American Vision Partners and related eye-care companies have agreed to a proposed settlement over a 2023 cyberattack. Cash benefits are limited to a smaller group, the payment amount is not fixed, and doing nothing could surrender future legal claims.
TL;DR
- American Vision discovered a cyberattack on or about November 14, 2023. The settlement notice says an unauthorized third party accessed its network and information belonging to approximately 1.6 million people.
- The plaintiffs allege the information potentially accessed included names, birth dates, Social Security numbers, contact details, medical-treatment information and health-insurance information. The defendants deny wrongdoing.
- A proposed settlement creates a $1.75 million fund, but only the approximately 258,070 people whose Social Security numbers and other personal information were compromised belong to the class eligible to claim cash benefits.
- Eligible claimants may seek either a variable pro-rata payment or reimbursement of documented losses traceable to the incident, capped at $3,000 per claimant.
- The defendants also agreed to cybersecurity measures valued in the notice at approximately $2,787,630, separate from the cash fund. The notice does not state how long each measure must remain in place.
- The court has not approved the settlement finally and has made no finding that the defendants did anything wrong. The final fairness hearing is scheduled for December 10, 2026.
The proposal offers money and security changes, but its most immediate consequence is procedural: class members must act if they want payment, want out, or want the judge to hear an objection.
Transparency Notice
This investigation relies on the court-authorized long-form notice for the proposed settlement in Hulewat et al. v. Medical Management Resource Group LLC d/b/a American Vision Partners, et al., Case No. 2:24-cv-00377-DJH. The notice contains allegations made by the plaintiffs, the defendants’ denial, and the proposed settlement terms. The court has not decided whether the defendants are liable and has not yet granted final approval to the settlement.
The Facts
The lawsuit followed a cyberattack that American Vision discovered on or about November 14, 2023. According to the settlement notice, an unauthorized third party gained access to the defendants’ computer network and information associated with approximately 1.6 million individuals.
The defendants are Medical Management Resource Group, LLC, doing business as American Vision Partners; Barnet Dulaney Perkins Eye Center, PC; and Southwestern Eye Center, Ltd. The case is being overseen by Judge Diane J. Humetewa in the United States District Court for the District of Arizona.
The plaintiffs allege that cybercriminals may have accessed names, dates of birth, Social Security numbers, contact information, medical-treatment information and health-insurance information. The latter medical and insurance records are forms of protected health information under the Health Insurance Portability and Accountability Act, commonly called HIPAA.
The notice does not establish that every listed data category was exposed for every affected person. It also does not report a judicial finding about what security failure permitted access, whether the defendants could have prevented it, or whether the compromised information was subsequently misused.
“No court or other judicial body has made any judgment or other determination that Defendant has done anything wrong.”Long-form settlement notice, Question 2
One Incident, Two Very Different Classes
The headline number—approximately 1.6 million people—does not describe the group eligible to submit claims for money. The proposed settlement creates two classes with different rights.
The damages class
Approximately 258,070 U.S. residents whose Social Security numbers and other personal information were compromised belong to the damages settlement class. Subject to the exclusions stated in the notice, these are the people who may submit claims for cash benefits.
The injunctive-relief class
The second class includes all individuals whose personal information is collected or maintained by the defendants. “Injunctive relief” means a required change in conduct rather than a payment to each class member. Here, it refers to the defendants’ promised cybersecurity practices.
The proposed deal’s broadest class receives the benefit of promised security changes. Its much smaller damages class is the group eligible to ask for money.
This distinction matters because inclusion in the wider injunctive-relief class does not, by itself, make someone eligible for a cash claim. Anyone uncertain about inclusion is directed by the notice to the settlement administrator at AmericanVisionSettlement.com or (833) 630-5366.
What the $1.75 Million Fund Actually Offers
A damages-class member who submits a valid claim on time must choose between two forms of relief. The first is a pro-rata cash payment. In practical terms, the available money will be divided among qualifying claims, so the amount may rise or fall depending on the claims and the fund’s limit. The notice does not promise a specific payment.
The second option is reimbursement for documented out-of-pocket losses reasonably and fairly traceable to the incident, up to $3,000 per claimant. The notice identifies potentially eligible expenses including unreimbursed fraud or identity-theft losses, professional fees, credit-repair services, credit freezes, qualifying credit monitoring and certain communication, postage, copying, mileage and notary expenses.
Claimants seeking reimbursement must provide supporting records and attest that the losses came from the data incident rather than another cause. A self-prepared record, such as a handwritten receipt, is not enough by itself, although the administrator may consider it alongside other documentation.
The fund is not reserved exclusively for class-member checks
Class counsel plans to request attorneys’ fees equal to 33.33% of the settlement’s value and reasonable litigation costs. The lawyers also plan to request service awards of up to $2,500 for each plaintiff. The notice says court-approved fees, costs and service awards will be paid from the settlement fund. The judge may approve less than the requested amounts.
The Cybersecurity Commitments Are Worth More on Paper Than the Cash Fund
The notice values the proposed cybersecurity measures at approximately $2,787,630—more than the $1.75 million damages fund. It says the defendants will bear those costs separately from the fund.
