
Patients of an Arizona-based eye care network could soon see payouts of up to $3,000 apiece after a federal judge signs off on a settlement stemming from a late-2023 data breach that exposed Social Security numbers belonging to nearly 260,000 people. Medical Management Resource Group, which does business as American Vision Partners, agreed to the $1.75 million cash settlement in June 2026 while denying any wrongdoing.
The breach, which unfolded between November 14 and December 6, 2023, exposed patient names, birth dates, contact information, medical history, clinical records, medications, and health insurance details, according to The HIPAA Journal. Social Security numbers were exfiltrated for a smaller subgroup of 258,070 people, and it's that group that stands to benefit most directly from the cash fund. As Cleveland.com reports, a class action lawsuit accused American Vision Partners of failing to adequately protect patients' sensitive information.
The case, consolidated as *Hulewat et al. v. Medical Management Resource Group LLC d/b/a American Vision Partners, et al.*, is pending before U.S. District Judge Diane J. Humetewa in the District of Arizona. The lawsuit also named partner providers Barnet Dulaney Perkins Eye Center, PC, and Southwestern Eye Center, Ltd. as co-defendants, clarifying which clinic brands actually treated the affected patients. Medical Management Resource Group provides shared IT infrastructure, administrative support, and practice management services to 12 affiliated ophthalmology practice groups spanning Arizona, Texas, New Mexico, Nevada, and California, which explains how a single breach rippled across so many regional eye clinics.
Who Qualifies and What They Can Get
The settlement splits affected individuals into two groups. A Damages Settlement Class of roughly 258,070 people whose Social Security numbers were compromised can pursue a pro rata cash payment or up to $3,000 in reimbursement for documented out-of-pocket losses tied to the breach, per the settlement notice. A broader Injunctive Relief Class covering about 1.6 million patients nationwide won't receive direct payouts but benefits from the operational security changes American Vision Partners is required to make.
That pro rata payment amount isn't fixed. It depends on the total number of verified claims submitted, so the more people who file, the smaller each individual share could shrink. Claimants seeking the $3,000 reimbursement must submit documentation such as receipts for credit-monitoring services to support their losses.
A Notably Smaller Number Than Federal Filings Suggested
The settlement's scope looks modest next to what American Vision Partners initially told federal regulators. In February 2024, the company reported the breach to the U.S. Department of Health and Human Services' Office for Civil Rights as affecting 2,350,236 patients, though the official OCR portal was later revised down to 2,264,157 individuals, according to The HIPAA Journal. That means the class action's 1.6 million patient figure, and especially the 258,070-person damages class, represents a fraction of the total population the company originally flagged as impacted. The breach was described as one of the largest involving an eye care physician services company.
Beyond the cash fund, American Vision Partners agreed to pay for cybersecurity measures valued at more than $2.7 million, which include hiring a chief information officer and creating a cybersecurity steering committee. All class members who don't opt out will automatically receive two years of complimentary medical data monitoring once the court grants final approval, with no separate claim form required.
Legal Fees Could Take a Sizable Cut
Plaintiffs' attorneys are requesting up to 35% of the $1.75 million cash fund for legal fees, according to a settlement summary reported by PR Newswire. On top of that, the settlement allows for expense reimbursements up to $75,000 and service awards of up to $10,000 for each of the 17 named class representatives who brought the case. Those figures mean a substantial share of the $1.75 million pool could go toward legal costs before any money reaches the hundreds of thousands of eligible patients.
Settlement notice recipients and anyone who believes they were impacted by the breach can submit a claim online or mail a printed claim form to the settlement administrator. The deadline to file a claim is November 12, 2026, per Cleveland.com's reporting, while class members have until October 2026 to object to or exclude themselves from the settlement ahead of the Final Fairness Hearing, scheduled for December 10, 2026, in Phoenix.
Not the Company's First Regulatory Trouble
This isn't the first time American Vision Partners and its affiliated practices have faced federal scrutiny. In January 2023, the company and Barnet Dulaney Perkins Eye Center entered into a $725,000 consent decree with the U.S. Department of Justice to resolve allegations that they violated the Americans with Disabilities Act by failing to provide transfer assistance to surgical eye patients with mobility disabilities. Judge Humetewa's approval of the current data breach settlement would close out a separate chapter of legal exposure for the Arizona-based provider network.








-4.webp?w=1000&h=1000&fit=crop&crop:edges)
