REEVE-WOODS EYE CENTER
Disclosed Nov 14, 201411 years ago30,000 affectedConfirmed
OCR investigated the covered entity (CE), Reeve-Woods Eye Center, after the CE reported a breach of 43,000 individuals’ electronic protected health information (ePHI) regarding malware that infiltrated its electronic network on, or around, August 1 through September 17, 2014. The malware caused, among other things, the system to disclose screenshots and keystrokes outside the CE’s network. The types of ePHI involved in the breach included patients' names, social security numbers, dates of birth, addresses, telephone numbers, dates of service, insurance information, diagnosis codes, treatment information, and medical histories. The CE informed and cooperated with the FBI regarding the incident. In response to OCR’s contact in this matter, the CE ensured the proper breach notifications were provided, cleared the system of the malware, and took steps to increase its safeguards and technical security measures.
What is known
| People affected | 30,000 (as reported to HHS) |
|---|---|
| Disclosed | Nov 14, 2014 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: REEVE-WOODS EYE CENTERoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): REEVE-WOODS EYE CENTER (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Nov 14, 2014 | |
| HHS archivetotal | Nov 15, 2014 | 30,000 |
History of this record
- 2026-09-25 · attack: unknown to lost-device · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 30000 · backfill source
- 2026-09-25 · summary: empty to OCR investigated the covered entity (CE), Reeve-Woods Eye Center, after the CE reported a breach of 43,000 individuals’ electronic protected health information (ePHI) regarding malware that infiltrated its electronic network on, or around, · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.