August 6th, 2026
The 13 Biggest Dental Data Breaches of All Time
Industry Research — Dental Cybersecurity
No dental practice thinks it is a target until the morning the schedule will not load.
The biggest dental data breaches of the last several years should put that idea to rest for good. Dental practices, multi-location groups, and the insurers behind them hold exactly the data attackers want: Social Security numbers, government IDs, financial accounts, insurance details, and treatment records, often for entire families and, in the Medicaid cases, millions of children. The breaches below are ranked by the number of people affected, and every one of them carries a specific lesson about how the attack happened and what the organization could have done differently. Medix Dental IT has spent more than 20 years securing dental environments, so this is written from the defender’s side of the table, not as a scare piece.
The 13 Biggest Dental Data Breaches of All Time
The Biggest Dental Data Breaches at a Glance
| Rank | Organization | People Affected | Year | Attack Vector |
|---|---|---|---|---|
| 1 | MMG Fusion (software vendor) | 15,000,000 | 2020 | Network intrusion, unreported for years |
| 2 | DentaQuest (benefits administrator) | ~15,000,000 | 2026 | ShinyHunters extortion |
| 3 | MCNA Dental (benefits administrator) | 8,923,662 | 2023 | LockBit ransomware |
| 4 | Delta Dental of California (insurer) | 6,928,932 | 2023 | MOVEit supply-chain zero-day |
| 5 | Great Expressions Dental Centers (DSO) | 1,925,397 | 2023 | Network intrusion |
| 6 | Dental Care Alliance (DSO) | 1,723,375 | 2020 | Network intrusion |
| 7 | Absolute Dental (dental group) | 1,223,635 | 2025 | IT-vendor (MSP) compromise |
| 8 | Risas Dental & Braces (dental group) | 618,189 | 2023 | Network intrusion |
| 9 | Park Dental / The Dental Specialists (dental groups) | 277,109 | 2024 | Email-account compromise |
| 10 | First Choice Dental (dental group) | 228,287 | 2023 | Ransomware |
| 11 | Chord Specialty Dental Partners (DSO) | 173,430 | 2025 | Email-account compromise |
| 12 | Professional Dental Alliance (dental group) | 172,933 | 2021 | Vendor phishing compromise |
| 13 | Henry Schein (distributor / software) | 166,432 | 2023 | BlackCat ransomware |
1. MMG Fusion: 15 Million Records (2020)
MMG Fusion, a Maryland software vendor that sold practice-management and marketing tools to dental and oral-healthcare providers, is the largest dental-sector breach confirmed in a federal enforcement action, and almost nobody has heard of it. An unauthorized actor gained access to MMG’s network on December 21, 2020 and reached protected health information, names, phone numbers, addresses, email addresses, dates of birth, and appointment details, belonging to roughly 15 million dental patients across its provider clients, per the HHS Office for Civil Rights settlement.
What makes this the cautionary tale of the entire list is not the intrusion. It is what MMG did next, which was nothing. The company failed to notify the affected dental practices, or the government, for more than two years. When the HHS Office for Civil Rights finally settled the matter in March 2026, the penalty was just $10,000 plus a three-year corrective action plan, small because the company was by then effectively defunct. Worth noting the order in which OCR listed the violations. The failure to conduct a comprehensive and accurate risk assessment came first, ahead of the impermissible disclosure and the missed breach notifications. That ordering is not incidental. OCR is running an enforcement initiative aimed squarely at the risk-analysis requirement, and a current, documented risk analysis is the first thing regulators ask for after any breach. If your practice or group cannot produce one, that becomes the finding before anyone examines how the attacker got in. The lesson for every practice and DSO is that your software vendor is holding your patients’ data under your name, and a business associate that hides a breach leaves you exposed with no warning and no way to notify your own patients on time. Vendor breach-notification clauses and the right to audit are not legal boilerplate. They are the only thing standing between you and a silent two-year exposure.
