
Greenbelt, Maryland-based Center for Vein Restoration said that the data security incident it suffered in October compromised the sensitive personal information of close to 450,000 individuals.
Founded in 2007, Center for Vein Restoration is among leading clinical leaders in vein treatment in the US. With more than 100 clinics located across the U.S., including 22 states and the District of Columbia, the healthcare provider offers minimally invasive vein treatment to its patients.
In a data security incident notification posted on its website, CVR said that on October 6, it identified unusual activity in its internal network. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
CVR said it also took steps to contain the incident, recover the affected systems and notify law enforcement agencies about the cyber security incident.
Following an investigation, the healthcare company determined that the compromised information included patients’ names, residential addresses, dates of birth, Social Security numbers and driver’s license numbers.
The cyber attack also compromised patients’ healthcare information, including their medical record numbers, diagnosis details, lab results, medications, treatment information, health insurance information, provider names, dates of treatment, and financial information. For employees, information related to employment was compromised during the incident.
CVR reported the incident to the U.S. Department of Health and Human Services, stating that the cyber security incident affected at least 446,094 individuals.
“To help prevent something like this from happening again, we have implemented, and will continue to adopt, additional safeguards and technical security measures to further protect and monitor our systems,” reads the notice.
CVR has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general.
The healthcare provider has also offered complimentary identity protection and credit monitoring services through TransUnion to all affected individuals.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543