EyeCare of Bartlesville
Disclosed Mar 13, 201511 years ago4,000 affectedConfirmed
The covered entity’s (CE) database was hacked and held by an outside malware virus. The computer server’s hard drive contained the unencrypted, password protected health information (PHI) of approximately 4,000 individuals. The electronic PHI (ePHI) contained names, addresses, telephone numbers, dates of birth, insurance identification numbers, and diagnosis codes. Since the malware virus was discovered, the CE confirmed that nothing had been copied or removed from the computer, just locked. The CE destroyed the hard drive so that no further access to the hard drive was possible. The CE provided breach notification to HHS, affected individuals, and posted notice on its website. In addition, the CE retrained workforce members, and instituted a requirement of quarterly employee privacy and security awareness training. The CE improved safeguards by changing all passwords. Following OCR’s investigation, the CE further improved safeguards by changing anti-virus software, encrypting all information saved to its hard drive, and moving ePHI to a cloud based system. It revised procedures to require weekly computer virus scans and monthly audit reports. It also changed vendors to those that
What is known
| People affected | 4,000 (as reported to HHS) |
|---|---|
| Disclosed | Mar 13, 2015 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): EyeCare of Bartlesville (Healthcare Provider, OK)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 13, 2015 | 4,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.