Linda Hulewat v. Medical Management Resource Group LLC, et al.

District Court, D. Arizona·Decided June 30, 2026·No. 2:24-cv-00377·Unknown

Opinion

WO

Linda Hulewat, No. CV-24-00377-PHX-DJH

Plaintiff, ORDER

v.

Medical Management Resource Group LLC, et al., Defendants. On November 17, 2025, Plaintiffs Linda Hulewat, Karen Foti Williams, Ralph Gallegos, Michael Martinez, Lynnae Anderson, Marie Therese Montoya, Charles Peterson, Robert Kirk, Marilyn Zajacka, Lynda Israel, Latricia Pelt, Barry Pelt, Ken Waters, Robert Ahrensdorf, and David Yeager (collectively, “Plaintiffs”) filed an Unopposed Motion for Preliminary Approval of Class Action Settlement (Doc. 83). As the Motion is unopposed, Defendants Medical Management Resource Group, LLC, Barnet Dulaney Perkins Eye Center, PC, and Southwestern Eye Center, Ltd. (collectively, “Defendants”) did not file a response. For the reasons stated below, the Court will grant Plaintiff’s Motion. I. Background This case arises from a cyberattack and resulting data breach (the “Data Breach”) that occurred on or around November 14, 2023. (See generally Doc. 28). Defendants generally provide eye care physician services to patients across the country. (Id. at ¶ 2). In their practice, Defendants collect and store patients’ Personally Identifiable Information (“PII”) and Private Health Information (“PHI”). Around November 14, 2023, cybercriminals infiltrated Defendants’ computer systems and absconded with patients’ PII and PHI. (Id. at ¶ 4). The impacted patients, including Plaintiffs, were notified of the Data Breach on or about February 15, 2024. (See id. at ¶ 120). Plaintiffs allege that Defendants failed to protect their sensitive information, resulting in the Breach. (Id. at ¶ 1). Consequently, multiple cases were brought regarding the Data Breach, which were all ultimately consolidated into the present action. (See Doc. 16). In the time since, several defendants were dismissed from the action for lack of personal jurisdiction. (See Doc. 74). Defendants, likewise, sought dismissal of the action based on a failure to state a claim. (See Doc. 52). However, during the pendency of Defendants’ Motion to Dismiss, the parties scheduled and attended mediation with a highly experienced mediator. (Doc. 83 at 12). Plaintiffs and Defendants were ultimately able to reach a settlement with the assistance of the mediator. (Id.) II. Proposed Settlement Agreement The parties entered into a Class Action Settlement Agreement (the “Settlement Agreement”) on November 17, 2025. The pertinent terms of the Agreement are as follows. The “Settlement Class” is comprised of the Damages Settlement Class Members and the Injunctive Relief Class. The Injunctive Relief Class is defined as: [A]ll individuals whose personal information is collected or maintained by Defendant. Excluded from the Injunctive Relief Class are Defendant, their representatives, any judicial officer presiding over the matter, and such judicial officers immediate family members and staff. Plaintiffs Linda Hulewat; Karen Foti Williams; Ralph Gallegos; Michael Martinez; Lynnae Anderson; Marie Therese Montoya; Charles Peterson; Robert Kirk; Marilyn Zajacka; Lynda Israel; Latricia Pelt; Barry Pelt; Ken Waters; Robert Ahrensdorf; and David Yeager are Injunctive Relief Class Members. (Doc. 83-1 at 8). Simultaneously, Damages Settlement Class Members include: [T]he approximately 258,070 U.S. residents whose Social Security numbers and other personal information were compromised in the Data Breach. Excluded from the Damages Class are the Defendant, their representatives, any judicial officer presiding over the matter, and such judicial officers immediate family members and staff. The Damages Settlement Class Members are eligible to submit a claim under the Damages Class Benefits. Plaintiffs Karen Foti Williams, Michael Martinez, Robert Kirk, Lynda Israel, Ken Waters, and David Yeager are Damages Settlement Class Members. (Id. at 7). These two groups, in combination, make up the Settlement Class. (Id. at 12). Those encompassed in the Damages Settlement Class, whose Social Security numbers were compromised, will be entitled to receive monetary compensation. (See id.). At the same time, the Injunctive Relief Class will all benefit from the various security measures Defendants will implement. (See id. at 16–17). A. Settlement Fund Under the terms of the Agreement, Defendants will endow a non-reversionary “Settlement Fund” in the amount of $1,750,000.00. (Id.) This Fund will be used to pay for Notice and Settlement Administration Costs; all taxes owed by the Settlement Fund; any Court-approved attorney fees, costs, and expenses; any Court-approved Service Awards approved by the Court, and all valid Claims made by the Damages Settlement Class. (Id. at 14). Damages Settlement Class Members will have the opportunity to submit a Claim to receive either a Pro-Rata Cash Payment or be reimbursed for Out-of-Pocket Expenses. A Pro-Rata Cash Payment will entitle a claimant to a pro rata settlement payment, “which may increase or decrease the cash payment, subject to the Settlement Fund cap.” (Id. at 51). Alternatively, a Claim for Out-of-Pocket Expenses can be submitted for “documented out-of-pocket losses reasonably and fairly traceable to the Data Breach.” (Id. at 15). Such Claims must be supported by documentation and attestation and are subject to a $3,000.00 individual cap. (Id. at 16). A “Settlement Administrator” shall be appointed to provide Class Members with notice, review claims, and distribute funds to all valid claimants accordingly. (Id. at 28–32). The Agreement provides opt-out and objection procedures for Damages Settlement Class Members. (Id. at 22–24). B. Injunctive Relief Aside from the Settlement Fund, the Agreement provides for various forms of Injunctive Relief regarding Defendants’ cybersecurity as consideration to the Injunctive Relief Class. (Id. at 16–17). As part of the Injunctive Relief, Defendants shall, amongst other things, implement a Chief Information Officer role, retain an Information Security Training Specialist, create a Cybersecurity Steering Committee, implement an enterprise- wide cybersecurity training program, engage an independent third-party vendor to conduct periodic penetration testing, and administer an improved disaster recovery solution. (Id. at 17–18). C. Fees, Service Awards, and Releases The Agreement allows for Class counsel to submit a motion for attorney fees and expenses and for Plaintiffs to seek Service Awards of $2,500.00. (Id. at 21–22). Finally, Damages Settlement Class Members release Defendants from all claims related to the Data Breach and are enjoined from pursuing any such claims. (Id. at 24–25). At the same time, Defendants release Plaintiffs, Damages Settlement Class Members, and Class Counsel of all claims arising out of this Litigation. (Id. at 25). Injunctive Class Members release Defendants from any and all claims for injunctive and/or declaratory relief as described in the Agreement, but Injunctive Relief Class Members do not release or otherwise waive any individual claims for monetary relief. (Id. at 25–26). III. Legal Standard While the Ninth Circuit has declared a strong judicial policy for settlement of class actions, Class Plaintiffs v. City of Seattle, 955 F.2d 1268, 1276 (9th Cir. 1992), Federal Rule of Procedure 23(e) still requires court approval of any class action settlement. Fed. R. Civ. P. 23(e). “Approval under [Rule] 23(e) involves a two-step process in which the Court first determines whether a proposed class action settlement deserves preliminary approval and then, after notice is given to class members, whether final approval is warranted.” Nat’l Rural Telecomms. Coop. v. DIRECTV, Inc., 221 F.R.D. 523, 525 (C.D. Cal. 2004). At the preliminary approval stage, “courts must peruse the proposed compromise to ratify both [1] the propriety of the certification and [2] the fairness of the settlement.” Staton v. Boeing Co.,

