EyeMed Vision Benefits
ent_50750d1e59e7132d163a7503
Disclosures
17
State AG · HHS OCR · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
2,329,942
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- EyeMed Vision Benefits
- Normalized
- eyemed vision benefits— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- eyemed.com
Disclosure history (17)newest first
- Massachusetts State AGas reporting2023-06-07
EyeMed Vision Care, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-07. 6 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas reporting2023-01-01
EYEMED VISION CARE, LLC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-375). The register records the breach as discovered on April 7, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- South Carolina State AGas reporting2021-01-27
EyeMed Vision Care LLC notified South Carolina residents of a data breach occurring between June 24 and July 1, 2020. An unauthorized individual accessed an EyeMed email mailbox and sent phishing emails to contacts in the address book. EyeMed secured the mailbox, engaged a cybersecurity firm, reset passwords, and provided two years of free identity monitoring via Kroll. Personal information of vision benefit recipients may have been accessed.
- California State AGas victim2020-12-11
EyeMed discovered on July 1, 2020, that an unauthorized individual accessed an email mailbox starting June 24, 2020, and sent phishing emails. The mailbox contained personal information of vision benefits recipients. EyeMed secured the mailbox, engaged a cybersecurity firm, changed passwords, and offered two years of identity monitoring via Kroll.
- Delaware State AGas victim2020-12-11
EyeMed, a vision benefits administrator, disclosed a data breach where an unauthorized individual accessed an EyeMed email mailbox and sent phishing emails to contacts in the address book. Access occurred from June 24, 2020, to July 1, 2020. EyeMed discovered the incident on July 1, 2020, blocked access, and engaged a cybersecurity firm. Personal information of individuals receiving vision benefits may have been viewed or copied. EyeMed implemented password changes, security training, and provided two years of free identity monitoring via Kroll.
- New Hampshire State AGas reporting2020-12-01
EyeMed Vision Care LLC filed a supplemental and final security breach notice with the New Hampshire Attorney General on December 1, 2020. The filing confirms approximately 33,745 New Hampshire residents were affected. The initial notification was filed on September 28, 2020, when the investigation was ongoing.
- Maine State AGas reporting2020-11-30
EyeMed Vision Care LLC reported an unauthorized access incident occurring between June 24, 2020, and July 1, 2020. The breach affected approximately 2,329,942 individuals, including 23,057 Maine residents. The incident involved the acquisition of Social Security Numbers and personal identifiers. EyeMed notified affected individuals in writing on September 28, 2020, and offered identity theft protection services.
- Oregon State AGas reporting2020-10-12
EyeMed Vision Care LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2020-10-12. The breach occurred during 6/24/2020 - 7/1/2020. The breach was discovered on 7/1/2020. 547,370 individuals were affected. Notice was sent on 10/12/2020.
- Washington State AGas reporting2020-10-12
EyeMed Vision Care LLC reported a phishing incident where an unauthorized individual accessed an email mailbox and sent phishing emails. Access occurred June 24-July 1, 2020. Discovered July 1, 2020. Approximately 19,625 Washington residents affected. Data included PII, PHI, and financial info. Notifications sent starting Oct 12, 2020.
- Massachusetts State AGas reporting2020-09-28
EyeMed Vision Care LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-09-28. 108,478 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas reporting2020-09-28
EyeMed Vision Care LLC disclosed that an unauthorized individual gained access to an EyeMed email mailbox between June 24 and July 1, 2020. The actor sent phishing emails to addresses in the mailbox's address book. EyeMed discovered the incident on July 1, 2020, blocked access, and engaged a cybersecurity firm. Personal information, potentially including names and health-related data, may have been viewed or acquired. EyeMed offered two years of identity monitoring via Kroll.
- Montana State AGas reporting2020-09-28
EyeMed Vision Care notified Montana residents of a data security incident where an unauthorized individual accessed an email mailbox and sent phishing emails to contacts in the address book. Access occurred June 24–July 1, 2020. EyeMed discovered the incident on July 1, 2020, blocked access, engaged a cybersecurity firm, and provided two years of identity monitoring services via Kroll.
- Maine State AGas reporting2020-09-28
EyeMed Vision Care LLC reported an unauthorized access incident occurring between June 24, 2020, and July 1, 2020. The breach affected 54,266 individuals, including 23 Maine residents. Compromised data included names and Social Security Numbers. EyeMed provided two years of complimentary identity monitoring through Kroll, including credit monitoring and fraud consultation. The investigation was ongoing as of the filing date of September 28, 2020.
- OHIOHHS OCRas reporting2020-09-28
EyeMed Vision Care LLC reported to HHS on 2020-09-28 a Hacking/IT Incident affecting 1,474,000 individuals. Breached information located on Email. Employees were victims of an email phishing attack compromising PHI including names, addresses, DOB, SSNs, driver's licenses, diagnoses, and medications.
- Illinois State AGas reporting2020-01-01
EYEMED VISION CARE LLC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-522). The register records the breach as discovered on December 11, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas reporting2020-01-01
EYEMED VISION CARE filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-384). The register records the breach as discovered on July 1, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas reporting2020-01-01
EYEMED VISION CARE, LLC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-504). The register records the breach as discovered on September 28, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.