DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Eyemart Express notifies patients of breach

Posted on March 22, 2021 by Dissent

Eyemart Express posted a notice of breach in local media:

Farmers Branch, Texas, March 21, 2021 — Eyemart Express, LLC has discovered it was targeted by a cyber attack that affected certain Eyemart Express email accounts. Importantly, the attack did not affect Eyemart Express’ internal systems that store medical or billing records. Once the incident was discovered on December 11, 2020, Eyemart Express immediately took steps to stop the attack and conducted a thorough investigation of the incident. The investigation revealed that the unauthorized actor accessed limited personal information for a small number of Eyemart Express customers. The information included names, e-mail addresses, and the subject lines of email communications between Eyemart Express and those customers, such as email subject lines regarding eye exam appointments and eyeglass order status updates. Eyemart Express notified all those affected customers by letter. There is no evidence at this time that the incident, which began on August 21, 2020, affected additional customers or additional personal information, but we learned that the unauthorized actor may have been capable of obtaining additional personal information located in certain email accounts. Therefore, in order to be as transparent as possible, Eyemart Express is providing this general notice to all customers. Eyemart Express customers with questions about the incident may call 855-654-0481 toll-free for additional information, Monday through Friday, 8:00 a.m. to 8:00 p.m. CT. Eyemart Express provides eyewear at over 200 locations nationwide, and also does business as Eyewear Express, Vision 4 Less, and Visionmart Express.

Source: Waco Tribune

Comment: This seems to be a reportable HIPAA breach, so we may see it on HHS’s public breach tool at some point.


Related:

  • Little Rock Psychologist Indicted by Federal Grand Jury for Defrauding Medicare and Arkansas Blue Cross Blue Shield
  • A Swath of Bank Customer Data Was Hacked. The F.B.I. Is Investigating.
  • Ph: Department of the Interior and Local Government to probe alleged data breach by hackers
  • Two suspected Scattered Spider hackers plead not guilty over Transport for London cyberattack
  • Threat actors have reportedly launched yet another campaign involving an application connected to Salesforce
  • Russian hackers target IVF clinics across UK used by thousands of couples
Category: Breach IncidentsHackHealth Data

Post navigation

← Ca: Nunavut schools confirm school information system vendor suffered ransomware attack
MA: Stratus Technologies posts about ransomware attack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Leavenworth, Kansas cyberattack disrupts city services
  • They’ve escaped a lot of media attention, but Anubis RaaS is a threat to the medical sector
  • “In the most expedient time possible…”
  • Portugal updates cybercrime law to exempt security researchers
  • LockBit 5’s “new secure blog domain” infra leaked already
  • NL: Nuenen accidentally leaks addresses of 1,000 asylum center opponents
  • Ex-teen hackers warn parents are clueless as children steal ‘millions’
  • UK Government Considers Computer Misuse Act Revision
  • Japan issues arrest warrant against teen suspected of cyberattack using AI
  • How old is the average hacker? What does a new research report suggest? (1)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Privacy concerns raised as Grok AI found to be a stalker’s best friend
  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.