EyeMed Vision Care, a major provider of vision care benefits, has agreed to pay $5 million to settle a class action lawsuit stemming from a 2020 phishing email data breach. The breach, which exposed sensitive information, has resulted in EyeMed incurring approximately $12.6 million in total costs, including multiple regulatory fines and settlements with state authorities. As part of the settlement, affected class members are eligible to receive up to $100 for lost time spent responding to the incident, and up to $10,000 for documented, unreimbursed out-of-pocket expenses directly related to the breach. Additionally, an estimated $50 prorated cash payment will be distributed from the remaining funds, with the final amount depending on the number of claims submitted. The settlement allocates $1.6 million, or one-third of the fund, for attorneys' fees, and awards $2,500 to each of the three class representatives. EyeMed has also committed to implementing a series of security enhancements as a condition of the settlement. These measures include stricter authorization requirements for individuals accessing the company’s network, updated internal password reset protocols, and mandatory security awareness training for all employees. The company will also introduce auditing mechanisms to identify weak passwords and strengthen multifactor authentication protocols. Furthermore, EyeMed will reduce the retention period for the email mailbox that was compromised in the breach, aiming to limit future exposure. The breach and subsequent litigation have prompted EyeMed to reevaluate and bolster its cybersecurity posture. Regulatory scrutiny from multiple states has underscored the importance of robust data protection practices in the healthcare sector. The settlement is designed not only to compensate affected individuals but also to drive lasting improvements in EyeMed’s information security framework. The incident highlights the significant financial and reputational risks associated with phishing attacks and inadequate email security. EyeMed’s response demonstrates a commitment to addressing both the immediate and systemic issues revealed by the breach. The case serves as a cautionary example for other organizations handling sensitive health and personal data. By agreeing to these terms, EyeMed aims to restore trust with its customers and regulators while mitigating the risk of similar incidents in the future. The settlement and security upgrades are expected to set a precedent for how healthcare benefit providers respond to large-scale data breaches.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
EyeMed agreed to pay $5 million to settle litigation related to an email breach, according to reports published by BankInfoSecurity and GovInfoSecurity. The two references describe the same settlement development and do not provide an earlier incident date in the supplied content.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.