Skip to content
Hipsana

Articles / If something happened

Dental HIPAA Breach and Enforcement Report (2026)

The largest known exposure of dental patients' data, an estimated 15 million people, never appeared on the public breach list at all. It surfaced only in 2026, when federal regulators settled with the dental-software vendor that lost the data in 2020 and never reported the loss. The largest breach a dental provider actually reported is smaller and better known: the 2023 ransomware attack on MCNA Dental, which exposed 8.9 million people. Both numbers point the same way. Dental data rarely leaks because a master hacker beat a hardened wall. It leaks through an ordinary failure: a compromised login, a compromised vendor, ransomware behind one of them. And the failure regulators punish afterward is rarely the breach itself. It is the one document underneath it that most independent practices begin and never finish. We read the public HHS data so you can see both patterns plainly, and what they mean for a practice your size.

The short answer: the public record tells two stories at once. Dental practices get breached through ordinary failures rather than exotic attacks: ransomware, a compromised inbox, a compromised vendor. And when OCR investigates, it increasingly fines the practice for never having run an accurate, thorough risk analysis, the foundation the entire Security Rule sits on at 45 CFR § 164.308(a)(1)(ii)(A). The breach gets the headlines. The missing risk analysis gets the penalty.

This report explains how dental practices actually get breached and the one failure OCR keeps fining them for. It is general information, not legal advice for your specific situation. For that, consult a healthcare attorney or a qualified HIPAA compliance professional.

Bar chart of four 2024 to 2026 HIPAA settlements under OCR's Risk Analysis Initiative: Health Fitness Corporation $227,816 for a misconfigured server, Top of the World Ranch $103,000 for a phishing email, Bryan County Ambulance Authority $90,000 for ransomware, and MMG Fusion $10,000 for a dental-software breach that exposed patient data and was never reported to the practices it served. The breaches and amounts differ, but OCR's finding in every case was the same: failure to conduct a risk analysis under 45 CFR 164.308(a)(1)(ii)(A).
Selected settlements under OCR's Risk Analysis Initiative, 2024 to 2026: four different triggers, one recurring finding. Source: HHS / OCR settlement announcements.

What this report covers

This is a plain reading of two public datasets that rarely get read together: the breaches healthcare practices report to the federal government, and the settlements the government reaches with them afterward. One shows how patient data actually leaks. The other shows what it costs when regulators get involved, and why. We pointed the lens at dental and small independent practices, because the published numbers say something specific about practices your size, and most summaries miss it.

How dental practices actually get breached

Start with the scale. In 2024, the most recent full year HHS has reported to Congress, it received 742 reports of large breaches, those affecting 500 or more people, with 663 of them for breaches that occurred that year. Across those, the records of more than 242 million individuals were exposed or impermissibly disclosed, an annual record. One incident drove most of it: the ransomware attack on the billing clearinghouse Change Healthcare alone accounted for an estimated 192 million. Hacking and IT incidents were the leading cause by far, 81% of the large breaches that year, and the trend has not reversed: by the HIPAA Journal's running tally of the breach portal, 2025 set a new record, with 772 large breaches reported.

That large-breach list is the part of the iceberg above the water. The same year, HHS received 74,299 reports of breaches affecting fewer than 500 people. Those smaller incidents, the kind a solo practice is far likelier to have, are not posted by name; federal law only requires public listing of the breaches affecting 500 or more. So when you read the named cases below, remember they are the visible minority. Most small-practice breaches never appear with a name attached.

The dental cases, by the numbers

Filter the public breach portal to dental and oral-health organizations and a clear shape appears. The headline numbers come from large dental insurers and software vendors, the entities that hold millions of records at once. The cause, almost every time, is mundane.

