex billing databases, necessitated a manual review process to link specific health data to individual identities. This “review of the affected files” was only completed shortly before the March 2024 filings, a common defense in healthcare data breach cases where the volume of records impedes rapid notification.

Regulatory Timeline of Events

Table 10. 1: M&D Capital Premier Billing Regulatory Disclosure Timeline
Date Event Regulatory Implication
June 20, 2023 Network Intrusion Begins Start of unauthorized access period reported to AG.
July 8, 2023 Breach Detected Discovery date; triggers incident response and forensic clock.
Jan 2024 Client Notification M&D notifies corporate clients (e. g., Island Ambulatory) of chance impact.
March 18, 2024 CA Attorney General Filing Official public notice filed; consumer notification letters mailed.
April 5, 2024 Maryland AG Filing Island Ambulatory Surgery Center files separate/concurrent notice.
Jan 27, 2026 Settlement Claim Deadline End of the claims period for the $1M settlement fund.

Island Ambulatory Surgery Center’s Parallel Disclosures

The regulatory trail is not limited to M&D Capital Premier Billing alone. As a co-defendant and a primary covered entity, Island Ambulatory Surgery Center LLC also faced mandatory reporting obligations. The investigation reveals that Island Ambulatory relied on M&D Capital for billing services, meaning their patient data was resident on the compromised M&D systems. Following M&D’s disclosure, Island Ambulatory Surgery Center filed its own breach reports in multiple jurisdictions, including a notable filing with the Maryland Attorney General on April 5, 2024. These parallel filings show the cascading effect of a third-party vendor breach. While M&D Capital was the custodian of the data, the legal responsibility to notify patients frequently falls on the direct healthcare provider. The regulatory reports filed by Island Ambulatory mirrored the findings of M&D, citing the same June 20 to July 8, 2023 exposure window. yet, the dual-reporting structure complicated the regulatory, as patients received notifications that referenced both entities, sometimes leading to confusion regarding the source of the data leak. The January 2026 settlement consolidated these liabilities, with both M&D and Island Ambulatory contributing to the $1 million fund to resolve the claims arising from these joint regulatory admissions.

Forensic Specifics in the AG Report

The California Attorney General report contains specific admissions regarding the nature of the cyberattack. Unlike generic “security incident” descriptions, the M&D filing acknowledged that an “unauthorized party had gained access to its IT network.” This phrasing, distinct from ransomware descriptions that focus on encryption, suggests a data exfiltration event where information was copied and removed. The report confirmed that the attackers accessed “files containing confidential personal and medical information,” indicating that the breach was not limited to a specific database likely involved file servers or document repositories where unstructured data (like PDF scans of patient charts) was stored. The inclusion of “medical diagnosis” and “treatment” information in the compromised data fields is particularly damaging. In the context of the California Consumer Privacy Act (CCPA) and the California Confidentiality of Medical Information Act (CMIA), the exposure of such granular health data triggers higher statutory damages and stricter scrutiny. The regulatory disclosure did not specify if the data was encrypted at rest, a detail frequently omitted in initial AG filings serious in the subsequent settlement negotiations. The absence of an “encryption safe harbor” claim in the report implies that the data was likely accessible in a readable format once the network perimeter was breached.

