When Medical Management Resource Group LLC reached a $1.75 million settlement in August 2026 for a breach affecting over 2.35 million individuals, it revealed more than just financial penalties. It exposed specific control gaps that can turn a security incident into protracted litigation and outlined remedies you can implement before you're in the defendant's seat.
Scope: What This Guide Covers
This guide walks you through the control failures that led to the American Vision Partners breach settlement, the technical and organizational commitments mandated by the settlement, and the steps you can take now. Use this as a reference to evaluate your current security posture against the failures that trigger class action exposure.
What you'll find here:
- The timeline and technical facts from the breach
- Specific security controls required by the settlement (valued at $2,787,630)
- Implementation guidance for each control category
- Common gaps that invite litigation
- A quick reference table mapping controls to HIPAA Security Rule specifications
What this guide doesn't cover:
- Legal strategy for responding to active litigation
- Cyber insurance policy negotiation
- Forensic investigation procedures
Key Concepts and Definitions
Unauthorized access and exfiltration: The American Vision Partners incident involved both. An attacker gained entry to systems around November 14, 2023, and removed files containing Protected Health Information. The forensic investigation confirmed exfiltration by December 6, 2023, but notification to the Office for Civil Rights didn't occur until February 6, 2026.
Class action exposure vs. OCR enforcement: The settlement resolved lawsuits alleging negligence, breach of contract, unjust enrichment, and violation of the Arizona Consumer Fraud Act. These claims run parallel to potential HIPAA enforcement. Your organization faces both tracks.
Injunctive relief: Beyond cash payments, the settlement created an Injunctive Relief Subclass covering all individuals whose information the defendant collects or maintains. This subclass benefits from mandatory security improvements, providing a court-ordered security roadmap you can study.
Chief Information Security Officer (CISO) appointment: The settlement required the appointment of a CISO to oversee security. This was a binding commitment valued as part of the $2,787,630 in security measures.
Requirements Breakdown
The settlement's security commitments provide a checklist of what the court considered necessary to prevent recurrence. While it doesn't itemize every measure, it establishes these categories:
Executive accountability: Appointment of a CISO with direct oversight authority. This role must have budget, reporting lines to executive leadership, and authority to halt projects that introduce unacceptable risk.
Technical safeguards: The $2,787,630 valuation suggests investments in access controls, encryption, network segmentation, intrusion detection, and endpoint protection. The settlement doesn't specify vendors, but the price tag indicates enterprise-grade tooling.
Monitoring and detection: The timeline (suspicious activity identified November 14, confirmation of exfiltration by December 6) suggests detection capabilities existed but response was slow. Effective monitoring must compress that window.
Incident response: The gap between December 6, 2023 (confirmation of exfiltration) and February 6, 2026 (OCR notification) underscores the need for documented response procedures with clear escalation triggers.
Implementation Guidance
Establish CISO Authority
If your organization lacks a dedicated CISO, don't assume the title alone satisfies the requirement. The role needs:
- Direct reporting to the CEO or board: Security can't be subordinated to IT operations or compliance.
- Budget authority: The CISO must control spending for security tools, staff, and remediation.
- Cross-functional reach: Access controls, vendor management, and clinical system security all fall within scope.
Consider a covered entity that distributes security responsibilities across IT, compliance, and legal teams. When a vulnerability surfaces in a patient portal, who has authority to take the system offline? If the answer is "we'd need to convene a meeting," you don't have effective security leadership.
Map Controls to Addressable Specifications
The HIPAA Security Rule at 45 CFR §164.308(a)(1)(ii)(B) requires a risk management process. The American Vision Partners breach demonstrates what happens when risk management is documented but not operationalized.
