Class Action Settlement Reached in Eye Physicians of Central Florida Data Breach

A federal court in Florida has approved a settlement in the case of Connell v. Eye Physicians of Central Florida, P.L.C.

A federal court in Florida has approved a settlement in the case of Connell v. Eye Physicians of Central Florida, P.L.C., addressing a data breach that exposed the personal and medical information of patients. The preliminary approval came on February 23, 2026, more than two years after the unauthorized access occurred on November 5, 2023. If you received a notification about this breach—perhaps notification of compromised insurance information or medical records from Eye Physicians of Central Florida—you may be eligible to file a claim for compensation, identity protection services, or both.

This article explains what happened, who qualifies for compensation, how much affected individuals can receive, and the critical deadlines for taking action. The settlement provides multiple forms of relief. Patients whose information was exposed can receive reimbursement for documented losses caused by the breach, ranging from $2,000 for ordinary losses (like bank fees or time spent addressing fraud) up to $7,500 for extraordinary losses (such as documented identity theft). Additionally, all settlement class members receive two free years of comprehensive identity theft protection through CyEx Identity Defense Complete, including identity theft insurance and victim assistance services. The clock is ticking, however—you have until May 15, 2026, to submit your claim.

Table of Contents

What Data Was Compromised in the Eye Physicians Breach?

On November 5, 2023, an unauthorized third party gained access to eye Physicians of Central Florida’s systems, exposing sensitive patient information. The compromised data included names, addresses, dates of birth, medical diagnoses, treatment information, health insurance details, and financial information. For patients of an ophthalmology practice, this means not only personal identifiers but also specific information about eye conditions and treatments—data that could be particularly sensitive to some individuals.

The scope of the breach was significant enough to trigger a formal class action settlement, indicating that many patients were potentially affected. If you visited Eye Physicians of Central Florida at any point and received a breach notification letter, your information was likely included in this incident. Unlike smaller data exposure incidents that might affect only billing records, this breach touched multiple categories of protected health information, increasing the risk of identity theft and medical fraud.

What Data Was Compromised in the Eye Physicians Breach?

Settlement Timeline and Court Approval Process

The settlement received preliminary court approval on February 23, 2026—roughly 2.5 years after the breach occurred. This preliminary approval is a significant milestone because it means the court has determined that the settlement terms are fair, reasonable, and adequate for the affected patients. However, preliminary approval is not final approval. There will be a final approval hearing later in 2026, so the settlement process is still ongoing.

Understanding this timeline helps explain why claims are still being accepted and why deadlines are structured the way they are. The delay between breach and settlement approval is typical in data breach cases. During this period, the parties negotiated terms, and the settlement administrator had to identify affected individuals and prepare notification. The preliminary approval decision represents the court’s initial agreement to the settlement terms; final approval will come after the claim filing deadline and any final hearing that may occur. This matters for claimants because it affects when funds will actually be distributed—typically after final approval.

Eye Physicians Settlement Compensation by Loss TypeOrdinary Losses (up to)2000$ (+ years for protection)Extraordinary Losses (up to)7500$ (+ years for protection)Identity Protection (years)2$ (+ years for protection)Maximum Total Value9500$ (+ years for protection)Source: Connell v. Eye Physicians of Central Florida Settlement Agreement, Settlement Website eyephysicianscentralflsettlement.com

Ordinary Loss Compensation—What You Can Claim

The settlement caps ordinary loss reimbursement at $2,000 per claimant. Ordinary losses include concrete, quantifiable expenses directly related to the breach, such as bank fees charged after fraudulent transactions, postage and long-distance charges incurred while contacting financial institutions, or travel expenses to resolve fraud issues in person. Additionally, you can claim up to three hours of lost time at a rate of $25 per hour, for a maximum of $75 for time loss. For example, if you spent two hours contacting your insurance company to correct fraudulent claims and paid $15 in phone charges, you could claim $65 in lost time plus $15 in communication costs.

