On May 4, 2026, Princeton Family Eye Care detected suspicious activity within its email environment and engaged third-party cybersecurity experts. By June 2026, it was determined that an unauthorized third party had accessed a company email account. A data-review firm was then brought in to analyze the affected account.
The breach reportedly exposed sensitive personally identifiable information and protected health information for 933 Texas residents. This included names, addresses, dates of birth, Social Security numbers, driver's license numbers, government-issued ID numbers (such as passport or state ID cards), medical information, medical record numbers, treatment details, and health insurance information.
The data breach was reported to the Texas Attorney General’s office on August 10, 2026, and the company began notifying affected individuals. It remains unclear if any further regulatory actions are pending or if other states were impacted beyond Texas.