Three Healthcare Providers Notify Patients About 2024 Data Breaches
Data breaches have recently been announced by Consultants in Pain Medicine in Texas, Claris Vision Holdings in Massachusetts, and Precision Orthopedics and Sports Medicine in Maryland.
Consultants in Pain Medicine Texas
Consultants in Pain Medicine, a San Antonio, Texas-based pain management practice, has recently notified the Texas Attorney General about a security incident that saw unauthorized individuals access its network between June 26, 2024, and July 7, 2024. The forensic investigation confirmed that the attackers had access to patient data and exfiltrated files from the network. The file review concluded on January 17, 2025, and it was confirmed that full names, Social Security numbers, dates of birth, driver’s license numbers or state identification numbers, financial account information, passport numbers, medical information, and/or health insurance policy information had been stolen.
Notification letters started to be mailed to the affected individuals on February 14, 2025. Individuals whose Social Security numbers were involved were offered complimentary credit monitoring and identity theft protection services. The data breach has yet to be added to the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals were affected in total. The Texas Attorney General was informed that 2,062 Texans were affected; however, the HHS’ Office for Civil Rights breach total indicates the protected health information of 1,124 individuals was compromised.
Claris Vision Holdings
Claris Vision Holdings, a Massachusetts-based provider of vision care services, has notified the Attorney General of Massachusetts about a data security incident. Hackers had access to its network from July 10, 2024, and August 5, 2024, and while data theft was not confirmed, files containing patient data were accessible to the hackers.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The review of the exposed files was completed on December 18, 2024, and individual notification letters have now been mailed to the affected individuals. It is unclear what types of data were involved, but that information has been detailed in the individual notification letters. The affected individuals have been offered complimentary single bureau credit monitoring, credit report, and credit score services for 24 months.
The affected patients had previously received vision services from Claris Vision Holdings and its affiliate partners Eye Health Associates, Eye Health Associates of RI, Koch Eye Associates, Candescent Eye Surgicenter (St. James Surgery Center), and Candescent Eye Health Surgicenter (Greater New Bedford Surgery Center). The incident is not yet displayed on the HHS’ Office for Civil website, so it is unclear how many patients have been affected.
Precision Orthopedics and Sports Medicine
On February 13, 2025, Precision Orthopedics and Sports Medicine in Maryland notified 1,903 current and former patients about a September security incident that exposed some of their protected health information. On September 12, 2024, unauthorized activity was identified in its email system. The account was immediately secured, and an investigation was launched to determine the cause of the activity.
The investigation confirmed that an unauthorized third party accessed certain employee email accounts between September 10, 2024, and September 12, 2024, as a result of responses to phishing emails. The review of the accounts confirmed on January 2, 2025, that protected health information was involved. The types of data varied from patient to patient and may have included names plus one or more of the following: date of birth, services received, date(s) of service, treating provider, medication information, diagnostic information, and treatment information.
Patients have been advised to be vigilant against any misuse of their information by monitoring their accounts and statements from their healthcare providers. Email security measures are being reviewed, and safeguards will be enhanced, as necessary, to prevent similar breaches in the future.


