Vision Care Providers Settle Data Breach Class Actions After Patient Data Exposures
Two vision care providers Total Vision in California and Naper Grove Vision Care in Illinois have reached settlements in class action lawsuits following cyberattacks that compromised sensitive patient data.
Total Vision Settlement
Total Vision LLC, which operates optometry centers across California, suffered a hacking incident on or around October 30, 2020, when attackers accessed a database containing patient information, including names, addresses, dates of birth, Social Security numbers, and prescription details. The breach affected 138,402 current and former patients and was reported to the HHS’ Office for Civil Rights.
Two class action lawsuits were consolidated into Ramey, et al. v. Total Vision, LLC, et al. in the Superior Court of California, County of San Diego, alleging negligence, breach of implied contract, and violations of California’s unfair competition law, Confidentiality of Medical Information Act, and security notification laws. Plaintiffs claimed the breach led to attempted identity theft and data misuse, though the defendants denied wrongdoing.
The settlement, finalized after mediation on November 21, 2023, includes:
- A $475,000 settlement fund, covering attorneys’ fees, administrative costs, and class member benefits.
- Reimbursement of up to $1,000 per class member for documented losses.
- Pro rata cash payments for those not claiming losses, depending on valid claims.
- $224,000 in improved data security measures by the defendants.
- Deadlines: Exclusion/objection by September 4, 2026, claims by October 5, 2026, and a final fairness hearing on December 18, 2026.
Naper Grove Vision Care Settlement
Naper Grove Vision Care in Naperville, Illinois, experienced a May 2025 ransomware attack by the Interlock group, which accessed protected health information of 20,093 individuals, including names, addresses, birth dates, driver’s license numbers, insurance details, medical records, and some Social Security numbers. The breach was detected on May 24, 2025.
Multiple lawsuits were consolidated into In re Naper Grove Data Breach Litigation in the Circuit Court of the Eighteenth Judicial Circuit, DuPage County, Illinois, alleging negligence, breach of implied contract, and violations of the Illinois Consumer Fraud and Deceptive Business Practices Act. The defendant denied all claims.
The settlement includes:
- A $50,000 settlement fund for pro rata cash payments or reimbursement of up to $1,000 per class member for documented losses.
- A one-year credit and medical data monitoring service for all class members.
- Deadlines: Exclusion/objection and claims by September 18, 2026, with a final approval hearing on October 20, 2026.
Both settlements were reached without admission of fault or liability.
Source: https://www.hipaajournal.com/vision-care-providers-data-breach-settlements/
Naper Grove Vision Care TPRM report: https://www.rankiteo.com/company/naper-grove-vision-care
Total Vision LLC TPRM report: https://www.rankiteo.com/company/totalvisioncare
"id": "totnap1784199825",
"linkid": "totalvisioncare, naper-grove-vision-care",
"type": "Ransomware",
"date": "7/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '138,402 current and former '
'patients',
'industry': 'Healthcare',
'location': 'California, USA',
'name': 'Total Vision LLC',
'type': 'Vision Care Provider'},
{'customers_affected': '20,093 individuals',
'industry': 'Healthcare',
'location': 'Illinois, USA',
'name': 'Naper Grove Vision Care',
'type': 'Vision Care Provider'}],
'attack_vector': 'Hacking',
'data_breach': {'number_of_records_exposed': ['138,402', '20,093'],
'personally_identifiable_information': 'Names, addresses, '
'dates of birth, '
'Social Security '
'numbers, driver’s '
'license numbers',
'sensitivity_of_data': 'High (Social Security numbers, '
'medical records, insurance details, '
'driver’s license numbers)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Protected Health Information '
'(PHI)']},
'date_detected': ['2020-10-30', '2025-05-24'],
'description': 'Two vision care providers, Total Vision in California and '
'Naper Grove Vision Care in Illinois, reached settlements in '
'class action lawsuits following cyberattacks that compromised '
'sensitive patient data.',
'impact': {'data_compromised': 'Sensitive patient data including names, '
'addresses, dates of birth, Social Security '
'numbers, prescription details, driver’s '
'license numbers, insurance details, medical '
'records',
'financial_loss': ['$475,000 settlement fund (Total Vision)',
'$50,000 settlement fund (Naper Grove)'],
'identity_theft_risk': 'Attempted identity theft and data misuse '
'reported',
'legal_liabilities': ['Violations of California’s unfair '
'competition law, Confidentiality of Medical '
'Information Act, and security notification '
'laws',
'Violations of Illinois Consumer Fraud and '
'Deceptive Business Practices Act']},
'investigation_status': 'Settled',
'post_incident_analysis': {'corrective_actions': ['$224,000 in improved data '
'security measures (Total '
'Vision)',
'One-year credit and '
'medical data monitoring '
'service (Naper Grove)']},
'ransomware': {'ransomware_strain': 'Interlock group'},
'references': [{'source': 'Class action lawsuit settlement details'}],
'regulatory_compliance': {'legal_actions': ['Class action lawsuits'],
'regulations_violated': ['California’s unfair '
'competition law',
'Confidentiality of '
'Medical Information Act',
'California security '
'notification laws',
'Illinois Consumer Fraud '
'and Deceptive Business '
'Practices Act'],
'regulatory_notifications': ['Reported to HHS’ '
'Office for Civil '
'Rights']},
'threat_actor': 'Interlock group',
'title': 'Vision Care Providers Settle Data Breach Class Actions After '
'Patient Data Exposures',
'type': ['Data Breach', 'Ransomware']}