Back to Exposure Report
Healthcare / Practice ManagementAugust 2026United States

American Vision Partners

2.26 million patients. Most of them believed they were dealing with their local eye doctor.

Patient recordsFull field list not yet disclosed
1

What happened?

Medical Management Resource Group, operating as American Vision Partners, reported a data breach affecting approximately 2.26 million patients. AVP provides management services to ophthalmology and optometry practices across the southwestern United States. No threat actor has been publicly attributed as of this writing.

2

What data was actually inside?

The complete field list has not been publicly enumerated as of this writing. Reporting places the affected population at approximately 2.26 million patients.

What a management services organisation holds for its client practices, labeled as inference: patient demographics, insurance and billing records, appointment histories, and clinical documentation sufficient to support claims submission — which in ophthalmology means diagnosis codes and procedure records.

Ophthalmology data is more revealing than it first appears. Diabetic retinopathy screening confirms diabetes. Macular degeneration and glaucoma correlate strongly with age. Visual field testing feeds driving licence eligibility determinations.

3

Who gets hurt and how?

2.26 million patients who visited an eye clinic. For them the practice was local — a familiar waiting room, a named physician, a neighbourhood office. The data was never local. It sat in one central system serving dozens of clinics.

The demographic record attached to an eye exam is unusually current, because an eye exam is one of the few routine appointments people actually keep. That makes the contact and insurance data more useful for fraud than a stale record from a one-off encounter.

The diagnostic inferences carry their own weight. A record confirming diabetic retinopathy discloses a chronic condition with insurance and employment implications, and no notification letter reverses it.

4

What did they think they were doing right?

Consolidating administrative functions into a management services organisation is, on its own terms, a security improvement. A single MSO can afford professional IT staff, a documented HIPAA compliance programme, and modern systems that no individual three-physician practice could fund alone. That is the argument for the model and it is a real one.

Centralisation improves the average level of protection and simultaneously concentrates the consequence. Fifty practices with fifty separate systems produce fifty small breaches at worst. Fifty practices on one platform produce one breach of 2.26 million. The security posture went up; the blast radius went up faster.

5

What did they not know about their own data?

Management services organisations grow by acquisition, and every practice acquisition moves another set of records into the central system. That migration is where inventories go stale.

The acquired practice arrives with its own history: a legacy practice management system, scanned paper charts from before the digital transition, records for patients who have not visited in a decade, and retention practices set by whoever ran the office in 2011. The integration project prioritises what the clinics need to operate. The archive comes along because leaving it behind creates legal risk, and it is rarely re-inventoried once it lands.

So the affected population in an MSO breach is typically larger than the active patient base, and the organisation frequently cannot say by how much until it counts.

If you handle patient data, could you identify within 24 hours exactly which records were accessed in a breach?

6

What does attribution look like the morning after?

HIPAA applies with its 60-day notification deadline, HHS Office for Civil Rights reporting, and publication on the OCR breach portal. At 2.26 million individuals, media notice is required in affected jurisdictions, and state statutes apply in parallel.

The structural complication is determining who notifies. Depending on how the MSO relationship is papered, the management company may act as a business associate to each practice, in which case each practice is a covered entity with its own obligation and its own OCR filing. That turns one incident into dozens of parallel notification processes, each requiring the practice to know which of its patients were in the central system — a question only the MSO can answer.

7

What would have changed the outcome?

Re-inventorying after every acquisition — because the records you inherited are records you must now be able to speak for.

If you acquired the records, you own the notification. Consolidation is happening across healthcare, veterinary care, dentistry, and professional services, and in each case the acquiring organisation absorbs a data estate assembled to someone else's standards. The integration plan covers the systems that must keep running. Very few cover the archive that came with them, which is exactly where the affected population turns out to be larger than anyone expected. See also our analysis of the Radiology Associates of Richmond breach.

American Vision Partners found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.