Cyber Incident Victim: Retina & Vitreous of Texas
Date:
Feb 2023
Location:
United States of America
Summary
Retina & Vitreous of Texas experienced a data security incident involving unauthorized access to its network, potentially compromising personal and protected health information of current and former patients and employees. The breach exposed sensitive details including names, addresses, medical diagnoses, treatment information, insurance carrier data, and subscriber identification numbers. Following discovery of unusual network activity, the organization secured its systems, conducted an investigation, and identified affected individuals through a comprehensive review. Notifications were subsequently issued to those potentially impacted, along with resources for assistance. The incident underscores the risks to healthcare data privacy, with the organization expressing regret for any resulting concerns.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Retina & Vitreous of Texas, PLLC detected unusual activity within its network on February 1, 2023, prompting an immediate investigation into the incident. The organization confirmed unauthorized access to its systems and took steps to secure the environment upon discovery. By February 15, 2023, the investigation revealed that personal and protected health information may have been acquired without authorization during the breach. Retina & Vitreous initiated a comprehensive review to identify affected individuals and determine the scope of compromised data, which concluded on March 21, 2023. The review established that current and former patients' information exposed in the incident included names, addresses, medical diagnoses, treatment details, insurance carrier information, and insurance subscriber identification numbers. No employee data was explicitly mentioned as compromised in the notification. The organization did not disclose technical details about the attack vector, duration of unauthorized access, or whether ransomware or data exfiltration occurred.

Retina & Vitreous formally notified potentially impacted individuals about the breach on April 10, 2023, approximately ten weeks after initial detection. The notification established a dedicated call center (1-888-566-0069) operating during Central Time business hours to address inquiries. The organization acknowledged the incident affected both personal and protected health information but did not specify the total number of impacted individuals or particular systems involved. No evidence of identity theft or fraud stemming from the breach was cited in the notification. Retina & Vitreous described privacy and data protection as top priorities while expressing regret for any inconvenience caused to affected parties. The public disclosure did not reference law enforcement involvement, regulatory filings, or specific security enhancements implemented post-incident beyond securing the environment.
