All Breaches
May 28, 2025 Verified Healthcare

Andover Eye Associates 2025 Data Breach (1.6 Thousand People Affected)

The 2025 Andover Eye Associates data breach involved unauthorized access to emails in two employee accounts. The notice filed with the Massachusetts Attorney General says the access occurred on May 28, 2025.

The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as a hacking/IT incident involving email and reported 1,638 affected individuals.

How Was the Incident Discovered?

Andover Eye Associates was alerted to suspicious activity in two employee accounts on June 10, 2025 and launched an investigation. The investigation confirmed that an unauthorized person accessed certain emails in those accounts.

When Was the Review Completed?

The organization conducted a detailed review of potentially affected emails to identify the information present and the people to whom it related. That review was completed on November 4, 2025, followed by the notification process.

What Information Was Affected?

The official sample notice confirms that the information varied by person and included names. The other fields are masked in the public template, so their scope cannot be independently confirmed.

What Should Affected People Do?

Notice recipients should review account activity, credit reports, and health-insurance explanations of benefits for transactions or services they do not recognize. The organization said it had seen no evidence of fraudulent use linked to the event as of the notice.

1.6 Thousand
Affected People
1
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

1
Names

Additional Information

Added DateJuly 29, 2026
Breach DateMay 28, 2025
Domainandovereye.org