
Columbia Eye Clinic, a medical and surgical ophthalmology practice with four locations in Columbia and Lexington, South Carolina, has disclosed a data security incident that may have exposed patients’ protected health information. The clinic announced the incident on March 14, 2025, describing it as an "information technology network disruption that impacted the clinic’s accessibility to certain electronic systems," language often associated with ransomware attacks.
According to the clinic, the incident was detected on January 13, 2025, and a forensic investigation later confirmed that an unauthorized party had accessed its network between January 9 and January 13. While the investigation is ongoing, preliminary findings indicate that the intruder may have viewed or obtained certain patient data. The potentially compromised information includes names, contact details, dates of birth, procedure codes, and other details used for obtaining pre-approvals for eye-related procedures. However, there is no evidence that the electronic medical record system or practice management systems were accessed, and there have been no indications of misuse of the exposed data.
Following the discovery of the breach, Columbia Eye Clinic implemented a series of security measures to safeguard its systems. The clinic reset all passwords, rebuilt its IT environment using backup systems, deployed new devices and software, and enhanced security protocols. Additionally, the clinic introduced new monitoring software and strengthened security measures across its network.
As the e-discovery process continues, Columbia Eye Clinic is working to identify the individuals affected by the breach. Once this process is complete, the clinic will mail notification letters to those impacted. In the meantime, the incident has been reported to the U.S. Department of Health and Human Services’ Office for Civil Rights as involving the protected health information of at least 500 individuals.
© 2025, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543