Q&A: The Regulatory Impact

Q1: Why did M&D Capital wait until March 2024 to file with the California AG? A1: The company a lengthy forensic investigation and data review process. They needed to identify exactly whose data was in the compromised files before issuing notifications, a process that finished in early 2024. Q2: Did the California AG fine M&D Capital for the delay? A2: There is no public record of a specific fine from the California AG for the delay itself as of early 2026. The $1 million settlement resolves the civil liability, regulatory investigations can proceed separately. Q3: What specific California laws were triggered by this filing? A3: The filing was made pursuant to California Civil Code § 1798. 82, which mandates notification of any security breach involving unencrypted personal information. Q4: Did the report mention ransomware? A4: The regulatory filings describe “unauthorized access” and “suspicious activity” do not explicitly use the term “ransomware,” suggesting a data theft or espionage focus rather than a pure encryption-extortion attack. Q5: How California residents were affected? A5: While the total breach affected 284, 326 individuals nationally, the specific California count is a subset. yet, the filing with the CA AG is mandatory regardless of the number, as long as one resident is affected. Q6: Did Island Ambulatory file a separate report in California? A6: Island Ambulatory was listed as a related entity in various filings. In vendor breaches, the vendor (M&D) files on behalf of the covered entity, or they file jointly to avoid duplicate notices. Q7: What data types were listed in the “Medical Information” category? A7: The report specified diagnoses, medications, and treatments. This goes beyond standard billing codes and reveals actual clinical history. Q8: Was financial data part of the California report? A8: Yes, the filing confirmed the exposure of “financial information,” which includes bank account numbers or credit card details used for billing payments. Q9: Did the March 2024 filing trigger the class action lawsuit? A9: Yes, the class action complaints were filed shortly after the March 2024 notices were sent, citing the details admitted in the regulatory report as proof of negligence. Q10: Is the California AG report public? A10: Yes, the California Department of Justice maintains a searchable database of data breach notifications where this filing is accessible to the public. Q11: Did the report indicate if the breach was resolved? A11: The report stated that M&D “secured their network” on July 8, 2023, implying the vulnerability was patched and the unauthorized access was terminated on that date. Q12: What role did “ASC Strategic Services” play in the report? A12: ASC Strategic Services LLC was listed as a related company in the breach notice, indicating they are likely an affiliate or subsidiary of M&D Capital involved in the data processing. Q13: Did the report mention Social Security numbers? A13: Yes, Social Security numbers were explicitly listed as compromised data elements in the regulatory filing. Q14: How does the “Jan 2026” settlement relate to this report? A14: The settlement fund of $1 million is the direct financial resolution of the claims that arose from the facts established in this March 2024 regulatory report. Q15: Was the notification sent via email or mail? A15: The regulatory filing indicates that data breach notification letters were mailed to affected individuals, which is the standard requirement for formal legal notice. Q16: Did the report mention credit monitoring? A16: Yes, the filing noted that M&D Capital was offering credit monitoring services to affected individuals, a standard mitigation step included in the settlement. Q17: Who signed the regulatory filing? A17: The filing was submitted by legal counsel on behalf of M&D Capital Premier Billing LLC. Q18: Did the breach involve email accounts or a server? A18: The report refers to the “computer network” and “IT network,” which implies a broader system compromise rather than just a single email account compromise. Q19: Were other states notified simultaneously? A19: Yes, filings in Maryland, Maine, and other states occurred around the same March-April 2024 timeframe, following the completion of the forensic review. Q20: Does the report absolve M&D of liability? A20: No, a data breach report is an admission of a security incident, not an absolution. It serves as the factual basis for regulators and plaintiffs to assess liability.

for the Settlement Class

The details contained within the California Attorney General’s report directly influenced the structure of the January 2026 settlement. The admission that Social Security numbers and financial data were compromised placed the class members in a high-risk category for identity theft, justifying the provision for credit monitoring and the cash payments for documented losses. The “Common Fund” of $1, 000, 000 was calculated based on the risks associated with this specific type of data exposure. Had the report only listed names and addresses, the settlement value would likely have been significantly lower. also, the “medical information” disclosure opened the door for claims related to medical identity theft, a complex crime where a thief uses a victim’s insurance to obtain care. This specific risk factor, documented in the regulatory trail, necessitated the inclusion of “medical monitoring services” as an option for class members in the settlement agreement. The March 2024 disclosure thus served as the blueprint for the relief package approved by the Supreme Court of New York, Queens County.

“The forensic investigation confirmed that an unauthorized third party gained access to its network on June 20, 2023, and maintained access until July 8, 2023.” , Excerpt from M&D Capital Premier Billing Regulatory Filing

The regulatory trail also highlights the interconnected nature of modern healthcare billing. The breach at M&D Capital did not just affect their direct clients cascaded down to the patients of the healthcare providers they served, such as Island Ambulatory Surgery Center. The regulatory filings by these downstream entities demonstrate the “fan-out” effect of a supply chain breach, where a single vulnerability in a billing vendor triggers a multi-state regulatory compliance event for dozens of medical practices. The March 2024 reports stand as the definitive record of this widespread failure, documenting exactly how a three-week security lapse resulted in a multi-year legal and financial.

Skolnick v. M&D Capital. The Class Action Mechanism Driving the Settlement.

The Legal Vehicle: Skolnick v. M&D Capital

The operative legal method driving the $1 million resolution is the class action lawsuit captioned Jacqueline Skolnick, et al. v. M&D Capital Premier Billing, LLC and Island Ambulatory Surgery Center LLC. Filed on March 28, 2024, in the Supreme Court of the State of New York, County of Queens, the case bears Index No. 706879/2024. This litigation consolidated the claims of approximately 284, 326 individuals whose sensitive personal and medical data was exposed during the July 2023 network intrusion. The presiding judge, Justice Joseph J. Risi, oversaw the proceedings from the initial filing through the preliminary approval of the settlement in late 2025.

