Dark dental office with a monitor showing a US map of connected practice locations radiating from one red central hub

One break-in in 2023. Two hundred and forty-six practices exposed at once.

The Great Expressions data breach exposed 1,925,397 people through a single intrusion into one DSO’s network, and that is exactly what makes it worth studying. Great Expressions Dental Centers is a dental support organization that, at the time of the breach, ran around 246 practices across nine states. When attackers got into its systems for six days in early 2023, they did not have to breach 246 practices one at a time. They breached one centralized network and reached the patient records of nearly two million people. That is the double edge of the DSO model, and understanding it is the difference between scaling safely and scaling a single point of catastrophic failure.

What happened in the Great Expressions breach

According to BankInfoSecurity, attackers had access to Great Expressions’ IT systems over a roughly six-day window, from about February 17 to 22, 2023. In that time they reached a broad set of patient data and exfiltrated it. The organization began notifying affected individuals in May 2023, and reported the incident to federal regulators as a hacking event affecting 1,925,397 people.

The exposed data was extensive: names, dates of birth, addresses, driver’s license numbers, Social Security numbers, financial account and payment card information, health insurance details, and clinical records including diagnoses, prescriptions, treatment information, and x-ray images. Great Expressions later settled a class action for $2.7 million in the U.S. District Court for the Eastern District of Michigan. The primary sources do not disclose how the attackers first got in, so the exact entry point is not public.

Why centralization is a strength and a target

Here is the part every DSO leader needs to sit with. The entire operational case for a dental support organization is centralization. One platform, one set of standards, one team supporting many locations. That is what makes a DSO efficient. It is also what makes it a bigger prize. The same centralized systems that let you run 246 practices from a shared backbone mean that a single successful intrusion exposes all 246 practices’ patients at once.

A solo practice that gets breached exposes one office. A DSO that gets breached exposes everyone. Risk does not add up across your locations, it concentrates into the shared systems that hold everything. That concentration is the whole lesson: when 246 practices feed one backbone, that backbone is the crown jewel, and it has to be defended like one. The six-day access window is a reminder that a repository this large needs to be watched constantly, because on a data store holding two million records, the difference between a contained incident and a catastrophe is how fast anyone notices.

What DSOs and multi-location groups should do now

You cannot un-centralize a DSO, and you should not want to. But you can make sure centralization does not mean a single foothold reaches everything. These are the controls that separate the two:

  • Segment so one compromised location cannot reach the others. Centralized does not have to mean flat. If breaching one practice’s machine opens a path to all 246, the network is one flat target wearing a DSO’s name. Access boundaries between locations are what keep a single foothold from becoming a group-wide breach.
  • Guard the shared backbone like the crown jewel it is. The systems that let you run many practices from one platform hold everyone’s data at once, so they deserve stronger controls than any single location would get on its own. The more a system aggregates, the more monitoring and access restriction it has earned.
  • Enforce one security baseline, not per-location drift. Most DSOs standardize scheduling and billing but let each office’s security run on its own habits. One enforced baseline across every practice closes the weak-link problem where the least-protected location becomes the way into the whole group.
  • Do not let every location’s most sensitive data pool in one reachable place. This breach was severe because Social Security numbers, financial data, and full clinical records for two million people sat together. Separating and archiving the most sensitive fields means one compromised system does not hand over everything the group has ever collected.

Scale multiplies the damage

Great Expressions is a large group, but the lesson repeats at every scale. Centralization concentrates risk, and it shows up throughout the biggest dental data breaches on record, from vendor-driven incidents like the DentaQuest breach to the DSO intrusions that expose hundreds of practices in one shot. What ties them together is an enormous store of data behind defenses built for something much smaller, run by a group that standardized its operations but never standardized its security.

The mindset that closes the gap is treating security as core infrastructure, the same way you treat the practice management system every location depends on. A shared backbone without segmentation is a shared liability. The protection that matches the scale is one baseline across every location, active monitoring on the systems that hold the most, and architecture that stops a single foothold from reaching all of it.

That is the work we do for the dental groups and DSOs we protect at Medix Dental IT. We build one enterprise-grade security baseline across every location, monitor for the lateral movement that turns a single foothold into a group-wide breach, and architect the segmentation that keeps two million records from sitting behind one compromised login. If an attacker got into one of your locations tonight, how many of the others could they reach? A cybersecurity assessment gives you the real answer. Prevention is always cheaper than panic.

Posted in Dental Cybersecurity, News

Filter By: