Skip to Primary Navigation

Healthcare provider pays $4.5m penalty for lax data policies and risk assessment

Pair of glasses on eye chart
Photo: Getty Images

Nine staff sharing one email account among glaring errors in company systems.

A data breach that exposed the records of over two million clients of Ohio-based healthcare provider EyeMed Vision Care has led to penalties totalling $4.5m for the company. The case highlights the dangers of poor risk assessments and, particularly, failure to use multi-factor authentication (MFA).

EyeMed’s systems were breached when

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience