top of page

131,000 Patients, 67 Days, One $850,000 Settlement: What the Alabama Ophthalmology Associates Data Breach Shows About Medical Privacy Accountability

  • Writer: Elliott Lipinsky
    Elliott Lipinsky
  • 16 minutes ago
  • 10 min read

A patient's Social Security number sat inside a compromised computer network for more than a week before anyone noticed. Then, according to the practice's own breach notification, more than two additional months passed before letters went out to the people whose information was taken. That gap, between when a hacking incident is discovered and when the people harmed by it are actually told, is where accountability in medical data breaches is won or lost. The Alabama Ophthalmology Associates data breach, disclosed in the spring of 2025, is a case study in that gap, and in how difficult it still is for a patient to get a straight, timely answer about who touched their most sensitive records.

What happened: the confirmed facts

Alabama Ophthalmology Associates, a Birmingham based eye care practice referred to in its own notice as AOA, reported that an unknown actor gained unauthorized access to its computer network and that certain patient data may have been acquired without authorization. That description comes directly from the notification letter the practice sent to affected individuals and filed with state regulators, including the Vermont Attorney General's office, which published the notice as part of its public security breach notice registry on April 8, 2025. Filing a breach notice with a state attorney general is a legal obligation in most states once a threshold number of that state's residents are affected, and it is one of the few places a patient can go to see, in the entity's own words, what it says happened.

According to that notice, AOA became aware of unusual activity in its network environment on January 30, 2025. The practice states that its subsequent investigation, conducted with the help of outside cybersecurity specialists, determined that data may have been accessed or taken between January 22, 2025, and January 30, 2025. AOA says it completed a comprehensive review of the affected files on March 19, 2025, and began mailing notification letters to patients on April 7, 2025.

Those are the dates AOA itself has put on the record. What is not in that filed notice, and what this office was unable to independently confirm through a government source, is a precise count of how many people were affected nationwide. Trade publications that track healthcare data breaches, including HIPAA Journal, have reported a figure of 131,576 individuals, a number those outlets attribute to federal breach reporting. A separate account from a class-action tracking site, published in connection with the resulting settlement, put the number of notified individuals at approximately 153,575. This office reviewed both figures and could not resolve the discrepancy through any government filing. Readers should treat the true total as somewhere in that range, confirmed by AOA to be a six figure number of patients, but not pinned down to an exact, publicly verified figure.

The exact timeline, day by day

Piecing together only what AOA has stated in its filed notice and its public statement, the sequence runs as follows.

Between January 22 and January 30, 2025, an unauthorized party accessed AOA's network and, the practice says, may have acquired data during that window. On January 30, 2025, AOA identified unusual activity and says it moved to secure its network and hire independent forensic investigators. Seven weeks later, on March 19, 2025, AOA states it finished determining which files and which individuals were affected. Nineteen days after that, on April 7, 2025, the practice began mailing notification letters, a date corroborated by the Vermont Attorney General's public notice filing dated April 8, 2025.

Do the arithmetic on AOA's own dates and the total time from discovery to the start of patient notification is 67 days. That figure matters because the federal HIPAA Breach Notification Rule, enforced by the U.S. Department of Health and Human Services Office for Civil Rights, generally requires covered healthcare entities to notify affected individuals "without unreasonable delay and in no case later than 60 days following the discovery of a breach," according to the rule as published on HHS's own website. HIPAA does allow a delay if law enforcement asks for one to avoid interfering with a criminal investigation, and AOA's notice does state that the practice cooperated with law enforcement. This office found no public record explaining whether that exception was invoked here, or why notification took a week longer than the general federal standard contemplates. That is a real, documented gap in the public record, not an accusation, and it is exactly the kind of gap that transparency laws exist to close.

What data was exposed, according to the practice's own account

AOA's filed notification letter states that the categories of information involved may have included a patient's name, date of birth, Social Security number or other government identification number, and diagnosis or treatment information, along with other health related information. AOA's own public statement, issued around the same time, adds that addresses, driver's license information, and health insurance details were also among the data types involved for at least some individuals, while specifying that not every data element was affected for every person notified. In plain terms, the combination described, a name tied to a Social Security number and to specific medical diagnoses, is among the most sensitive pairings of personal data that exists, useful not only for opening fraudulent credit accounts but for medical identity theft, insurance fraud, and targeted phishing built around a person's actual health history.

