Laurel Eye Clinic, an ophthalmology and optometry practice, discovered an external system breach on January 26, 2025, which reportedly occurred on January 22, 2025. The clinic engaged a third-party cybersecurity firm to conduct a forensic investigation. Notification letters were mailed to affected individuals starting on April 22, 2026, approximately 15 months after discovery. The clinic also posted a notice on its website in March 2025.
The breach affected approximately 42,295 individuals. The compromised data may include patient names, Social Security numbers, medical information, financial information, financial account information, driver's license information, usernames and passwords, and health insurance information. The specific types of data exposed varied by individual. It is unclear if there are additional states affected beyond the publicly confirmed Maine, New Hampshire, and Massachusetts.
Laurel Eye Clinic offered 12 months of complimentary credit monitoring and identity theft restoration services through Cyberscout, a TransUnion company, to affected individuals. The clinic also implemented enhanced cybersecurity measures following the incident. Details can emerge later, and notices may be delayed.