Oculus Pathology Notifies 20,000 Patients About April 2026 Security Incident
Texas-based Oculus Pathology has disclosed a data breach affecting more than 20,000 patients. Data breaches have also been announced by Paradigm Healthcare Services in California and LeMaitre Vascular in Massachusetts.
Oculus Pathology, Texas
Oculus Pathology, an Austin, Texas-based anatomic and clinical pathology laboratory that provides services to hospitals, ambulatory surgery centers, and physician groups, has notified 20,040 patients that some of their protected health information has been exposed and potentially stolen.
On April 1, 2026, suspicious activity was identified related to an employee’s email account. Action was taken to secure its email system, and third-party cybersecurity specialists were engaged to investigate the activity and determine the nature and scope of the incident. The investigation determined that the account had been accessed by an unauthorized third party, and other email accounts were also compromised between March 31, 2026, and April 2, 2026.
The affected email accounts were reviewed to determine the individuals affected and types of data involved. The data review determined that personally identifiable information and protected health information were exposed, including names, dates of birth, Social Security numbers, driver’s license/ state identification numbers, individual tax identification numbers, financial account numbers (with or without access information), payment card numbers (with or without access information), clinical information, provider names, health insurance information, diagnoses, prescription information, medical treatment/procedure information, medical record numbers, Medicare numbers, and patient IDs. No misuse of the exposed information has been detected; however, the affected individuals have been advised to remain vigilant against identity theft and fraud.
Paradigm Healthcare Services, California
Paradigm Healthcare Services, a San Francisco, California-based third-party school Medi-Cal billing company, identified unauthorized access to its local computer network on October 13, 2025. Third-party cybersecurity professionals were engaged to investigate the incident and determine the nature and scope of the activity.
The investigation confirmed that the unauthorized access was limited to its local network between October 8, 2025, and October 15, 2025. The online service documentation and billing platform and Student Health Network were not affected. Data exposed in the incident included names, dates of birth, gender information, and Medi-Cal member identification numbers. The data breach has been reported to the California Attorney General. The number of affected individuals has yet to be publicly disclosed.
LeMaitre Vascular, Massachusetts
LeMaitre Vascular, a Burlington, Massachusetts-based medical device company that makes products for treating peripheral vascular disease, has notified regulators about a breach of patient information. The company experienced a network disruption that confirmed that its network was accessed by an unauthorized third party, who may have viewed or obtained sensitive information. It is unclear when the breach occurred and when it was detected; however, the review of the exposed files was completed on September 14, 2026.
Data compromised in the incident included names, Social Security numbers, USCIS Alien Registration numbers, driver’s license numbers, financial account numbers, and medical records. The number of affected individuals has yet to be publicly disclosed, although almost 1,000 Massachusetts residents are known to have been affected.