Core Allegations and Legal Theories

Plaintiff Jacqueline Skolnick, acting as the Class Representative, asserted three primary causes of action against the defendants: negligence, breach of implied contract, and unjust enrichment. The complaint argued that M&D Capital Premier Billing and its client, Island Ambulatory Surgery Center, failed to implement reasonable cybersecurity necessary to protect Patient Health Information (PHI) and Personally Identifiable Information (PII). Specifically, the plaintiffs contended that the defendants did not follow industry standards for data encryption and network monitoring, which directly facilitated the unauthorized access detected on July 8, 2023. The lawsuit further alleged that the defendants delayed notification, as affected individuals were not informed until March 2024, nearly eight months after the breach discovery.

From Litigation to Mediation

Court records indicate that the defendants initially denied all liability and wrongdoing, filing motions to dismiss the claims. yet, rather than proceeding to a protracted trial, the parties engaged in alternative dispute resolution. On February 27, 2025, the legal teams for both sides participated in a full-day mediation session. This negotiation resulted in the “Common Fund” structure, where M&D Capital agreed to pay a non-reversionary sum of $1, 000, 000. The term “non-reversionary” is serious here; it ensures that no portion of the settlement fund returns to the defendants, even if the number of claimant filings is lower than anticipated. Instead, any residual funds are redistributed pro rata to the participating class members.

Procedural Milestones and Approval

The transition from a disputed lawsuit to a structured settlement followed a strict procedural timeline mandated by New York state law. Following the successful mediation in February 2025, the plaintiffs filed an unopposed motion for preliminary approval. Justice Risi granted this motion on October 8, 2025, which provisionally certified the settlement class and authorized the notice program. This order triggered the 90-day window for class members to file claims, object, or opt out. The objection and exclusion deadline was set for December 13, 2025, while the final deadline for submitting claim forms was scheduled for January 27, 2026.

Table 11. 1: Procedural Timeline of Skolnick v. M&D Capital (Index No. 706879/2024)
Event Date Significance
Breach Discovery July 8, 2023 M&D Capital detects unauthorized network access.
Complaint Filed March 28, 2024 Skolnick initiates class action in Queens Supreme Court.
Mediation Session February 27, 2025 Parties agree to $1M Common Fund structure.
Preliminary Approval October 8, 2025 Justice Risi certifies the class for settlement purposes.
Objection Deadline December 13, 2025 Last date for class members to oppose terms.
Claim Deadline January 27, 2026 Final cutoff for victims to request monetary compensation.

Class Counsel and Legal Fees

The court appointed a specific team of attorneys to represent the settlement class, as “Class Counsel.” This group includes Andrew Shamis of Shamis & Gentile, P. A., Jeff Ostrow of Kopelowitz Ostrow Ferguson Weiselberg Gilbert, and attorneys Mariya Weeks, Raina Borrelli, Jean Martin, and Jen Czeisler. The settlement agreement stipulates that Class Counsel can apply for attorneys’ fees up to $350, 000 (35% of the total fund) plus reimbursement of litigation costs. These fees are paid directly from the $1 million fund, reducing the net amount available for claimant distribution. also, the Class Representative, Jacqueline Skolnick, is allocated a service award of up to $3, 000 for her role in the litigation.

Defense Position and Release of Claims

While agreeing to the $1 million payout, M&D Capital and Island Ambulatory Surgery Center maintained a denial of all legal claims. The settlement agreement contains specific language stating that the resolution is not an admission of guilt or a validation of the plaintiff’s negligence theories. By accepting the settlement terms, class members agree to a “Release of Claims,” which legally bars them from filing any future lawsuits against the defendants regarding the July 2023 data breach. This release became for all class members who did not actively opt out by the December 13, 2025 deadline.

“Defendants do not in any way acknowledge, admit to, or concede any of the allegations made in the Complaint, and expressly disclaim and deny any fault or liability, or any charges of wrongdoing that have been or could have been asserted in the Action.”
, Excerpt from the Settlement Agreement, Skolnick v. M&D Capital.

The Settlement Class Definition

The court defined the “Settlement Class” as all individuals residing in the United States whose Private Information was accessed or acquired during the Data Incident. This definition encompasses the 284, 326 individuals notified by M&D Capital in March 2024. The broad definition ensures that patients from various healthcare providers serviced by M&D, not just Island Ambulatory Surgery Center, are eligible for relief, provided their data was resident on the compromised server during the intrusion window.

February 11, 2026. The Final Approval Hearing at Queens County Supreme Court.