The listed commitments include creating and maintaining a chief information officer role; retaining a dedicated information-security training specialist; and operating a steering committee that includes the company’s security officer, chief information officer, chief executive officer, general counsel and other senior managers.
The proposal also calls for company-wide cybersecurity training, monthly vulnerability scans and periodic penetration testing by an independent vendor. Penetration testing is a controlled effort to find weaknesses by testing how systems withstand attempted intrusion. The notice says identified risks would be classified using the Common Vulnerability Scoring System, a framework for rating their severity.
Other commitments cover tighter classification and access controls for electronic health information, outside management of security-monitoring operations and the corporate firewall, improved email security and disaster recovery, regular risk assessments by external vendors, and updated incident-response policies.
These are described as contractually enforceable obligations if the settlement becomes final. There is, however, a significant detail missing from the notice: it says the measures will remain in place for a minimum period “to be addressed in a long-form settlement agreement,” but it does not provide the duration for each commitment.
The Deadlines—and the Cost of Doing Nothing
The legal choices are not interchangeable. Filing a claim seeks a benefit. Objecting asks the court not to approve some or all of the deal as presented. Opting out rejects the settlement and preserves the right to pursue a separate case over the incident, while giving up settlement benefits.
Deadline for mailed opt-out requests and objections to be postmarked.
Deadline to submit a claim online or have a mailed claim postmarked.
Scheduled final fairness hearing at the Sandra Day O’Connor U.S. Courthouse in Phoenix, where the judge will consider the settlement, objections, attorneys’ fees, costs and service awards.
A final fairness hearing is the proceeding at which the judge decides whether a class settlement is fair, reasonable and adequate. It is not a trial over whether the defendants caused the alleged harm. Approval would make the settlement binding, subject to any appeals.
“If you do nothing, you will not receive any benefits from this settlement.”Long-form settlement notice, Question 22
If the settlement receives final approval, a class member who neither claims nor opts out receives no damages-class benefit but remains bound by the release. That release covers claims that were or could have been brought against the defendants and related entities over the data incident. The precise legal scope appears in Section 7 of the settlement agreement, according to the notice.
What the Court Has—and Has Not—Decided
The court authorized distribution of the notice so potentially affected people could learn about the deal and their options. That authorization is not a ruling that the plaintiffs proved their allegations, and it is not final approval of the settlement.
The defendants deny wrongdoing. The plaintiffs and class counsel support the proposal because, according to the notice, it avoids the expense and risk of trial and appeals while providing benefits. The court has not chosen either side on the underlying claims.
Benefits will be distributed only after the court approves the settlement and the time for appeals has expired. If appeals are filed, distribution must wait until they are resolved. The notice does not provide a payment date.
What a Legitimate Fix Looks Like
Editorial analysisThe source document is a settlement notice, not a forensic security report. It does not explain the attack’s technical cause, identify a previously ignored warning, or establish that any defendant violated a legal duty. That limits what can responsibly be said about whether the proposed remedies address the original weakness.
The listed measures nevertheless provide a framework against which the final agreement and implementation can be judged.
Measurable duration
Each promised control should have a clear start date, minimum duration and responsible executive—not merely a general commitment to maintain better security.
Independent verification
External testing is more meaningful when the agreement specifies how often it occurs, how serious findings are tracked and who confirms remediation.
Visible accountability
A steering committee can distribute responsibility or dilute it. The final terms should make clear who owns unresolved risks and how compliance is documented.
Usable compensation
A claims process should tell affected people what evidence is acceptable and how disputed claims can be corrected before rejection.
What to Watch
- The fee motion: Class counsel’s request for 33.33% of the settlement’s value, along with litigation costs, remains subject to court approval.
- The security timetable: The notice lists extensive cybersecurity obligations but does not disclose the minimum duration assigned to each one.
- Objections: Timely objections may identify disputes over the fund, releases, fee request, security terms or other provisions. The court will consider valid objections at the fairness hearing.
- Final approval: The federal district court must still determine whether the proposal is fair, reasonable and adequate.
- Claim volume: Because the ordinary cash payment is pro rata, the notice cannot yet state what each approved claimant will receive.
- Appeals and distribution: Even after approval, benefits will not be distributed until the appeal period ends and any appeals are resolved.
What Remains Unresolved
The proposed settlement supplies a structure for compensation and future security practices, but it does not resolve the incident’s full factual record. The notice does not identify the technical route of entry, establish which safeguards existed before November 2023, determine whether particular stolen records were misused, or quantify losses across the affected population.
It also leaves the value of an ordinary cash claim unknown. That figure depends on valid claims, available funds and court-approved deductions. The enforceable duration of the cybersecurity commitments is another material detail not provided in the notice itself.
The next decisive public event is the December 10, 2026 fairness hearing—unless its date or time changes. Until the judge rules and any appeals are resolved, this remains a proposal: consequential enough to require action, but not yet final.
The source document for this investigation is attached below.



