Hello. Vision benefits provider EyeMed agreed to pay $5 million to settle a consumer data-breach lawsuit stemming from a phishing attack in June 2020.
I’ve noticed a swing lately toward quicker settlements, often after two or three years of court gyrations for the simpler cases. But EyeMed’s situation wasn’t simple.
EyeMed has had to deal with a few complicated legal actions in the five years after its breach, which affected nearly more than two million people. The New York Department of Financial Services launched a case that found violations such as a lack of multifactor authentication, faulty data-disposal policies and an instance of nine employees sharing email credentials. The agency fined EyeMed $4.5 million in 2022. Several state attorneys general also sued the company, winning a $2.5 million settlement in 2023, and requiring EyeMed to improve cybersecurity and undergo regular security audits.
The consumer settlement, which is due for final court approval in December, calls for reimbursements for people who can prove monetary losses related to the breach, or $50 each with few questions asked.
More news below.
|