Dental organizationYearPeople affectedReported cause
MCNA Dental2023~8.9 millionRansomware (LockBit)
Delta Dental of California2023~6.9 millionVendor / supply chain (MOVEit)
Absolute Dental (NV)2025~1.2 millionCompromised IT-vendor account
First Choice Dental (WI)2023228,287Ransomware
Chord Specialty Dental Partners (DSO)2024173,430Compromised employee email
Delta Dental of Virginia2025145,918Compromised employee email
32 Pearls (WA)202523,517Ransomware
Olde Towne Medical & Dental (VA)20252,567Ransomware
Selected dental-sector breaches, with the cause as reported to regulators or in public breach notices, as of July 2026. The MMG Fusion exposure is discussed below; it never appeared on the public portal. Each figure is the count the organization reported as affected or notified; where the HHS portal shows a different number, the note below the table explains why.

The portal figure is only as current as the last form an organization filed. HHS tells an entity that is unsure of the total at filing to report an estimate and update it later through an addendum. So a portal entry and a later notification letter can disagree. First Choice Dental's entry still shows 1,000, the interim count filed in 2023, while its own notification letters put the figure far higher. Delta Dental of Virginia went the other way, its entry revised down to 126,953, below the 145,918 in its own notices. The figures above are the count each organization reported as affected or notified.

Read down the last column. The biggest dental breach on record, MCNA Dental in 2023, was ransomware. The next largest came in through trusted access rather than a forced entry: Delta Dental of California through the MOVEit flaw in a file-transfer vendor, Absolute Dental through a single compromised account belonging to its outside IT vendor, and both Chord Specialty Dental Partners and Delta Dental of Virginia through a staff email account an attacker had quietly taken over. The smaller cases follow the same script, ransomware that locked the files at a Washington practice and a Virginia clinic. What they share is not sophistication. Where the entry point is known in these cases, it was trusted access rather than forced entry: a compromised login or a compromised vendor, not a direct break-in of a hardened system. The door tends to be unlocked before the attacker arrives. Which vendors hold a key is the question behind every business associate agreement, and a breach is a clock that starts the moment you find it.

What OCR actually fines you for

Here is where the second dataset matters more than the first. OCR's Risk Analysis Initiative, whose first settlement landed in October 2024, was a deliberate decision to concentrate enforcement on a single failure the agency kept finding behind breach after breach: regulated entities that never performed a complete, accurate risk analysis of where their patient data lives and what threatens it. OCR's position, stated more plainly with each settlement, is that this failure is itself the violation. The attacker who encrypted the files did not create the legal exposure. The gap an honest risk analysis should have caught, and a real plan should have closed, did.

The settlements that have come out of the initiative make the point better than any summary. The breach that drew OCR's attention is different every time. The finding is the same every time.

EntityAnnouncedSettlementWhat triggered itWhat OCR found
Bryan County Ambulance Authority (OK)2024$90,000RansomwareNo risk analysis
MMG Fusion (dental software)2026$10,000PHI exposed and posted onlineNo risk analysis; failed to notify clients
Health Fitness Corporation2025$227,816Server left misconfiguredNo risk analysis
Top of the World Ranch2026$103,000Phishing emailNo risk analysis
Selected settlements under OCR's Risk Analysis Initiative: different triggers, one recurring finding. Source: HHS Office for Civil Rights settlement announcements.

Primary sources: Bryan County, MMG Fusion, Health Fitness Corporation, Top of the World Ranch, PIH Health, and the four April 2026 ransomware settlements.

The dollar figures range widely, from the $10,000 paid by the dental software vendor MMG Fusion to the $227,816 paid by a wellness company for a server left exposed for nearly three years, with settlements like Deer Oaks – The Behavioral Health Solution at $225,000 and a Syracuse surgery center at $250,000 in between. Across the settlements we reviewed, the breach that triggered the investigation was almost always ransomware, with a few phishing emails and a misconfigured server making up most of the rest, but the violation OCR cited was the same missing risk analysis in every one. The full list is in the appendix below. The check is never the real cost. Every settlement carries a corrective action plan, often monitored for two to three years, that orders the practice to build the program it skipped. By the middle of 2026, the six settlements we reviewed from that year alone had brought OCR $1,278,000. An OCR investigation is an expensive and public way to be told to do the paperwork.

