Operation PAR, a Florida-based SUD treatment provider, has announced a data breach affecting more than 145,700 individuals. Data breaches have also been announced by Vanderbilt Health in Tennessee, Averhealth Holdings in Virginia, and the Texas-based nationwide optical and optometric service provider Eyemart Express. Operation PAR, Florida Operation PAR, Inc.
, a Pinellas Park, Florida-based addiction treatment and mental health service provider, has identified unauthorized access to its computer network and the exposure of the protected health information of 145,714 current and former clients. Suspicious activity was identified within its computer network on June 10, 2025. Immediate steps were taken to secure its systems, and an investigation was launched to determine the nature and scope of the activity.
A year to the day after the incident was identified, Operation PAR confirmed that the impacted files contained personal and protected health information. Data compromised in the incident included first and last names, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information.
Steps have since been taken to augment security and prevent similar incidents in the future. Notification letters started to be mailed to the affected individuals on June 25, 2026, who were provided with information on best practices to protect their information and prevent fraud and misuse. Credit monitoring and identity theft protection services do not appear to have been offered.
While not stated in the notification letters, this appears to have been an attack by the Worldleaks threat group, which added Operation PAR to its dark web data leak site in July 2025. The group proceeded to leak the stolen data. Eyemart Express, Texas Farmers Branch, Texas-based Eyemart Express, a nationwide provider of optical and optometric services, has disclosed further information about a data breach reported to the HHS’ Office for Civil Rights on May 18, 2026.
Unauthorized access to parts of the Eyemart Express network was discovered on February 13, 2026. Immediate action was taken to secure its network, and an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation confirmed that an unauthorized third party breached its network the previous day (February 12, 2026), and gained access to files containing names, addresses, dates of birth, Social Security numbers, prescription information, insurance information, and information about eyeglass purchases.
Eyemart Express has reviewed its policies and procedures related to data security and is implementing additional measures to reduce the risk of similar incidents in the future. The protected health information of up to 25,000 individuals was potentially compromised in the incident. Individuals who had their Social Security numbers exposed have been offered complimentary credit monitoring and identity theft protection services.
While not stated in the breach notice, this was a cyberattack by the PayoutsKing threat group. The threat group claimed to have exfiltrated 435 GB of data in the attack, including customer and employee information. The group proceeded to leak the stolen data when the ransom was not paid.
Vanderbilt Health, Tennessee Nashville, Tennessee-based Vanderbilt Health, the operator of 8 hospitals and more than 180 ambulatory, primary care, and specialty clinics in the state, has identified unauthorized access to an employee’s email account. An employee was tricked by a phishing attempt into clicking a malicious link, resulting in the theft of their credentials.
Unauthorized account access was detected on March 27, 2026, and the forensic investigation confirmed that the account was compromised on March 23, 2026. An unauthorized individual had access to emails and associated documents containing patient information such as names, medical record numbers, diagnoses, procedure information, provider/facility names, and admission, discharge, and visit dates.
The breach was confined to the email account. There was no unauthorized access to electronic medical records, and financial information and Social Security numbers were not involved. In response to the incident, Vanderbilt Health is enhancing its email and digital security measures and has provided additional security awareness training to the workforce.
The number of affected individuals has yet to be publicly disclosed. Averhealth Holdings, Virginia Averhealth Holdings, the parent company of Avertest, a provider of drug testing services for substance use monitoring, diagnostic laboratory testing, and random drug-testing programs, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 9,909 individuals.
Suspicious activity was identified within its email environment on January 20, 2026. Steps were taken to contain the incident, and an investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity professionals. The investigation determined that there had been unauthorized access to parts of its network between December 19, 2025, and January 21, 2026.
On May 6, 2026, Averhealth Holdings discovered that the threat actor behind the attack had obtained files containing personal information and protected health information. The types of information varied from individual to individual and included names in combination with one or more of the following: clinical information, diagnosis, digital/electronic signature, date of birth, driver’s license number, health insurance policy-related number, medical cost, medical dates of service, medical history, medical provider name, medical record number, medical treatment/procedure information, mental or physical condition, minor, patient account number, and/or Social Security number.
Originally published at hipaajournal.com
