Healthcare provider · Vision and eye care services · Specialty clinic network · USA
Eye care and ophthalmology practice.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Tri-Century Eye Care, an ophthalmology practice in Bucks County, Pennsylvania, detected a breach on September 3, 2025 and confirmed on September 19, 2025 that patient and employee data were compromised. The PEAR ransomware group claimed the attack (announced September 18, 2025), asserting theft of over 3 TB. About 200,000 individuals were affected per HHS. Exposed data included names, addresses, dates of birth, Social Security numbers, medical/health and treatment/diagnostic information, health insurance information, billing/payment information, and tax/financial information. (NOTE: prior record count 256,144 was a DBC parse; official figure ~200,000. Fields expanded from SSN/contact-only to the full confirmed set incl. medical + financial.)
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
200K records analyzed
Tri-Century Eye Care is an ophthalmology and vision-care practice with several locations in Bucks County, Pennsylvania, providing eye exams, medical eye care, and surgical/ophthalmic services. It maintains patient identity, insurance, billing, and clinical records.
Eye-care providers collect patient identity, contact, insurance, billing, appointment, and treatment records tied to vision care and clinical services.
Tri-Century Eye Care detected a breach on September 3, 2025 and, on September 19, 2025, confirmed that patient and employee PII/PHI were compromised. The PEAR ransomware group claimed the attack (announced September 18, 2025), asserting theft of over 3 TB of data. About 200,000 individuals were affected per HHS; class-action investigations followed.
The exposure combined identity, financial, and clinical data (SSNs, dates of birth, medical/treatment and insurance information, and billing/tax/financial data) for roughly 200,000 patients and employees, an unusually complete bundle for an eye-care practice that enables identity theft, payment fraud, and medical fraud, plus credible treatment- and billing-themed scams.
• Full identity theft and synthetic identity construction using SSN and DOB | • Payment and tax fraud using exposed billing/financial/tax data | • Medical identity fraud and insurance abuse using diagnosis and insurance data | • Targeted phishing and vishing referencing eye care or billing | • Doxxing and physical targeting from exposed home addresses
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Unknown
An ambiguous label without enough reliable public sourcing for a stable threat actor profile. It may refer to a short-lived group, handle, acronym, or non-actor entity.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation