U.S.Vision, Inc.,
bd_e91a5ca72815c0dd · schema v1 · pii pii-v1
Full breach record for U.S.Vision, Inc., →SightCare, Inc. reported a data breach involving its business associate, U.S. Vision, Inc. An unauthorized individual accessed U.S. Vision's network between April 20, 2021, and May 17, 2021. The incident potentially exposed patient personal information, including names, dates of birth, addresses, Social Security numbers, driver's license numbers, financial account information, and protected health information (diagnoses, prescriptions, medical record numbers). SightCare notified affected individuals via notice letters dated October 28, 2022, offering credit monitoring and identity restoration services.
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3a70be4ee1cba8bcCalifornia State AGfiled 2022-10-28Verified
- bd_e39c5fc00cafebbaCalifornia State AGfiled 2022-11-30(33d gap)Verified
- bd_8895c6bff85665b8Delaware State AGfiled 2021-09-03(420d gap)Candidate
- bd_40755fd7d00dcd24California State AGfiled 2024-03-19(508d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 509d gap
- bd_6dd0d0cf51cb59a5Washington State AGfiled 2024-03-20(509d gap)Verified
- bd_9e4a698e2832d914Oregon State AGfiled 2024-03-20(509d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-558717
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 28, 2022
- Raw hash
- 60ec74acff7535f14ba754705c0dac74e843d798e9953693406f5f99d6025d6c
Reporting entity
- Name
- SightCarenorm: sightcare
- Domain
- sightcare.com
Victim entity
- Name
- U.S.Vision, Inc.,norm: usvision
Incident
- Discovered
- May 12, 2021
- Materiality determined
- —
- Notification sent
- Oct 28, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Third party
- via U.S. Vision, Inc.
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 months(534 days from discovery to filing)
- Compliance flags
- CA 60-day late · 534d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 12, 2021→ Notified: Oct 28, 2022534d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.