MEDIUMRegulatoryTier 1

California dental office hit with data breach affecting more than 6,600 individuals

SourceBecker's Dental + DSO ReviewTier 1Hard News

By Ariana Portalatin

Originally at beckersdental.com

Summary & scoring by The Bell Brief (Dr. Jennifer Bell) using the Drill-Down Protocol (Drill-Down Score) — not the original publisher.

Why it matters for dental

Dental practices face immediate HIPAA enforcement risk and potential state AG action after a California solo practice exposed 6,658 patients’ PHI, reminding owners and DSOs that even small clinics are targets and must maintain current breach protocols or risk license-level penalties.

Key points

  • Breach discovered 2 Sept 2024; notifications mailed starting July 2025—nearly 10-month delay triggers mandatory HHS-OCR investigation.
  • Affected practice is a single-location, non-DSO office in Crescent City, CA, proving small practices remain high-value targets for ransomware or insider incidents.
  • OCR portal listing automatically flags the practice for federal audits and possible civil monetary penalties of $100–$50,000 per violation tier.
  • State AG may levy separate CCPA/CPRA fines up to $7,500 per affected California resident for failure to secure ePHI.

Who should care

OwnerDSOStaff

Read the original on Becker's Dental + DSO Review

Full reporting and any paywall content live on beckersdental.com. We summarize and score; we do not republish.

Open original

Related