Eyemart Express network data incident

Regulator records describe hacking or unauthorized access affecting an Eyemart Express network server between February 12 and February 13, 2026. Regulator records associate personal identifiers, financial information, medical information, and health-insurance information with the incident.

Last modified

Summary

  • Environment: Reporting healthcare provider associated with the affected network server and exposed records.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Regulator records describe hacking or unauthorized access affecting an Eyemart Express network server between February 12 and February 13, 2026. [2][3]

Impact

Regulator records associate personal identifiers, financial information, medical information, and health-insurance information with the incident. [2]

Documented data types include:

  • Names — Names; reported by the Texas Attorney General and varying by individual. [2]
  • Clinical information — Medical information; reported by the Texas Attorney General and varying by individual. [2]
  • Financial account information — Financial-account information; the Texas field combines account and payment-card examples, and data varied by individual. [2]
  • Dates of birth — Dates of birth; reported by the Texas Attorney General and varying by individual. [2]
  • Payment card information — Credit- or debit-card information; the Texas field combines account and payment-card examples, and data varied by individual. [2]
  • Social Security numbers — Social Security numbers; reported by the Texas Attorney General and varying by individual. [2]
  • Health insurance information — Health-insurance information; reported by the Texas Attorney General and varying by individual. [2]
  • Contact information — Addresses; reported by the Texas Attorney General and varying by individual. [2]
  • Driver’s license numbers — Driver’s-license numbers; reported by the Texas Attorney General and varying by individual. [2]

A cited record reports 45,460 individuals (Texas residents in report BR-0005190; a subset of the overall count and not additive; as of 2026-07-21). [2][3]

A cited record reports 189,450 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005190; regulator-reported and not independently verified; as of 2026-07-21). [2][3]

A cited record reports 25,000 individuals (Individuals in the HHS OCR incident report; the healthcare-report population is retained separately from the later Texas-reported overall figure and is not additive; as of 2026-05-18). [2][3]

Timeline

  1. Activity began

    Start of the access range recorded in Texas Attorney General report BR-0005190.

    [2]
  2. Documented activity ended

    End of the access range in Texas report BR-0005190 and date shown on the California submitted-notice page.

    [2]
  3. Discovery

    Detected date recorded in Texas Attorney General report BR-0005190; the California page separately records February 13 as a incident date.

    [2]
  4. Public disclosure

    California Attorney General reported date for the submitted Eyemart Express sample notice; not asserted as the mailing date for every person.

    [1]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

HHS OCR classified the incident as a hacking or IT incident involving a network server. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3]