Recommended Free Tools
Medical Management Resource Group LLC, doing business as American Vision Partners (AVP), was sued after a data breach that reportedly affected approximately 2.35 million individuals. The company detected unauthorized network access on November 14, 2023, and later determined that patient information had been obtained. A proposed class action, Hulewat v. Medical Management Resource Group, LLC, Case No. 2:24-cv-00377, was filed in the U.S. District Court for the District of Arizona on February 23, 2024.
The case should not be confused with the separate Eye Care Leaders breach litigation. The available court materials show that two practice-related defendants were dismissed from the Arizona action in May 2025 for lack of personal jurisdiction. They do not establish a final judgment, settlement or merits ruling against MMRG/AVP.
What happened in the American Vision Partners breach?
AVP is a management-services organization that supports ophthalmology practices; it is not an insurer or a single eye clinic. SecurityWeek reported that it supported approximately 120 practices in Arizona, Texas, New Mexico and Nevada.
- November 14, 2023: AVP detected unauthorized access to its network.
- December 6, 2023: The company determined that information belonging to patients of client practices had been obtained.
- Early February 2024: AVP publicly disclosed the incident and began notifying affected individuals.
- February 22, 2024: SecurityWeek reported that the company faced litigation over the breach.
- February 23, 2024: Linda Hulewat filed the proposed class action in federal court in Arizona.
- May 2025: The court dismissed two practice defendants for lack of personal jurisdiction.
The original report described the impact as roughly 2.3 million people. The more specific figure reported to the U.S. Department of Health and Human Services was approximately 2.35 million individuals. That is a reported breach-population figure, not proof that every person experienced identity theft or that every listed type of information was exposed for every individual.
#1 Best Overall
Sources: SecurityWeek and the filed complaint.
What information may have been exposed?
Reported categories include names, addresses and other contact information, dates of birth, medical information, insurance information, driver’s-license numbers, passport or other government identification numbers, and Social Security numbers in some cases. The complaint also alleges exposure of financial account or card information.
Those descriptions should be read carefully:
- The company’s breach notice may identify different information for different people.
- The complaint contains plaintiffs’ allegations, not judicial findings.
- The available sources do not establish that every affected individual had a Social Security number or financial information exposed.
- Potential exposure is not the same as confirmed misuse.
What does the lawsuit allege?
The complaint alleges that MMRG/AVP and related entities failed to use reasonable safeguards, did not adequately monitor and protect patient information, delayed disclosure of the incident, and left affected people exposed to identity theft and fraud risks.
The plaintiffs seek class certification, damages, equitable relief, attorneys’ fees and other remedies. These claims remain allegations unless established through later court proceedings. A complaint alone does not prove negligence, a statutory violation or actual identity theft.
Where does the case stand?
The case is Hulewat v. Medical Management Resource Group, LLC, No. 2:24-cv-00377, in the U.S. District Court for the District of Arizona. In a May 2025 order, the court dismissed Eye Associates of Nevada / Wellish Vision Institute and Marc Ellman, M.D., P.A. / Southwest Eye Institute for lack of personal jurisdiction.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The order does not establish that MMRG/AVP lost the case. The materials reviewed do not establish a final merits judgment or an approved settlement involving MMRG/AVP. Readers should therefore be skeptical of advertisements claiming that the company has already paid compensation or that everyone who received a breach notice is automatically entitled to money.
Read the May 16, 2025 court order for the jurisdictional ruling.
Is this the Eye Care Leaders breach?
No. Eye Care Leaders involved a different company, different systems and separate litigation concerning ransomware attacks in 2021. Similar subject matter does not make the cases the same. Information about that separate matter appears on the Eye Care Leaders settlement site.
What should affected individuals do?
1. Verify the notice
Check the notifying entity, the affected practice, the incident dates and the information categories listed in your letter. A breach notice does not automatically mean you are part of a lawsuit, and a lawsuit’s eventual class definition may differ from the company’s notification population.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →2. Use official monitoring instructions
SecurityWeek reported that affected individuals were offered free credit monitoring and identity-protection services. Follow the enrollment instructions in an official notice, but do not assume monitoring prevents identity theft. Do not enter personal information into a link from an unsolicited text or email.
3. Consider a credit freeze
A security freeze is generally more preventive against new-account fraud than monitoring alone. Request freezes directly from Equifax, Experian and TransUnion. You can temporarily lift a freeze when applying for credit, although doing so may add an extra step.
4. Review financial and medical records
Obtain reports through AnnualCreditReport.com and check bank, card and insurance statements. Also watch for unfamiliar medical providers, prescriptions, claims or insurance activity. Standard credit monitoring may not detect medical identity theft, tax fraud, account takeover or activity that does not reach a credit bureau.
5. Secure existing accounts
Change passwords reused elsewhere and enable multifactor authentication, especially for email, financial and insurance accounts. Contact a financial institution immediately if you see unauthorized transactions.
Best Value
6. Document losses and beware scams
Keep the breach notice, monitoring enrollment records, suspicious communications, receipts and records of time or financial losses. Report suspected identity theft through the Federal Trade Commission’s IdentityTheft.gov recovery process and notify the relevant insurer or provider.
Large healthcare breaches can generate phishing messages, attorney advertisements and fake claims websites. A law-firm solicitation is not necessarily an official court notice, and paying an upfront fee is not automatically required to preserve rights. No current settlement or claims deadline is established by the sources reviewed here, so do not rely on an unofficial website for that information.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Credit monitoring versus a credit freeze
| Option | What it does | Limitation |
|---|---|---|
| Credit monitoring | Alerts you to certain reported changes or new activity. | It may not prevent fraud or detect medical identity theft, tax fraud or account takeover. |
| Credit freeze | Restricts access to a credit file for most new-credit applications. | You must lift or manage it when legitimate creditors need access. |
| Fraud alert | Signals that creditors should take additional steps to verify your identity. | It is not the same as blocking access to your credit file. |
If AVP’s notice offers monitoring, compare its scope and duration with the protection you already have. Paid identity-monitoring services can add features such as dark-web or bank-account monitoring, but they vary by plan and may exclude medical identity theft or losses caused by scams. Free freezes, credit reports and official recovery resources are often the appropriate first steps.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




