The EyeCare Partners lawsuit is a consolidated federal class action accusing the St. Louis–based eye care network of failing to protect patient data and then waiting roughly a year to tell more than 17,000 people their information had been exposed. Two suits filed in the Eastern District of Missouri in February 2026 have been combined before U.S. District Judge Henry Edward Autrey, and the case is in its early stages.{1CourtListener. Staley v. Eyecare Partners, LLC}{2PACER Monitor. Thompson v. Eyecare Partners, LLC}
What Happened in the Breach
Between December 3, 2024, and January 28, 2025, an unauthorized third party accessed multiple email accounts managed by EyeCare Partners. The company detected suspicious activity in one of those accounts on January 28, 2025, and hired a forensic firm to investigate.{3EyeCare Partners. Notice of Data Security Incident}{4Becker’s ASC Review. EyeCare Partners Suffers Data Security Incident}
The compromised inboxes contained information belonging to patients across the EyeCare Partners network, including affiliates such as The Ophthalmology Group, Ophthalmology Consultants, and Ophthalmology Associates.{5Federman & Sherwood. EyeCare Partners LLC Data Breach Investigated} Exposed data included names, addresses, dates of birth, Social Security numbers, driver’s license and government ID numbers, health plan information, and limited clinical information.{6ClassAction.org. EyeCare Partners Data Breach Lawsuits} EyeCare Partners said medical records and detailed clinical notes were not accessed.{3EyeCare Partners. Notice of Data Security Incident}
The company initially reported 17,110 affected individuals to the U.S. Department of Health and Human Services and later revised the figure to 17,622.{7HIPAA Journal. Data Breach: EyeCare Partners}{} The method the intruder used has not been publicly confirmed, though EyeCare Partners’ response, which included reminding employees how to recognize suspicious emails, points to a possible phishing entry point.{8ClaimDepot. EyeCare Partners Data Breach}
Why the Notification Timing Is the Heart of the Case
EyeCare Partners identified the suspicious activity on January 28, 2025. Its review of the impacted email accounts was not completed until November 11, 2025, and notification letters did not go out to affected individuals until February 3, 2026. The breach was reported to HHS and state attorneys general around the same time.{7HIPAA Journal. Data Breach: EyeCare Partners}{6ClassAction.org. EyeCare Partners Data Breach Lawsuits}
HIPAA’s Breach Notification Rule requires covered entities to notify affected individuals “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.”{} Under HHS guidance, the 60-day clock starts when the incident is first known, not when an internal investigation wraps up. The regulations treat that deadline as an outer limit and state that an entity’s investigation must be conducted promptly; letting an investigation drag on does not extend the notification window.{9U.S. Department of Health and Human Services. Breach Notification Rule} EyeCare Partners waited roughly a year, a timeline that significantly exceeds the 60-day limit absent a documented law enforcement delay request or other narrow exception.
The Class Action Complaints
Within days of the notification letters going out, affected patients sued. The first case, Staley v. Eyecare Partners, LLC (Case No. 4:26-cv-00194), was filed on February 9, 2026, in the U.S. District Court for the Eastern District of Missouri under diversity jurisdiction, with breach of fiduciary duty among its causes of action.{1CourtListener. Staley v. Eyecare Partners, LLC} A second suit, Thompson v. Eyecare Partners, LLC (Case No. 4:26-cv-00228), followed shortly after.
On April 16, 2026, Judge Autrey consolidated the two cases. The same day, EyeCare Partners filed an unopposed motion to stay the case or, alternatively, to extend its deadline to respond to the class action complaint.{2PACER Monitor. Thompson v. Eyecare Partners, LLC} Judge Autrey issued a scheduling order on April 17, 2026, and on June 11, 2026, the court granted an extension of time to file documents.{1CourtListener. Staley v. Eyecare Partners, LLC} No motion for class certification has been filed. Separately, Federman & Sherwood said it was investigating the adequacy of EyeCare Partners’ cybersecurity safeguards and potential legal claims on behalf of affected individuals.{5Federman & Sherwood. EyeCare Partners LLC Data Breach Investigated}
What EyeCare Partners Is Offering Affected Patients
EyeCare Partners is offering 24 months of complimentary credit monitoring, credit report, and credit score services through Cyberscout, a TransUnion company. The services include credit file alerts, access to credit reports, and proactive fraud assistance. People who received a notification letter have 90 days from the date of receipt to enroll, and the company has set up a toll-free line for questions.{8ClaimDepot. EyeCare Partners Data Breach} Signing up for the offered services does not waive the right to participate in the class action.
A Separate Wage-and-Hour Case
The data breach litigation is not the only case involving the company. In Vanorden v. ECP Optometry Services LLC (Case No. CV-24-01060-PHX-DWL), filed in the U.S. District Court for the District of Arizona, two former employees brought a collective action under the Fair Labor Standards Act. Plaintiffs Jodeci Vanorden and Gabriella Gantt alleged a company-wide practice of requiring hourly employees to work off the clock without overtime pay and said a supervisor instructed them to manipulate timecards and threatened disciplinary action if they recorded overtime.{10U.S. District Court for the District of Arizona. Vanorden v. ECP Optometry Services LLC}
EyeCare Partners argued it was not the plaintiffs’ employer and that only its subsidiary, ECP Optometry Services, employed them. On December 23, 2024, the court granted conditional certification of the collective action under the Ninth Circuit’s lenient standard and authorized notice to potential class members, noting that arguments about personal jurisdiction over non-Arizona opt-in plaintiffs were premature.{10U.S. District Court for the District of Arizona. Vanorden v. ECP Optometry Services LLC} That case is separate from the data breach litigation and involves a different group of potential plaintiffs.
The Financial Cloud Over Any Recovery
EyeCare Partners operates over 700 locations across 18 states with more than 1,000 providers, and generated roughly $1.85 billion in revenue in 2024. It also carries a heavy debt load.{11EyeCare Partners. EyeCare Partners Announces Change in Executive Office}{12S&P Global Ratings. EyeCare Partners LLC Ratings} In May 2024, the company completed a debt exchange covering approximately $2.1 billion in term loan debt and secured $275 million in new financing.{13EyeCare Partners. EyeCare Partners Announces Refinancing Transactions} In December 2025, S&P Global Ratings downgraded the company’s credit rating to CCC- with a negative outlook, warning that a default or distressed exchange was likely within six months. S&P cited cash reserves of about $17.8 million, weaker demand, doctor attrition, and a debt-to-EBITDA ratio of roughly 16 times, with cash flow deficits projected through at least 2027.{} That backdrop adds uncertainty for anyone who eventually seeks damages, since the defendant is already straining to service existing obligations.