Medical Eye Services, Inc.
ent_94c25c9ee26e69b577a86e81
Disclosures
16
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
664,824
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Medical Eye Services, Inc.
- Normalized
- medical eye— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- medeye.net
Disclosure history (16)newest first
- Massachusetts State AGas victim2024-02-01
Medical Eye Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-01. 14 Massachusetts residents were affected.
- Maine State AGas victim2024-01-31
Medical Eye Services, Inc. experienced an external system breach (hacking) that occurred between May 28, 2023 and May 31, 2023. The breach was discovered on August 23, 2023. The compromised information includes names and Social Security Numbers. This incident affected 11 Maine residents, who were notified on January 3, 2024. The company offered 12 months of identity monitoring services through Kroll, LLC. This notice is a supplement to a previous notification from November 14, 2023.
- California State AGas victim2024-01-30
Medical Eye Services, Inc. (MESVision) disclosed that an unauthorized individual exploited a vulnerability in its MOVEit file-transfer server to exfiltrate information on May 28 and May 31, 2023. The company discovered the incident on August 23, 2023. Affected data may include personal information of individuals enrolled in vision benefit plans. MESVision took the server offline, engaged a cybersecurity firm, reported to the FBI, and is offering credit monitoring services.
- Illinois State AGas victim2024-01-01
MEDICAL EYE SERVICES, INC (MESVISION) filed a data-breach notice with the Illinois Attorney General in January 2024 (case 24-01-051). The register records the breach as discovered on May 28, 2023. Additional entities named: SAN JOAQUIN VALLEY COLLEGE, INC, SCRIPPS RESEARCH INSTITUTE, TRI COUNTIES BANK, MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas reporting2023-11-22
Medical Eye Services (vendor) exploited MOVEit vulnerability on Aug 23, 2023, affecting Blue Shield of California (victim). Data exfiltrated May 28-31, 2023. Incident reported to FBI. Notifications mailed Nov 17, 2023 to NH residents. Data included names, SSNs, DOBs. Remediation: system rebuild, credit monitoring offered.
- New Hampshire State AGas victim2023-11-20
Medical Eye Services, Inc. (MESVision) notified the NH AG of a security incident involving its MOVEit file-transfer server. An unauthorized individual exploited a vulnerability to access the server and exfiltrated data on May 28 and 31, 2023. MESVision discovered the breach on August 23, 2023. Approximately 436 New Hampshire residents were affected. Data likely included names and SSNs. MESVision engaged forensic investigators, reported to the FBI, rebuilt the system, and offered 18 months of credit monitoring via Kroll.
- Maine State AGas victim2023-11-17
Medical Eye Services, Inc. reported an external system breach that occurred between May 28, 2023, and May 31, 2023. The breach was discovered on August 23, 2023, and affected 209 Maine residents. The compromised information included names and Social Security Numbers. In response, the company offered 12 months of identity monitoring services provided by Kroll, LLC.
- Oregon State AGas victim2023-11-17
Medical Eye Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-11-17. The breach occurred during 5/28/2023 - 5/31/2023. The breach was discovered on 8/23/2023. 664,824 individuals were affected. Notice was sent on 11/17/2023.
- Massachusetts State AGas victim2023-11-17
Medical Eye Services, Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-11-17. 1,955 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2023-11-15
Medical Eye Services, Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-11-15. 2,433 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2023-11-15
Medical Eye Services, Inc. (MESVision) reported a security incident involving its MOVEit server. Unauthorized access occurred May 28-31, 2023, via exploitation of a MOVEit vulnerability. MESVision discovered the breach on August 23, 2023. Approximately 35,746 Washington residents were affected. Data exposed included names, DOBs, SSNs, and vision claims/treatment info. MESVision engaged forensic investigators, notified the FBI, rebuilt the system, and offered credit monitoring.
- Maine State AGas victim2023-11-15
Medical Eye Services, Inc. reported an external system breach that occurred from May 28, 2023, to May 31, 2023. The breach, discovered on August 23, 2023, affected 19 Maine residents. The compromised information includes names and Social Security numbers. The company provided written notification to affected individuals on November 14, 2023, and offered 12 months of identity monitoring services through Kroll, LLC.
- NEW YORKHHS OCRas victim2023-11-14
Medical Eye Services, Inc. reported to HHS on 2023-11-14 a Hacking/IT Incident affecting 377,931 individuals. Breached information located on Network Server. A software application used by its business associate exposed PHI including names, DOBs, addresses, SSNs, diagnoses, and claims.
- California State AGas victim2023-11-14
Medical Eye Services, Inc. (MESVision) disclosed that an unauthorized individual exploited a vulnerability in its MOVEit file-transfer server to exfiltrate personal information on May 28 and May 31, 2023. The company discovered the incident on August 23, 2023. Affected data may include names and health-related information for individuals enrolled in vision benefit plans. MESVision took the server offline, engaged a cybersecurity firm, reported the incident to the FBI, and is offering 18 months of complimentary credit monitoring and identity restoration services through Kroll.
- Montana State AGas victim2023-11-14
Medical Eye Services, Inc. (via MESVision) notified Montana residents of a data security incident involving the MOVEit file-transfer system. An unauthorized individual exploited a vulnerability to access the server and exfiltrate data between May 28 and May 31, 2023. The breach was discovered on August 23, 2023. Affected data likely included names and Social Security numbers. The company engaged forensic investigators, reported to the FBI, rebuilt the system, and offered 18 months of credit monitoring via Kroll.
- Oregon State AGas victim2023-11-14
Medical Eye Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-11-14. The breach occurred during 5/28/2023 - 5/31/2023. The breach was discovered on 8/23/2023. 346,828 individuals were affected. Notice was sent on 11/14/2023.