A class action lawsuit has been filed against Total Vision, LLC, a network of optometry centers based in California, after an unauthorized party gained access to a company database on October 30, 2020, exposing patients' medical and personal information. The exposed data reportedly included names, addresses, dates of birth, Social Security numbers, and prescription information belonging to patients treated at Total Vision's optometry centers, including practices operated by John C. Pack, O.D. and Beverly Bianes, O.D., Inc.
Two lawsuits were filed in San Diego Superior Court — one by plaintiff Anjanette Ramey on January 15, 2021, and a second by a plaintiff proceeding as Jane Doe on April 23, 2021 — and were later consolidated into a single Amended Consolidated Class Action Complaint filed November 18, 2021. The complaint accuses Total Vision of violating the California Confidentiality of Medical Information Act, the state's Security Notification Laws, and the Unfair Competition Law, along with claims for negligence and breach of implied contract, alleging the company failed to reasonably safeguard patients' confidential medical records.
Total Vision denies any wrongdoing. After the parties mediated the dispute in November 2023, they reached a settlement now pending final court approval.
Total Vision has agreed to pay $475,000 to resolve claims related to the October 2020 data security incident, settling all claims on behalf of a class of roughly 88,722 people who received a written notice about the breach at a California address. The fund covers pro-rata cash payments to everyone who submits a valid claim, plus reimbursement of up to $1,000 for documented out-of-pocket losses tied to the breach, such as identity theft, credit monitoring, or fees to freeze credit.
Beyond the cash fund, Total Vision has also committed to maintaining improved data security measures for a minimum of two years, an investment the company values at more than $224,000 annually. The settlement class includes only people whom Total Vision's own records show were mailed a direct notice of the breach in December 2020 — it does not extend to every patient who visited a Total Vision practice during the relevant period. Claims must be submitted no later than October 3, 2026.
Because Total Vision's settlement pays out on a pure pro-rata basis rather than guaranteeing a fixed dollar amount, each claimant's cash payment depends on how many people file valid claims once the $475,000 fund is reduced by attorneys' fees of up to $158,333.33, costs of about $22,000, administration costs of up to $100,250, and incentive awards of $5,000 to each of the two class representatives. Anyone who submits a timely, valid claim by October 3, 2026 receives a share of what remains.
Class members can also separately claim reimbursement of up to $1,000 for documented out-of-pocket expenses fairly traceable to the breach, such as identity theft losses, credit freeze fees, or costs from a fraudulent tax return — though that portion requires mailing supporting documentation rather than filing online. Payments will be issued by check or, for those who provide an email tied to a PayPal or Venmo account, by electronic transfer, following the December 18, 2026 final approval hearing. Anyone with questions about their claim can contact the settlement administrator at 1-888-250-6810.
Eligibility for the Total Vision settlement is unusually narrow: unlike many data breach settlements that accept self-attestation, only people whose names appear on Total Vision's own mailing list — those who were sent a direct-mail notice about the October 2020 breach at a California address — qualify as settlement class members. If a postcard notice about this case was mailed to you, you're on that list. Total Vision estimates approximately 88,722 people meet this criteria.
To submit a claim, class members complete a short claim form with their contact information and, optionally, documentation of out-of-pocket losses tied to the breach. No proof of being a Total Vision patient is required beyond appearing on the settlement class list, since the company itself identified who received the breach notice.
An unauthorized party accessed Total Vision's database on October 30, 2020, exposing patients' names, addresses, dates of birth, Social Security numbers, and prescription information.
Only people whose names appear on Total Vision's own mailing list — those the company identified as having been sent a direct-mail breach notice to a California address in December 2020.
There's no fixed payout — each claimant receives a pro-rata share of the $475,000 fund after fees and costs, divided among everyone who files a valid claim by October 3, 2026.
Yes. Claimants can also seek reimbursement of up to $1,000 for documented out-of-pocket losses fairly traceable to the breach, such as identity theft or credit monitoring costs.
Class counsel is requesting up to $158,333.33 in fees — almost exactly one-third of the $475,000 settlement fund — plus roughly $22,000 in litigation costs.
Yes. Anjanette Ramey and the plaintiff proceeding as Jane Doe are each seeking a $5,000 incentive award for serving as class representatives, subject to court approval.
Yes. As part of the settlement, Total Vision committed to maintaining improved data security measures for at least two years, an investment it values at over $224,000 annually.
California law lets health care patients use a pseudonym in privacy-related lawsuits, so the second plaintiff proceeded as "Jane Doe" to protect her identity as a patient.
No. Unlike the pro-rata cash payment, which can be filed online, claims for documented out-of-pocket expenses must be mailed with supporting documentation — they can't be submitted electronically.
Payments won't go out until after the December 18, 2026 final approval hearing, and only if the settlement receives final court approval and becomes effective.