Sheldon M. Golden O.D., Optometric
Disclosed Dec 19, 20178 years ago7,583 affectedConfirmed
Sheldon M. Golden O.D., Optometric Corporation, the covered entity (CE), reported a breach that occurred at its West Covina, CA location when a computer server was infected with a variant of the CrySiS ransomware virus, which encrypted some files on its local computer drives. The breach affected approximately 7,583 individuals' protected health information (PHI) and included full names, addresses, dates of birth, claims information, billing codes, and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE ensured all documents containing PHI are maintained on secure, encrypted servers along with its medical records. The CE also changed its firewall rules to prohibit any remote access to local drives in order to safeguard electronic PHI. OCR obtained assurances that the CE implemented the corrective actions listed.
What is known
| People affected | 7,583 (as reported to HHS) |
|---|---|
| Disclosed | Dec 19, 2017 |
| Happened | Nov 6, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Sheldon M. Golden O.D., Optometricoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Sheldon M. Golden O.D., Optometric (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Dec 19, 2017 | |
| HHS archivetotal | Dec 19, 2017 | 7,583 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 7583 · backfill source
- 2026-09-25 · summary: empty to Sheldon M. Golden O.D., Optometric Corporation, the covered entity (CE), reported a breach that occurred at its West Covina, CA location when a computer server was infected with a variant of the CrySiS ransomware virus, which encrypted some · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.