Note who turns up on that list. MMG Fusion is a dental software vendor, and OCR's settlement with it cited not just a missing risk analysis but a failure to tell the dental practices it served that their patients' data had been exposed. The initiative is not aimed at dentistry. Dentistry is not exempt from it.

What this means for an independent practice

Put the two datasets side by side and the instruction for a small practice writes itself. Breaches arrive through ordinary doors: ransomware, a compromised inbox, a vendor with access. Fines arrive through one document: the risk analysis that was never finished. In its 2024 report, OCR named the failures it keeps finding underneath these cases, incomplete risk analyses, user accounts with more access than they need, and weak authentication like default passwords and single-factor remote logins. None of that is exotic. It is the same handful of safeguards a small practice can put in place on purpose, for a fraction of what a settlement costs. What that program runs per year is its own question, and the risk analysis is the line item everything else depends on.

Your practice's facts can change the answer, so for your specific situation, consult a healthcare attorney or qualified compliance professional.

The cheapest version of this is the one you build before OCR builds it for you. The Scorecard checks ten core Security Rule controls that line up with the issues OCR raises most, then sends you a short written read of where your practice stands. About three minutes, no cost. It is a starting point, not a substitute for the formal risk analysis this report is about.Check my practice →

How we compiled this report

This report reads two public datasets together, as of July 2026. The aggregate figures, the annual breach counts and the share by cause, come from the HHS annual Reports to Congress on breaches of unsecured protected health information, the agency's own tally. The named breach cases come from the HHS Office for Civil Rights breach portal, which by law lists only breaches affecting 500 or more people, supplemented where a case was not yet posted by company and state breach notices and by the reporting of the HIPAA Journal and Becker's Dental Review. Settlement details come from OCR's own enforcement announcements, linked above and listed in the appendix.

To build the dental breach table, we filtered the breach record to dental insurers, dental service organizations, and dental practices, and kept the largest cases alongside a few smaller ones that show what a typical practice faces. To build the enforcement table and the appendix, we read every settlement since October 2024 in which OCR's announcement cited a missing risk analysis, the first landing that October, the agency's own count placed the March 2026 MMG Fusion settlement at its twelfth, and recorded for each the breach that triggered it and the violation OCR found. In every settlement we reviewed, that violation was a failure to conduct an accurate and thorough risk analysis under 45 CFR § 164.308(a)(1)(ii)(A).

Two limits are worth stating plainly. Counts move: where a breach total was still being finalized we have marked it approximate, and where a vendor never reported a breach, as with MMG Fusion, the figure is OCR's later estimate rather than a portal entry. And this is a read of the public record, not legal advice; we are not a law firm. We update these figures as the record changes and we date every version, most recently in July 2026. Verify any specific number against the primary source before relying on it.

Appendix: the settlements we reviewed

These are the settlements since October 2024 in which OCR's cited violation included the missing risk analysis and we could confirm the breach that triggered the investigation, listed by announcement date. Not all of them are counted in OCR's formal Risk Analysis Initiative tally; PIH Health's announcement, for one, does not carry the initiative's label. In each, OCR's cited violation was the same: a failure to conduct an accurate, thorough risk analysis under 45 CFR 164.308(a)(1)(ii)(A). OCR has announced other risk-analysis settlements we have not detailed here, including Deer Oaks – The Behavioral Health Solution ($225,000). Concentra's $112,500 settlement came under OCR's separate Right of Access Initiative, not the risk-analysis push.

