[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fabUsuVO6-KHSj-0AvbUHvgFK6rm7S7-FLsxojhs8hgA":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":18,"dataClasses":19,"description":22,"source":23,"isVerified":4,"isSpamList":24,"isSensitive":4,"processingStatus":25,"logoUrl":26,"contentUpdatedAt":16,"hasEnglishDescription":4,"severity":27},"6a6739ecf5ad0d55e6573d5e","HeartOfAmericaEyeCare2026","Heart of America Eye Care 2026 Data Breach","heart-of-america-eye-care-2026","heartofamericaeyecare.com",{"name":12,"sector":13,"country":14,"website":10},"Heart of America Eye Care","Healthcare","United States","2026-04-01T00:00:00.000Z","2026-07-27T10:58:52.517Z",0,null,[20,21],"Personal information under review","Protected health information under review","\u003Cp>\u003Cstrong>The Heart of America Eye Care 2026 data breach\u003C\u002Fstrong> involved an unauthorized third party accessing certain files in the organization's network and viewing or taking them from April 1 through April 7, 2026. The organization secured its network, opened an investigation with third-party specialists, and began reviewing the affected files.\u003C\u002Fp>\n\u003Cp>The HHS Office for Civil Rights public record classifies the event as a Hacking\u002FIT Incident involving a Network Server and reports 500 people. Because the organization's own notice says the file review was ongoing, LeakData treats that figure as a verifiable lower bound rather than an exact nationwide total. Specific data fields have not been published.\u003C\u002Fp>\n\u003Ch2>How Was the Heart of America Eye Care Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the incident notice on the domain of MVP VIP Holdco dba Heart of America Eye Care. It directly confirms unauthorized third-party access, files viewed or taken from April 1 through April 7, steps to secure the network, use of outside specialists, and the contact number 816-350-4701.\u003C\u002Fp>\n\u003Cp>The second source is the HHS Office for Civil Rights breach portal. Its official row identifies the company as a Missouri healthcare provider, classifies the event as a hacking\u002FIT case involving a network server, reports 500 people, and gives a June 5, 2026 submission date. ClaimDepot's summary links to the same two sources.\u003C\u002Fp>\n\u003Ch2>What Happened From April 1 Through April 7, 2026?\u003C\u002Fh2>\n\u003Cp>The organization's investigation found that an unauthorized person accessed certain network files between April 1 and April 7. The notice's “viewed or taken” wording means some information may have been viewed or removed from the network. Heart of America Eye Care secured its environment after becoming aware of the event.\u003C\u002Fp>\n\u003Cp>The public sources do not disclose the initial-entry method, account or vulnerability used, actor identity, malware, or a ransom demand. A separate dark-web claim does not replace the scope confirmed by the organization. LeakData relies only on the official finding of access and possible taking of information.\u003C\u002Fp>\n\u003Ch2>What Information Was Involved?\u003C\u002Fh2>\n\u003Cp>Heart of America Eye Care said it was reviewing the relevant files to determine whether personal information or protected health information was involved; that work was ongoing when the notice was published. The organization did not publish a confirmed list of fields such as names, SSNs, birth dates, diagnoses, prescriptions, insurance numbers, or financial data.\u003C\u002Fp>\n\u003Cp>The HHS portal confirms that the event entered the HIPAA healthcare-notification process, but it does not by itself identify which PHI fields were present. Accordingly, data classes remain at “personal information under review” and “protected health information under review.” LeakData does not add unsupported detailed fields.\u003C\u002Fp>\n\u003Ch2>What Risks Come From an Uncertain Data Scope?\u003C\u002Fh2>\n\u003Cp>Because the fields have not been disclosed, it is not possible to say that a particular person definitely faces an identity, financial, or health-data risk. Still, viewing or taking network files may increase the chance of targeted messages to people associated with the organization. A recipient should not assume which fields were involved before receiving an individual notice.\u003C\u002Fp>\n\u003Cp>Criminals may use the organization's name, a real clinic location, or general eye-care context in fake portal, appointment, billing, or result messages. Even when such a message appears authentic, avoid its inbound link. Independently open the provider's website, patient portal, or a previously known telephone number.\u003C\u002Fp>\n\u003Ch2>How Many People Were Affected and How Did the Organization Respond?\u003C\u002Fh2>\n\u003Cp>The HHS row lists 500 people. Because the organization said the file review was still underway and that affected people would be contacted directly after completion, LeakData stores the figure as a lower bound: pwnCount and totalRecords are null, affectedCountStatus is “lower_bound,” and affectedCountLowerBound is 500.\u003C\u002Fp>\n\u003Cp>Heart of America Eye Care secured its network, retained third-party specialists to determine the scope of the activity and affected information, and began reviewing the relevant data. It said it would directly notify affected individuals once scope was established. The public notice did not promise credit monitoring or a specific enrollment package.\u003C\u002Fp>\n\u003Ch2>What Should Patients and Related People Do?\u003C\u002Fh2>\n\u003Cp>People associated with the organization should watch for mailed and emailed notices, but independently confirm that an unexpected message genuinely came from Heart of America Eye Care. Review patient portals, medical bills, and insurance explanation-of-benefits statements for an unfamiliar service, provider, or claim.\u003C\u002Fp>\n\u003Cp>Even if a caller knows real facts about the event, do not disclose a password, full SSN, payment card, insurance identifier, or one-time code. Independently open the official site, call 816-350-4701, or write to the organization at 4801 South Cliff Avenue, Suite 100, Independence, Missouri, with questions.\u003C\u002Fp>","Official healthcare-provider notice and HHS report confirming unauthorized access to and possible taking of network files",false,"completed","\u002Fuploads\u002Flogo\u002Fheartofamericaeyecare_com.svg","Low"]