Princeton Family Eye Care, operated by Deseye, PLLC, has notified patients of a data security incident that may have exposed personal and health-related information. The practice, located in Princeton, Texas, discovered unauthorized activity within its email systems and began working with cybersecurity professionals to investigate.
Companies that handle sensitive patient records, including medical histories and government-issued identification numbers, carry a heightened responsibility to protect that data from unauthorized access. When a breach occurs at a healthcare provider, the fallout can extend well beyond the clinic walls, potentially exposing patients to identity theft and medical fraud for years to come.
Princeton Family Eye Care’s Data Breach Investigation
According to the notice posted on the practice’s website, Deseye, PLLC d/b/a Princeton Family Eye Care detected suspicious activity within its email environment on May 4, 2026. The practice promptly engaged third-party cybersecurity experts to investigate and contain the activity. By June 2026, the forensic investigation determined that an unauthorized third party had gained access to a company email account.
Following that discovery, Princeton Family Eye Care retained a data-review firm to analyze the contents of the compromised account and identify which individuals may have had their information exposed. Once that review was complete, the practice worked to verify current mailing addresses and issue notification letters to affected patients. The practice has stated it is not aware of any actual misuse of the exposed information to date, though that does not eliminate the risk of future misuse.
Email-based breaches like this one, often called business email compromise incidents, are a common attack vector against small and mid-sized healthcare practices. Unlike a direct network intrusion, an attacker who gains control of a single email account can often access months or years of stored patient correspondence, referral letters, billing records, and attachments containing highly sensitive information, all without triggering the same security alerts that a broader system-wide intrusion might set off. This can allow unauthorized access to persist for weeks before it is discovered, as appears to have happened here between the initial detection in early May and the confirmed forensic findings in June.
The combination of data types identified in this breach, government identification numbers alongside dates of birth and medical information, is particularly valuable to identity thieves and fraudsters. Social Security numbers and driver’s license numbers can be used to open new financial accounts, while medical information paired with insurance details can enable medical identity theft, where a bad actor obtains treatment or prescriptions using a victim’s identity and insurance coverage. Patients affected by breaches involving this data combination are frequently targeted with follow-up phishing attempts that impersonate the healthcare provider, a legitimate-looking credit monitoring service, or even law enforcement, so recipients of a genuine breach notice should be especially cautious about unsolicited calls or emails referencing the incident.
When Did This Breach Occur?
Princeton Family Eye Care detected suspicious activity in its email environment on May 4, 2026. The subsequent forensic investigation, completed in June 2026, confirmed that an unauthorized third party had accessed a company email account during this period.
What Information Was Breached?
The practice determined that potentially impacted emails and files contained a combination of the following data types, though not every affected individual had every category exposed: names, dates of birth, contact information, government-issued identification numbers such as a driver’s license, passport, or Social Security number, and limited medical information, including treatment details, health insurance records, or a medical record number.
What You Can Do
Individuals who received a notification letter from Princeton Family Eye Care, or who are otherwise concerned they may have been affected, can take several steps to protect themselves:
- Review financial account statements and credit reports regularly for unauthorized activity
- Request a free credit report at annualcreditreport.com or by calling (877) 322-8228
- Consider placing a fraud alert or security freeze with the major credit bureaus (Equifax, Experian, and TransUnion)
- Watch for phishing emails, calls, or letters that reference this breach and never provide personal information in response
- Contact Princeton Family Eye Care’s dedicated call center at (888) 650-3654 with any questions about the incident
File a Data Breach Lawsuit Against Princeton Family Eye Care
If you received a breach notification letter from Princeton Family Eye Care, or have learned that your personal or medical information may have been exposed in this incident, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.