August 6th, 2026
MCNA Dental Data Breach: What It Means for Dental Practices
Industry Research — Dental Cybersecurity, News
Nine million people is not a rounding error. It is a warning about how these attacks actually work.
The MCNA Dental data breach exposed the personal and health information of 8,923,662 people, making it one of the largest breaches in the history of the dental sector. MCNA is not a dental practice. It is one of the largest administrators of government-sponsored Medicaid and CHIP dental benefits in the country, holding identity data for millions of patients, many of them children, in one place. When a ransomware crew got in, they did not smash through a hardened front door. They logged in, moved quietly for over a week, and copied hundreds of gigabytes out before anyone noticed. That gap between getting in and getting caught is the whole story, and it is the part every dental practice and DSO should learn from.
What happened in the MCNA Dental breach
According to reporting from TechCrunch, the LockBit ransomware gang gained access to MCNA’s network on February 26, 2023. The intrusion was not discovered until March 6, roughly a week and a half later. In that window, the attackers reached a large store of patient data and exfiltrated it. LockBit later claimed on its leak site to have taken around 700GB of data and demanded a $10 million ransom.
MCNA did not pay. On April 7, 2023, LockBit published the entire stolen dataset, as BleepingComputer documented from the company’s own notice. The company completed its forensic review in early May and began notifying the 8,923,662 affected individuals, along with their parents, guardians, and guarantors, at the end of that month. The exposed data was a full identity-theft kit: names, addresses, dates of birth, phone numbers, email addresses, Social Security numbers, driver’s license and government ID numbers, Medicaid and Medicare ID numbers, health insurance details, and dental treatment records. Healthplex, Inc. was later named as a co-defendant in the class action that followed. It stands as one of the largest healthcare breaches disclosed in 2023.
Why dwell time is the number that matters
Here is the detail most of the coverage skips past. The attackers were inside MCNA’s network for roughly a week and a half before anyone knew. Security teams call that dwell time, the stretch between initial access and detection, and it is where breaches are won or lost. A login by itself does not leak nine million records. What leaks nine million records is a week of undetected movement, during which an intruder maps the network, finds the largest store of data, and quietly copies hundreds of gigabytes out the door.
Nobody watching meant nobody saw the bulk transfer. Moving 700GB is not subtle if a system is actually looking for it. That volume of data leaving the network should have tripped an alarm on day one, not gone unnoticed for over a week. The uncomfortable truth is that most dental organizations have no system watching for this at all. They have antivirus on the endpoints and a firewall at the edge, and they assume that is a security program. It is not. Neither of those tools is designed to flag an attacker who is already inside, using valid credentials, slowly draining a database.
What dental practices and DSOs should do now
You cannot fix MCNA’s network. But you can make sure your own organization shrinks dwell time from weeks to hours, so a single foothold never becomes a nine-million-record headline. Four moves do most of the work:
- Put detection on every endpoint, not just antivirus. Endpoint detection and response watches for what an intruder does after they are already in, lateral movement between machines, privilege escalation, and unusual bulk transfers. That is what turns a ten-day silence into a same-day alert. Antivirus looks for known malware and misses an attacker using a valid login entirely.
- Alarm on bulk data leaving the network. Seven hundred gigabytes walking out the door is the single loudest signal an attack gives you, and at MCNA nothing heard it. Alerting on abnormal outbound volume is one of the cheapest ways to catch exfiltration while it is happening instead of reading about it on a leak site.
- Have someone actually watching the alerts. Detection tools only shrink dwell time if a human or a monitored service responds when they fire. A tool nobody is watching produces a report after the breach, not a stop during it. This is the gap most dental organizations do not know they have until it is too late.
- Rehearse how fast you can respond. Speed after detection is the other half of dwell time. Know in advance who isolates a compromised machine, who cuts off the account, and how quickly, so the window between the first alert and containment is measured in minutes rather than the week MCNA lost.
Detection is the control that was missing
MCNA is a large administrator, but the mechanics are the same ones that play out across dentistry every month. We see smaller versions of it constantly in the practices we protect, and they run through the biggest dental data breaches on record, from the DentaQuest extortion breach to the everyday attacks that never make headlines. An attacker gets in through a trusted login, then works undetected because nothing is watching. For a DSO that undetected foothold is worse, because it scales across every location and every centralized system at once.
The question to ask is not “do we own security tools.” It is “would anyone here notice an intruder on day three.” MCNA had tools. What it did not have was something watching for an attacker already inside, moving between systems and draining a database. Antivirus and a firewall do not answer that question. Detection does.
That is the work we do for the dental groups and DSOs we protect at Medix Dental IT. We put detection on every endpoint, monitor for the lateral movement and data exfiltration that turn a foothold into a catastrophe, and keep dwell time measured in hours instead of weeks. If you have ever wondered how long an intruder could move inside your network before anyone noticed, that is the number a cybersecurity assessment answers. Better to learn it from us than from a leak site.
Posted in Dental Cybersecurity, News