2. DentaQuest: About 15 Million Records (2026)
DentaQuest, a Sun Life subsidiary and one of the largest administrators of Medicaid and CHIP dental benefits in the country, was hit by the ShinyHunters extortion group in 2026. Attackers reached part of DentaQuest’s network between May 17 and May 20, 2026, exfiltrated roughly 234GB of data, and published it after the company did not meet their demands. Notification letters began going out on a rolling basis on July 17, 2026, and DentaQuest has confirmed that at least 15 million individuals were affected. Filings with the Texas, Massachusetts and South Carolina attorneys general alone account for more than 4.5 million notification letters, and an independent researcher who deduplicated the leaked files by name and date of birth put the potential ceiling nearer 23.4 million, with roughly 1.7 million unique Social Security numbers found in a single folder. Fifteen million is the confirmed figure; the higher number is an estimate, and the gap between the two is the point. We covered the incident and what it means for practices in our DentaQuest data breach analysis.
Early coverage of this breach put the figure at 2.6 million, which was the count of unique email addresses in the leaked dataset rather than a count of people. Most Medicaid and CHIP enrollees, especially children, have no email address on file, so that number understated the breach by roughly six times. Treat an early breach count as a floor and revisit it.
The pattern here echoes MCNA and Delta Dental: the biggest counts in dentistry come from the benefits administrators and insurers, because they aggregate identity data for millions of patients, many of them children in public dental programs, in one place. When your organization is that kind of data concentrator, you are a named target for professional extortion crews, not a target of opportunity. That reality demands the enterprise-grade controls to match, continuous monitoring, tight segmentation so one foothold cannot reach the whole store, and an extortion-response plan built before the ransom note arrives.
3. MCNA Dental: 8.9 Million Records (2023)
MCNA Dental, one of the largest administrators of government-sponsored dental benefits in the country, suffered one of the biggest dental-sector breaches on record. The LockBit ransomware gang accessed MCNA’s network in late February 2023, exfiltrated roughly 700GB of data, and demanded a $10 million ransom. When MCNA refused, LockBit published the stolen data. The final count was 8,923,662 individuals, many of them children enrolled in Medicaid and CHIP dental programs, along with their parents and guardians.
What went wrong: the intruder moved through MCNA’s network for roughly a week and a half before detection, long enough to copy hundreds of gigabytes out the door. That points to gaps in monitoring and segmentation that let a single foothold reach an enormous store of identity data. Dwell time is the enemy, and endpoint detection that flags lateral movement and bulk transfers in hours, not days, is the difference between an incident and a catastrophe. We broke down that week and a half of undetected access in our MCNA Dental data breach analysis.
4. Delta Dental of California: 6.9 Million Records (2023)
Delta Dental of California and its affiliates were caught in the MOVEit mass-hack, the year’s defining supply-chain attack. The Clop ransomware group exploited a zero-day vulnerability in Progress Software’s MOVEit file-transfer tool before any patch existed, exfiltrating data from thousands of organizations that used it. For Delta Dental of California, that meant 6,928,932 individuals exposed, including Social Security numbers, financial accounts, and passport numbers.
The technical flaw was the vendor’s, not Delta Dental’s, but the regulatory failures were organizational. New York’s financial regulator later faulted the wider Delta Dental organization for lacking a written incident-response plan, for retaining sensitive files longer than its own tools defaulted to, and for notifying regulators roughly six months after detection. The affiliated Delta Dental Insurance Company and Delta Dental of New York settled with NYDFS for $2.25 million over their MOVEit response. The lesson is that you inherit your vendors’ risk. You cannot outsource the obligation to vet third-party tools, minimize the data you hand them, and notify on time. Our Delta Dental data breach analysis goes deeper on why the fine landed on the response rather than the intrusion.
