Borgfeld Dental Center PLLC dba Henwood Family Dentistry Data Breach
Borgfeld Dental Center Data Breach Affects 7,300 Patients
What happened in the Borgfeld Dental Center PLLC dba Henwood Family Dentistry data breach?
The Borgfeld Dental Center PLLC dba Henwood Family Dentistry data breach was reported on October 2, 2023 and affected 7,300 individuals. The breach type was Unauthorized Access/Disclosure involving Electronic Medical Record, Network Server. This breach occurred in Texas. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Borgfeld Dental Center PLLC dba Henwood Family Dentistry Breach Details
Borgfeld Dental Center PLLC Data Breach Report
Incident Overview
Borgfeld Dental Center PLLC, operating under the name Henwood Family Dentistry in Texas, experienced an unauthorized access and disclosure incident affecting approximately 7,300 patients. The breach was discovered and reported to the Texas Attorney General on October 2, 2023. The unauthorized access occurred within the facility's electronic medical record (EMR) system and network server infrastructure, compromising sensitive patient health information and personal data maintained by the dental practice.
Discovery and Response Timeline
The dental center identified the unauthorized access to its systems during a routine security review or incident investigation process. Upon discovery, Borgfeld Dental Center initiated an internal investigation to determine the scope of the breach, identify which patient records were accessed without authorization, and assess what specific information may have been compromised. The organization notified affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach affecting unsecured protected health information (PHI). The submission date of October 2, 2023, indicates the breach was reported to state authorities within the required timeframe.
Technical Details of the Breach
The breach involved unauthorized access to both the electronic medical record system and network server infrastructure. Network server compromises typically indicate either a vulnerability in the organization's IT infrastructure, inadequate access controls, or a failure in network segmentation that allowed an unauthorized party to gain entry to systems containing patient data. EMR systems are primary targets for healthcare data breaches because they contain comprehensive patient information in a centralized, digitized format. The unauthorized access classification suggests that an individual or threat actor gained access to systems they were not authorized to use, rather than an authorized user intentionally disclosing information. This could result from compromised credentials, exploitation of software vulnerabilities, inadequate firewall protections, or insufficient authentication mechanisms such as multi-factor authentication.
Organizational Context
Borgfeld Dental Center PLLC operates as Henwood Family Dentistry, a dental practice providing oral healthcare services to patients in Texas. As a dental practice, the organization maintains comprehensive patient records including treatment histories, clinical notes, radiographic images, and personal health information. The practice is classified as a HIPAA-covered entity due to its transmission of health information in electronic form in connection with healthcare transactions. With 7,300 affected individuals, the practice likely operates multiple locations or has served a substantial patient population over several years. Dental practices of this size typically employ multiple dentists, hygienists, administrative staff, and IT personnel responsible for maintaining patient data security and system integrity.
Patient Population Impact
Approximately 7,300 patients had their protected health information potentially accessed without authorization. This represents a significant portion of the practice's patient database, suggesting either a broad system compromise affecting multiple patient records simultaneously or an extended period during which unauthorized access occurred undetected. Patients affected by this breach were notified of the incident and informed about the types of information that may have been compromised. The notification process, required under HIPAA regulations, must include a description of the breach, the types of information involved, steps patients should take to protect themselves, and information about credit monitoring or identity theft protection services if applicable.
HIPAA Compliance and Regulatory Context
Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals, the media (if more than 500 residents of a state are affected), and the Secretary of Health and Human Services of breaches of unsecured PHI. The fact that this breach was reported to state authorities indicates compliance with notification requirements. Dental practices must implement administrative, physical, and technical safeguards to protect patient information, including access controls, encryption, audit logs, and workforce security measures. Unauthorized access incidents often result from gaps in these safeguards, such as inadequate user access management, failure to implement encryption on network servers, insufficient monitoring of system access, or delayed patching of known vulnerabilities. The breach demonstrates the importance of regular security assessments, penetration testing, and staff training on data security protocols within healthcare organizations.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Borgfeld Dental Center PLLC dba Henwood Family Dentistry Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements and medical bills carefully for unauthorized healthcare services or claims; contact your insurance provider and healthcare providers immediately if you identify suspicious activity
Change passwords for any online accounts associated with the dental practice or healthcare providers, and use strong, unique passwords that are not reused across multiple accounts
Enroll in any complimentary credit monitoring or identity theft protection services offered by Borgfeld Dental Center; maintain documentation of the breach notification and keep records of any fraudulent activity discovered
Consider placing a security freeze with credit bureaus to prevent unauthorized access to your credit file; monitor financial accounts regularly for suspicious transactions and report any fraud to your financial institutions immediately
Be cautious of unsolicited communications claiming to be from healthcare providers or financial institutions; verify requests for personal information through official channels before providing sensitive data
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Texas Breaches
Search all breaches reported in Texas