A ransomware group known as thegentlemen claims it stole data from Northern New Jersey Eye Institute, a South Orange-based ophthalmology practice. The claim has not been confirmed by the organization, and the number of affected patients is unknown. If you were a patient, monitor your credit reports, watch for phishing attempts, and consider a credit freeze as a precaution.
| Company | Northern New Jersey Eye Institute |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Patient Names and Contact Information, Dates of Birth, Medical Record Numbers and Treatment History, Insurance and Billing Information, Social Security Numbers, Diagnostic and Surgical Records |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Northern NJ Eye Institute Data Breach?
A ransomware group calling itself thegentlemen has claimed it broke into the network of Northern New Jersey Eye Institute. The group posted the claim on its dark web leak site. This listing is the only current source describing the alleged attack.
According to the group’s own posting, the Northern NJ Eye Institute data breach involved unauthorized access to internal systems. The claim did not specify an exact date of intrusion. However, the practice’s discovery date has not been publicly disclosed at this time.
Northern New Jersey Eye Institute has not publicly confirmed this incident. As a result, there is no independent confirmation of how the attackers may have gained entry. There is also no public statement describing any forensic investigation, containment steps, or law enforcement involvement. Readers should treat the claim as unconfirmed until the practice or an official regulator filing says otherwise.
Who was affected?
Northern New Jersey Eye Institute operates clinics in South Orange, West Caldwell, and Elizabeth, New Jersey. The practice treats patients for cataracts, LASIK and related vision correction, glaucoma, corneal and retinal disease, and diabetic eye care. Because of this range of services, the potentially affected population could include current and former patients across multiple age groups.
The exact number of affected individuals has not been publicly disclosed. Ransomware.live’s listing does not include a specific victim count. In addition, no information has been released about whether employees, in addition to patients, may be included in any exposed data.
Given that the practice accepts Medicare and more than a dozen private insurance plans, its patient base likely spans a broad demographic. This may include older adults receiving cataract or glaucoma treatment. It could also include younger patients seeking LASIK or cosmetic eye procedures. Until an official notification is issued, the scope of affected individuals remains unclear.
What Information Was Potentially Exposed?
Because Northern New Jersey Eye Institute has not confirmed the incident, the exact data categories involved are not officially verified. However, healthcare practices of this type typically store certain categories of sensitive patient information. Based on the nature of the business, the following types of data could plausibly be involved if the claim is accurate.
- Patient names and contact information
- Dates of birth
- Medical record numbers and treatment history
- Insurance and billing information
- Social Security numbers
- Diagnostic and surgical records related to eye care
If this information was in fact accessed, patients could face a heightened risk of medical identity theft. This means someone could use a stolen identity to obtain medical services or prescriptions in another person’s name. This type of fraud can be especially difficult to detect because it may not show up on a typical credit report.
In addition, exposed Social Security numbers and insurance details could lead to traditional identity theft. Criminals could open new credit accounts, file fraudulent tax returns, or target victims with convincing phishing attempts. Because medical data often includes highly personal health details, affected individuals may also face privacy concerns beyond financial risk.
What is the company doing?
Northern New Jersey Eye Institute has not issued a public statement confirming or responding to the ransomware group’s claim. Therefore, no specific remediation steps, notification timeline, or protective services can be confirmed at this time. This article will be updated if the practice releases an official statement or notifies affected patients.
Because the incident remains unconfirmed by the organization itself, it is not yet known whether credit monitoring or identity protection services will be offered. Patients concerned about their information should watch for direct communication from the practice. In the meantime, individuals can take independent protective steps described below.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. You can request a free copy from each of the three major credit bureaus through AnnualCreditReport.com. Reviewing these reports often is one of the simplest ways to catch fraud early.
Because healthcare breaches can lead to delayed fraud, ongoing vigilance matters more than a single check. For example, fraudulent activity may not appear for months after a breach. As a result, consider setting a recurring reminder to review your reports every few months.
Consider a Fraud Alert or Credit Freeze
If Social Security numbers were part of the exposed data, placing a fraud alert or credit freeze can add a strong layer of protection. A fraud alert requires lenders to verify your identity before opening new credit. A credit freeze goes further by blocking access to your credit file entirely.
Both options are free and can be requested directly through each credit bureau. Because a freeze is more restrictive, it may take extra steps to lift temporarily when you need new credit. However, this extra effort is often worth the added security.
Protect Against Medical Identity Theft
Because this breach involves a healthcare provider, patients should also review their insurance statements and medical records closely. Look for any services or claims you don’t recognize. This could indicate someone else is using your identity to receive medical care.
If you notice suspicious entries, contact your insurance provider and the medical practice immediately. In addition, request a copy of your health information disclosure history if available. This step can help confirm whether your medical records were accessed inappropriately.
Stay Alert for Phishing Attempts
Following any data breach, scammers often use stolen information to craft convincing phishing emails or phone calls. Be cautious of messages claiming to be from Northern New Jersey Eye Institute or related healthcare providers. Never click links or share personal details unless you can verify the sender.
Instead, contact the organization directly using a phone number or website you trust. This helps you confirm whether a message is legitimate. Because phishing attempts often escalate after a breach, staying alert in the coming months is especially important.
Consult a Data Breach Attorney
If you believe your information was exposed in this incident, speaking with a data breach attorney can help clarify your options. Many attorneys offer free consultations to review your situation. They can also advise whether you may qualify to join a potential class action.
Because laws around data breach claims vary by state, professional legal guidance can help you understand applicable deadlines. This is especially useful if the practice later confirms the breach and provides more details. Acting sooner rather than later can help preserve your legal options.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
