Warby Parker
ent_a367b53a046fb16977bbf7d8
Disclosures
4
HHS OCR enforcement · State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
197,986
nationwide · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Warby Parker
- Normalized
- warby parker— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0001504776
- Domain
- warbyparkerfoundation.org
Disclosure history (4)newest first
- FEDERALHHS OCR enforcementas victim2025-02-20
HHS OCR imposed a $1.5M civil money penalty on Warby Parker, Inc. for HIPAA Security Rule violations. A credential stuffing attack in 2018 compromised ePHI of nearly 200,000 individuals. Violations included failure to conduct risk analysis, implement sufficient security measures, and review system activity logs.
- Oregon State AGas victim2018-12-27
Warby Parker reported a data breach to the Oregon Attorney General. The breach was reported on 2018-12-27. The breach occurred during 9/25/2018 - 9/25/2018. The breach was discovered on 11/26/2018. Notice was sent on 12/20/2018.
- Montana State AGas victim2018-12-20
Warby Parker notified customers of credential stuffing attacks using stolen credentials from other breaches. Unauthorized parties attempted to access accounts between late September and late November 2018. Affected data included names, emails, prescription info, and last 4 digits of payment cards. Customers were required to reset passwords.
- NEW YORKHHS OCRas victim2018-12-20
Warby Parker Inc. reported to HHS OCR a hacking/IT incident (credential stuffing) affecting 197,986 individuals. Unauthorized access occurred between September 25 and November 30, 2018, compromising ePHI including names, addresses, emails, payment card info, and prescriptions. OCR imposed a $1.5M penalty in Dec 2024 for Security Rule violations.