Eyecare Center of Snohomish Data Breach Exposes Patient Health and Personal Information

Published: 24 August 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: August 2026

Eyecare Center of Snohomish, a Washington optometry practice, confirmed a ransomware attack by the group thegentlemen, which claimed to have stolen patient data. The exact number affected and specific data types have not been fully disclosed, but patient health and personal records may be at risk. Affected individuals should watch for notification letters, monitor their credit, and consider a credit freeze immediately.

CompanyEyecare Center of Snohomish
IndustryHealthcare
Data Types ExposedPatient Names and Contact Information, Dates of Birth, Medical and Vision Treatment Records, Health Insurance Information, Appointment and Billing History, Social Security Numbers
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the Eyecare Center of Snohomish Data Breach?

Eyecare Center of Snohomish, an optometry practice serving the Snohomish, Washington community, has confirmed it was the target of a ransomware attack. A threat actor group known as thegentlemen has claimed responsibility for breaching the clinic’s network. This group has publicly listed the practice as one of its victims, pointing to real evidence that patient data was accessed.

The clinic disclosed the incident to the public in August 2026. As of now, the exact date the intrusion began has not been publicly disclosed. This is common in ransomware cases, where attackers often sit inside a network for weeks or months before their presence is detected or before they choose to reveal the attack.

Because thegentlemen operates as an extortion-focused group, the typical pattern involves stealing files before triggering any encryption or making public threats. As a result, investigators generally assume that data theft occurred before the clinic became aware of the breach. The practice has not yet released a full forensic timeline explaining how the attackers gained entry.

Following discovery, Eyecare Center of Snohomish likely engaged cybersecurity specialists to investigate the scope of the intrusion. This kind of forensic review typically aims to determine which systems were accessed, what data was taken, and whether the attackers still retain access. However, specific findings from that investigation have not been made public at this time.

Who was affected?

The breach may affect patients of Eyecare Center of Snohomish, a clinic that has served the local community since 1964. Because the practice offers both medical eye exams and optical retail services, the affected population could include long-term patients as well as more recent customers who purchased eyewear or contact lenses.

The exact number of individuals affected by this breach has not been publicly disclosed. Given the practice’s decades of operation, however, the patient population impacted could be substantial. It is also possible that employee records were exposed, though this has not been confirmed.

Because eye care clinics often serve patients of all ages, it is possible that minors are among those affected. Parents who brought children to the clinic for vision exams should remain alert to notification letters addressed to their child’s name as well as their own.

What Information Was Potentially Exposed?

The specific data categories compromised in this incident have not been fully itemized in public statements. However, based on the nature of the business and the type of information optometry clinics typically store, certain categories of data are commonly at risk in breaches like this one.

  • Patient names and contact information
  • Dates of birth
  • Medical and vision treatment records
  • Health insurance information
  • Appointment and billing history
  • Possible Social Security numbers used for billing or insurance purposes

If Social Security numbers or health insurance details were included in the stolen data, affected patients could face a heightened risk of identity theft. Criminals often use this type of information to open fraudulent credit accounts. In addition, stolen health insurance details can be used to submit fake medical claims, which can be difficult for victims to detect and unwind.

Medical record exposure carries its own distinct risks beyond financial fraud. For example, exposed treatment histories could be used for targeted phishing scams that reference real appointments or diagnoses to appear more convincing. This makes it harder for patients to recognize a scam message as fraudulent, since the details feel personal and accurate.

What is the company doing?

In response to the attack, Eyecare Center of Snohomish has acknowledged the incident and is working to address the situation. This typically includes securing affected systems, reviewing network access controls, and working with security professionals to prevent further unauthorized activity.

The clinic is also expected to notify affected individuals as required under applicable state and federal laws. Because health information may be involved, the practice may have obligations under HIPAA to inform patients whose protected health information was compromised. Notification letters, when sent, typically explain what data was involved and what protective steps are being offered.

It has not been publicly confirmed whether the clinic is offering credit monitoring or identity protection services to affected patients. If such services become available, they would typically be detailed in official notification letters mailed directly to those impacted.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should request a free copy of their credit report from each of the three major credit bureaus. Reviewing these reports carefully can help you spot new accounts or credit inquiries you did not authorize. Because fraud can take time to surface, checking reports periodically over the coming months is wise.

You are entitled to a free credit report from each bureau on a regular basis. In addition, many banks and credit card issuers now offer free credit monitoring tools. Using these tools consistently makes it easier to catch suspicious activity early, before serious damage occurs.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers were part of the exposed data, placing a fraud alert on your credit file is a strong protective step. A fraud alert requires creditors to take extra steps to verify your identity before opening new accounts in your name. This can slow down or stop identity thieves who try to use your information.

For even stronger protection, consider a credit freeze, which restricts access to your credit file entirely. This means most lenders cannot open new accounts in your name until you lift the freeze. Because a credit freeze is free to place and remove, it is one of the most effective tools available to consumers.

Watch for Medical Identity Theft and Insurance Fraud

Because this breach involves a healthcare provider, patients should also watch for signs of medical identity theft. This includes reviewing insurance statements, known as explanation of benefits notices, for treatments or services you did not receive. If something looks unfamiliar, contact your insurer right away.

In addition, keep an eye on your medical records for inaccuracies that could result from fraudulent claims filed under your name. Correcting these errors early can prevent complications with future medical care or insurance coverage. If you suspect misuse, report it to both your insurance provider and the clinic directly.

Stay Alert for Phishing and Scam Attempts

Following any healthcare data breach, affected individuals often become targets of phishing emails, texts, or phone calls. Scammers may reference real appointment details or personal information to appear legitimate. Because of this, treat unexpected messages asking for personal or financial information with caution.

Never click on links or provide sensitive information in response to unsolicited messages. Instead, verify any request by contacting the organization directly using a phone number or website you know to be legitimate. This simple habit can prevent most phishing attempts from succeeding.

Consult a Data Breach Attorney

If you received a notification letter about this breach, it may be worthwhile to speak with an attorney who focuses on data breach cases. An attorney can help you understand whether you qualify for compensation and what legal options may be available. Many offer free initial consultations to evaluate your situation.

Because deadlines for filing claims can vary depending on the circumstances, acting sooner rather than later is generally advisable. A consultation can also help clarify what documentation you should keep, such as notification letters or evidence of related fraud, in case you decide to pursue a claim.



Related Data Breaches

See the latest data breaches we're tracking →