The Honorable Joseph J. Risi presided over the final approval hearing for the Skolnick et al. v. M&D Capital Premier Billing LLC class action settlement on the morning of February 11, 2026. Held at the Queens County Supreme Court in Jamaica, New York, this proceeding marked the legal conclusion of the litigation stemming from the July 2023 data breach. The hearing addressed the fairness, reasonableness, and adequacy of the $1 million non-reversionary settlement fund established to compensate the approximately 284, 326 individuals whose private health information was compromised. ### Judicial Review of the Settlement Agreement The primary objective of the February 11 session was to secure the court’s final judgment on the settlement terms proposed in late 2025. Under New York Civil Practice Law and Rules (CPLR) Article 9, the court examined whether the agreement provided sufficient relief to the class members compared to the risks and delays of continued trial. The plaintiffs, represented by class counsel, argued that the $1 million fund represented a significant recovery, particularly given the complexities of proving specific damages in data breach cases. The court reviewed the distribution plan, which allocates funds for valid claims, administrative costs, and legal fees. A key component of the approval was the “non-reversionary” nature of the fund, ensuring that no portion of the $1 million settlement returns to M&D Capital Premier Billing or Island Ambulatory Surgery Center. Instead, any residual funds after the initial distribution be redistributed to claimants on a pro rata basis or donated to a cy-près recipient approved by the court, rather than reverting to the defendants. ### Financial Allocation and Attorneys’ Fees of the hearing focused on the disbursement of the settlement capital. The court approved the request for attorneys’ fees and litigation costs, capped at $350, 000, representing 35% of the total fund. This fee structure is consistent with standard contingency fee arrangements in complex class action litigation. also, the court authorized service awards totaling $18, 000 for the six class representatives, Jacqueline Skolnick, Ashley Dixon, Candice Facon, Benjamin Kashvili, Youn Lee, and Jillian Maloney, who each received $3, 000 for their role in the lawsuit and participating in the discovery process. The remaining capital, approximately $632, 000 (after deducting administrative expenses estimated at roughly $150, 000), is for direct payments to class members. The settlement administrator, Epiq Global, reported on the claims process, noting that the deadline for submitting claims had passed on January 27, 2026. The administrator is tasked with validating these submissions before dispersing checks.

Table 1: Settlement Fund Disbursement Breakdown (Approved Feb 11, 2026)
Category Allocation Amount (Approx.) Percentage of Fund Recipient/Purpose
Net Settlement Fund $632, 000 63. 2% Class Member Payments (Cash A & B)
Attorneys’ Fees & Costs $350, 000 35. 0% Class Counsel (Legal Services)
Service Awards $18, 000 1. 8% 6 Class Representatives ($3k each)
Administrative Expenses Variable (Est. Included above) N/A Epiq Global (Notice & Processing)
Total Fund $1, 000, 000 100% Total Liability Cap