What is confirmed, what remains unknown, and why the difference matters

It is confirmed, by AOA's own filed notice, that unauthorized access to its network occurred, that the access window ran from January 22 to January 30, 2025, and that Social Security numbers and health information were among the data types potentially exposed. It is confirmed that notification letters began going out April 7, 2025.

It is not confirmed, in any government filing this office could locate, exactly how many people were affected, why the investigation took seven weeks to complete, or whether the 60 day federal notification benchmark was met or exceeded for a documented reason. It is also not confirmed whether the breach involved a ransomware demand, a data extortion threat, or simple unauthorized access without further exploitation. AOA's own statement describes the incident only as unauthorized network access investigated with the help of a forensics firm, language that is common in breach notices and that does not, by itself, indicate whether attackers actually copied data off the network or whether the "may have been acquired" language reflects a more cautious, worst case assumption made for notification purposes.

This distinction between what a covered entity confirms and what it merely cannot rule out is not a technicality. Under HIPAA, an entity must send notice if it cannot demonstrate a low probability that data was compromised, which means the presence of a notification letter does not by itself prove data was stolen and misused. At the same time, a patient receiving that letter has no way, on their own, to determine which side of that line their particular record falls on. That asymmetry, where the organization holding the data knows far more than the patient it is writing to, is the underlying reason breach notification laws exist at all, and it is the reason the specifics of a timeline like this one deserve scrutiny rather than a passing glance.

The class-action settlement: what was resolved and what was not

The breach led to consolidated civil litigation captioned In re Alabama Ophthalmology Associates, P.C., Data Breach Litigation, filed in the Circuit Court of Jefferson County, Alabama. According to the court-authorized settlement administration website and reporting from class-action tracking outlets, the case resolved through a proposed settlement of $850,000, with preliminary court approval reported as granted on February 19, 2026. The settlement's own claims administration site describes the settlement class as all United States residents notified by AOA that their information may have been affected by the January 2025 data incident.

The settlement's own materials list two ways a class member can be compensated: reimbursement of up to $5,000 for documented out of pocket losses tied to the breach, incurred between January 22, 2025, and July 6, 2026, or an alternative cash payment, without documentation, estimated at approximately $60 per claimant, an amount that the settlement administrator states explicitly could rise or fall depending on how many people file valid claims. Every class member, regardless of which cash option they choose, is also offered two years of medical identity theft monitoring and protection services, described by the settlement administrator as including up to $1,000,000 in identity theft insurance coverage. Under the settlement's published schedule, the deadline to exclude oneself from the settlement or to object to it was June 5, 2026, and the deadline to file a claim was July 6, 2026. As of this writing, both of those dates have already passed, and this office could not confirm a specific date for the settlement's final fairness hearing through any source reviewed. Patients who believe they qualify and have not yet acted should check the official settlement website directly for current status, since deadlines in class settlements can occasionally be extended by the court.

It bears stating plainly what a settlement like this does and does not do. It compensates class members for documented losses and offers monitoring services going forward. It does not, on its own, establish that AOA violated any specific law, since settlements of this kind are typically resolved without an admission of liability. And it does not retroactively undo the underlying exposure of Social Security numbers and health records that, once out of an organization's control, cannot be put back.

What affected patients should do now, and what should happen next

Anyone who received a letter from Alabama Ophthalmology Associates, or who was a patient of the practice around January 2025 and is unsure whether they were notified, has concrete steps available. Enroll in the identity monitoring services offered through the breach response, since they are free to affected individuals and provide an early warning system for new accounts opened in your name. Place a free credit freeze with each of the three major credit bureaus, which is a stronger protection than monitoring alone because it blocks new credit from being opened without your explicit action to lift the freeze. Watch for medical identity theft specifically, not just financial fraud, by reviewing insurance explanation of benefits statements for treatment you did not receive, since a stolen medical record can be used to obtain care or prescriptions fraudulently in a victim's name. Keep the original notification letter and any confirmation of claim submission, since documentation matters both for the settlement claims process and for any future dispute over unauthorized accounts or medical charges. And review the settlement's claim form and deadlines directly on the official settlement administration site rather than relying on a secondhand summary, since exact figures and dates can change as a case moves through court approval.

