Jessy Edwards  |  October 20, 2022

Category: Data Breach

Top Class Actions’s website and social media posts use affiliate links. If you make a purchase using such links, we may receive a commission, but it will not result in any additional charges to you. Please review our Affiliate Link Disclosure for more information.

Silhouette glasses in front of laptop computer screen with programming code.
(Photo Credit: Zapp2Photo/Shutterstock)

EyeMed data breach fine overview: 

  • Who: EyeMed Vision Care LLC will pay $4.5 million to the New York Department of Financial Services (DFS) to settle claims it breached state cybersecurity rules.
  • Why: The DFS found the company breached state cybersecurity rules before a 2020 hack that exposed hundreds of thousands of consumers’ personal data.
  • Where: The settlement is in New York. 

EyeMed Vision Care LLC will pay $4.5 million to the New York Department of Financial Services (DFS) to settle claims it breached state cybersecurity rules before a 2020 hack that exposed hundreds of thousands of consumers’ personal data.

On Oct. 18, the settlement was approved and signed by the DFS Superintendent of Financial Services Adrienne A. Harris in New York. 

The DFSis the insurance regulator of New York, responsible for ensuring the safety of New York’s insurance industry and promoting the reduction and elimination of fraud, abuse, and unethical conduct with respect to insurance licensees.

EyeMed is a vision services health insurance company. 

According to the department’s investigation, a cyberattacker was able to access six years’ worth of sensitive data in a July 2020 phishing hack of EyeMed Vision Care.

It said the health insurance company violated DFS’ Cybersecurity Regulation for not using multifactor authentication throughout its email network. 

EyeMed also failed to sufficiently limit internal access to the email mailbox breached in the attack by allowing nine employees to share login credentials to the affected platform, and failed to dispose of data in an appropriate timeline, the DFS investigation found.

“Had these controls been in place, the July 1, 2020, cybersecurity event could have been prevented or been limited in scope,” it said. 

EyeMed breach exposed sensitive data of consumers, investigation found

The 2020 breach exposed the sensitive health data of hundreds of thousands of consumers, including the data of minors, DFS said. 

As a result of the investigation, EyeMed has agreed to “conduct a comprehensive cybersecurity risk assessment” and an action plan to make sure the company is protected against breaches in the future. 

“This settlement demonstrates DFS’s ongoing commitment to protecting consumers while ensuring the safety and soundness of financial institutions from cyber threats,” Superintendent Harris said in a statement. 

Meanwhile, in February, Allergan agreed to pay nearly $30 million to resolve class action claims it used anti-competitive tactics to raise the price of Restasis eye drops. 

Were you affected by the EyeMed data breach? Let us know what you think of this settlement in the comments! 


Don’t Miss Out!

Check out our list of Class Action Lawsuits and Class Action Settlements you may qualify to join!


Read About More Class Action Lawsuits & Class Action Settlements:

We tell you about cash you can claim EVERY WEEK! Sign up for our free newsletter.

6 thoughts onEyeMed fined $4.5M following data breach

  1. Zandra Cosby says:

    If it’s not too late please add me! My spouse and I had Eyemed

  2. Jannette says:

    Add me

  3. Marsha’ Caston says:

    Please add me.I have had EyeMed for about 10 plus years.

  4. Frank Thomas says:

    We have had Eyemed for many years.

  5. Erica Santos says:

    I’ve had EyeMed from 2014 to present!!!

  6. Lori Henry says:

    If it goes back 6 years then I was affected by Eyemed breach.

Leave a Reply

Your email address will not be published. By submitting your comment and contact information, you agree to receive marketing emails from Top Class Actions regarding this and/or similar lawsuits or settlements, and/or to be contacted by an attorney or law firm to discuss the details of your potential case at no charge to you if you qualify. Required fields are marked *

Please note: Top Class Actions is not a settlement administrator or law firm. Top Class Actions is a legal news source that reports on class action lawsuits, class action settlements, drug injury lawsuits and product liability lawsuits. Top Class Actions does not process claims and we cannot advise you on the status of any class action settlement claim. You must contact the settlement administrator or your attorney for any updates regarding your claim status, claim form or questions about when payments are expected to be mailed out.