Nearly half of the total allotment of funds will go towards security improvements.
What happened
Total Vision, a network of eye care providers in California, faced a data breach in October of 2020, and a settlement has now been reached. The data breach resulted in medical and personal data information being accessed for 88,722 California residents. In total, it was reported to the Department of Health and Human Services (HHS) that 138,402 individuals were impacted, but this lawsuit seems to only apply to those residing in California.
Under the terms of the settlement, Total Vision has agreed to pay $475,000, some of which will go towards improved data security measures. Class members can receive up to $1,000 for claim and have until October 5th, 2026, to do so. A final fairness hearing is scheduled for December 18th, 2026.
The backstory
According to the agreement, the data stolen in 2020 stolen information included names, birth dates, Social Security numbers, medical information, and more. No malicious group was named as responsible for the breach.
It’s common for no threat group to be identified in an attack against a healthcare company. In fact, Paubox regularly covers instances where organizations are breached, the data obtained is put on the dark web, and no one learns of who conducted the incident. Unlike ransomware attacks, in these instances, malicious actors move much more silently and are not interested in seeking public attention, but rather want to quickly make money on the dark web by selling data.
Going deeper
According to the court documents, Total Vision will attest to “improved data security measures implemented in response to the Litigation and after the Data Security Incident, which Total Vision agrees to maintain for a minimum period of two years.” The value of their improved security measures is stated as $224,000, which means that Total Vision will set aside that amount of money in an account that is specifically dedicated to improving cybersecurity. What this money will go towards is kept vague, which could be intentional, allowing Total Vision discernment over what they believe is most vulnerable in their IT environment. For instance, they may decide to put more funds toward training, tools or software, or auditing. Total Vision will have two years to implement their improved cybersecurity systems or protocols.
The big picture
Unique to this incident is the emphasis on improving cybersecurity tools, which could set the groundwork for future lawsuits against other organizations.
In some cases, class action lawsuits can feel punitive without creating true change for an organization’s cybersecurity systems, which means that breaches aren’t necessarily less likely to occur in the future. According to Paubox data, health care data breach costs average around $6.6 million per incident, which can impact an organization’s financial health. If more of that money goes back into the organization to improve its systems, it could support its overall business trajectory rather than weaken it.
In this case, with specific funds going toward improvements, we may see positive change in the organization rather than just punishment. If other judges follow suit in different cases, lawsuits may shift away from punitive action and toward helping organizations take steps to prevent future breaches. While this may mean less money for victims, if the money is used properly, it will hopefully allow Total Vision to recover from the incident more quickly and prevent other breaches from occurring.
FAQs
Is it common for money to be put towards improved security measures
It is normal for organizations to commit to improved security measures, but the terms of the agreement are not usually stated so clearly in the settlement. With a clear focus on improved security, it’s clear that Total Vision and the plaintiffs are focused on preventing future security incidents.
Is the agreement only valid in California? What about victims outside of the state?
According to court documents, the settlement only applies to individuals who are currently residing in California and were victimized by this incident. Considering that there were possible victims residing outside of California, it’s possible that an additional lawsuit could be formed by those individuals.
