173,000 Patients Affected by Chord Specialty Dental Partners Email Data Breach
CDHA Management, LLC and Spark DSO, LLC, which do business as Chord Specialty Dental Partners, have recently notified the U.S. Department of Health and Human Services’ Office for Civil Rights about a data breach that involved unauthorized access to the protected health information of up to 173,430 individuals.
The Tennessee-based dental service organization provides business and operational support services to more than 60 dental practices in Indiana, Delaware, New Jersey, Pennsylvania, Tennessee, and Virginia. On or around September 11, 2024, suspicious activity was identified in an employee email account. Third-party digital forensics specialists were engaged to investigate the activity and confirmed that an unauthorized third party had gained access to several employee email accounts from August 19, 2024, to September 25, 2024.
A comprehensive and time-intensive review of the affected accounts was recently concluded, and it was confirmed that names, addresses, Social Security numbers, driver’s license numbers, bank account information, payment card information, dates of birth, medical information, and health insurance information were stored in the accounts. The types of information involved varied from individual to individual, and while data has been exposed, no evidence has been found to indicate any of the exposed data has been or will be misused.
On or around March 14, 2025, notification letters started to be mailed to the affected individuals, who have been offered complimentary credit monitoring and identity theft protection services out of an abundance of caution. Chord Specialty Dental Partners said its policies and procedures related to data security have been reviewed and will be enhanced, as appropriate, to prevent similar incidents in the future.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy


