Hermitage Eye Care
Disclosed Nov 5, 20214 years ago11,672 affectedConfirmed
The covered entity (CE), Hermitage Eye Care, reported that its business associate (BA) experienced a security incident in which the electronic protected health information (ePHI) of 11,672 individuals was accessible via a patient portal on the Internet. The ePHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, and conditions. The BA notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to this incident and OCR’s investigation, the BA implemented additional administrative, technical, and security safeguards to better protect ePHI.
What is known
| People affected | 11,672 (as reported to HHS) |
|---|---|
| Disclosed | Nov 5, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Hermitage Eye Care (Healthcare Provider, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 5, 2021 | 11,672 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.