Absolute Dental Confirmed Data Breach Affecting Over 1.2 Million Individuals
Absolute Dental, a Nevada dental practice with over 50 locations in Las Vegas, Carson City, Reno, Sparks, and Minden, has completed its investigation of a February 2025 cyberattack and has confirmed that more than 1.2 million individuals had some of their personal and protected health information exposed. Absolute Dental reported the data breach to the HHS’ Office for Civil Rights in May 2025 using a placeholder figure of 501 affected individuals. At the time, it was unclear how many individuals had been affected. While the breach portal has not yet been updated with the new total, the Oregon Attorney General was informed that 1,223,635 individuals have been affected. Absolute Dental explained in its substitute breach notice that an issue was identified within its information systems on February 26, 2025. Steps were taken to secure its systems and investigate the nature and scope of the activity. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that an unauthorized third party had access to its network between February 26, 2025, and...
Couple Plead Guilty to $1M Fraud Scheme Involving Stolen Patient Data
A former business clerk at Montefiore Medical Center and his partner have pleaded guilty to stealing thousands of patient records and using the stolen data to defraud government agencies out of almost $1 million. Wilkins Estrella, 40, of Hackensack, New Jersey, had worked at the Bronx hospital for almost a decade. He was terminated in 2020 after an internal audit of access logs revealed he had been accessing patient records without authorization from at least 2020 to 2022. The review confirmed that more than 4,000 medical records were accessed without any legitimate business purpose for doing so. Montefiore Medical Center reported the data breach to the HHS’ Office for Civil Rights and referred the matter to law enforcement for criminal prosecution. Along with his romantic partner, Charlene Marte, 31, of the Bronx, New York, Estrella misused patient data to open debit card accounts in patients’ names and had those cards sent to their own addresses and those of family members. The pair then used data from multiple sources to target COVID-19 relief funds from the Internal Revenue...
UI Community HomeCare Hacking Incident Affects 211,000 Patients
On Friday last week, University of Iowa Health Care and its affiliated UI Community HomeCare, a home infusion and medical equipment service provider, announced a hacking incident that was identified on July 3, 2025. Immediate action was taken to contain the threat, and its systems were safely restored within one business day. Third-party cybersecurity experts were engaged to conduct a forensic investigation to determine the nature and scope of the unauthorized activity, and it was confirmed that a cybercriminal hacker had access to the UI Community HomeCare network on July 3, 2025. While the networks of University of Iowa Health Care and affiliated UI Community HomeCare are separate, both entities share some patients, employees, and data files. Some of those data files were exfiltrated by the hacker, although the investigation confirmed that there was no unauthorized access to its electronic medical record system. The review of the affected data revealed that the files contained the personal and protected health information of approximately 211,000 individuals. Notification letters...
New York Counseling Provider and Florida Cancer Center Announce Data Breaches
Family Counseling Services of the Finger Lakes in New York and the Cancer Care Center of North Florida have confirmed that patient data was compromised in recent hacking incidents. Family Counseling Services of the Finger Lakes Family Counseling Services of the Finger Lakes in New York has discovered unauthorized access to its email environment. Suspicious activity was identified on or around February 4, 2025, and the forensic investigation confirmed that a limited number of email accounts had been accessed by an unauthorized third party between January 14, 2025, and February 4, 2025. The email accounts were immediately secured, and a review was conducted to determine the extent of data exposure. The file review was completed on June 30, 2025, and confirmed that the exposed data included full names, in combination with one or more of the following: date of birth, Social Security number, driver’s license number, bank account number, medical information, and health insurance information. Family Counseling Service is unaware of any misuse of the exposed data; however, the affected...
Data Breaches Announced by The Black Hills Regional Eye Institute & The Children’s Center of Hamden
Data breaches have recently been announced by Black Hills Regional Eye Institute in South Dakota and the Children’s Center of Hamden in New York. Black Hills Regional Eye Institute The Black Hills Regional Eye Institute in Rapid City, South Dakota, has fallen victim to a cyberattack that was identified on or around January 8, 2025. Systems were rapidly taken offline to prevent further unauthorized access and to contain the incident, and an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation confirmed on or around February 7, 2025, that patient information had been accessed and acquired by the threat actor, who had access to certain systems from January 4, 2025, to January 8, 2025. A comprehensive file review was conducted to determine the individuals affected and the types of data involved, which concluded on July 30, 2025. Black Hills Regional Eye Institute determined that the compromised data included patients’ first and last names in combination with one or more of the following: date of birth, Social Security...