A critical limitation to understand: ordinary loss claims require documentation. Simply claiming you spent time dealing with the breach is not sufficient—you’ll need receipts, phone bills, affidavits, or other proof of the actual expenses and time spent. If you incurred $500 in banking fees due to fraudulent charges connected to the breach and spent five hours resolving the situation, you could claim the $500 in fees plus the maximum $75 for time loss (three hours at $25/hour), totaling $575. However, if you can’t document the bank fees, you can only claim the documented lost time.

Ordinary Loss Compensation—What You Can Claim

Extraordinary Loss Compensation—For Documented Fraud

Beyond ordinary losses, the settlement provides up to $7,500 per claimant for extraordinary losses—meaning documented monetary losses from fraud or identity theft directly caused by the breach. This is where significant compensation becomes possible, but with an important caveat: the loss must be documented and directly connected to the data breach. For example, if fraudsters opened credit cards in your name using the personal information from Eye Physicians’ breach and incurred $5,000 in unauthorized charges before you caught the fraud, you could potentially claim that $5,000 (subject to the $7,500 cap).

The distinction between ordinary and extraordinary losses is important for your claim strategy. An extraordinary loss claim requires stronger evidence linking the fraud to the breach and proof of the actual monetary harm suffered. If you experienced identity theft but can’t demonstrate a direct connection to the Eye Physicians breach, or if the loss fell within a category covered by your credit card fraud protection, you might face challenges. However, if you have documentation showing fraudulent accounts opened using data from the breach, those documented losses can be claimed up to the $7,500 limit.

Identity Theft Protection Benefit—Two Years of CyEx Coverage

All settlement class members automatically receive two years of CyEx Identity Defense Complete at no cost. This service includes identity theft insurance and access to victim assistance services. Even if you don’t file a monetary claim for losses—perhaps because you haven’t experienced fraud yet or don’t have sufficient documentation—this protection alone provides significant value given that your personal, medical, and financial information was exposed.

A practical note: this identity protection is provided at no cost to settlement members, but only for two years. When your coverage expires in 2028 (assuming you’re reading this shortly after the settlement), you may want to evaluate whether to purchase continued identity protection. The inclusion of identity theft insurance means that if fraud does occur during the coverage period and causes losses, you have both monitoring and insurance protection rather than having to pursue separate claims. This is particularly valuable because identity theft can occur months or even years after a breach becomes public.

Identity Theft Protection Benefit—Two Years of CyEx Coverage

Critical Deadlines—When You Must Act

Two essential deadlines govern your participation in this settlement. The exclusion and objection deadline is April 29, 2026—the last day you can opt out of the settlement or formally object to its terms if you choose not to participate. Most individuals should not exclude themselves, as that would give up all rights to compensation and protection. The claim filing deadline is May 15, 2026, by which time all compensation claims must be submitted online, postmarked, or emailed.

If you miss this deadline, you generally lose the right to file a claim, though you remain a settlement class member entitled to the identity protection benefit. This timing is important to understand because it means you have less than seven weeks from the preliminary approval date to gather documentation, complete your claim form, and submit it. If you suffered documented losses from fraud or identity theft, now is the time to gather receipts, bank statements, credit reports, and any other evidence. Many claimants underestimate how much time documentation gathering requires—don’t wait until May to begin this process. Even if you haven’t experienced fraud yet, you should register to ensure you receive the CyEx identity protection benefit when it becomes available.

The Broader Context of Data Breach Settlements

The Eye Physicians settlement reflects a growing trend of court-approved settlements in healthcare data breach cases. As medical practices store increasingly sensitive information in digital systems, breaches have become more common, and settlements have become a mechanism for compensating affected individuals. This settlement’s terms—offering both direct monetary compensation and identity protection services—represent a standard approach in modern breach settlements.

What’s notable about this particular settlement is the relatively modest settlement amount (undisclosed in public filings, but reflected in the compensation caps offered) coupled with substantial identity protection benefits. Eye Physicians did not admit wrongdoing, which is standard in settlement negotiations, but agreed to settle to resolve the litigation. For affected patients, this means compensation is available without waiting for a full trial, though the trade-off is that liability was never definitively established in court.

You Might Also Like

Open Settlements You Can Claim Now

Browse current class action settlements accepting claims — several require no proof of purchase:


Leave a Reply