The First Sight Family Vision 2026 data breach is a security incident that occurred through the third-party RXNT system used by the Battle Ground, Washington-based optometry clinic for electronic prescriptions and patient pharmacy communications. The clinic previously operated under the name Jason R. Egbert OD PC; therefore, it is listed under its former legal name in the public health breach record. According to the official announcement, RXNT detected unauthorized activity in the solution used by some of its customers on March 3, 2026, and upon investigation, it was determined that between March 1, 2026, and March 3, 2026, an unauthorized person had accessed certain data stored in the system.RXNT began notifying affected customers as of May 1, 2026, while First Sight Family Vision informed its patients with a notice dated June 3, 2026. In the public health breach record, the incident is listed as a notification concerning the protected health information of 1,225 individuals under Jason R. Egbert OD PC.
Leaking Data Types and Risks
The official notification stated that the affected information varies by individual. The disclosed data types include patient names, dates of birth, demographic information, addresses, contact information, patient ID, prescription information, the provider who wrote the prescription, the prescription itself, the pharmacy that received the prescription, and, in limited cases, Social Security numbers. The notification also explicitly states that payment card, bank account, or other financial information is not included in the scope of the incident. Therefore, financial data categories were not used in this record. In contrast, prescription information and patient ID carry a high risk in terms of health privacy and social engineering.
The combination of name, date of birth, address, and contact information with prescription details can make fake messages targeting the user's actual health relationships more convincing. Information about the provider who wrote the prescription and the pharmacy facilitates fraudsters reaching the person under the pretext of medication renewal, pharmacy delivery, insurance approval, missing patient forms, or identity verification. In some limited cases, the Social Security number is also included, making certain users more vulnerable to identity theft. Individuals who find a match should also check whether SSN information is included in their own notifications; however, even if there is no SSN, the prescription and patient information should not lead to underestimating the security of the health account.
Verified Scope and Boundaries
This record is specifically limited to the coverage of First Sight Family Vision / Jason R. Egbert OD PC. The RXNT incident is a broader third-party event affecting multiple healthcare organizations; however, this page describes the First Sight patient group listed with 1,225 individuals in the public health breach record. The incident date is between March 1, 2026 and March 3, 2026; the discovery date is March 3, 2026, the customer notification start is May 1, 2026, and the First Sight announcement date is June 3, 2026. These date and number details are consistent with the official announcement, state notifications, and the public health breach record.
The scope limit has also been maintained in the data fields. Since the official announcement stated that financial cards, bank accounts, or other financial information are not included, this record does not contain financial data. The Social Security number is also considered a field that may only be applicable in limited cases, not for all users. Patient names, birth dates, demographic information, addresses and contact details, patient IDs, and prescription information are the headings verified within the scope of the incident. Therefore, user matching does not necessarily mean that each data type definitely belongs to that user; however, health and identity risk should be evaluated together.
User Groups at Risk
The main group at risk consists of individuals who have a patient relationship with First Sight Family Vision and whose data is processed through RXNT in electronic prescription or pharmacy communication processes. These individuals may be current patients, former patients, people with a prescription history, or patient groups whose pharmacy communication is managed by the clinic. Notification made under the former legal name, Jason R. Egbert OD PC, means that the user may not remember the clinic by this name. Therefore, individuals who have received services from First Sight Family Vision in the Battle Ground area should evaluate record matching not only with the current brand name but also with the former legal name.
Users with prescription information should be more cautious against fake calls and messages made using the drug name, provider, or pharmacy relationship. Demographic information and patient identity can be used in patient portal or pharmacy account verification requests. In limited cases, because a Social Security number is present, some users need to implement stronger credit and identity protection measures. For children, elderly patients, or individuals tracking prescriptions on behalf of a family member, the risk may be indirect; requests made through contact information belonging to a patient's relative should also be carefully verified.
Urgent Measures to Be Taken
Users who find a match in this record should first check the notification they received from First Sight Family Vision or RXNT and verify which types of data are included in their own letters. Since prescription, pharmacy, and provider information is involved, unexpected medication refill messages, pharmacy delivery notifications, insurance approval requests, and patient form update links should be confirmed directly through a known clinic or pharmacy channel. If the same password is used for the patient portal, email account, or pharmacy account, passwords should be made unique and multi-factor authentication should be enabled on accounts where possible.
Users who find that their Social Security number is included in their record should check their credit reports and consider credit freezing or fraud alert options. Attention is also needed on the health account side for users without an SSN: prescription history, pharmacy records, patient portal messages, and insurance explanation documents should be reviewed periodically. Payment card or bank account information is excluded in the official announcement; therefore, steps like renewing financial cards may not be required as a general precaution, but the risk of identity theft and fraud originating from health data continues.
Long-Term Security Strategies
The First Sight Family Vision incident demonstrates how important third-party electronic prescription and patient communication systems used by healthcare organizations are in terms of patient privacy. Users should track over the long term which clinics use which patient portal, prescription, or pharmacy services; they should not leave unnecessary active accounts on old portals and should keep their contact information up to date. In breaches involving prescription information, the risk is not limited to financial accounts. Personal health information can be used in the future for more convincing phishing messages or fake pharmacy scams.
Strict access restrictions, data minimization, clarification of incident notification timelines, and rapid data segregation per customer are critical for third-party service providers on the institution's side. On the user side, patient portal and email security, retention of notification letters, early detection of unexpected prescriptions or pharmacy activities, and verification of requests originating outside the healthcare institution are the strongest defense. In limited cases where an SSN is present, the user should definitely read their notification; if the SSN is affected, they should extend identity protection measures over the long term.
Record Control and User Action
A match with the First Sight Family Vision 2026 record indicates that the user may be included in the First Sight / Jason R. Egbert patient dataset processed through RXNT. In case of a match, the user should consider prescription and demographic information risks, verify the data fields in their own notification, and check patient portal, pharmacy, insurance, and communication accounts. Since Social Security numbers appear in limited samples, users whose notification includes SSN should consider options such as credit report, credit freeze, and fraud alert.
This record does not contain any financial card or bank account information; because the official announcement excluded these types of data from the incident. Nevertheless, health and prescription information is valuable enough for personal fraud attempts. Users should directly verify unexpected messages using the names of clinics, pharmacies, or RXNT through official communication channels, should not enter credentials via links, and should report unusual activity on the patient portal. Notifications coming under the old name Jason R. Egbert should not be ignored either, as they may be related to First Sight Family Vision.