
Alabama Ophthalmology Associates (AOA), an ophthalmology practice based in Birmingham, Alabama, has confirmed that the personal and protected health information of over 131,000 individuals was compromised in a data breach earlier this year. The breach, which affected current and former patients, was disclosed by the organization on April 10.
The breach was detected on January 30, 2025, after the practice noticed unusual activity within its network environment. Upon further investigation, AOA discovered that an unknown actor had gained unauthorized access to its systems between January 22 and January 30, 2025. This prompted the organization to secure its network and initiate a detailed investigation with the help of an independent digital forensics and incident response firm.
On February 19, the BianLian ransomware group claimed responsibility for the attack on Alabama Ophthalmology Associates, further raising concerns about the scope and impact of the breach. The compromised data includes a range of personal and medical information, such as names, addresses, dates of birth, driver’s license information, Social Security numbers, medical information, and health insurance details. However, not all individuals had every type of data exposed.
Following the completion of its investigation in mid-March, AOA began notifying impacted individuals on April 7, 2025, and has since set up a toll-free call center to assist those affected. The call center operates Monday through Friday, from 8:00 a.m. to 8:00 p.m. Central Time, to answer any questions regarding the breach.
The breach at AOA is the second major healthcare data incident to come to light recently, with more than 700 healthcare data breaches reported across the United States in 2024 alone. These breaches collectively compromised the personal information of over 180 million individuals, as detailed by the Department of Health and Human Services (HHS). The breach at AOA serves as a stark reminder of the ongoing cybersecurity threats facing healthcare providers, particularly in light of the growing number of ransomware attacks targeting medical institutions.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543