In May 2026, Heart of America Eye Care experienced a data breach during which an unauthorized party gained access to its systems. The CMD Organization claimed responsibility on the dark web, alleging access to 730 GB of data.
The breach involved individual health information, including names, dates of birth, and potentially medical records. Approximately 7,500 individuals were notified of the incident. Specific types of data like SSN or financial data have not been explicitly confirmed. It remains unclear when consumers were notified or if regulators were notified, though as a private medical provider, it is likely subject to HIPAA breach notification rules.
Further details, including the exact content of the notification letter or specific state Attorney General filings, are not yet publicly available. Additional information may emerge as investigations proceed.