ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

American Vision Partners says data breach compromised the data of over 2.3m eye patients

Arizona-based healthcare management company American Vision Partners said it experienced a data security incident that compromised the sensitive personal information of more than 2.3 million eye patients.

 

Phoenix, Arizona-based Medical Management Resource Group, LLC, doing business as American Vision Partners, provides  medical billing and collections services and solutions to ophthalmology practices in the south-eastern United States. Its services include healthcare management consulting, coding, credentialing, insurance and patient collections, along with state of the art software and IT services.

 

In a notice of data breach filed with the Office of the Maine Attorney General on behalf of the client in the healthcare sector, American Vision Partners said that on  November 14, it identified suspicious activities in certain parts of its internal network. 

 

The company immediately launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident and notified relevant law enforcement authorities about the cyber attack.

 

On December 6, the investigation concluded that an unauthorised third party accessed and obtained personal information associated with patients of eye care clinics that obtained services from American Vision Partners.

According to AVP, The affected practices include Barnet Dulaney Perkins Eye Center, PC, Box Canyon Surgery Center, Cataract and Surgical Center of Lubbock, Desert Peaks Surgery Center, Eye Associates of Nevada, Jack E. Abrams, M.D. Professional Corporation (d.b.a. Abrams Eye Institute), Laser Eye Center of Lubbock, Patrick D. Aiello, M.D. (d.b.a. Aiello Eye Institute), Retinal Consultants of Arizona, Southwest Eye Institute, Southwestern Eye Center, Vantage Eye Center, Vantage Surgery Center, and West Texas Eye Associates.

 

The healthcare IT services provider added that the compromised data included patients’ names, contact information, dates of birth, Social Security numbers, certain medical information including services received, clinical records, medications and insurance information.

 

American Vision Partners’ filing with the state regulator also revealed that the data security incident compromised the personal information of at least 2,264,157 individuals.

 

The IT provider has urged all affected individuals to remain vigilant, review their credit reports and financial statements on a regular basis, and report suspicious transactions to relevant law enforcement authorities. It is also offering two years of complimentary credit monitoring and Identity Protection Services through TransUnion to all the individuals affected by the data breach.

 

With a data breach this huge, American Vision Partners could face multiple class action lawsuits as several renowned law firms have urged individuals to come forward if they have received the notice of the data security incident. The company also failed to share vital details including how the threat actor infiltrated its internal network and whether any steps have been taken to avoid such an incident in the future.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543