Hattiesburg Eye Clinic Data Breach Exposes Patient Medical Records and Personal Information

Published: 15 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

Hattiesburg Eye Clinic suffered a ransomware attack claimed by a group called thegentlemen, potentially exposing patient medical records, Social Security numbers, and personal information. The number of affected individuals has not been publicly disclosed. Anyone who has received care at the clinic should monitor their credit reports and insurance statements closely and consider placing a credit freeze immediately.

CompanyHattiesburg Eye Clinic
IndustryHealthcare
Data Types ExposedFull Names and Contact Information, Dates of Birth, Medical Records and Diagnosis History, Treatment and Surgical History, Insurance Information, Social Security Numbers, Billing and Payment Details
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Hattiesburg Eye Clinic Data Breach?

Hattiesburg Eye Clinic, a longtime ophthalmology practice serving south Mississippi, has confirmed a ransomware attack on its computer network. A cybercriminal group calling itself “thegentlemen” has claimed responsibility for breaching the clinic’s systems. As a result, patient data may have been accessed or stolen by the attackers.

The clinic has operated in Hattiesburg since 1974 and is known as one of the region’s oldest and largest eye care practices. It offers cataract surgery, LASIK, glaucoma treatment, retina care, and other specialized eye services. Because the practice handles sensitive medical information for thousands of patients, any breach of its systems raises serious data security concerns.

Details about the exact discovery date of the intrusion have not been publicly disclosed. However, ransomware groups like thegentlemen typically gain access through phishing emails, compromised credentials, or unpatched software vulnerabilities. In many similar cases, attackers steal data before deploying encryption, then threaten to leak stolen files unless a ransom is paid.

Following discovery of the incident, the clinic likely began an internal investigation to determine the scope of the intrusion. This process often involves bringing in outside cybersecurity specialists to identify which systems were accessed and what data was involved. As of now, the clinic has not released a full public account of its forensic findings.

Who was affected?

The individuals affected by this breach are most likely current and former patients of Hattiesburg Eye Clinic. Given the practice’s decades of operation and its role as a major regional eye care provider, the number of patients in its systems could be substantial.

The exact number of people affected by this breach has not been publicly disclosed. In addition to patients, employees of the clinic could also be impacted if their personnel records were stored on the same network. Because the clinic offers pediatric eye care, it is also possible that minors’ information was involved.

The clinic serves patients throughout south Mississippi and surrounding areas. As a result, the geographic reach of this breach could extend well beyond Hattiesburg itself, touching families across the broader region who have relied on the practice for eye care over the years.

What Information Was Potentially Exposed?

While a complete inventory of compromised data has not been made public, healthcare providers like Hattiesburg Eye Clinic typically store a wide range of sensitive patient information. Based on the nature of the practice and the type of attack involved, the following categories of data may have been exposed.

  • Full names and contact information
  • Dates of birth
  • Medical records and diagnosis history
  • Treatment and surgical history
  • Insurance information
  • Social Security numbers
  • Billing and payment details

If confirmed, exposure of medical records could lead to serious consequences for patients. For example, stolen health information can be used to commit medical identity theft, where a criminal uses someone else’s identity to obtain treatment or medication. This can result in incorrect information being added to a victim’s medical file, which can complicate future care.

Additionally, if Social Security numbers or financial details were exposed, affected individuals face a heightened risk of traditional identity theft. Criminals could use this data to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. Because medical data often includes a fuller picture of a person’s life, it can also be used for highly targeted phishing scams.

What is the company doing?

Hattiesburg Eye Clinic has not released extensive public details about its remediation efforts. However, organizations facing a confirmed ransomware attack typically take immediate steps to contain the threat. This often includes isolating affected systems, resetting credentials, and working with cybersecurity firms to assess the damage.

In response to incidents like this, healthcare providers are generally required to notify affected patients and may need to offer credit monitoring or identity protection services. Because Hattiesburg Eye Clinic operates as a healthcare entity, it may also have obligations under federal health privacy law to report the breach to regulators and affected individuals within a specific timeframe. At this time, further updates from the clinic regarding notification and remediation have not been publicly disclosed.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected patients should request a copy of their credit report from each of the three major credit bureaus. Reviewing these reports carefully can help identify any unfamiliar accounts or inquiries that may signal fraud.

Under federal law, consumers are entitled to a free credit report from each bureau every year. Because identity thieves often wait months before using stolen data, it’s wise to check your reports periodically rather than just once. This ongoing vigilance gives you the best chance of catching fraudulent activity early.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers were part of this breach, affected individuals should strongly consider placing a fraud alert or credit freeze on their credit files. A fraud alert requires creditors to verify your identity before opening new accounts in your name.

A credit freeze offers even stronger protection by blocking access to your credit report entirely. As a result, most lenders won’t be able to approve new credit applications until the freeze is lifted. Both options are free to set up and can be requested directly through each credit bureau.

Protect Against Medical Identity Theft

Because medical records may have been exposed, patients should closely review any statements from their health insurance provider. Look for services or treatments listed that you don’t recognize.

If you notice discrepancies, contact your insurer immediately to dispute the charges. You should also request an accounting of disclosures from Hattiesburg Eye Clinic to see who has accessed your medical records. This can help you spot unauthorized use of your health information before it causes lasting harm.

Stay Alert for Phishing Attempts

After a healthcare data breach, affected individuals often become targets of follow-up phishing scams. Attackers may use stolen information to craft convincing emails or phone calls that appear to come from the clinic or insurance providers.

Therefore, be cautious of unsolicited messages asking for personal or financial details. Never click links or provide sensitive information unless you can verify the request through official channels. When in doubt, contact the organization directly using a phone number you look up independently.

Consult a Data Breach Attorney

Given the sensitive nature of the data potentially involved, affected individuals may want to speak with an attorney who focuses on data breach cases. Many offer free consultations to help you understand your rights.

In addition, a qualified attorney can advise whether you may be eligible to join a class action lawsuit related to this breach. This is especially important if you experience financial losses or identity theft tied to this incident.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

See the latest data breaches we're tracking →