Linda Hulewat v. Medical Management Resource Group LLC, et al., (D. Ariz. 2026).

Linda Hulewat v. Medical Management Resource Group LLC, et al. (Linda Hulewat v. Medical Management Resource Group LLC, et al.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

NCNB Texas National Bank v. Johnson
11 F.3d 1260 (Fifth Circuit, 1994)
Amchem Products, Inc. v. Windsor
521 U.S. 591 (Supreme Court, 1997)
Wal-Mart Stores, Inc. v. Dukes
131 S. Ct. 2541 (Supreme Court, 2011)
In Re Bluetooth Headset Products Liability
654 F.3d 935 (Ninth Circuit, 2011)
Ellis v. Costco Wholesale Corp.
657 F.3d 970 (Ninth Circuit, 2011)
Staton v. Boeing Co.
327 F.3d 938 (Ninth Circuit, 2003)
Ginger McCall v. Facebook, Inc.
696 F.3d 811 (Ninth Circuit, 2012)
Robert Radcliffe v. Experian Information Solutions
715 F.3d 1157 (Ninth Circuit, 2013)
Rodriguez v. West Publishing Corp.
563 F.3d 948 (Ninth Circuit, 2009)
In Re Tableware Antitrust Litigation
484 F. Supp. 2d 1078 (N.D. California, 2007)
Theodore H. Frank v. Netflix, Inc.
779 F.3d 934 (Ninth Circuit, 2015)
Denise Edwards v. the First American Corp
798 F.3d 1172 (Ninth Circuit, 2015)
Just Film, Inc. v. Sam Buono
847 F.3d 1108 (Ninth Circuit, 2017)
Sarah Murphy v. Sfbsc Management, LLC
944 F.3d 1035 (Ninth Circuit, 2019)
Hanlon v. Chrysler Corp.
150 F.3d 1011 (Ninth Circuit, 1998)
Wright v. Linkus Enterprises, Inc.
259 F.R.D. 468 (E.D. California, 2009)
Spann v. J.C. Penney Corp.
314 F.R.D. 312 (C.D. California, 2016)