5. Great Expressions Dental Centers: 1.9 Million Records (2023)
Great Expressions Dental Centers, a DSO operating around 246 practices across nine states at the time, was breached over a six-day window in February 2023. Attackers infiltrated its IT systems between roughly February 17 and 22 and reached a wide set of patient data, names, dates of birth, Social Security numbers, and dental and medical records, along with employee banking information. The final count was 1,925,397 individuals, and the company later settled a class action for $2.7 million, per HIPAA Journal.
This is the DSO risk-concentration lesson repeating at scale. A group supporting hundreds of practices centralizes patient records into systems that, once breached, expose everyone at once, and a six-day dwell time on a repository that large is a detection failure. The defenses are the ones this whole list keeps pointing back to: endpoint detection that flags lateral movement in hours, segmentation so a single foothold cannot reach two hundred practices’ worth of data, and data minimization so the most sensitive fields are not sitting together in one reachable place. Our Great Expressions data breach analysis digs into how centralization concentrated the damage across 246 practices.
6. Dental Care Alliance: 1.7 Million Records (2020)
Dental Care Alliance, a DSO supporting more than 320 affiliated practices across about 20 states at the time, was described in contemporaneous reporting as one of the largest healthcare breaches disclosed in 2020. By HIPAA Journal’s year-end ranking it landed fifth, behind Trinity Health, MEDNAX, Inova Health System, and Magellan Health. Attackers accessed the network over a window of nearly a month in fall 2020, from September 18 to October 13, and reached patient files; the count was initially reported at 1,004,304 and later amended upward to 1,723,375. A subset had Social Security numbers, financial accounts, or driver’s license numbers exposed. The case settled for $3 million in 2022.
The takeaway is structural. A DSO that aggregates protected health information from hundreds of practices becomes a single high-value target, and a month of dwell time on a repository that large is a monitoring failure. Every practice a group acquires either raises or lowers that risk, which is why IT due diligence before an acquisition is as much a security control as a financial one. Centralization is a strength operationally and a risk concentration in security terms. The same platform that makes a group efficient makes it a bigger prize. Our Dental Care Alliance data breach analysis covers how that IT risk became acquisition risk.
7. Absolute Dental: 1.2 Million Records (2025)
Absolute Dental, a Nevada group with more than 50 locations, was breached through its IT vendor. An attacker ran a malicious version of a legitimate software tool through an account belonging to the practice’s managed services provider, and used that trusted access to reach 1,223,635 patient records. The court granted preliminary approval of a $3.3 million class-action settlement in March 2026 and scheduled the final fairness hearing for late July 2026. Payments to class members follow final approval, and the claims against the IT consulting firm named alongside Absolute Dental were not resolved by that settlement. The full account of how one vendor account opened the door is in our Absolute Dental data breach analysis.
What went wrong is the cleanest cautionary tale in this list: a single MSP account became a master key. The lesson for every practice and DSO that outsources IT is that your vendor’s access is your attack surface. MSP accounts need phishing-resistant MFA, least-privilege scoping, and monitored remote-access sessions, because the entry point here was not a dental employee. It was the IT vendor everyone trusted by default.
8. Risas Dental & Braces: 618,000 Records (2024)
Risas Dental & Braces, a multi-state group across Arizona, Colorado, Texas, and Nevada, detected unauthorized activity on its systems in July 2023. The investigation found that an attacker had reached internal file stores and downloaded patient data, affecting 618,189 individuals. Notably, the notification did not list Social Security numbers or full treatment records among the exposed data, which made this a less severe breach per person than several smaller ones on this list.
That contrast is the lesson. Breach severity is not just headcount, it is what data was reachable. Risas limited the damage because the data disclosed in its notice did not amount to the full identity-theft kit. Segmenting and minimizing the most sensitive data, so that a server compromise does not automatically mean SSNs walk out the door, is what shrinks the blast radius when, not if, an attacker gets in.
9. Park Dental and The Dental Specialists: 277,000 Records (2024)
Two affiliated Minnesota dental groups, Park Dental and The Dental Specialists, disclosed a combined 277,109 affected patients (238,667 and 38,442) from a single email-account compromise in January 2024. An attacker reached multiple employee Microsoft email accounts over about two weeks. The organizations stated that multifactor authentication was in place but was circumvented during the intrusion.
