AOA FOCUS logo

You’ve been breached—now what?

November 6, 2025

A practice owner’s guide to cyber incident response.

Tag(s): Practice Management, Perfect Your Practice

Cybercrime Breach Skeleton Illustration


Key Takeaways

  • Cyberattacks can strike even well-protected practices, making a clear response plan essential.  
  • Understanding how to contain a breach, fulfill legal obligations and mobilize expert support helps reduce disruption and protect patient trust. 

Even the best prevention strategies cannot guarantee immunity from cyberattacks. As health care practices, optometric practices are held legally and financially accountable for protecting patient data and properly reporting and handling breaches. Familiarizing yourself with the obligations you will face in the unfortunate case of a cyberattack on your practice can put you in a better position to respond swiftly and effectively. 

  • Identify and contain the breach – Start by minimizing the damage. Contact IT support to help you disconnect affected systems from the network. Have a cyber forensic team investigate how the breach occurred, how to prevent further breaches and how to repair any damaged systems or equipment.
  • Determine what data was compromised – Categorize the data that was exposed to assess whether it was protected health information (PHI), financial records or internal business data. Document what data was accessed or stolen and confirm whether encrypted data remained secure. Assess the potential impact on patients, employees and third-party vendors. 
  • Notify Affected Parties – Familiarize yourself with HIPAA and state privacy law requirements for breach notification. Depending on the scope of the breach, your practice may need to report the incident to the Department of Health and Human Services (HHS) and your state attorney general’s office. Generally, patients whose data may have been impacted should be notified in writing as soon as possible. 
  • Coordinate Response Vendors – Responding to and recovering from a breach often requires a team of experts. You may need to identify vendors for the following services:
    • IT support/cyber forensic team to investigate the breach, recover data and repair.
    • Legal counsel specializing in health care privacy to help ensure your breach response is legally compliant and to handle any associated legal claims.
    • Public relations support to facilitate patient communication and reputation management.
    • Credit monitoring providers for affected patients. 

Cyber incident response requires swift action and can take up a significant amount of time and resources. In the case of a breach, having the right cyberliability insurance can help ease the burden of breach response and return your focus to providing quality patient care. AOAExcel®’s endorsed partner, Lockton Affinity, offers cyberliability insurance that provides AOA members with quick access to a network of cyber incident response professionals to facilitate streamlined and effective breach response with just one phone call. Learn more about protecting your practice with coverage designed for risks unique to optometric practices.  

The AOA Insurance Alliance is administered by Lockton Affinity, LLC d/b/a Lockton Affinity Insurance Brokers LLC in California #0795478. Coverage is subject to actual policy terms and conditions. Policy benefits are the sole responsibility of the issuing insurance company. Coverage may be provided by an excess/surplus lines insurer which is not licensed by or subject to the supervision of the insurance department of your state of residence. Policy coverage forms and rates may not be subject to regulation by the insurance department of your state of residence. Excess/Surplus lines insurers do not generally participate in state guaranty funds and therefore insureds are not protected by such funds in the event of the insurer’s insolvency. The American Optometric Association will receive a royalty fee for the licensing of its name and trademarks as part of the insurance program offered to the extent permitted by applicable law.