25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Florida SUD Treatment Provider Announces 145,700-record Data Breach

Operation PAR, a Florida-based SUD treatment provider, has announced a data breach affecting more than 145,700 individuals. Data breaches have also been announced by Vanderbilt Health in Tennessee, Averhealth Holdings in Virginia, and the Texas-based nationwide optical and optometric service provider Eyemart Express.

Operation PAR, Florida

Operation PAR, Inc., a Pinellas Park, Florida-based addiction treatment and mental health service provider, has identified unauthorized access to its computer network and the exposure of the protected health information of 145,714 current and former clients. Suspicious activity was identified within its computer network on June 10, 2025. Immediate steps were taken to secure its systems, and an investigation was launched to determine the nature and scope of the activity.

A year to the day after the incident was identified, Operation PAR confirmed that the impacted files contained personal and protected health information. Data compromised in the incident included first and last names, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information. Steps have since been taken to augment security and prevent similar incidents in the future.

Notification letters started to be mailed to the affected individuals on June 25, 2026, who were provided with information on best practices to protect their information and prevent fraud and misuse. Credit monitoring and identity theft protection services do not appear to have been offered. While not stated in the notification letters, this appears to have been an attack by the Worldleaks threat group, which added Operation PAR to its dark web data leak site in July 2025. The group proceeded to leak the stolen data.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Eyemart Express, Texas

Farmers Branch, Texas-based Eyemart Express, a nationwide provider of optical and optometric services, has disclosed further information about a data breach reported to the HHS’ Office for Civil Rights on May 18, 2026. Unauthorized access to parts of the Eyemart Express network was discovered on February 13, 2026. Immediate action was taken to secure its network, and an investigation was launched to determine the nature and scope of the unauthorized activity.

The investigation confirmed that an unauthorized third party breached its network the previous day (February 12, 2026), and gained access to files containing names, addresses, dates of birth, Social Security numbers, prescription information, insurance information, and information about eyeglass purchases. Eyemart Express has reviewed its policies and procedures related to data security and is implementing additional measures to reduce the risk of similar incidents in the future. The protected health information of up to 25,000 individuals was potentially compromised in the incident. Individuals who had their Social Security numbers exposed have been offered complimentary credit monitoring and identity theft protection services.

While not stated in the breach notice, this was a cyberattack by the PayoutsKing threat group. The threat group claimed to have exfiltrated 435 GB of data in the attack, including customer and employee information. The group proceeded to leak the stolen data when the ransom was not paid.

Vanderbilt Health, Tennessee

Nashville, Tennessee-based Vanderbilt Health, the operator of 8 hospitals and more than 180 ambulatory, primary care, and specialty clinics in the state, has identified unauthorized access to an employee’s email account. An employee was tricked by a phishing attempt into clicking a malicious link, resulting in the theft of their credentials. Unauthorized account access was detected on March 27, 2026, and the forensic investigation confirmed that the account was compromised on March 23, 2026. An unauthorized individual had access to emails and associated documents containing patient information such as names, medical record numbers, diagnoses, procedure information, provider/facility names, and admission, discharge, and visit dates.

The breach was confined to the email account. There was no unauthorized access to electronic medical records, and financial information and Social Security numbers were not involved. In response to the incident, Vanderbilt Health is enhancing its email and digital security measures and has provided additional security awareness training to the workforce. The number of affected individuals has yet to be publicly disclosed.

Averhealth Holdings, Virginia

Averhealth Holdings, the parent company of Avertest, a provider of drug testing services for substance use monitoring, diagnostic laboratory testing, and random drug-testing programs, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 9,909 individuals.

Suspicious activity was identified within its email environment on January 20, 2026. Steps were taken to contain the incident, and an investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity professionals. The investigation determined that there had been unauthorized access to parts of its network between December 19, 2025, and January 21, 2026. On May 6, 2026, Averhealth Holdings discovered that the threat actor behind the attack had obtained files containing personal information and protected health information.

The types of information varied from individual to individual and included names in combination with one or more of the following: clinical information, diagnosis, digital/electronic signature, date of birth, driver’s license number, health insurance policy-related number, medical cost, medical dates of service, medical history, medical provider name, medical record number, medical treatment/procedure information, mental or physical condition, minor, patient account number, and/or Social Security number.

Notification letters were mailed to the affected individuals on July 2, 2026. At the time of issuing notifications, Averhealth Holdings was unaware of any misuse of the impacted information. As a precaution against data misuse, complimentary credit monitoring services have been offered to individuals who had their Social Security numbers exposed or stolen.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist