Black Hills Regional Eye Institute
Disclosed Mar 6, 20251 year ago106,763 affectedConfirmed
The covered entity (CE), Black Hills Regional Eye Institute, reported that it was the subject of a cybersecurity incident that affected the protected health information (PHI) of 106,763 individuals. The PHI involved included clinical, demographic, and financial information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative, technical, and security safeguards.
What is known
| People affected | 106,763 (as reported to HHS) |
|---|---|
| Disclosed | Mar 6, 2025 |
| Happened | Jan 8, 2025 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2025 data breach report: Black Hills Regional Eye Institutein.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Black Hills Regional Eye Institute (Healthcare Provider, SD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Mar 6, 2025 | 1 |
| HHS archivetotal | Mar 31, 2025 | 106,763 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 398 to 106763 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Black Hills Regional Eye Institute, reported that it was the subject of a cybersecurity incident that affected the protected health information (PHI) of 106,763 individuals. The PHI involved included clinical, demog · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.