More broadly, this incident is a reminder of what should happen at the institutional level every time a healthcare provider holds Social Security numbers and diagnosis codes in the same network. Entities that store that combination of data owe patients cybersecurity practices proportionate to the harm a breach can cause, not the minimum a regulation technically requires. When a breach does happen, the public interest in a fast, plain-language, fully quantified notice outweighs the institution's interest in taking extra time to manage its own message. A 67 day gap between discovery and the start of notification may or may not have been justified here. What is not in dispute is that patients are entitled to know, promptly and in full, when their most sensitive information has left an organization's control, and to know it from a clear, government-verifiable account rather than having to piece together the story from scattered filings and trade press months later.

Frequently asked questions

Was Alabama Ophthalmology Associates hacked?

According to the practice's own filed breach notification, an unknown actor gained unauthorized access to AOA's network, and data may have been acquired without authorization between January 22 and January 30, 2025. AOA identified the unusual activity on January 30, 2025, and engaged outside forensic investigators.

What information was exposed in the breach?

AOA's notification letter states the involved data may have included a patient's name, date of birth, Social Security number or other government identification number, and diagnosis or treatment information. The practice's public statement adds that addresses, driver's license information, and health insurance details were also involved for at least some individuals, while noting that not every data element applied to every person.

How many people were affected?

AOA's own filed notice does not state an exact number in the portions reviewed for this article. Trade publications tracking healthcare breach reporting have cited a figure of 131,576 individuals, while a class-action tracking source cited approximately 153,575 notified individuals. This office could not resolve that discrepancy through a government filing, and readers should treat the precise total as unconfirmed beyond a six figure range.

Is there a settlement, and how do I file a claim?

Yes. A consolidated case, In re Alabama Ophthalmology Associates, P.C., Data Breach Litigation, filed in the Circuit Court of Jefferson County, Alabama, resolved through a proposed $850,000 settlement. The settlement offers reimbursement up to $5,000 for documented losses or an estimated $60 no-documentation cash payment, plus two years of identity monitoring. According to the settlement administrator, the claims deadline was July 6, 2026, and the opt-out and objection deadline was June 5, 2026. Both dates have passed as of this writing, so anyone who has not yet acted should check the official settlement website immediately to confirm current status.

Does receiving a settlement payment mean I cannot pursue anything else?

Class action settlements typically resolve the claims covered by the settlement in exchange for the benefits offered, and anyone with questions about how a settlement affects their individual rights should read the settlement notice carefully or consult with an attorney about their specific circumstances before taking action.

What should I do if I get a medical bill or insurance notice I do not recognize?

Contact your health insurer and the provider named on the bill immediately, request a written explanation, and consider placing a fraud alert or credit freeze with the major credit bureaus. Medical identity theft can be harder to spot than financial fraud because it often shows up first in insurance paperwork rather than a bank statement.

If you received a data breach notification letter, whether from Alabama Ophthalmology Associates or any other organization, and you are not sure what your rights are or what steps actually protect you, the Law Offices of Elliott Owen Lipinsky in Selma, Alabama is available to help you understand your options. Call (334) 230-7986 to talk through your notification letter, ask questions about credit freezes, identity monitoring enrollment, or settlement claim deadlines, and get straightforward information about consumer protections available to Alabama residents after a data breach. This post is provided for general information about a matter of public record and is not a solicitation to represent any individual in this specific litigation.



Recent Posts

See All

Comments


Subscribe Form

Thanks for submitting!

(334) 230-7986

801 Alabama Avenue, Suite 210, Selma, AL 36701

  • Google Places

©2026 Law Offices of Elliott Owen Lipinsky

bottom of page