---
title: "Eyemart Express network data incident"
description: "Evidence-backed account of Eyemart Express network data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/eyemart-express-network-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/eyemart-express-network-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/eyemart-express-network-data-incident-2026/stix.json"
---

# Eyemart Express network data incident

Regulator records describe hacking or unauthorized access affecting an Eyemart Express network server between February 12 and February 13, 2026. Regulator records associate personal identifiers, financial information, medical information, and health-insurance information with the incident.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Reporting healthcare provider associated with the affected network server and exposed records.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Regulator records describe hacking or unauthorized access affecting an [Eyemart Express](https://eyemartexpress.com/) network server between February 12 and February 13, 2026. [2](#source-2) [3](#source-3)

## Impact

Regulator records associate personal identifiers, financial information, medical information, and health-insurance information with the incident. [2](#source-2)

Documented data types include:

- Names — Names; reported by the Texas Attorney General and varying by individual. [2](#source-2)
- Clinical information — Medical information; reported by the Texas Attorney General and varying by individual. [2](#source-2)
- Financial account information — Financial-account information; the Texas field combines account and payment-card examples, and data varied by individual. [2](#source-2)
- Dates of birth — Dates of birth; reported by the Texas Attorney General and varying by individual. [2](#source-2)
- Payment card information — Credit- or debit-card information; the Texas field combines account and payment-card examples, and data varied by individual. [2](#source-2)
- Social Security numbers — Social Security numbers; reported by the Texas Attorney General and varying by individual. [2](#source-2)
- Health insurance information — Health-insurance information; reported by the Texas Attorney General and varying by individual. [2](#source-2)
- Contact information — Addresses; reported by the Texas Attorney General and varying by individual. [2](#source-2)
- Driver's license numbers — Driver's-license numbers; reported by the Texas Attorney General and varying by individual. [2](#source-2)

A cited record reports 45,460 individuals (Texas residents in report BR-0005190; a subset of the overall count and not additive; as of 2026-07-21). [2](#source-2) [3](#source-3)

A cited record reports 189,450 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005190; regulator-reported and not independently verified; as of 2026-07-21). [2](#source-2) [3](#source-3)

A cited record reports 25,000 individuals (Individuals in the HHS OCR incident report; the healthcare-report population is retained separately from the later Texas-reported overall figure and is not additive; as of 2026-05-18). [2](#source-2) [3](#source-3)

## Timeline

### February 12, 2026 — Activity began

Start of the access range recorded in Texas Attorney General report BR-0005190. [2](#source-2)

### February 13, 2026 — Documented activity ended

End of the access range in Texas report BR-0005190 and date shown on the California submitted-notice page. [2](#source-2)

### March 17, 2026 — Discovery

Detected date recorded in Texas Attorney General report BR-0005190; the California page separately records February 13 as a incident date. [2](#source-2)

### July 24, 2026 — Public disclosure

California Attorney General reported date for the submitted Eyemart Express sample notice; not asserted as the mailing date for every person. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

HHS OCR classified the incident as a hacking or IT incident involving a network server. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3](#source-3)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/eyemart-express-network-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Data Security Breach List — 2026 records

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/privacy/databreach/list>

<a id="source-2"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-3"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Individual Count · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: 45,460 individual
2. **Exposed Data Category · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Names
3. **Began At · 100% confidence · current**  
   February 2026 Eyemart Express network intrusion: 2026-02-12
4. **Affected Organization · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Eyemart Express, LLC
5. **Affected Individual Count · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: 189,450 individual
6. **Exposed Data Category · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Clinical information
7. **Disclosed At · 100% confidence · current**  
   Eyemart Express regulator and individual notifications: 2026-07-24
8. **Resulted In · 100% confidence · current**  
   February 2026 Eyemart Express network intrusion: Eyemart Express personal and health-data exposure
9. **Resulted In · 100% confidence · current**  
   February 2026 Eyemart Express network intrusion: HHS OCR classified the incident as a hacking or IT incident involving a network server.
10. **Resulted In · 100% confidence · current**  
   February 2026 Eyemart Express network intrusion: Eyemart Express regulator and individual notifications
11. **Exposed Data Category · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Financial account information
12. **Exposed Data Category · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Dates of birth
13. **Affected Individual Count · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: 25,000 individual
14. **Exposed Data Category · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Payment card information
15. **Discovered At · 100% confidence · current**  
   February 2026 Eyemart Express network intrusion: 2026-03-17
16. **Exposed Data Category · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Social Security numbers
17. **Exposed Data Category · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Health insurance information
18. **Ended At · 100% confidence · current**  
   February 2026 Eyemart Express network intrusion: 2026-02-13
19. **Affected Organization · 100% confidence · current**  
   February 2026 Eyemart Express network intrusion: Eyemart Express, LLC
20. **Exposed Data Category · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Contact information
21. **Exposed Data Category · 100% confidence · current**  
   Eyemart Express personal and health-data exposure: Driver's license numbers

</details>
