MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryMulti-Stage ChainRansom DemandedTargetedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Family Vision of Anderson
bd_ac69d64f3136078e · schema v1 · pii pii-v1
Full breach record for Family Vision of Anderson →Family Vision of Anderson, P.A., an optometry practice, experienced a ransomware attack in May 2023. The incident exposed the personal and protected health information of approximately 62,631 individuals, including names, Social Security numbers, dates of birth, and eye care records. The breach was reported to the South Carolina Department of Consumer Affairs and the Maine Attorney General in July 2023. Affected individuals received notification letters and were offered credit monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2641be88c2200e5aMontana State AGfiled 2023-07-26(1d gap)Candidate
- bd_41dd9378fe1e409fMaine State AGfiled 2023-07-26(1d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/FamilyVisionofAndersonPA.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2023
- Raw hash
- cc1790056e3f732e4dd5176556b1751be76f5ec005d698492b95ad746f1bf57e
Reporting entity
- Name
- Family Vision of Andersonnorm: family vision of anderson
Victim entity
- Name
- Family Vision of Andersonnorm: family vision of anderson
Incident
- Discovered
- May 22, 2023
- Materiality determined
- Jul 26, 2023
- Notification sent
- Jul 26, 2023
- Affected individuals
- 62,631
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified South Carolina Department of Consumer AffairsFiled notice with Attorney General of Maine
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.