Dark dental office with monitors showing a vendor supply-chain network with one compromised node and security alerts

Sometimes the breach is not your fault. The fine still can be.

The Delta Dental data breach exposed nearly 6.93 million people through a flaw that was never Delta Dental’s to fix. The company was one of thousands of organizations caught in the 2023 MOVEit mass-hack, a supply-chain attack that exploited a vendor’s software before a patch existed. Delta Dental of California could not have patched that hole. And yet, three years later, two affiliated Delta Dental entities agreed to a $2.25 million penalty with New York’s financial regulator, not for the vulnerability, but for how the organization responded to it. That distinction is the most important lesson in this entire breach, and it applies directly to every dental practice and DSO that relies on outside vendors.

What happened in the Delta Dental breach

In late May 2023, the Clop ransomware group exploited a zero-day vulnerability in Progress Software’s MOVEit Transfer, a widely used file-transfer tool, before Progress knew the flaw existed. Over a window of roughly May 27 to 30, the attackers exfiltrated data from thousands of organizations that ran the software. According to SecurityWeek, Delta Dental of California and its affiliates were among the victims, with nearly 6.93 million individuals exposed.

The exposed data was severe: names, addresses, Social Security numbers, financial account numbers, and passport numbers. The technical fault was entirely the vendor’s. But the follow-up was where Delta Dental’s own decisions came into play, and where a financial regulator later found real problems.

Why you inherit your vendor’s risk

Here is the part that should stop every practice owner and DSO leader cold. In April 2026, the New York Department of Financial Services announced that Delta Dental Insurance Company and Delta Dental of New York agreed to a $2.25 million penalty over their handling of the breach. The regulator did not fault them for the MOVEit zero-day. It faulted them for three things they controlled entirely.

First, the organization had no written incident-response plan when the breach hit. Second, it had extended the default retention setting in MOVEit, keeping exfiltrated files sitting in the tool for longer than 30 days, which meant more data was exposed than needed to be. Third, it was slow to notify. New York’s rules require notification within 72 hours. The webshell the attackers planted was identified on June 1, 2023, and the regulator was not told until December 15, 2023, roughly six months later. None of those failures were technical. They were governance, and they are exactly the failures that turn a breach you did not cause into a fine you have to pay.

This is the reality of the modern dental data supply chain. Your patient data flows to your clearinghouse, your insurance administrators, your file-transfer tools, and your analytics platforms. You cannot audit every one of their codebases or patch their zero-days. But you can control what you hand them, how long they keep it, and how fast you react when one of them fails. Regulators know you cannot prevent every vendor flaw. They will still hold you accountable for the parts you could have handled.

What dental practices and DSOs should do now

You cannot stop the next MOVEit. But you can build the posture that keeps a vendor’s breach from becoming your regulatory problem. Start with the parts a regulator will actually hold you to:

  • Keep a vendor inventory and a signed agreement for each one. List every platform and integration that can touch patient data, and confirm there is a current business associate agreement in place. You cannot manage risk from vendors you have never mapped.
  • Minimize the data you share and how long anyone keeps it. Delta Dental’s penalty grew partly because files sat in a transfer tool longer than they needed to. Send vendors only what they require, and confirm retention settings delete data on a schedule instead of hoarding it.
  • Write your incident-response plan before you need it. The single cleanest lesson here is that Delta Dental had no written plan. Know in advance who gets called, who notifies regulators and patients, and on what clock. A breach is the worst time to be improvising the response.
  • Know every notification clock that applies to you. HIPAA is not the only rule. Depending on your structure and states, a financial or state regulator may impose a far shorter deadline, as New York’s 72-hour rule shows. Missing a notification window is its own violation, separate from the breach.

The vendor caused the breach. You own the response.

Delta Dental was not careless with a password here. It was one of thousands of downstream victims of a vendor’s zero-day, and that is precisely why this case is worth studying. The exposure flows to organizations that never chose the breached vendor’s security. We saw the same shape in the DentaQuest breach, and it runs through most of the biggest dental data breaches on record. For DSOs the exposure multiplies, because every unstandardized vendor relationship across every location is another link in the chain, and a buyer doing IT due diligence before an acquisition will treat weak vendor governance as a priced risk.

So separate the two things that got tangled in the headlines. The vulnerability was not Delta Dental’s to prevent. The missing incident-response plan, the over-retained files, and the six-month notification delay were entirely its own, and those are what cost $2.25 million. A vendor’s “HIPAA compliant” sales page never governs any of them. You do.

That is the work we do for the dental groups and DSOs we protect at Medix Dental IT. We map every vendor and integration that can reach your patient data, tighten retention and access so a third-party leak exposes as little as possible, and build the incident-response readiness that keeps a vendor breach from turning into your fine. If a MOVEit-style incident hit one of your vendors tomorrow, would you know within 72 hours, and could you prove you were ready? A cybersecurity assessment answers both. Prevention is always cheaper than panic.

Posted in Dental Cybersecurity, News

Filter By: