Back to the register

Hermitage Eye Care, PLLC dba Dover Eye Care

ArchivedSubmitted 11/05/2021
State
TN
Covered entity type
Healthcare Provider
Individuals affected
11,672
Business associate present
Yes
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Hermitage Eye Care, reported that its business associate (BA) experienced a security incident in which the electronic protected health information (ePHI) of 11,672 individuals was accessible via a patient portal on the Internet. The ePHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, and conditions. The BA notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to this incident and OCR’s investigation, the BA implemented additional administrative, technical, and security safeguards to better protect ePHI.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.

We use essential cookies to run this site and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.

Hermitage Eye Care, PLLC dba Dover Eye Care (TN), 11/05/2021 | InfoSec Signals