Medical Management Resource Group LLC (MMRC), doing business as American Vision Partners, has agreed to settle class action litigation stemming from a 2024 data breach. MMRC identified suspicious activity within its computer systems on November 14, 2023. The forensic investigation confirmed on or around December 6, 2023, that certain systems had been accessed by an unauthorized third party, and files had been exfiltrated from its network, some of which contained patient information.
Data compromised in the incident included names, contact information, dates of birth, medical information, clinical records, and medications. A subset of individuals also had their Social Security numbers compromised. The data breach was reported to the HHS Office for Civil Rights on February 6, 2026, as affecting more than 2.
35 million individuals; however, the OCR breach portal was later updated with a slightly smaller figure of 2,264,157 individuals. The class action lawsuit states that approximately 1. 6 million Americans were affected by the data breach.
Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint – Hulewat et al. v. Medical Management Resource Group LLC d/b/a American Vision Partners, et al – as they had overlapping claims.
The consolidated lawsuit was filed in the United States District Court for the District of Arizona, where it is currently pending. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The lawsuit also named Barnet Dulaney Perkins Eye Center, PC, Marc Ellman, M.
D. , P. A.
d/b/a Southwest Eye Institute, Southwestern Eye Center, Ltd. , and Eye Associates of Nevada d/b/a Wellish Vision Institute as co-defendants. The defendants filed a motion to dismiss, and the defendants Eye Associates of Nevada d/b/a Wellish Vision Institute and Marc Ellman, M.
D. P. A.
d/b/a Southwest Eye Institute were dismissed from the action. The lawsuit alleges that the cyberattack and data breach occurred as a result of the failure of the defendants to implement reasonable and industry-standard data security practices, and asserted claims for negligence, negligence per se , breach of third-party beneficiary contract, unjust enrichment, and violation of the Arizona Consumer Fraud Act.
The parties engaged in informal discovery and discussed the option of a settlement to avoid the cost and risks of a trial and related appeals. A suitable settlement was negotiated that was acceptable to all parties, and the settlement agreement has received preliminary approval from the court. Under the terms of the settlement, a $1,750,000 settlement fund will be established to cover attorneys’ fees, settlement administration costs, and service awards for the seventeen class representatives.
The remainder of the settlement fund will be used to pay benefits to the class members. Settlement class members are divided into two subclasses: A Damages Subclass that consists of approximately 258,070 individuals who had their Social Security numbers and other private information compromised in the incident, and an Injunctive Relief Subclass, which consists of all individuals whose personal information is collected or maintained by the defendant.
Individuals in the Damages Subclass may submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $3,000 per class member. Alternatively, members of this subclass may claim a pro rata cash payment, the value of which will depend on the number of valid claims received. Members of the injunctive relief subclass may not submit a claim but will benefit from commitments to improve business practices and additional cybersecurity measures.
Those measures include the appointment of a Chief Information Security Officer (CISO) to oversee security and a host of cybersecurity measures, valued at $2,787,630. The deadline for objection and opting out is October 13, 2026. Claims must be submitted by November 12, 2026, and the final fairness hearing has been scheduled for December 10, 2026.
March 12, 2024: Class Action Lawsuits Filed Against American Vision Partners Over Data Breach Class action lawsuits are stacking up against Medical Management Resource Group LLC (MMRC), which does business as American Vision Partners, over a major data breach that was announced in early February. MMRC discovered a breach of its systems on November 14, 2023, and the investigation confirmed that the protected health information of 2,350,236 individuals was stored on the compromised parts of its network.
The individuals affected by the data breach had their names, contact information, dates of birth, medical information, clinical records, Social Security numbers, and health insurance information exposed. Notification letters were sent to those individuals last month and they were offered complimentary credit monitoring services. Between February 23 and February 28, three class action lawsuits were filed in the US District Court for the District of Arizona by patients whose protected health information was compromised in the breach.
The lawsuits allege negligence and claim that MMRC/American Vision Partners failed to implement reasonable and appropriate cybersecurity measures to protect the sensitive data stored on their networks and failed to follow industry best practices for cybersecurity despite being aware of the high risk of cyberattacks on the healthcare sector. The lawsuits, Yaeger v.
Medical Management Resource Group LLC d/b/a American Vision Partners, Daley v. Medical Management Resource Group LLC d/b/a American Vision Partners, and Moudgal v.
Originally published at hipaajournal.com


