NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Legal News about HIPAA Compliance

The HIPAA Journal legal news section contains details of the latest enforcement activities by the Department of Health and Human Services’ Office for Civil Rights, including settlements and civil monetary penalties, and legal actions taken against covered entities by state attorneys general.

You will also find brief details of class action lawsuits and other legal actions filed against covered entities for HIPAA violations, privacy violations, and data breaches, along with other legal news specifically relating to HIPAA or other legal matters of particular relevance to the healthcare industry.

Changes to HIPAA Rules are detailed in the HIPAA Updates category, although this section does include updates to state legislation, in particular any changes to breach notification and cybersecurity laws that are relevant to healthcare organizations.

American Vision Partners Settles Data Breach Litigation for $1.75M

Medical Management Resource Group LLC (MMRC), doing business as American Vision Partners, has agreed to settle class action litigation stemming from a 2024 data breach. MMRC identified suspicious activity within its computer systems on November 14, 2023. The forensic investigation confirmed on or around December 6, 2023, that certain systems had been accessed by an unauthorized third party, and files had been exfiltrated from its network, some of which contained patient information. Data compromised in the incident included names, contact information, dates of birth, medical information such as the services received, clinical records, and medications, and for a subset of individuals, Social Security numbers. The data breach was reported to the HHS Office for Civil Rights on February 6, 2026, as affecting more than 2.35 million individuals, although the OCR breach portal was later updated with a slightly smaller figure of 2,264,157 individuals. The class action lawsuit states that approximately 1.6 million Americans were affected by the data breach. Multuiple class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint - Hulewat et al. v. Medical Management Resource Group LLC d/b/a American Vision Partners, et al – as they had overlapping claims. The consolidated lawsuit was filed in the United States District Court for the District of Arizona where It is currently pending. The lawsuit also named Barnet Dulaney Perkins Eye Center, PC, Marc Ellman, M.D., P.A. d/b/a Southwest Eye Institute, Southwestern Eye Center, Ltd., and Eye Associates of Nevada d/b/a Wellish Vision Institute as co-defendants. The defendants filed a motion to dismiss, and defendants Eye Associates of Nevada d/b/a Wellish Vision Institute and Marc Ellman, M.D. P.A. d/b/a Southwest Eye Institute were dismissed from the action. The lawsuit alleges that the cyberattack and data breach occurred as a result of the failure of the defendants to implement reasonable and industry standard data security practices, and asserted claims for negligence, negligence per se, breach of third-party beneficiary contract, unjust enrichment, and violation of the Arizona Consumer Fraud Act. The parties engaged in informal discovery and discussed the option of a settlement to avoid the cost and risks of a trial and related appeals. A suitable settlement was negotiated that was acceptable to all parties, and the settlement agreement has received preliminary approval from the court. Under the terms of the settlement, a $1,750,000 settlement fund will be established to cover attorneys’ fees, settlement administration costs, and service awards for the seventeen class representatives. The remainder of the settlement fund will be used to pay benefits to the class members. Settlement class members are divided into two subclasses, one (damages subclass) of which consist of approximately 258,070 individuals who had their Social Security numbers and other private information compromised in the incident, and an injunctive relief subclass, which consists of all individuals whose personal information is collected or maintained by the defendant. Individuals in the damages subclass may submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $3,000 per class member. Alternatively, members of this subclass may claim a pro rata cash payment, the value of which will depend on the number of valid claims received. Members of the injunctive relief subclass may not submit a claim but will benefit from commitments to improve business practices and implement additional cybersecurity measures. Those measures include the appointment of a chief Information Security Officer (CISO) to oversee security and a host of cybersecurity measures, valued at $2,787,630. The deadline for objection and opting out is Octiober 13, 2026. Claims must be submitted by November 12, 2026, and the final fairness hearing has been scheduled for December 10, 2026.

Medical Management Resource Group LLC (MMRC), doing business as American Vision Partners, has agreed to settle class action litigation stemming...

Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit

Tift Regional Health System data breach settlement

Tift Regional Health System Inc, a non-profit health system serving patients in south central Georgia, has agreed to pay $1.2...

DAP Health Settles Data Breach Lawsuit for $1,300,000

DAP Health data breach settlement

DAP Health, a nonprofit community healthcare network based in Southern California, has agreed to settle a class action lawsuit that...

OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits

OnePoint Patient Care; Clay-Platte Family Medicine data breach settlements

Individuals affected by data breaches at OnePoint Patient Care and Clay-Platte Family Medicine may be entitled to claim benefits after...

Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits

Highland Health Systems; Albany Gastroenterology Consultants data breach settlements

Settlements have received preliminary approval to resolve class action data breach complaints against Highland Health Systems and Albany Gastroenterology Consultants...

Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation

The volume and sensitive nature of the data stolen from Change Healthcare in its 2024 ransomware attack have led to...

News Categories

Notices

Five Healthcare Providers Settle Pixel Class Action Lawsuits

Over the past 18 months, many healthcare providers have settled class action lawsuits over their use of website tracking and...

Ransom Cartel Mastermind Sentenced to 16 Years in Prison

The Belarusian cybercriminal behind the Ransom Cartel ransomware group has been sentenced to 16 years in prison for his role...

Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance

Data breach settlements: McKenzie Health System; Aspire Health Alliance

Settlements have been agreed to resolve class action data breach lawsuits against McKenzie Health System in Michigan and Aspire Health...

Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic

data breach settlements: Omni Healthcare Financial Holdings and Western Montana Clinic.

Settlements have been agreed to resolve class action data breach lawsuits against Omni Healthcare Financial Holdings and its subsidiaries, and...

FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices

ApolloMD data breach settlement

Him & Hers, a San Francisco, CA-based telehealth company, is being sued by the Federal Trade Commission (FTC) and the...

Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits

Banner HEalth LifeStance HEalth Group pixel settlements

Two healthcare providers have agreed to settle lawsuits over their use of pixels and other website tracking technologies. The tools...

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist