September 23rd, 2026
Hawaii Family Dental Data Breach: What It Means for Dental Practices
Industry Research — Dental Cybersecurity, News
Another dental breach hit the news feeds this month, and the coverage of it is worth a closer look than the incident itself.
A dental group on four Hawaiian islands was broken into through a single account, and shut that account down the same day it was found. That is a different kind of breach story than the one currently circulating about it.
On July 20, 2026, Hawaii Family Dental discovered that an unauthorized person had used a compromised account to reach patient information on July 19 and 20. The group, which runs 12 offices across Oahu, Maui, Kauai and the Big Island, has published its own notice describing what happened, and in a public statement dated August 26 it says the affected account was secured the same day it was discovered.
Separately, the Qilin ransomware group listed Hawaii Family Dental on its leak site on July 31 and claimed it had taken data. Those are two different accounts of the same incident, and keeping them apart is most of the work here.
The short answer: Hawaii Family Dental has confirmed a cyberattack. Its notice says an unauthorized person used a compromised account on July 19 and 20, 2026, that the information involved included names, dates of birth, contact details, dental insurance information and portions of medical and dental treatment information, and that Social Security numbers and financial account information were not involved. It says it has no evidence any information has been misused. A ransomware group separately claimed the attack on its leak site and that claim has not been independently verified. For a practice reading this, the useful detail is the entry point: one account, not a wall breached.
What the practice has actually said
The notice is short and specific, which is more than most breach statements manage. It is worth reading the wording rather than a summary of it.
On what happened: “On July 20, 2026, we discovered that an unauthorized person had used a compromised account to access patient information on July 19 and 20, 2026.” The notice goes on to say the practice “immediately took steps to secure our network and launched an investigation,” and that through that investigation “we determined that we experienced a cyberattack in which a threat actor may have had access to certain systems that stored patient information.” It adds: “We have no evidence that any information has been misused.”
On what was involved: “name, date of birth, phone number, email address, mailing address, dental insurance information, and portions of medical and dental treatment information.” And then the sentence that separates this from most breaches of its size: “Social Security numbers and financial account information were not involved.”
The August 26 public statement adds a detail the website notice leaves out, and it is the one worth noticing. “The affected account was secured the same day, and the IT and security team was engaged to investigate what happened and identify affected individuals.”
Same-day containment on a two-day intrusion is a good outcome. It is worth saying so plainly, because breach coverage rarely does.
What the attacker claimed, and why it reads differently
On July 31, roughly eleven days after the practice discovered the intrusion, the Qilin ransomware group posted Hawaii Family Dental on its leak site and claimed it held the group’s data. Threat trackers indexed the listing, and plaintiff firms opened investigations off the back of it.
Hold the two accounts side by side and they are describing different things. The practice describes unauthorized access through one compromised account over two days, contained on discovery. The leak site describes stolen data and a threat to publish. Both can be true at once. Neither has been independently verified against the other, and the practice has not commented on the group’s specific claims.
There is a practical wrinkle here worth knowing about, and it is one any practice could repeat. The notice page carries a noindex tag, which tells search engines not to list it. So the practice published a clear, accurate statement that search engines are instructed to ignore, while tracker and law firm pages written before that statement existed rank freely. Checked on September 11, 2026, Google’s AI Overview for this incident still described the breach as not officially confirmed.

That is worth sitting with, because it points at a gap most incident response plans have. Breach response has a technical half and a public-record half. This practice did the technical half well, contained the account the day it was found, and then lost the public-record half by default, to a meta tag nobody thought about. Weeks later the version of events that ranks is the one written before the practice spoke.
Your plan almost certainly covers the first half. Check whether it covers the second. A notice nobody can find does not correct the record.
Where the 45,853 figure comes from
You will see 45,853 patients attached to this incident. That figure comes from breach trackers and law-firm pages reporting a filing with the federal breach portal on August 21, not from anything Hawaii Family Dental has published. Its notice states no count at all.
Notification filings and public notices routinely carry different levels of detail, and a federal breach report is a legitimate source. The accurate way to say it is that the figure comes from a regulatory filing rather than from the practice’s public notice, which states no number.
As of September 11, 2026, the incident does not appear on Hawaii’s state breach notice list, published by the Department of Commerce and Consumer Affairs, though the practice says it has “notified the appropriate regulatory authorities as required by law.” Read that as a gap in the state list rather than a contradiction: the most recent entry on it is dated April 2024, so it does not appear to be a current record of what has been reported.
One compromised account is the whole story
Here is why this incident is worth a dental operator’s attention even though the data involved was comparatively limited.
The entry point was an account. Not an unpatched server, not a vendor, not a sophisticated intrusion chain anybody would need a security budget to stop. Somebody got hold of working credentials and used them, and it took a day to be noticed.
Account takeover is the failure mode we see most often in the dental groups we work with, and it is the one most reachable by ordinary controls. Multi-factor authentication on that account changes the odds considerably. So does alerting on a sign-in from an unusual location, or on an account suddenly reading far more records than its job requires.
The counterpoint is equally worth stating. This practice found it in a day and shut that account down the same day. Plenty of organizations would not have noticed for weeks, and dwell time is most of what separates a contained incident from a costly one. Somebody was watching. That part they got right.
What a dental practice or DSO should do about this
Each item below is worth doing regardless of how this particular incident resolves. That is the test we apply to any breach in the news.
1. Require MFA on every account that can reach patient data
Not enabled. Required. Check whether exceptions exist for service accounts, shared front-desk logins, remote access or payer portals, because that is where exceptions get granted and then forgotten. A single account that can reach patient records without a second factor is the exact shape of this incident.
2. Kill the shared logins
When we assess a practice we usually find at least one account that several people use. It cannot be attributed to a person, it is nearly useless in a log, it rarely gets disabled when someone leaves, and its password tends to be years old. Individual accounts per person are the fix. Where a system genuinely cannot do that, the compensating control is tighter monitoring on the account that remains shared.
3. Turn on alerting that a person actually reads
Impossible-travel sign-ins, logins at hours nobody works, new mailbox forwarding rules, bulk record access. These alerts exist in Microsoft 365 and most practice management platforms. The question is not whether they are available but whether they arrive somewhere a human sees them the same day.
4. Know what one account can actually reach
If a front desk login at one location is compromised, can it read patient records at the other eleven? For a multi-location group that is the question that decides whether an incident is local or organization-wide. Scope access by role and by location.
5. Rehearse the first day
This practice secured the account on the day it was found. That is what a prepared response looks like. Know now who has authority to disable an account immediately, who calls the forensics firm, who tells patients, and where the cyber insurance policy is.
6. Warn the front desk about the follow-on calls
Even without Social Security numbers, an attacker holding names, dates of birth, insurance details and treatment information can make a very convincing phone call. Tell your team that a caller knowing a patient’s details does not make them legitimate, and that the practice will never ask for a Social Security number or payment information by phone or email.
Hawaii Family Dental Data Breach FAQs
Has Hawaii Family Dental confirmed a data breach?
Yes. Its published notice says it discovered on July 20, 2026 that an unauthorized person had used a compromised account to access patient information on July 19 and 20, and that it “experienced a cyberattack in which a threat actor may have had access to certain systems that stored patient information.” It says it is notifying affected patients directly and has notified regulators. Some search results and summaries still describe the incident as unconfirmed, partly because the practice’s notice page is tagged noindex and search engines are told not to list it.
What information was involved in the Hawaii Family Dental breach?
According to the practice’s notice: name, date of birth, phone number, email address, mailing address, dental insurance information, and portions of medical and dental treatment information. The notice states that Social Security numbers and financial account information were not involved, and that there is no evidence any information has been misused.
How many patients were affected?
Hawaii Family Dental’s own notice does not state a number. Breach trackers and law firm pages report 45,853 individuals based on a federal breach portal filing dated August 21, 2026. Treat that as a figure from a regulatory filing rather than one the practice has published.
Was this a ransomware attack?
The Qilin ransomware group listed Hawaii Family Dental on its leak site on July 31, 2026 and claimed to hold its data. The practice’s own notice describes a cyberattack involving a compromised account and does not name an attacker, mention encryption, or mention a ransom demand. The attacker’s claim has not been independently verified. Both accounts can be accurate at once, and they describe different aspects of the same incident.
Does this affect my practice if I am not a Hawaii Family Dental patient?
Not directly. Hawaii Family Dental treats its own patients rather than acting as a vendor to other dental offices, so unlike a billing company or clearinghouse breach there is no vendor chain reaching into unrelated practices. The reason to read it is the entry point, which is the most common one in dentistry.
What should a patient of the practice do?
Watch for phishing calls, emails and texts that reference dental care, and verify anyone making unexpected contact by calling the practice directly on a number you already have. The practice’s notice says it will never ask for a Social Security number, payment information or passwords by phone, email or text, and it has published a dedicated assistance line for questions.
What does this mean for our own security review?
Treat it as a prompt to check one specific thing rather than everything: whether any account at your practice can reach patient data with a password alone. That single question covers the failure mode in this incident, and most practices find at least one exception when they look honestly.
The pattern behind this one
We have written about the biggest dental data breaches on record, and about the eAssist situation facing practices that use outsourced billing. Most of the large ones are vendor and payer incidents. This one is smaller and more ordinary, and that is exactly why it is worth reading.
The incidents we get called into are rarely sophisticated. They usually start the way this one did, with a working login that should have had a second factor on it. The controls that stop that are unglamorous and mostly sitting unused in systems practices already pay for.
If you want a second set of eyes on which accounts at your group can reach patient data without MFA, that is the kind of thing we check at Medix Dental IT. A cybersecurity assessment is the place to start, and our dental office cybersecurity checklist covers the controls we look at first. If something has already happened, what to do after a breach walks through the sequence, and what HIPAA breach notification actually requires covers the deadlines.
Posted in Dental Cybersecurity, News