Subscribe To Our Newsletter
Total Vision LLC has reached a $475,000 class action settlement to resolve claims that the California optometry network failed to safeguard sensitive patient data during an October 2020 cybersecurity breach.
Total Vision LLC, a major network of optometry practices operating throughout California, has agreed to establish a $475,000 class action settlement fund to resolve allegations that the healthcare provider failed to implement reasonable cybersecurity safeguards to protect patient files during an October 2020 data breach.
The lawsuit claims that unauthorized third parties accessed a company database server containing sensitive personal, financial, and medical information. While Total Vision denies all allegations of negligence, statutory violations, and liability, the company agreed to the financial payout and security commitments to bring the long-running litigation to a close. California residents who received a direct breach notification letter from Total Vision regarding the October 30, 2020 security incident can file a claim for up to $1,000 in expense reimbursements or receive a pro-rata cash payment.
The litigation stems from a cyberattack that took place on or around October 30, 2020. According to court records and reports filed with federal regulators, cybercriminals gained unauthorized access to a central database server maintained by Total Vision, exposing confidential record files belonging to approximately 88,722 individuals.
Plaintiffs in the consolidated lawsuit—styled Ramey, et al. v. Total Vision, LLC, et al. (Case No. 37-2021-00002017)—alleged that Total Vision failed to maintain adequate server security protocols, password protections, and network access controls. The complaint contended that the optometry network’s failure to maintain industry-standard digital security left patient databases vulnerable to external hackers, leading to attempted identity theft and unauthorized data exposure.
Cybersecurity breaches involving medical networks present significant risks because compromised records often contain both financial identifiers and confidential health data.
According to court filings and settlement documentation, the sensitive patient data exposed in the Total Vision security incident included:
Personal Identifiers: Full names, physical mailing addresses, and dates of birth.
Government Identification: Social Security numbers and related official identity details.
Confidential Medical Records: Optical prescription information, eye care histories, and patient account data.
When bad actors obtain combinations of Social Security numbers, dates of birth, and health records, affected individuals face an ongoing risk of targeted phishing scams, fraudulent credit applications, and medical identity theft.
The Total Vision lawsuit asserted claims under key California consumer protection and privacy frameworks designed to hold healthcare entities accountable for digital security lapses:
California Confidentiality of Medical Information Act (CMIA): This statute requires health systems, clinics, and medical providers to preserve the strict confidentiality of patient records. Under the CMIA, patients may seek statutory damages when a provider’s negligence results in the unauthorized release of confidential medical details.
California Unfair Competition Law (UCL): The complaint alleged that Total Vision engaged in unfair business practices by falsely representing that it maintained robust security controls to shield patient files from cyber threats.
By pursuing claims under state consumer statutes, the plaintiffs established that healthcare networks have a strict legal duty to treat patient cybersecurity with the same care as physical medical treatment.
You may qualify as an eligible class member to receive financial compensation if you meet the following court-approved criteria:
State Residency: You are a resident of the State of California.
Direct Breach Notification: Total Vision sent you a direct mail notice indicating that your personal or medical information was involved in the October 30, 2020 data security incident.
Court documents estimate that approximately 88,722 individuals meet these criteria. If you received a mailed settlement notice containing an ILYM ID and Claim ID, you are confirmed as an eligible class member.
The $475,000 gross settlement fund offers two distinct avenues for financial recovery, depending on whether you experienced out-of-pocket financial harm:
Reimbursement for Out-of-Pocket Expenses (Up to $1,000): If you incurred documented financial losses directly traceable to the data breach, you can submit a claim for up to $1,000. Eligible expenses include costs for credit monitoring services, credit freeze fees, bank transfer charges, replacement identification fees, or unreimbursed losses caused by identity theft or fraud.
Pro-Rata Cash Payout: Alternatively, class members who did not suffer documented financial losses—or who prefer a straightforward payout—can file a claim for a pro-rata cash payment. The exact dollar amount will depend on the total number of valid claims filed against the net settlement fund.
In addition to financial compensation, Total Vision has agreed to implement enhanced cybersecurity measures valued at more than $224,000 annually for a minimum of two years.
To receive a financial payment, class members must submit their claims within the strict timelines established by the San Diego County Superior Court:
Exclusion / Opt-Out Deadline: September 4, 2026
Objection Deadline: September 4, 2026
Claim Submission Deadline: October 5, 2026
Final Approval Hearing: December 18, 2026
Important Submission Rule: If you are claiming a pro-rata cash payment, you may file your claim online or by mail. However, if you are requesting reimbursement for documented out-of-pocket expenses (up to $1,000), court rules require you to print the PDF claim form and mail it directly to the settlement administrator alongside physical receipts or bank statements. Documented-loss claims cannot be submitted electronically.
If you received a data breach notice from Total Vision, you have the right to claim financial compensation for the exposure of your private medical data.
Here is how you can take action before the upcoming deadline:
Locate Your Class Notice: Retrieve the physical mail notice sent by the settlement administrator. You will need your last name, ILYM ID, and Claim ID printed on the document.
Gather Financial Proof (If Claiming Expenses): If you suffered financial losses or paid for identity protection services, collect supporting documentation such as bank statements, receipts, or fraud reports.
Submit Your Form: Visit the court-approved settlement portal at TotalVisionSettlement.com to file for a pro-rata cash payment online. If filing for out-of-pocket expense reimbursement, print and mail your completed paper form to the designated settlement administrator postmarked no later than October 5, 2026.
New cases and investigations, settlement deadlines, and news straight to your inbox.