October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

American Vision Partners Data Breach Lawsuit: What 2.35 Million People Should Know

American Vision Partners, doing business as Medical Management Resource Group, was sued after a breach reportedly affected approximately 2.35 million individuals. Here is what happened, what information may be involved and where the case stands.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Medical Management Resource Group LLC, doing business as American Vision Partners (AVP), was sued after a data breach that reportedly affected approximately 2.35 million individuals. The company detected unauthorized network access on November 14, 2023, and later determined that patient information had been obtained. A proposed class action, Hulewat v. Medical Management Resource Group, LLC, Case No. 2:24-cv-00377, was filed in the U.S. District Court for the District of Arizona on February 23, 2024.

The case should not be confused with the separate Eye Care Leaders breach litigation. The available court materials show that two practice-related defendants were dismissed from the Arizona action in May 2025 for lack of personal jurisdiction. They do not establish a final judgment, settlement or merits ruling against MMRG/AVP.

What happened in the American Vision Partners breach?

AVP is a management-services organization that supports ophthalmology practices; it is not an insurer or a single eye clinic. SecurityWeek reported that it supported approximately 120 practices in Arizona, Texas, New Mexico and Nevada.

  • November 14, 2023: AVP detected unauthorized access to its network.
  • December 6, 2023: The company determined that information belonging to patients of client practices had been obtained.
  • Early February 2024: AVP publicly disclosed the incident and began notifying affected individuals.
  • February 22, 2024: SecurityWeek reported that the company faced litigation over the breach.
  • February 23, 2024: Linda Hulewat filed the proposed class action in federal court in Arizona.
  • May 2025: The court dismissed two practice defendants for lack of personal jurisdiction.

The original report described the impact as roughly 2.3 million people. The more specific figure reported to the U.S. Department of Health and Human Services was approximately 2.35 million individuals. That is a reported breach-population figure, not proof that every person experienced identity theft or that every listed type of information was exposed for every individual.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources: SecurityWeek and the filed complaint.

What information may have been exposed?

Reported categories include names, addresses and other contact information, dates of birth, medical information, insurance information, driver’s-license numbers, passport or other government identification numbers, and Social Security numbers in some cases. The complaint also alleges exposure of financial account or card information.

Those descriptions should be read carefully:

  • The company’s breach notice may identify different information for different people.
  • The complaint contains plaintiffs’ allegations, not judicial findings.
  • The available sources do not establish that every affected individual had a Social Security number or financial information exposed.
  • Potential exposure is not the same as confirmed misuse.

What does the lawsuit allege?

The complaint alleges that MMRG/AVP and related entities failed to use reasonable safeguards, did not adequately monitor and protect patient information, delayed disclosure of the incident, and left affected people exposed to identity theft and fraud risks.

The plaintiffs seek class certification, damages, equitable relief, attorneys’ fees and other remedies. These claims remain allegations unless established through later court proceedings. A complaint alone does not prove negligence, a statutory violation or actual identity theft.

Where does the case stand?

The case is Hulewat v. Medical Management Resource Group, LLC, No. 2:24-cv-00377, in the U.S. District Court for the District of Arizona. In a May 2025 order, the court dismissed Eye Associates of Nevada / Wellish Vision Institute and Marc Ellman, M.D., P.A. / Southwest Eye Institute for lack of personal jurisdiction.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The order does not establish that MMRG/AVP lost the case. The materials reviewed do not establish a final merits judgment or an approved settlement involving MMRG/AVP. Readers should therefore be skeptical of advertisements claiming that the company has already paid compensation or that everyone who received a breach notice is automatically entitled to money.

Read the May 16, 2025 court order for the jurisdictional ruling.

Is this the Eye Care Leaders breach?

No. Eye Care Leaders involved a different company, different systems and separate litigation concerning ransomware attacks in 2021. Similar subject matter does not make the cases the same. Information about that separate matter appears on the Eye Care Leaders settlement site.

What should affected individuals do?

1. Verify the notice

Check the notifying entity, the affected practice, the incident dates and the information categories listed in your letter. A breach notice does not automatically mean you are part of a lawsuit, and a lawsuit’s eventual class definition may differ from the company’s notification population.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Use official monitoring instructions

SecurityWeek reported that affected individuals were offered free credit monitoring and identity-protection services. Follow the enrollment instructions in an official notice, but do not assume monitoring prevents identity theft. Do not enter personal information into a link from an unsolicited text or email.

3. Consider a credit freeze

A security freeze is generally more preventive against new-account fraud than monitoring alone. Request freezes directly from Equifax, Experian and TransUnion. You can temporarily lift a freeze when applying for credit, although doing so may add an extra step.

4. Review financial and medical records

Obtain reports through AnnualCreditReport.com and check bank, card and insurance statements. Also watch for unfamiliar medical providers, prescriptions, claims or insurance activity. Standard credit monitoring may not detect medical identity theft, tax fraud, account takeover or activity that does not reach a credit bureau.

5. Secure existing accounts

Change passwords reused elsewhere and enable multifactor authentication, especially for email, financial and insurance accounts. Contact a financial institution immediately if you see unauthorized transactions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Document losses and beware scams

Keep the breach notice, monitoring enrollment records, suspicious communications, receipts and records of time or financial losses. Report suspected identity theft through the Federal Trade Commission’s IdentityTheft.gov recovery process and notify the relevant insurer or provider.

Large healthcare breaches can generate phishing messages, attorney advertisements and fake claims websites. A law-firm solicitation is not necessarily an official court notice, and paying an upfront fee is not automatically required to preserve rights. No current settlement or claims deadline is established by the sources reviewed here, so do not rely on an unofficial website for that information.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Credit monitoring versus a credit freeze

Option What it does Limitation
Credit monitoring Alerts you to certain reported changes or new activity. It may not prevent fraud or detect medical identity theft, tax fraud or account takeover.
Credit freeze Restricts access to a credit file for most new-credit applications. You must lift or manage it when legitimate creditors need access.
Fraud alert Signals that creditors should take additional steps to verify your identity. It is not the same as blocking access to your credit file.

If AVP’s notice offers monitoring, compare its scope and duration with the protection you already have. Paid identity-monitoring services can add features such as dark-web or bank-account monitoring, but they vary by plan and may exclude medical identity theft or losses caused by scams. Free freezes, credit reports and official recovery resources are often the appropriate first steps.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.