Black Hills Regional Eye Institute Data Breach
Black Hills Regional Eye Institute Network Breach Affects 106,763
What happened in the Black Hills Regional Eye Institute data breach?
The Black Hills Regional Eye Institute data breach was reported on March 31, 2025 and affected 106,763 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in South Dakota. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Black Hills Regional Eye Institute Breach Details
Black Hills Regional Eye Institute Data Breach Report
Incident Overview
Black Hills Regional Eye Institute, a healthcare provider based in South Dakota, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was reported to the U.S. Department of Health and Human Services on March 31, 2025, affecting 106,763 individuals. This incident represents a substantial compromise of patient information stored on the organization's networked systems, exposing sensitive health and personal data to unauthorized parties. The breach occurred through hacking or IT-related security vulnerabilities that allowed threat actors to gain access to protected health information (PHI) maintained by the eye care facility.
Discovery and Response Timeline
The specific discovery date and investigation timeline have not been publicly detailed in available breach notification records. However, organizations typically discover network-based breaches through several mechanisms: automated security monitoring systems detecting unusual network activity, third-party security researchers notifying the organization of vulnerabilities, or forensic investigation following suspicious system behavior. Upon discovery, Black Hills Regional Eye Institute initiated an investigation to determine the scope of the breach, identify affected individuals, and assess what categories of patient information were compromised. The organization was required under HIPAA Breach Notification Rule to notify affected individuals without unreasonable delay and no later than 60 calendar days following discovery of the breach. The March 31, 2025 submission date to HHS indicates the organization met its regulatory notification obligations by this date.
Technical Details of the Breach
The breach location identified as "Network Server" indicates that the unauthorized access occurred at the infrastructure level rather than through a single workstation or portable device. Network server breaches typically result from one or more of the following vectors: exploitation of unpatched software vulnerabilities, weak or compromised authentication credentials, misconfigured firewall or access control settings, or sophisticated phishing attacks targeting employee credentials with administrative privileges. Hackers who gain access to networked servers can potentially access large volumes of patient data simultaneously, as these systems typically store centralized databases of electronic health records (EHRs), billing information, and administrative data. The scale of this breach—affecting over 106,000 individuals—suggests the threat actors maintained access to core systems containing comprehensive patient records rather than isolated data stores. Network-based breaches of this magnitude typically indicate either a prolonged period of undetected access or a significant security infrastructure gap that allowed rapid lateral movement through the organization's systems.
Organizational Context
Black Hills Regional Eye Institute operates as a specialized healthcare provider focused on ophthalmology and eye care services in South Dakota. The organization serves patients across the Black Hills region and surrounding areas of South Dakota, providing comprehensive eye examination, surgical, and treatment services. As an eye care facility, the organization maintains detailed patient records including vision prescriptions, surgical histories, diagnostic imaging results, and treatment plans. The scale of the breach affecting over 106,000 individuals suggests the organization operates multiple locations or has served a substantial patient population over an extended period. The fact that no business associate was involved in this breach indicates the compromised data was stored and managed directly by Black Hills Regional Eye Institute's own IT infrastructure rather than through third-party vendors or cloud service providers.
Patient Impact and Affected Information
The breach notification submitted on March 31, 2025, indicates that 106,763 individuals had their protected health information potentially accessed by unauthorized parties. This substantial number of affected patients represents a significant portion of the organization's patient base and suggests the breach compromised core patient database systems. Patients affected by this breach should assume that their personal health information may have been accessed, including but not limited to: names, dates of birth, Social Security numbers, medical record numbers, insurance information, eye care diagnoses and treatment histories, prescription information, and potentially financial account details used for billing purposes. The breach notification process required the organization to contact all affected individuals through mail, email, or telephone to inform them of the incident, the types of information compromised, and recommended protective measures. Patients who received breach notification letters from Black Hills Regional Eye Institute should review the specific details provided regarding which data elements were exposed in their individual cases, as breach scope can vary by patient record.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, any unauthorized access to unsecured PHI affecting more than 500 residents of a state or jurisdiction must be reported to prominent media outlets in addition to individual notification. A breach of this magnitude—affecting over 106,000 individuals—clearly exceeds this threshold and likely received media attention in South Dakota and potentially regional coverage. The breach also triggers mandatory reporting to the HHS Office for Civil Rights, which maintains a public breach notification log. Network server breaches represent a significant category of healthcare data breaches, accounting for a substantial percentage of incidents affecting large numbers of patients. According to HHS data, hacking and IT incidents have become increasingly common in healthcare, often resulting in larger-scale breaches than theft or loss of physical devices due to the centralized nature of networked data storage. Organizations are required under HIPAA Security Rule to implement appropriate administrative, physical, and technical safeguards to protect electronic PHI, including network security controls, access controls, encryption, and regular security assessments. The occurrence of this breach may indicate gaps in the organization's security posture that should be addressed through enhanced monitoring, vulnerability management, and employee security training.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Black Hills Regional Eye Institute Breach
Obtain and review your free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and monitor for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Monitor your financial accounts, credit card statements, and bank transactions regularly for unauthorized charges or suspicious activity. Contact your financial institutions immediately if you identify any fraudulent transactions.
Review your medical records and explanation of benefits (EOB) statements from your health insurance provider to verify that only authorized services have been billed to your account. Contact your insurance company and healthcare providers if you identify fraudulent claims.
Consider enrolling in credit monitoring and identity theft protection services, which may be offered free by Black Hills Regional Eye Institute as part of their breach response. These services can provide early warning of suspicious activity.
Be cautious of unsolicited communications claiming to be from healthcare providers, insurance companies, or financial institutions. Verify the legitimacy of any requests for personal information by contacting the organization directly using known contact information.
Change passwords for any online accounts associated with Black Hills Regional Eye Institute or your health insurance, using strong, unique passwords that are not reused across multiple accounts.
Document all communications related to the breach, including notification letters, credit monitoring enrollment confirmations, and any suspicious activity you discover, for your records and potential future reference.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More South Dakota Breaches
Search all breaches reported in South Dakota
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits