Moyes Eye Center, PC Data Breach
Moyes Eye Center Hacking Exposes 38,000 Patient Records
What happened in the Moyes Eye Center, PC data breach?
The Moyes Eye Center, PC data breach was reported on May 25, 2022 and affected 38,000 individuals. The breach type was Hacking/IT Incident involving Electronic Medical Record. This breach occurred in Missouri. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Moyes Eye Center, PC Breach Details
Moyes Eye Center Data Breach Report
Incident Overview
Moyes Eye Center, PC, a Missouri-based ophthalmology practice, experienced a significant data breach involving unauthorized access to its electronic medical record (EMR) system. The breach was discovered and reported to the U.S. Department of Health and Human Services on May 25, 2022, affecting approximately 38,000 individuals. The incident was classified as a hacking or IT-related security event, indicating that unauthorized actors gained access to protected health information (PHI) through electronic means rather than through physical theft or loss of records. This type of breach typically involves exploitation of network vulnerabilities, compromised credentials, or other cybersecurity weaknesses in the organization's IT infrastructure.
Discovery and Response Timeline
The specific discovery date and investigation timeline were not detailed in the breach notification submission, though the May 25, 2022 submission date indicates the breach was reported to HHS within the required 60-day notification window mandated by HIPAA Breach Notification Rule. Upon discovery of the unauthorized access, Moyes Eye Center initiated an investigation to determine the scope of the breach, identify which patient records were compromised, and assess what types of information were exposed. The organization's response would have included forensic analysis of their EMR systems, notification to affected individuals, and coordination with their business associate(s) who may have had access to the compromised data. The involvement of a business associate in this breach suggests that a third-party vendor or service provider with access to the EMR system may have been implicated in the security incident or may have been affected by the same vulnerability.
Technical Details of the Breach
The breach occurred within Moyes Eye Center's electronic medical record system, which represents a centralized repository of patient health information including clinical notes, diagnoses, treatment plans, and other sensitive medical data. Hacking incidents targeting EMR systems typically exploit vulnerabilities such as unpatched software, weak authentication mechanisms, inadequate access controls, or social engineering attacks that compromise employee credentials. The involvement of a business associate suggests the breach may have occurred through a third-party connection, supply chain vulnerability, or shared infrastructure. EMR systems are high-value targets for cybercriminals because they contain comprehensive patient health information that can be used for identity theft, insurance fraud, or sold on the dark web. The fact that this breach affected 38,000 individuals indicates either a prolonged period of unauthorized access or a significant vulnerability that exposed a large portion of the organization's patient database.
Organizational Context
Moyes Eye Center, PC is an ophthalmology practice located in Missouri specializing in eye care services. As a specialty medical practice, the organization maintains detailed patient records including vision prescriptions, surgical histories, diagnostic imaging results, and other sensitive health information specific to ophthalmologic care. The practice's reliance on electronic medical records for patient care delivery and administrative functions makes it dependent on strong cybersecurity infrastructure. The involvement of a business associate indicates the organization likely uses third-party vendors for services such as billing, claims processing, data hosting, or other healthcare IT functions. The scale of the breach—affecting 38,000 patients—suggests either a multi-location practice or a single location with a substantial patient population accumulated over many years of operations.
Patient Impact and Notification
Approximately 38,000 individuals had their protected health information potentially exposed in this breach. These patients likely included current and former patients of Moyes Eye Center whose records were stored in the compromised EMR system. The exposed information may have included names, addresses, dates of birth, Social Security numbers, insurance information, medical record numbers, diagnoses, treatment histories, prescription information, and other clinical details. Under HIPAA Breach Notification Rule requirements, Moyes Eye Center was obligated to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The organization was also required to notify prominent media outlets serving the affected area and to report the breach to HHS, which maintains a public breach notification log. Patients would have received written notification explaining the nature of the breach, the types of information exposed, steps the organization was taking to address the incident, and recommended actions for protecting themselves against potential misuse of their information.
HIPAA Compliance and Industry Context
This breach represents a violation of HIPAA Security Rule requirements, which mandate that covered entities and business associates implement appropriate administrative, physical, and technical safeguards to protect electronic PHI. The Security Rule requires risk assessments, access controls, encryption, audit controls, and incident response procedures—all of which should have prevented or detected this unauthorized access. Hacking incidents represent a significant portion of healthcare data breaches, accounting for a substantial percentage of breaches affecting large numbers of individuals. The healthcare industry has experienced increasing sophistication in cyberattacks, including ransomware, credential stuffing, and exploitation of remote access vulnerabilities. The involvement of a business associate in this breach underscores the importance of vendor management and the requirement that covered entities ensure their business associates maintain equivalent security standards. Moyes Eye Center would likely face regulatory scrutiny from HHS Office for Civil Rights regarding the adequacy of its security measures and may be subject to civil penalties if the investigation determines the organization failed to implement required safeguards or failed to promptly detect and respond to the breach.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Moyes Eye Center, PC Breach
Monitor credit reports from all three bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze with the bureaus
Review explanation of benefits (EOB) statements and medical bills carefully for unauthorized services or claims; contact your insurance provider and healthcare providers immediately if you identify suspicious activity
Change passwords for any online accounts associated with Moyes Eye Center or your health insurance, using strong, unique passwords for each account
Consider enrolling in credit monitoring and identity theft protection services if offered by the organization; monitor financial accounts regularly for unauthorized transactions
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies; verify requests independently before providing personal information
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you suspect identity theft or fraudulent activity related to this breach
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Missouri Breaches
Search all breaches reported in Missouri
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits