Total Vision Data Breach Settlement Receives Preliminary Court Approval

A proposed class action settlement involving Total Vision LLC has received preliminary court approval following litigation related to a 2020 data breach that affected 138,402 current and former patients, according to the approved source.

Settlement Terms

The settlement resolves consolidated class action lawsuit associated with a hacking incident that occurred on or around October 30, 2020. Total Vision LLC, which manages a group of optometry centers throughout California, reported that hackers accessed a database server containing patient information. The information on the server included names, addresses, dates of birth, Social Security numbers, and prescription information. The data breach report submitted to the U.S. Department of Health and Human Services Office for Civil Rights stated that 138,402 current and former patients were affected.

The litigation was brought through two class action lawsuits that were combined into a single complaint in the Superior Court of California, County of San Diego. The Ramey, et al. v. Total Vision, LLC, et al. lawsuit named Jane Doe and Anjanette Ramey as class representatives. The defendants included Total Vision LLC, and Beverly Bianes, O.D., Inc., and John C. Pack, O.D., and Beverly Bianes, O.D.

Allegations in the Litigation

The plaintiffs alleged that the defendants failed to properly secure the database server and protect patient information, resulting in the data breach. Also, breach notifications were not provided adequately following the security incident.

The plaintiffs alleged that they experienced several instances of attempted improper use of data and identity theft following the incident. The lawsuit asserted claims for breach of implied contract, negligence, violations of California’s unfair competition law, violations of the Confidentiality of Medical Information Act, and violations of California security notification laws.

The defendants disagreed with the allegations, denied liability, and disputed the claims asserted in the litigation.

Settlement Fund

The parties reached agreement on settlement terms during mediation held on November 21, 2023. The court has already given preliminary approval of the finalized settlement.

According to the settlement, the defendants are required to establish a settlement fund totaling $475,000. The fund will be used to cover attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives. Remaining funds will be distributed for class member benefits.

Eligible class members may submit claims to reimburse documented, unreimbursed losses that are attributed to the data breach, subject to a maximum reimbursement of $1,000 per class member. Class members may likewise claim a pro rata cash payment. The pro rata payment amount will depend on the number of valid claims that are received.

The defendants are also required to implement HIPAA-compliant data security measures valued up to $224,000.

Settlement Timeline

The last day to request exclusion from the settlement or submit an objection is September 4, 2026. Claims may be submitted up to October 5, 2026. The court has scheduled the final fairness hearing for December 18, 2026.