[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTdpZwfcQmAMmTKstrWtmbQlwxsZQ_v8EQ9BPLImerro":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":27,"source":28,"isVerified":4,"isSpamList":29,"isSensitive":4,"processingStatus":30,"logoUrl":31,"contentUpdatedAt":16,"hasEnglishDescription":4,"severity":32},"6a676244dad57ecd9a2b47da","TriCenturyEyeCare2025","Tri-Century Eye Care 2025 Data Breach","tri-century-eye-care-2025","tricenturyeye.com",{"name":12,"sector":13,"country":14,"website":10},"Tri-Century Eye Care, P.C.","Healthcare","United States","2025-09-03T00:00:00.000Z","2026-07-27T13:51:00.181Z",200000,[19,20,21,22,23,24,25,26],"Names","Social Security numbers","Dates of birth","Medical or health information","Treatment or diagnostic information","Health insurance information","Billing or payment information","Tax or financial information","\u003Cp>\u003Cstrong>The Tri-Century Eye Care 2025 data breach\u003C\u002Fstrong> involved suspicious network activity detected September 3, 2025 at the Pennsylvania eye-care practice. On September 19, the organization learned information suggesting that an unknown actor had unauthorized network access and acquired files containing some personal or protected health information. It found no evidence of access to its current electronic medical-record system.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights portal lists 200,000 affected individuals for Tri Century Eye Care PC and classifies the event as a network-server “Hacking\u002FIT Incident.” This official person total is used in pwnCount and totalRecords. importedRecordCount is zero because no raw person-level data was obtained.\u003C\u002Fp>\n\u003Ch2>How Was the Tri-Century Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary document is the organization's “Notice of Data Security Incident” dated October 30, 2025. The archived PDF describes the September 3 discovery, September 19 scope finding, an unknown actor acquiring files, data types, unaffected current EMR system, additional safeguards, HHS and FBI notifications, and the 1-800-405-6108 assistance line.\u003C\u002Fp>\n\u003Cp>The second source is the official HHS\u002FOCR entry dated October 31 for 200,000 people. ClaimDepot's incident page independently connects the same official notice and federal total. The attacker-group name mentioned by a secondary page is not carried into the LeakData record because the organization's own text describes only an unknown actor.\u003C\u002Fp>\n\u003Ch2>What Happened Between September 3 and 19, 2025?\u003C\u002Fh2>\n\u003Cp>When Tri-Century identified suspicious network activity September 3, it secured the environment and began an investigation with cybersecurity experts. By September 19, information indicated that an unknown actor had unauthorized network access and acquired certain files containing personal or protected health information belonging to employees and patients.\u003C\u002Fp>\n\u003Cp>The official notice does not disclose the actor's precise first and last moments of access. breachDate therefore uses September 3, the earliest verifiable discovery date, and dateDiscovered uses the same date. The September 19 scope finding, October 30 public notice, and October 31 HHS report are separate stages.\u003C\u002Fp>\n\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\n\u003Cp>The official notice lists names, Social Security numbers, dates of birth, medical or health information, healthcare treatment or diagnostic information, health-insurance information, billing or payment information, and tax or financial information as possible fields.\u003C\u002Fp>\n\u003Cp>Scope varies by person, and it should not be assumed that every field was present for everyone. Although the organization says files were acquired, that does not establish that every field appeared in every file or that all people were affected by every data type. Attacker-claimed samples are not used to expand the primary data classes.\u003C\u002Fp>\n\u003Ch2>Was the Current Electronic Medical-Record System Affected?\u003C\u002Fh2>\n\u003Cp>The organization specifically says there was no evidence of access to its current electronic medical-record system. This boundary matters: acquisition of certain files containing health information does not mean the entire active EMR system was entered or that the whole clinical database was copied.\u003C\u002Fp>\n\u003Cp>The LeakData description and tags preserve that distinction. Health, treatment, and diagnosis information are listed based on the official file review, while “electronic medical record” is not added as a separately affected system. Recipients should rely on their individual letters to understand which fields were associated with them.\u003C\u002Fp>\n\u003Ch2>How Should 200,000 People and Zero Imports Be Read?\u003C\u002Fh2>\n\u003Cp>200,000 is the affected-person count published in the HHS\u002FOCR portal; it is not a file, document, or leak-row count. pwnCount and totalRecords show this official person total. importedRecordCount 0 means that no raw, searchable person records were transferred into LeakData and does not mean the number of affected people is zero.\u003C\u002Fp>\n\u003Cp>The “200K+” wording in secondary headlines is not added as another total. The current federal row's 200,000 is retained as the single official person metric. If a later official regulatory update publishes a different figure, this record should be reviewed again instead of creating a duplicate page for the same event.\u003C\u002Fp>\n\u003Ch2>What Did the Organization Do and What Can Recipients Do?\u003C\u002Fh2>\n\u003Cp>Tri-Century said it implemented stronger password requirements, more frequent password changes, reduced access permissions, and offline storage of older data. HHS and the FBI were notified. The organization established the 1-800-405-6108 call center, available weekdays from 8:00 a.m. to 8:00 p.m. Eastern Time.\u003C\u002Fp>\n\u003Cp>Recipients should regularly review financial accounts, credit reports, and health-insurance Explanation of Benefits documents. An unfamiliar treatment, claim, bill, or payment should be verified directly with the relevant institution. Unexpected communications claiming to represent Tri-Century should not receive a full SSN, health information, password, payment details, or one-time code.\u003C\u002Fp>","Tri-Century official notice, HHS\u002FOCR report, and independent incident reporting",false,"completed","\u002Fuploads\u002Flogo\u002Ftricenturyeye_com.svg","High"]