This is the “MFA alone is not enough” case. Legacy push-prompt and SMS-based MFA can be defeated by phishing, token theft, and prompt-bombing, which is why phishing-resistant MFA (hardware keys or number-matching) matters. The second failure was that patient data was sitting in email inboxes at all. PHI that lives in a mailbox turns one hijacked account into a six-figure breach.
10. First Choice Dental: 228,000 Records (2023)
First Choice Dental, a group of clinics in and around Madison, Wisconsin, detected a ransomware event in October 2023. The attacker encrypted data and demanded a ransom, and the exposed data was a high-severity mix: names, Social Security numbers, passport numbers, driver’s licenses, financial accounts, and health information. The practice notified 228,287 people, the class-action settlement class was defined as 159,145 individuals, and First Choice agreed to a settlement valued at up to $1,225,000.
Two failures stand out, and both are about process rather than the hack itself. Notifications did not go out until roughly nine months after the attack, well past the 60-day window HIPAA expects. And the practice reported only an interim count of 1,000 individuals to federal regulators, a figure the official breach portal was never updated to correct. The lesson is that your incident-response and notification playbook is part of your security posture, not an afterthought once the technical fire is out.
11. Chord Specialty Dental Partners: 173,000 Records (2025)
Chord Specialty Dental Partners, a Tennessee-based DSO supporting more than 60 affiliated practices across six states, suffered an email-account compromise that exposed 173,430 individuals. Attackers had access to several employee mailboxes for more than five weeks before being caught, and the data in those inboxes included Social Security numbers, driver’s licenses, bank and payment-card details, and medical information. The breach triggered at least seven class-action lawsuits.
The pattern repeats: PHI accumulating in email, an account takeover that went undetected for weeks, and a long gap before patients were notified. The defense is the same playbook that would have helped Park Dental and the other email-compromise victims on this list: phishing-resistant MFA on every mailbox, anomalous-login alerting so an intrusion is caught in hours, and a hard rule that sensitive data does not live in inboxes. Our Chord Specialty Dental Partners data breach analysis lays out the four questions to put to your IT provider about mailbox security.
12. Professional Dental Alliance: 173,000 Records (2021)
Professional Dental Alliance was breached through its management and IT vendor, North American Dental Management. Attackers sent phishing emails to the vendor’s employees, several of whom handed over their credentials, and those harvested logins opened a few of the vendor’s email accounts holding patient data for affiliated practices across 10 states. The cascade reached 172,933 individuals in total across those affiliated practices, with Social Security numbers and financial accounts among the exposed data.
This is the business-associate version of the MSP problem. One vendor compromise exposed every affiliated practice at once. The lesson is that vendor risk management is patient-data security: a business associate’s email defenses, MFA, and phishing training are effectively your own, and they belong in your risk assessment and your contracts.
13. Henry Schein: 166,000 Records (2023)
Henry Schein, the dental industry’s largest distributor and the company behind widely used practice-management software, was hit by the BlackCat ransomware gang in fall 2023. The gang struck twice. The first attack came around October 14 and 15, 2023, and the attackers claimed to have stolen around 35TB of data, a figure Henry Schein never confirmed. Then on November 22, while restoration was underway and ransom negotiations were breaking down, they re-encrypted the company’s systems a second time and threatened a third. The final count was 166,432 individuals, revised up from an initial 29,112. Henry Schein reached a $2.9 million class-action settlement.
The second encryption is the lesson most organizations miss. Backups are necessary but not sufficient. Henry Schein began restoring while the attacker still had access, so the environment was re-compromised before it was confirmed clean. Recovery has to happen in an isolated, verified-clean environment, and your largest vendors are single points of failure whose outages can freeze ordering and software for practices nationwide.
The Most Common Threats Dental Practices and DSOs Face Today
Read these cases back to back and the same handful of attack patterns appear again and again. These are the threats to plan for now.
