The breach impacted approximately 45,800, reminding healthcare organizations that ransomware attacks can happen to practices of any size.
What happened
This month, Hawaii Family Dental (HFD), a 12-office practice, began notifying the public of a data breach stemming from a compromised account.
According to the notice, suspicious activity was first discovered on July 20th, 2026, when HFD discovered that an unauthorized individual had used a compromised account to access patient information between July 19th and July 20th. Following the discovery, the practice launched an investigation which determined that they had experienced a cyberattack. Currently, HFD does not have any evidence that stolen data has been misused.
Going deeper
According to the notice, accessed information included names, dates of birth, phone numbers, email addresses, mailing addresses, dental insurance information, and some medical and dental treatment information. No Social Security numbers or financial account information were involved. According to their report to the Department of Health and Human Services (HHS), the data breach impacted approximately 45,853 individuals.
In the know
While HFD has not stated the incident was a ransomware attack, it has been claimed by long-standing threat group Qilin, a group that is notorious for their double extortion practices. Under this strategy, threat groups make data inaccessible through encryption while simultaneously stealing it. They then demand payment for a decryptor tool and to release stolen data. Groups generally threaten to sell or leak the data if the ransom is not paid.
Qilin was first observed in 2022, but they’ve now amassed approximately 2311 victims. The group is largely driven by opportunity, meaning that they attack groups based on perceived vulnerability and ease, rather than selecting specific targets. Groups like these tend to attack smaller organizations or those that use outdated systems, defying the common notion that smaller organizations are safer because they draw less attention.
Qilin has posted a leak notice for HFD, which includes a small amount of the stolen data that is provided to verify their claim.
What’s next
In response to the attack, HFD has said they are committed to enhancing their “data privacy and security safeguards to reduce the likelihood of a similar event.” They have begun notifying impacted patients. No lawsuit has been filed yet, but multiple firms claim to be investigating the incident for a potential class action suit. While it’s highly likely HFD will face a lawsuit, if no financial information or Social Security numbers were involved, they may see a smaller settlement cost, if they choose mediation. It’s unclear if a ransom has been demanded by Qilin, or if HFD is engaging in any negotiations.
The big picture
According to a Paubox article, approximately 60% of physicians work in a small practice, but it doesn’t make them any less vulnerable. In fact, dental practices have been a significant target for ransomware gangs. The HHS is currently investigating three dental breaches that have occurred within the last three months, which doesn’t include investigations that are now over or ones that have yet to be announced. Dental practices are not necessarily more prone to breaches than other health practices, but they tend to store highly valued data without robust IT systems, which can make attacks more successful. The American Dental Association (ADA) provides specific guidelines for practices following a data breach, which includes implementing dental-specific safeguards and conducting risk assessments.
In 2023 the largest data breach of the year took place at dental insurer MCNA, impacting approximately 5 million individuals. While the breach at HFD is small in comparison, it shows that dental practices of every size need to closely monitor their systems and maintain strict security standards.
FAQs
Does it mean data is safe if an organization has “no evidence that any information has been misused?”
No, while it’s a good sign that there is no evidence data has been misused, it’s almost impossible to know what exactly happens to data once it is compromised. It could be on the dark web, already available, or waiting to be sold.
What exactly was compromised?
HFD said an account was compromised, which could refer to different accounts the practice uses. However, many breaches stem from email accounts because they can be an easy vector, allowing the threat actor to send a malicious email and providing the opportunity for an employee to unknowingly click a link or download a file.
Is it possible HFD won’t face a lawsuit following the breach?
It’s always possible, but it’s become very common for healthcare practices to face data breaches following an incident, even if the breach only involved a limited amount of data.
