On January 8, 2025, the Black Hills Regional Eye Institute in Rapid City, South Dakota, appeared on the leak site of the qilin ransomware group. The medical practice, which provides ophthalmology and optometry services, may have had its internal files exfiltrated after a ransomware attack on its network. Patients whose personal and medical information was stored in those systems may now face heightened risks of identity theft and doxxing.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Black Hills Regional Eye Institute
Get alerted the next time Black Hills Regional Eye Institute files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Black Hills Regional Eye Institute’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that qilin listed the Black Hills Regional Eye Institute on its leak site with samples of stolen data. The breach involved internal files exfiltrated during a ransomware incident. No exact patient count has been disclosed, and the full scope of exposed records remains unclear from available reporting. The incident follows the group’s typical pattern of encrypting victim networks, exfiltrating data, and then threatening to publish it unless a ransom is paid.
Why This Matters for You and Your Family
When a local medical provider is hit, the people affected are often ordinary families who live nearby and trusted the clinic with sensitive details. Medical records, addresses, phone numbers, dates of birth, and insurance information can give criminals everything needed to open accounts in your name, file fraudulent tax returns, or sell your data on underground forums. For parents, a child’s vision exam record or vaccination note can become another thread that ties your household together in the eyes of attackers. Once your data leaves a trusted clinic, you cannot get it back — you can only limit what criminals do with it next.
The Doxxing and Identity-Chain Implications
Medical breaches rarely stop at one record. A single leaked email or phone number can be linked to your social-media handles, your children’s gaming accounts, and other services where the same password was reused. Attackers follow these chains to build full profiles, leading to targeted phishing, account takeovers, or public doxxing. Credential leaks like this one frequently cascade into gaming account compromises because children often use family email addresses or phone numbers. The longer these connections remain unmapped, the easier it becomes for criminals to move from one account to the next.