[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2o3c2rs93m49b":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"6a70bb04ef0a764acfbe8ba5","RetinaGroupOfFlorida2024","Retina Group of Florida 2024 Data Breach","retina-group-of-florida-2024","retinagroupflorida.com","2024-11-06T00:00:00.000Z","2026-08-03T16:00:04.350Z","Official consumer notice, HHS OCR, and independent breach reporting","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2025-1608-retina-florida-mso-llc-dba-retina-group-of-fl\u002Fdownload",[14,16],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",152691,"known",null,"people","High",[23,24,25,26,27,28,29,30,31,32],"Names","Physical addresses","Contact information","Dates of birth","Social security numbers","Driver's license numbers","Health insurance information","Medical information","Financial account information","Payment card information","\u003Cp>\u003Cstrong>The 2024 Retina Group of Florida data breach\u003C\u002Fstrong> involved unauthorized access to the eye-care provider's network between November 6 and November 9, 2024. The organization said certain information may have been taken. The U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) reports 152,691 affected people.\u003C\u002Fp>\u003Cp>The incident concerns the network operated by Retina Group of Florida, a Florida practice focused on diagnosing and treating retinal conditions. The organization identified unusual activity on November 9, 2024.\u003C\u002Fp>\u003Ch2>How did the Retina Group of Florida data breach happen?\u003C\u002Fh2>\u003Cp>The official notice says part of the network was accessed without authorization between November 6 and November 9 and that certain information may have been taken. The organization notified law enforcement, investigated with outside specialists, and changed network passwords.\u003C\u002Fp>\u003Cp>The public notice does not disclose the initial-access method, an exploited vulnerability, or the responsible actor. The incident is therefore not attributed to an unconfirmed attack technique or threat group.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The categories varied by person. Disclosed data types may have included names, addresses and other contact information, dates of birth, Social Security numbers, and copies of driver's licenses.\u003C\u002Fp>\u003Cp>Health-insurance information, medical records, and payment information may also have been involved for some people. Notification sources also identify financial-account or credit\u002Fdebit-card information; not every category applied to every individual.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The current HHS OCR entry reports 152,691 affected individuals for the network-server Hacking\u002FIT Incident. An independent incident summary updated in March 2026 reports at least 153,429 people; this record uses the official HHS total and does not combine the two figures.\u003C\u002Fp>\u003Ch2>What risks can this information create?\u003C\u002Fh2>\u003Cp>Social Security numbers combined with dates of birth and addresses can increase the risk of identity theft or fraudulent account applications. A driver's-license copy and payment information may also be used in impersonation and financial-fraud attempts.\u003C\u002Fp>\u003Cp>Medical-record and health-insurance details can help an attacker create targeted messages that appear to refer to a real appointment or treatment relationship. Accurate health details do not prove that the sender is authorized.\u003C\u002Fp>\u003Ch2>How did the organization respond?\u003C\u002Fh2>\u003Cp>Retina Group of Florida completed its review of the affected network contents on August 18, 2025, and began confirming mailing addresses. Individual notification letters are dated September 16, 2025.\u003C\u002Fp>\u003Cp>The organization offered eligible people 12 months of complimentary credit monitoring and identity-protection services through Cyberscout, a TransUnion company. It also said it reviewed its policies and procedures.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can monitor credit reports, bank and card accounts, health-insurance statements, and medical bills for unfamiliar activity. If a Social Security number was involved, a credit freeze or fraud alert may be appropriate.\u003C\u002Fp>\u003Cp>For an unexpected message claiming to come from Retina Group of Florida, a doctor, or an insurer, use contact details from the organization's official website rather than a link or number supplied in the message.\u003C\u002Fp>","","Retina Group of Florida Data Breach (152.7 Thousand People Affected)","The Retina Group of Florida data breach affected 152,691 people and may have exposed identity, financial, insurance, and medical information.","\u002Fuploads\u002Flogo\u002Fretina-group-of-florida-official.svg",false,{"name":40,"sector":41,"country":42,"website":43,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":19},"Retina Group of Florida","Healthcare","United States","https:\u002F\u002Fwww.retinagroupflorida.com\u002F"]