Skip to content

EyeMed Vision Care

Disclosed Sep 28, 20205 years ago1,474,000 affectedConfirmed

Official notice

EyeMed Vision Care, a business associate (BA), reported that employees were the victims of an email phishing attack that compromised the protected health information (PHI) of 1,474,000 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, drivers’ license numbers, diagnoses/conditions, medications prescribed, and other treatment information. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA implemented additional administrative, technical, and security safeguards to protect PHI. OCR provided technical assistance to the BA regarding the HIPAA Privacy Rule.

What is known

People affected1,474,000 (as reported to HHS)
DisclosedSep 28, 2020
DiscoveredJul 1, 2020
HappenedJun 24, 2020
AttackPhishing
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: EyeMed Vision Careoag.ca.gov · Official notice
Washington Attorney General breach notice: EyeMed Vision Careatg.wa.gov · Official notice
Oregon DOJ breach notice: EyeMed Vision Carejustice.oregon.gov · Official notice
HHS OCR breach report (archive, resolved): EyeMed Vision Care (Business Associate, OH)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CASep 28, 2020
HHS archivetotalSep 28, 20201,474,000
Washington AGresidents of WAOct 12, 202019,625
Oregon DOJresidents of OROct 12, 2020547,370
History of this record
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 1474000 · backfill source
  • 2026-09-25 · summary: empty to EyeMed Vision Care, a business associate (BA), reported that employees were the victims of an email phishing attack that compromised the protected health information (PHI) of 1,474,000 individuals. The PHI involved included names, addresses · backfill source
  • 2026-09-25 · attack: unknown to phishing · backfill source
  • 2026-09-25 · discovered: empty to 2020-07-01 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about EyeMed Vision Care

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.