Incident Of The Week: May Eye Care And Health First Both Report Breaches Of Customer Information

Ransomware and Phishing Hit Healthcare Organizations

Add bookmark

When it comes to data breaches, it’s been a bad time for healthcare organizations. On Thursday, Pennsylvania-based May Eye Care Center and Associates reported that 30,000 patient records were breached after it became a victim of a ransomware attack on July 29.

Also on Thursday, Florida-based Health First said it notified the Department of Health & Human Services in October of a data breach earlier this year that exposed the personal information of 42,000 patients, according to DataBreaches.net.

May Eye Care’s server was infected with ransomware that compromised its electronic health record system. The breach included patient names, dates of birth, addresses, medical diagnoses, treatment details, clinical notes and insurance information. Some patients’ social security numbers were also exposed, Health IT Security reported.

Officials hired a third-party forensics team to help investigate and contacted the FBI. May also hired an IT security firm to review and bolster its security systems and policies. The company said all patients included in the breached data have been notified.

“While we believe these attacks were targeted at our office for the purpose of obtaining monetary payments from May Eye Care, our primary concern is to make sure that patients have complete information and take all necessary precautions in the event that any personal information was compromised during this breach,” officials said in a letter to patients, according to DataBreaches.net.

The letter also said there is no evidence to suggest any patients’ protected health information has been directly accessed or used without their notification, DataBreaches.net said. The site said May did not pay any ransom for its data and was able to restore operations from backups without any data loss.

While the breach was added to the Office of Civil Rights breach reporting tool on Oct. 11, no explanation was given for why it took longer than the HIPAA-required 60 days to notify the public, Health IT Security noted.

In the case of Health First, a forensic review revealed “a small number of our employees were the victims of a phishing scam which compromised some of our customers’ information,” between February and May 2018, the site reported. “The criminals were able to gain access of these employees’ email accounts for a limited period of time.”

Once the breach was discovered, Health First officials blocked the unauthorized access and changed the email account passwords of the employees who were affected. The company said it is “initiating new security measures to prevent a similar event from happening again.” It is also offering an identity protection service to monitor the identities of impacted customers for a year for free.

Health First officials also told Florida Today this week that the data breach “was fairly low-level,” but it may have included some customers' Social Security numbers. “Mostly it appears to have involved information such as addresses and birth dates. No medical information was compromised,” according to the report.


Upcoming Events

16th Automotive Cybersecurity Summit 2026

March 18 - 19, 2026

Sheraton Ann Arbor Hotel, Ann Arbor, Michigan

16th Automotive Cybersecurity Summit 2026

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":null,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":null,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[],"featured_content_portal_embedded":null}" >