VITAS Hospice Services, a Florida-based hospice care provider, and Tri Century Eye Care, a Pennsylvania-based eye care practice, have reported significant data breaches affecting nearly 520,000 individuals. Both organizations notified the U.S. Department of Health and Human Services after discovering that sensitive health information had been accessed and exfiltrated in separate hacking incidents. VITAS Hospice reported that the breach stemmed from a compromised vendor account, which allowed an unauthorized party to access its systems between September 21 and October 27, 2025, ultimately affecting 319,177 people. Tri Century Eye Care reported a separate incident impacting 200,000 individuals.
The compromised data includes a range of sensitive personal and health information, such as names, addresses, dates of birth, phone numbers, Social Security numbers, driver's license numbers, and next of kin contact details. Both organizations are in the process of notifying affected patients and former patients about the breaches. These incidents highlight ongoing threats to specialty healthcare providers and the risks posed by third-party vendor access to critical systems.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
Tri Century Eye Care said it introduced enhanced security measures in response to the incident involving sensitive patient and employee data.
VITAS said it engaged a cybersecurity firm to investigate the incident and took steps to strengthen its security posture after the breach.
Both healthcare providers reported their breaches to regulators and law enforcement and began notifying affected individuals, offering credit monitoring and identity protection services.
Following its investigation, Tri Century Eye Care determined that an unknown actor had accessed and acquired files containing sensitive patient and employee information.
VITAS said the intruder's access and data exfiltration activity continued until October 27, 2025, concluding the known breach window.
An unauthorized actor gained access through a compromised vendor account connected to VITAS Hospice Services, beginning a period of access to company data.
Tri Century Eye Care identified suspicious activity on its systems and began investigating a potential security incident affecting patient and employee data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.