Ocuco, Inc., an optical software solutions provider based in Dublin, Ireland, with U.S. headquarters in Florida, experienced a data breach between March 28 and April 1, 2025. The company discovered the unauthorized access on April 1, 2025, after a third party claimed to have stolen information from Ocuco's environment via a dark web posting. Ocuco stated that the breach originated from a vulnerability in third-party software, which was not disclosed to them in time to prevent unauthorized access. Consumers began receiving notification letters in June-July 2025.
More than 240,961 patients of eye care providers who are Ocuco customers were affected. The compromised data included names, addresses, Social Security numbers (SSNs), medical record numbers, health insurance numbers, provider names, prescriptions/medications, treatment/diagnosis information, lab results, medical histories, payments for health services, workers’ compensation claims with medical information, health insurance coverage/claim information, financial account numbers (without access codes), driver’s license numbers, dates of birth, gender, and personal health numbers (for Canadian individuals). At the time of notification, Ocuco was unaware of any misuse of the data.
Data breach details can continue to emerge over time, and notifications to affected individuals may be delayed.