### Resolution of Claims and Liability The Final Approval Order dismisses the litigation with prejudice, meaning the plaintiffs cannot file the same claims again. The lawsuit, filed under Index No. 706879/2024, alleged negligence, breach of implied contract, and unjust enrichment. The plaintiffs contended that M&D Capital Premier Billing failed to implement adequate cybersecurity measures, leading to the unauthorized access of sensitive data, including Social Security numbers, medical diagnosis codes, and health insurance information. Throughout the settlement process and at the final hearing, the defendants, M&D Capital Premier Billing LLC and Island Ambulatory Surgery Center LLC, maintained their denial of all liability. The settlement agreement explicitly states that the $1 million payment is not an admission of wrongdoing a compromise to avoid the uncertainty and expense of prolonged litigation. The court’s approval validates this resolution, releasing the defendants from all future claims related to the July 2023 data incident. ### Claims Processing and Compensation Tiers With the court’s final approval, the focus shifts to the distribution of benefits. The settlement structure offers two primary tiers of compensation for the 284, 326 eligible class members. The “Documented Loss Payment” (Cash Payment A) allows individuals to claim up to $5, 000 for proven out-of-pocket expenses, such as bank fees, communication charges, and costs associated with credit freezing or identity theft resolution. The second option, “Cash Payment B,” provides a flat cash payment, initially estimated at $75. yet, the final amount depends on the total number of valid claims submitted. The “pro rata” clause ensures that if the total value of valid claims exceeds the available net settlement fund, all payments be reduced proportionally. Conversely, if participation is low, the per-person payment may increase. to monetary relief, the settlement provides two years of “CyEx” medical monitoring services. This benefit is particularly relevant given the exposure of medical history data. The monitoring package includes dark web surveillance for medical credentials and insurance fraud alerts, a service valued separately from the cash fund. ### The Role of the Settlement Administrator Epiq Global, appointed as the Settlement Administrator, presented data on the notice campaign’s reach. The notification process, which commenced in November 2025, involved sending direct mail and email notices to the identified class members. The administrator’s report confirmed that the notice program met the “due process” requirements by reaching a high percentage of the affected population. Epiq Global is responsible for the final adjudication of claims. This involves verifying documentation for the $5, 000 loss claims and ensuring no duplicate filings for the flat fee payments. The distribution of funds is expected to commence approximately 75 days after the Final Approval Order becomes non-appealable, placing the estimated payout date in mid-2026. ### Key Questions Addressed at the Hearing 1. What was the specific legal standard for approval? The court applied the standard that the settlement must be “fair, reasonable, and adequate” for the class members, ensuring the relief outweighs the chance rewards of a trial. 2. Did any class members object? The deadline to object was December 13, 2025. The court record reflected a minimal number of objections, which is common in settlements of this magnitude, and none were sufficient to derail the approval. 3. What happens to uncashed checks? If class members fail to cash their settlement checks within the allotted time ( 180 days), those funds not return to the defendants. They likely be redistributed to a cy-près beneficiary, frequently a non-profit organization related to data privacy or consumer protection. 4. How does this settlement compare to similar healthcare breaches? The $1 million fund for ~284, 000 victims equates to roughly $3. 51 per person gross, before fees. While lower than massive financial breaches, it aligns with healthcare settlements where specific financial harm is harder to prove than direct credit card theft. 5. What specific data was exposed? The breach involved names, addresses, Social Security numbers, medical billing details, insurance information, and diagnosis codes. The sensitivity of this data drove the inclusion of medical monitoring services. 6. Who represented the defendants? Counsel for M&D Capital Premier Billing and Island Ambulatory Surgery Center were present to confirm their clients’ assent to the fund and the release of claims. 7. Is the credit monitoring retroactive? No, the two-year credit and medical monitoring service begins upon activation by the class member after the final settlement approval. 8. Can victims still sue individually? No. Unless a class member validly exercised their right to “opt-out” by the December 13, 2025 deadline, they are bound by this settlement and cannot pursue separate legal action for the same breach. 9. What was the ” Date”? The settlement becomes 30 days after the entry of the Final Approval Order, provided no appeals are filed. This triggers the timeline for payment distribution. 10. Why was Island Ambulatory Surgery Center included? As a client of M&D Capital, Island Ambulatory’s patient data was processed on the compromised network. They were named as a co-defendant to ensure a detailed release of liability for all parties involved in the data chain. ### for Data Privacy Litigation The conclusion of Skolnick et al. v. M&D Capital Premier Billing LLC highlights the continued legal risks healthcare vendors face regarding third-party data handling. The settlement show the strict liability standards frequently applied in public opinion, even if legally denied in court. For the victims, the February 11 hearing brings closure to a three-year saga of uncertainty regarding their medical privacy. The focus remains on the administrative execution of the settlement, ensuring that the approved funds reach the verified claimants.

Keep exploring...

Breaking News and Daily Headlines from Around the World You Need to Know

Lorem ipsum dolor sit amet consectetur adipiscing elit, auctor ridiculus vitae laoreet duis facilisi, phasellus pulvinar et malesuada nec nisl. Torquent eros fringilla vivamus...

Stay Informed with the Latest Updates on Politics, Sports, and Global Affairs

Lorem ipsum dolor sit amet consectetur adipiscing elit, auctor ridiculus vitae laoreet duis facilisi, phasellus pulvinar et malesuada nec nisl. Torquent eros fringilla vivamus...

Advertisements

spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img

Related Articles

How Buying Clothes from BLM Designated Stores Helps the Movement

Doing business like this takes much more effort than doing your own business at...

Streaming Services that Bring Your Favorite Teams Live

Doing business like this takes much more effort than doing your own business at...

Home Deliveries Are the Go To for Online Clothes Stores

Doing business like this takes much more effort than doing your own business at...

Take Precautions When Shopping at Huge Malls to Prevent Viruses

Doing business like this takes much more effort than doing your own business at...

This Building Can Be Seen from Space Due to its Immense Structure

Doing business like this takes much more effort than doing your own business at...

Protests Across the US Against the Ideas of President Trump

Doing business like this takes much more effort than doing your own business at...

What are Barack Obama’s Thoughts on the Current US Leadership?

Doing business like this takes much more effort than doing your own business at...

Taking Steps to Creating a Better Planet for Future Generations

Doing business like this takes much more effort than doing your own business at...