EntityAnnouncedSettlementTriggering breach
Bryan County Ambulance Authority (OK)Oct 2024$90,000Ransomware
Elgon Information Systems (MA)Jan 2025$80,000Ransomware
Northeast Surgical Group (MI)Jan 2025$10,000Ransomware
Health Fitness Corporation (IL)Mar 2025$227,816Misconfigured server
Guam Memorial Hospital (GU)Apr 2025$25,000Ransomware
PIH Health (CA)Apr 2025$600,000Phishing
Comstar (MA)May 2025$75,000Ransomware
Syracuse surgery center (NY)Jul 2025$250,000Ransomware
Top of the World Ranch (IL)Feb 2026$103,000Phishing
MMG Fusion (MD)Mar 2026$10,000Vendor breach (unreported)
Assured Imaging (AZ/CA)Apr 2026$375,000Ransomware
Regional Women's Health Group (Axia) (NJ/PA)Apr 2026$320,000Ransomware
Consociate Health (IL)Apr 2026$225,000Ransomware
Star Group Health Benefits Plan (CT)Apr 2026$245,000Ransomware
Selected settlements citing a missing risk analysis, by announcement date. Source: HHS Office for Civil Rights enforcement announcements. The financial penalty is rarely the largest cost; each settlement also carries a corrective action plan, typically monitored for two to three years.

How to cite this report

Journalists and researchers are welcome to cite this report. A suggested citation:

Hipsana, Dental HIPAA Breach and Enforcement Report (2026), https://hipsana.com/articles/dental-hipaa-breach-and-enforcement-report

Frequently asked questions

How many healthcare data breaches happen each year?

In 2024, the most recent year HHS has reported to Congress, it received 742 reports of breaches affecting 500 or more people, and across the breaches that occurred that year, more than 242 million individuals' records were exposed, plus another 74,299 smaller breaches affecting fewer than 500 people each. The smaller breaches, the kind a solo practice is likeliest to have, are reported to HHS but not posted publicly by name.

What is the largest dental data breach?

The largest a dental provider has reported is the 2023 ransomware attack on MCNA Dental, which exposed the records of roughly 8.9 million people after the LockBit group copied hundreds of gigabytes of data and published it when MCNA refused to pay. The second largest reported was Delta Dental of California, with about 6.9 million people affected through the MOVEit supply-chain attack the same year. A larger exposure, the records of an estimated 15 million people held by the dental-software vendor MMG Fusion, never appeared on the public breach list; it surfaced only when OCR settled with the vendor in 2026 over a 2020 breach it had never reported.

What does OCR actually fine dental and medical practices for?

Increasingly, for failing to conduct an accurate and thorough risk analysis, the foundational requirement of the HIPAA Security Rule at 45 CFR 164.308(a)(1)(ii)(A). Since late 2024, OCR's Risk Analysis Initiative has treated the missing risk analysis, rather than the breach that exposed it, as the central violation in case after case.

How large are HIPAA fines for small practices?

They vary widely. Recent settlements range from $10,000 paid by a dental software vendor to six-figure amounts in ransomware cases, with a small Illinois treatment center paying $103,000 and a wellness company paying $227,816. The financial penalty is rarely the largest cost; nearly every settlement also includes a corrective action plan monitored for two to three years.

What is the OCR Risk Analysis Initiative?

An enforcement focus the HHS Office for Civil Rights launched in 2024 to concentrate its resources on a single recurring failure: organizations that never performed a complete risk analysis of their electronic patient data. Its first settlement, with an Oklahoma ambulance service, came in October 2024, and OCR has resolved more than a dozen cases under it since, with the agency signaling it will extend the same scrutiny to risk management, acting on what the analysis finds, next.

How do most dental data breaches start?

Across the public cases, the most common reported cause is ransomware, and where the entry point behind it is known, it is a compromised login or a vendor with access to the practice's systems rather than a direct break-in. The common thread is a trusted login or a trusted third party, not a sophisticated attack.

Do small dental practices really get investigated?

Yes. Federal regulators have settled with single-location providers and with a treatment center whose breach affected 1,980 patients. Size is not a defense: a breach is what draws OCR's attention; the state of your compliance program is what determines the outcome.

Not sure where your practice stands?

The free HIPAA Scorecard checks ten core Security Rule controls and scores your practice out of 100. About three minutes, no cost. A starting point, not a full audit.

Check my practice →