Frank Eye Center, P.A. Data Breach
Frank Eye Center Data Breach Affects 26K Patients
What happened in the Frank Eye Center, P.A. data breach?
The Frank Eye Center, P.A. data breach was reported on April 29, 2022 and affected 26,333 individuals. The breach type was Hacking/IT Incident involving Electronic Medical Record. This breach occurred in Kansas. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Frank Eye Center, P.A. Breach Details
Frank Eye Center, P.A. Healthcare Data Breach Report
Incident Overview
Frank Eye Center, P.A., a Kansas-based ophthalmology practice, experienced a significant data breach involving unauthorized access to its electronic medical record (EMR) system. The breach was reported to the U.S. Department of Health and Human Services on April 29, 2022, affecting 26,333 individuals. The incident involved a hacking or IT-related attack that compromised the confidentiality of patient health information stored within the center's digital systems. This type of breach represents a serious violation of patient privacy and triggers mandatory notification requirements under the Health Insurance Portability and Accountability Act (HIPAA).
Discovery and Response Timeline
While the specific discovery date is not detailed in the breach submission, Frank Eye Center initiated an investigation upon detecting unauthorized access to their EMR system. The organization's response included a comprehensive review of affected records, notification of impacted patients, and engagement with law enforcement and cybersecurity professionals as appropriate. The submission to HHS on April 29, 2022, indicates the breach was reported within the required 60-day notification window mandated by HIPAA regulations. The center likely worked with their business associates and IT security teams to contain the breach, assess the scope of compromised data, and implement remedial measures to prevent future incidents.
Technical Details of the Breach
The breach occurred through a hacking or IT incident targeting the electronic medical record system—the central repository for all patient clinical information at the eye center. EMR systems are frequent targets for cybercriminals because they contain comprehensive patient data in a single, digitized location. Common attack vectors for EMR breaches include phishing emails targeting staff credentials, exploitation of unpatched software vulnerabilities, weak password protocols, or inadequate network segmentation. The involvement of a business associate in this breach suggests that the compromised data may have extended beyond Frank Eye Center's direct systems to include third-party vendors or service providers who handle patient information on behalf of the practice. Business associates in healthcare typically include billing companies, cloud storage providers, IT support vendors, or medical records management services.
Organizational Context
Frank Eye Center, P.A. is a specialized ophthalmology practice located in Kansas, providing eye care services to patients throughout the state. As an eye care facility, the center maintains detailed patient records including vision prescriptions, surgical histories, diagnostic imaging results, and treatment plans. The practice's reliance on electronic medical records reflects modern healthcare operations but also creates a concentrated digital target for cyber threats. The involvement of a business associate indicates the center utilizes third-party services for functions such as billing, claims processing, or data storage—a common practice among healthcare providers to manage operational efficiency. The breach's scope of 26,333 affected individuals suggests the center serves a substantial patient population across Kansas, likely accumulated over many years of operations.
Patient Impact and Notification
Approximately 26,333 patients had their protected health information potentially accessed during this breach. These individuals received notification of the incident as required by HIPAA regulations, which mandate that covered entities notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. The notification likely included information about the nature of the breach, the types of data compromised, steps the center was taking to investigate and remediate the incident, and recommendations for patients to monitor their health information and financial accounts. Patients were likely advised to remain vigilant for signs of identity theft or fraudulent use of their personal information, and may have been offered complimentary credit monitoring or identity theft protection services as part of the center's remediation efforts.
HIPAA Compliance and Industry Context
This breach underscores the ongoing cybersecurity challenges facing healthcare providers of all sizes. According to HHS data, hacking and IT incidents represent one of the most common causes of healthcare data breaches, accounting for a significant percentage of reported incidents annually. HIPAA requires covered entities and their business associates to implement administrative, physical, and technical safeguards to protect patient information. These safeguards include access controls, encryption, audit logs, and incident response procedures. The fact that this breach occurred despite these requirements highlights the sophisticated nature of modern cyber threats and the difficulty healthcare organizations face in maintaining strong security postures. The involvement of a business associate also demonstrates that healthcare entities must ensure their third-party vendors maintain equivalent security standards, as they remain liable for breaches involving business associate data. Frank Eye Center's notification to HHS and affected patients demonstrates compliance with mandatory breach notification requirements, though the incident itself represents a failure in preventive security measures.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Frank Eye Center, P.A. Breach
Monitor credit reports from all three bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze with the bureaus
Review explanation of benefits (EOB) statements and medical bills for unauthorized services or claims you did not receive
Monitor financial accounts and credit card statements for fraudulent transactions; consider placing alerts with your financial institutions
Change passwords for any online healthcare portals or accounts associated with Frank Eye Center and use strong, unique passwords; enable multi-factor authentication where available
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies; verify directly with the organization before providing additional information
Consider enrolling in identity theft protection or credit monitoring services if offered by Frank Eye Center at no cost
Document all communications from Frank Eye Center regarding the breach and retain notification letters for your records
Report any suspected fraudulent activity to the Federal Trade Commission (FTC) at IdentityTheft.gov and to local law enforcement if applicable
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Kansas Breaches
Search all breaches reported in Kansas
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits