Retina Group of Florida, an eye care medical group with 22 locations, experienced a major data breach. The cybersecurity incident sensitive information belonging to at least 152,691 patients of the specialized ophthalmology practice.
The breach was disclosed to the U.S. Department of Health and Human Services on Sept. 3, 2025, reported as a hacking incident. The data breach compromised both personally identifiable information (PII) and protected health information (PHI).
Exposed information could include names, addresses and other contact information, dates of birth, Social Security numbers, driver's license copies, health insurance information, medical records and payment information. The combination of exposed information increases the risk of identity theft, financial fraud and potential misuse of sensitive health data.
In addition to required state and federal disclosures, the eyecare group will work to notify affected patients by mail.
If you received a notice or believe your personal information may have been compromised in this breach:
For additional details about the ophthalmology practice, visit the Retina Group of Florida website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.