Skip to content

EyeCare of Bartlesville

Disclosed Mar 13, 201511 years ago4,000 affectedConfirmed

Official notice

The covered entity’s (CE) database was hacked and held by an outside malware virus. The computer server’s hard drive contained the unencrypted, password protected health information (PHI) of approximately 4,000 individuals. The electronic PHI (ePHI) contained names, addresses, telephone numbers, dates of birth, insurance identification numbers, and diagnosis codes. Since the malware virus was discovered, the CE confirmed that nothing had been copied or removed from the computer, just locked. The CE destroyed the hard drive so that no further access to the hard drive was possible. The CE provided breach notification to HHS, affected individuals, and posted notice on its website. In addition, the CE retrained workforce members, and instituted a requirement of quarterly employee privacy and security awareness training. The CE improved safeguards by changing all passwords. Following OCR’s investigation, the CE further improved safeguards by changing anti-virus software, encrypting all information saved to its hard drive, and moving ePHI to a cloud based system. It revised procedures to require weekly computer virus scans and monthly audit reports. It also changed vendors to those that

What is known

People affected4,000 (as reported to HHS)
DisclosedMar 13, 2015
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMar 13, 20154,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about EyeCare of Bartlesville

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.