Mattax Neu Prater Eye Center, Inc. Data Breach
Mattax Neu Prater Eye Center Data Breach Affects 92K Patients
What happened in the Mattax Neu Prater Eye Center, Inc. data breach?
The Mattax Neu Prater Eye Center, Inc. data breach was reported on June 28, 2022 and affected 92,361 individuals. The breach type was Hacking/IT Incident involving Electronic Medical Record. This breach occurred in Missouri. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Mattax Neu Prater Eye Center, Inc. Breach Details
Mattax Neu Prater Eye Center Hacking Incident
Opening Summary
Mattax Neu Prater Eye Center, Inc., a Missouri-based ophthalmology provider, experienced a significant data breach involving unauthorized access to its electronic medical record (EMR) system. The breach was reported to the U.S. Department of Health and Human Services on June 28, 2022, affecting 92,361 individuals. The incident involved a hacking or IT-related intrusion into the organization's networked systems, resulting in potential exposure of sensitive patient health information and personal identifiers maintained within the EMR infrastructure.
Investigation and Response Timeline
The entity discovered the unauthorized access to its electronic medical record system through security monitoring and investigation protocols. Upon discovery, Mattax Neu Prater Eye Center initiated a comprehensive investigation to determine the scope and nature of the breach, identify affected individuals, and implement remedial measures. The organization notified affected patients in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured protected health information. The submission date of June 28, 2022, indicates the organization met its obligation to report the breach to HHS within the required timeframe.
Technical Details of the Breach
The breach was classified as a hacking or IT incident, which typically involves unauthorized access to computer systems, networks, or databases through exploitation of security vulnerabilities, credential compromise, or other cyber attack vectors. The location of the breach—the electronic medical record system—indicates that the compromised infrastructure was the primary repository for patient clinical data, treatment histories, and associated personal information. EMR systems are high-value targets for threat actors because they contain comprehensive patient records with multiple data elements useful for identity theft, medical fraud, and other malicious purposes. The involvement of a business associate in this breach suggests that a third-party vendor or service provider with access to the organization's systems may have been the initial point of compromise, or that the breach affected data shared with or stored by a business associate entity.
Organizational Context
Mattax Neu Prater Eye Center, Inc. is a specialized ophthalmology and eye care provider located in Missouri. As an eye care center, the organization maintains detailed patient records including vision prescriptions, surgical histories, diagnostic imaging results, and treatment plans specific to ocular conditions. The scale of the breach—affecting over 92,000 individuals—suggests the organization operates multiple locations or has served a substantial patient population over an extended period. Eye care providers typically maintain records for patients across a wide geographic region, as patients may travel for specialized procedures or consultations. The organization's use of electronic medical records and integration with business associates indicates a modern healthcare IT infrastructure designed to support clinical operations and care coordination.
Patient Impact and Notification
The breach affected 92,361 individuals whose information was stored in the compromised electronic medical record system. These patients likely included current and former patients of Mattax Neu Prater Eye Center who had received eye care services and had their clinical information documented in the EMR. The notification process required the organization to contact each affected individual to inform them of the breach, the types of information potentially exposed, the steps the organization was taking to investigate and remediate the incident, and recommended actions patients should take to protect themselves. Given the June 28, 2022 submission date, notifications would have been sent in the weeks preceding this date, with the organization working to identify and locate all affected individuals to ensure comprehensive notification coverage.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, covered entities and business associates must notify affected individuals of breaches of unsecured protected health information. The rule defines a breach as unauthorized acquisition, access, use, or disclosure of protected health information that compromises the security or privacy of such information. Hacking and IT incidents represent a significant category of healthcare data breaches, accounting for a substantial portion of reported incidents in recent years. The involvement of a business associate in this breach underscores the importance of vendor risk management and the requirement that covered entities ensure business associates implement appropriate safeguards for protected health information. The scale of this incident—affecting over 90,000 individuals—places it among the larger healthcare data breaches reported in 2022 and reflects the growing sophistication of cyber threats targeting healthcare organizations.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Mattax Neu Prater Eye Center, Inc. Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review medical records and explanation of benefits statements from healthcare providers and insurance companies for unauthorized services, treatments, or claims; contact providers immediately if suspicious activity is identified
Monitor financial accounts and banking statements for unauthorized transactions; set up account alerts with financial institutions to detect suspicious activity
Consider enrolling in credit monitoring and identity theft protection services if offered by the organization; maintain vigilance for phishing emails, calls, or mail attempting to solicit personal information using details from the breach
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Missouri Breaches
Search all breaches reported in Missouri
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits