The personal information of millions of individuals may have been stolen by threat actors as a result of a data breach at Eye Care Leaders, a firm that provides electronic health record and practice management solutions.
The Durham, North Carolina-based company, which sells eye care management software solutions, claims to work with more than 9,000 ophthalmologists and optometrists. At least 23 of these eye care providers have been impacted by a data breach that Eye Care Leaders disclosed in December 2021.
Eye Care Leaders took down the compromised systems within 24 hours after the breach was detected, but not before the attackers accessed databases and files containing patient records.
Potentially compromised information included names, addresses, birth dates, gender, phone numbers, email addresses, driver’s license numbers, health insurance information, medical record numbers, Social Security numbers, and eye care-related medical information.
“The forensics investigation revealed that databases and files compromised as part of the incident did not include credit card or financial information,” a data breach notification letter sent to Texas Tech University Health Sciences Center (TTUHSC) patients reads.
TTUHSC says Eye Care Leaders informed it on April 19 of patient data compromise, but claims that it has no evidence of any patient information being “accessed or used without authorization.”
TTUHSC informed the U.S. Department of Health and Human Services that the data of more than 1.29 million of its patients might have been compromised in the incident.
As of June 19, a list of impacted eye care providers that HIPAA Journal is maintaining shows that the data of approximately 2.2 million patients was potentially compromised in the Eye Care Leaders data breach.
However, given the large number of customers the vendor claims to have, the total number of impacted individuals could be much higher.