Medical Management Resource Group breach hit 2.35 million eye care patients
- Organization
- Medical Management Resource Group, LLC (American Vision Partners)
- Exploit
- Hacking
- Industry
- Healthcare Services
Medical Management Resource Group, an Arizona company that trades as American Vision Partners and supplies management, IT and infrastructure services to ophthalmology practices across the southwestern United States, began notifying patients in February 2024 that their information had been taken in a network intrusion.
The company said it detected unauthorized activity on parts of its network on November 14, 2023, and isolated the affected systems. A review completed on December 6, 2023 confirmed that an unauthorized party had accessed and removed files containing patient data.
The exposed information varied by individual and included names, contact details, dates of birth and medical information such as services received, clinical records and medications. For some patients the files also held Social Security numbers and health insurance details. The filing with the US Department of Health and Human Services put the count at 2,350,236 people, drawn from the eye care practices MMRG supports in Arizona, California, Nevada, New Mexico and Texas.
MMRG said it brought in outside cybersecurity firms, contained the incident, notified law enforcement and regulators, and offered affected patients two years of complimentary credit monitoring and identity protection. Within weeks of the notifications going out, at least three proposed class actions had been filed over the company's handling of the data.
Sources
- HIPAA Journal, Medical Management Resource Group (American Vision Partners) Breach Affects 2.35M Patients
- SecurityWeek, Eye Care Services Firm Faces Lawsuit Over Data Breach Impacting 2.3 Million
- ClassAction.org, American Vision Partners Data Breach Lawsuit
- Eyewire+, American Vision Partners Notifies Patients of Cybersecurity Incident
- Top Class Actions, Consumers file class actions over American Vision Partners data breach