Black Hills Regional Eye Institute
bd_cea10e6d6457f3f2 · schema v1 · pii pii-v2
Full breach record for Black Hills Regional Eye Institute →Black Hills Regional Eye Institute LLP (BHREI) notified Nebraska AG of a cybersecurity incident impacting Protected Health Information. Suspicious activity was observed on January 8, 2025, and the unauthorized access was confirmed on July 30, 2025. BHREI engaged forensic investigators, took systems offline, and cooperated with law enforcement. Affected individuals are offered 12 months of Experian IdentityWorks monitoring. The breach impacted patients across multiple states including Nebraska, Iowa, and New York.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 8, 2025
Begins
Jan 8, 2025
Discovered
Aug 28, 2025
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteqilinbd_1d9d29c9796892b12025-01-08 · +232dCandidate
Regulatory filings (4) · sorted by filing gap
- Maine State AGbd_a4c07d307c395fa72025-08-28Verified by operator
- Illinois State AGbd_fffd2b61544a6a852025-09-01 · +4dVerified by operator
- HHS OCRbd_fe6bde07775a04da2025-03-31 · +150dVerified
- Indiana State AGbd_1d88275ce5aaa9b52025-03-06 · +175dVerified by operator
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Mar 6 (IN), last Sep 1 (IL) — a 179-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.