HackingIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
U.S.Vision, Inc.,
bd_8895c6bff85665b8 · schema v1 · pii pii-v1
Full breach record for U.S.Vision, Inc., →U.S. Vision, Inc. disclosed a data breach affecting individuals in multiple states, including 1,243 Rhode Island residents. Unauthorized access occurred between April 20, 2021, and May 17, 2021. The company discovered suspicious activity on May 12, 2021. Affected data included PII (names, DOB, addresses), vision care/treatment records, insurance info, and billing/claims data. The company engaged cybersecurity specialists and conducted file reviews.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3a70be4ee1cba8bcCalifornia State AGfiled 2022-10-28(420d gap)Verified
- bd_e91a5ca72815c0ddCalifornia State AGfiled 2022-10-28(420d gap)Verified
- bd_e39c5fc00cafebbaCalifornia State AGfiled 2022-11-30(453d gap)Verified
- bd_40755fd7d00dcd24California State AGfiled 2024-03-19(928d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 929d gap
- bd_6dd0d0cf51cb59a5Washington State AGfiled 2024-03-20(929d gap)Verified
- bd_9e4a698e2832d914Oregon State AGfiled 2024-03-20(929d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/04/U.S-Vision-Inc.Notice-Letter-Example.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 3, 2021
- Raw hash
- 3afa6eb60d07fdbc09ebd55735709cf4bfcc7d58592bc139c6a7e1f4752eb98a
Reporting entity
- Name
- U.S.Vision, Inc.,norm: usvision
Victim entity
- Name
- U.S.Vision, Inc.,norm: usvision
Incident
- Discovered
- May 12, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(114 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.