Ransomware and data-theft extortion. Gangs like LockBit and BlackCat encrypt systems and leak stolen data to force payment. Dental practices are attractive because encrypted systems halt scheduling, billing, and care across every location at once. The defense is immutable, offline backups tested with real restore drills, endpoint detection on every device, and network segmentation so one practice’s breach cannot reach the whole group.
Supply-chain and shared-software exploits. The Delta Dental of California breach came through a zero-day in a vendor’s file-transfer tool, not through Delta Dental’s own systems, and the more recent DentaQuest vendor breach shows the same pattern reaching dental practices through a partner they never directly chose. When the dental sector runs on a small set of shared platforms, one vendor flaw exposes millions. The defense is a vendor inventory and risk register, patch SLAs and breach-notification clauses in contracts, and minimizing the data you share with any third party.
MSP and IT-vendor compromise. Absolute Dental was breached through its own IT provider’s privileged access. Most practices and even mid-size DSOs hand an MSP deep, standing access through legitimate management tools. The defense is least-privilege and just-in-time access for vendors, phishing-resistant MFA on every MSP account, and monitoring of remote-management tool usage.
Business email compromise. Park Dental, Chord, and Professional Dental Alliance were all breached through hijacked mailboxes full of patient data. The defense is phishing-resistant MFA instead of push-prompt MFA that gets fatigue-approved, conditional access rules, mailbox anomaly alerting, and a discipline of never letting PHI accumulate in email.
Phishing and credential theft. This is the entry point feeding nearly every breach above. Stolen credentials let an attacker log in as a trusted user and operate undetected in an environment that has no security team watching. The defense is MFA everywhere, recurring phishing simulations, and an email gateway that detonates links and attachments before they reach staff.
The single pattern underneath all of it: dental organizations are almost never breached through a dramatic frontal assault on hardened systems. They are breached through trusted identities and trusted third parties, a phished login or a compromised vendor, after which the attacker quietly reaches a large hoard of long-retained patient data. For a DSO, centralization multiplies the damage, because one compromised identity or vendor scales across every practice at once. That is why so many of the names above are multi-location groups and management companies rather than single chairs.
What This Means for Your Practice or Group
None of the defenses these breaches point to are exotic. The baseline is consistent across every case: phishing-resistant multifactor authentication, endpoint detection and response on every device, identity governance inside your Microsoft 365 or Google Workspace tenant, immutable and tested backups, a vendor risk register, data minimization so you are not hoarding records you no longer need, and an incident-response plan you have actually rehearsed. Microsoft Research, studying accounts that showed suspicious activity, found that multifactor authentication reduced the risk of account compromise by 99.22% across that population, and by 98.56% in cases where credentials had already leaked. Most of the breaches above involved an identity that was not protected by it well enough. The financial stakes are not abstract either. IBM’s 2026 Cost of a Data Breach report put the average healthcare breach at $6.64 million, down from $7.42 million the year before. The figure fell, but healthcare still carries the highest breach costs of any industry, and it has held that spot for thirteen straight years.
One question we get constantly right now is whether to wait for the new HIPAA Security Rule before investing in any of this. The short answer is no. The proposed update, which would make several controls that are currently “addressable” into explicit requirements, including MFA, encryption, and asset inventories, was published in the Federal Register on January 6, 2025. The comment period closed that March with roughly 4,700 comments, OCR’s own target of a May 2026 final rule passed with nothing published, and the federal regulatory agenda now points to 2027. There is no final rule, and OCR has not confirmed whether the proposal will reach one in its current form.
That timeline is easy to misread as breathing room. It is not. The existing Security Rule is fully in force and OCR is actively enforcing it, and every control in the proposal is already what we would put in front of a client as a reasonable security program. Practices and groups that build toward it now are not gambling on a rule that may change. They are closing the same gaps that produced every breach on this list.
