Visionworks of America, Inc.
ent_8d17e8868d2e747cd173532f
Disclosures
6
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
74,944
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Visionworks of America, Inc.
- Normalized
- visionworks of america— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- visionworks.com
Disclosure history (6)newest first
- Oregon State AGas victim2024-10-11
Visionworks of America, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-10-11. The breach occurred during 7/15/2024 - 8/13/2024. The breach was discovered on 8/14/2024. 39,825 individuals were affected. Notice was sent on 10/10/2024.
- TEXASHHS OCRas victim2024-10-10
Visionworks of America, Inc. (TX) reported to HHS OCR on 2024-10-10 a Hacking/IT Incident affecting 39,825 individuals. An employee was targeted by an email phishing scheme that compromised PHI including demographic information. The CE notified HHS, affected individuals, and the media, provided complimentary credit monitoring, implemented additional administrative/technical/security safeguards, and retrained workforce members. Breached information located in Email.
- Illinois State AGas victim2024-10-01
VISIONWORKS OF AMERICA, INC filed a data-breach notice with the Illinois Attorney General in October 2024 (case 24-10-018). The register records the breach as discovered on July 15, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- TEXASHHS OCRas victim2014-11-21
Visionworks Inc. reported to HHS on 2014-11-21 a Theft affecting 47,683 individuals. Breached information located on Network Server.
- New Hampshire State AGas victim2014-11-11
Visionworks of America reported the loss of a decommissioned server containing unencrypted PHI and PI from its Annapolis, MD store. The server was likely discarded during a store remodel. 15 New Hampshire residents were affected. Data included names, addresses, DOB, health insurance info, and encrypted credit card data. No SSNs were populated. Credit monitoring offered.
- TEXASHHS OCRas victim2014-11-10
Visionworks Inc. (TX) reported to HHS on 2014-11-10 the loss of a partially encrypted, decommissioned network server from its in-store lab in Annapolis, Maryland, which was not recovered. The server's hard drive contained unencrypted PHI — including demographic, financial, and clinical information — of approximately 74,000 individuals. Remediation included full server encryption company-wide, physical security improvements, workforce retraining, a system disposal plan, and credit monitoring offered to affected individuals. OCR investigation completed.