Your risk analysis must:
- Identify where ePHI is stored, transmitted, and processed (including shadow IT and third-party systems)
- Assess current safeguards against known threat vectors (ransomware, credential stuffing, SQL injection)
- Document risk acceptance decisions in writing, with executive sign-off
- Trigger remediation when residual risk exceeds your defined threshold
Compress Detection-to-Confirmation Windows
The 22-day window between detecting suspicious activity and confirming exfiltration is a warning sign. Your security operations should:
- Deploy endpoint detection and response (EDR) tools with automated alerting
- Maintain centralized logging with retention periods sufficient for forensic analysis (NIST SP 800-92 recommends 90 days minimum for security logs)
- Establish on-call rotation for security incidents, not just infrastructure outages
- Run tabletop exercises quarterly to test investigation procedures
Implement Privilege Segmentation
Files containing names, dates of birth, Social Security numbers, medical information, clinical records, and health insurance information were accessible to the attacker. This suggests broad access permissions or insufficient network segmentation.
Practical steps:
- Audit privileged accounts monthly; remove dormant credentials
- Separate production ePHI from development and test environments
- Require multi-factor authentication for any system that stores or transmits ePHI (HIPAA Security Rule §164.312(a)(2)(i) makes this addressable, but post-breach settlements increasingly treat it as required)
- Limit lateral movement with network segmentation; an attacker who compromises one system shouldn't inherit access to your entire ePHI estate
Prepare for Rapid Notification
The February 2026 notification date for a December 2023 breach suggests either a complex investigation or process failures. The Breach Notification Rule at 45 CFR §164.408 requires notification without unreasonable delay and no later than 60 days following discovery.
Your notification plan should include:
- Pre-drafted templates for individual notices, media statements, and OCR submissions
- A decision tree for determining breach vs. security incident (apply the risk assessment framework at §164.402)
- Contact information for forensic investigators, legal counsel, and breach notification vendors
- A communication protocol that doesn't rely on compromised systems
Common Pitfalls
Treating security as an IT project: The settlement required a CISO, not a security tool. Organizations that view security as a technology deployment rather than an organizational capability will continue to fail.
Underestimating class action exposure: The $1.75 million settlement covered attorneys' fees, administration, service awards for seventeen class representatives, and claims from a Damages Subclass of approximately 258,070 individuals. This runs parallel to any OCR investigation. Budget accordingly.
Delaying executive involvement: If your CEO first hears about a breach from legal counsel, your incident response plan has failed. Security incidents require executive decision-making from the moment suspicious activity is detected.
Ignoring the injunctive relief subclass: Courts now routinely approve settlements that require specific security improvements. These commitments become enforceable obligations. If you're planning security investments, study recent settlement terms, they reveal what plaintiffs' counsel and judges consider adequate.
Conflating compliance and security: You can pass a HIPAA audit and still suffer a breach. Compliance establishes a floor; security requires continuous improvement. The American Vision Partners settlement valued security measures at $2,787,630, far more than typical compliance program costs.
Quick Reference Table
| Control Category | HIPAA Security Rule Reference | Settlement Indicator | Implementation Priority |
|---|---|---|---|
| Executive accountability | §164.308(a)(2) - Assigned security responsibility | CISO appointment required | Immediate |
| Access controls | §164.312(a)(1) - Unique user identification | Files with SSNs exfiltrated | High |
| Audit controls | §164.312(b) - Hardware, software, procedural mechanisms | 22-day detection-to-confirmation gap | High |
| Integrity controls | §164.312(c)(1) - Protect ePHI from improper alteration | Exfiltration confirmed | High |
| Transmission security | §164.312(e)(1) - Guard against unauthorized access during transmission | Network breach | Medium |
| Risk analysis | §164.308(a)(1)(ii)(A) - Assess potential risks and vulnerabilities | Litigation alleged failure to implement industry-standard practices | Immediate |
| Risk management | §164.308(a)(1)(ii)(B) - Implement security measures to reduce risks | $2,787,630 in post-breach security measures | Immediate |
| Incident response | §164.308(a)(6) - Identify and respond to security incidents | Multi-year notification delay | High |
How to use this table: Start with "Immediate" priorities. If you lack a designated security official with executive authority, or if your most recent risk analysis is more than 12 months old, address those gaps before deploying new technical controls. Then work through "High" priorities based on your current threat profile.
The American Vision Partners settlement demonstrates that courts will prescribe specific organizational and technical controls when they find security practices inadequate. You can implement those same controls now, or explain to a judge later why you didn't.