The same threats show up in the everyday attacks that never make headlines, which we cover in the common IT scams dental practices must avoid and in how AI is reshaping dental cybersecurity threats. The recovery half of the equation, the part that decides whether a breach is a bad week or a closed practice, lives in dental data backup and disaster recovery.
Final Thoughts from Tom Terronez
Every breach on this list looks obvious in hindsight, and almost none of them required a sophisticated attack. A phished password, an over-trusted IT vendor, patient data left sitting in an inbox. The organizations that get hurt are rarely the ones that did something exotic wrong. They are the ones that treated cybersecurity as antivirus plus a checkbox instead of a real program, and then learned the difference during an incident.
If you want an honest read on where your practice or group actually stands against these patterns, our team runs HIPAA cybersecurity assessments and managed IT support for dental service organizations against exactly this baseline. If you want a second set of eyes before something forces the conversation, happy to compare notes.
Biggest Dental Data Breaches FAQs
What was the biggest dental data breach ever?
Two incidents sit at roughly 15 million people, and which one ranks first depends on figures that are still moving. The MMG Fusion breach exposed the protected health information of roughly 15 million dental patients after a software vendor’s network was accessed in December 2020, a breach the company then failed to report for more than two years, and it is the largest dental-sector breach confirmed in a federal enforcement action. The 2026 DentaQuest breach is comparable in scale: the ShinyHunters extortion group published roughly 234GB of stolen data, and DentaQuest has confirmed at least 15 million individuals affected, with notification letters going out from July 17, 2026. Its final federal figure has not yet been published, and an independent analysis of the leaked files suggests the true number could be higher. After those two, the largest is the 2023 MCNA Dental ransomware attack at 8,923,662 individuals, followed by Delta Dental of California at 6,928,932 through the MOVEit supply-chain attack the same year.
What is the largest healthcare data breach in history?
The largest healthcare data breach on record is the 2024 ransomware attack on Change Healthcare, which affected roughly 192.7 million individuals, according to HIPAA Journal’s running tally of federal breach reports. Anthem’s 2015 breach at 78.8 million is second, followed by Conduent Business Services at 62.2 million in 2025. No dental-sector breach reaches those totals, because the largest counts come from clearinghouses and national insurers that touch nearly every patient in the country. The dental figures still belong in that conversation, though. At the confirmed 15 million, the largest dental breaches would rank around fourth or fifth on that all-time list, ahead of well-known incidents at Kaiser, HCA Healthcare, and Premera Blue Cross. If DentaQuest’s final federal count lands nearer the 23 million an independent analysis suggests, it would rank third.
How do most dental data breaches actually happen?
Rarely through a direct hack of hardened systems. The breaches on this list overwhelmingly started with a trusted identity or a trusted third party: phished or stolen credentials (often bypassing weak MFA), a compromised IT vendor with standing privileged access, or a zero-day in shared vendor software. The attacker logs in as someone legitimate, then reaches a large store of patient data that was retained longer and protected less than it should have been.
Are small dental practices targets, or just large groups and insurers?
Both. Large groups and insurers produce the biggest headline counts because they aggregate the most data, but small practices are breached constantly through the same phishing and vendor-compromise routes. Westend Dental, an Indianapolis practice hit by MedusaLocker ransomware in 2020, concealed the incident, telling state investigators it was an accidental hard-disk format rather than an attack, and was fined $350,000 by the Indiana Attorney General in a 2025 consent order. The cover-up, not the breach itself, drove the penalty. Size determines the headline number, not the risk of being hit.
What is the single most effective defense against these breaches?
Phishing-resistant multifactor authentication on every account, because compromised identities are the common thread. Microsoft Research measured MFA reducing the risk of account compromise by 99.22% across the population it studied, and by 98.56% where credentials had already leaked. It is not the only control you need, but most of the breaches above involved an identity that MFA, properly implemented, would have protected. Pair it with endpoint detection, immutable backups, and vendor access controls for a real program.
Posted in Dental Cybersecurity