Menu
Browse

Cyber Incident Victim: Millennium Eye Care

Date:

Nov 2021

Location:

United States of America

Summary

A ransomware attack compromised Millennium Eye Care, an ophthalmology provider, leading to the theft of sensitive patient data including names and Social Security numbers prior to file encryption. The organization enhanced network security and staff training, while offering affected individuals identity theft protection services and a reimbursement policy. Regulatory authorities were notified, though the total number of impacted patients remains unspecified.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Millennium Eye Care, a Freehold, New Jersey-based ophthalmology services provider, experienced a cybersecurity incident involving unauthorized access to its computer network by hackers who deployed ransomware. The attack was discovered on November 14, 2021, when the organization confirmed that attackers had exfiltrated a substantial volume of data prior to encrypting files in an extortion attempt. While the exact date of initial network compromise remains unspecified in breach notifications, the exfiltration preceded the ransomware deployment. Stolen data included protected health information such as patient names and Social Security numbers, though the full scope of compromised records was not quantified in available disclosures. Millennium Eye Care did not publicly confirm whether ransom demands were paid or specify the ransomware variant involved in the attack.

Cyber Incident Image

In response to the breach, Millennium Eye Care implemented enhanced network security measures to mitigate future risks and conducted supplemental cybersecurity training for staff to improve threat recognition capabilities. The organization mailed individual notifications to affected patients by December 22, 2021, detailing protective measures against identity theft and fraud. Remediation efforts included complimentary identity theft protection services and a $1,000,000 identity theft reimbursement policy for impacted individuals. Regulatory authorities were notified of the breach, though the incident had not been published on the HHS Office for Civil Rights breach portal as of the last available reporting, leaving the total number of affected patients undisclosed in public records. No operational disruptions or system downtime were explicitly cited in the organization's public statements regarding the incident's aftermath.

Sources
Sources available to members
1 source