CDHA Management, LLC and Spark DSO, LLC dba Chord Specialty Dental Partners Data Breach
Dental DSO Email Breach Affects 173K Patients in Tennessee
What happened in the CDHA Management, LLC and Spark DSO, LLC dba Chord Specialty Dental Partners data breach?
The CDHA Management, LLC and Spark DSO, LLC dba Chord Specialty Dental Partners data breach was reported on March 14, 2025 and affected 173,430 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Tennessee. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
CDHA Management, LLC and Spark DSO, LLC dba Chord Specialty Dental Partners Breach Details
Dental Services Organization Email Breach Notification
Opening Summary
CDHA Management, LLC and Spark DSO, LLC, operating under the brand name Chord Specialty Dental Partners, experienced a significant data breach affecting 173,430 individuals in Tennessee. The breach was discovered to involve unauthorized access to email systems, which are commonly used to store and transmit sensitive patient health information and personal identifiers. The breach was reported to the Tennessee Department of Health on March 14, 2025, triggering mandatory HIPAA breach notification requirements. This incident represents a substantial compromise of patient privacy affecting a large patient population across the dental services organization's operations.
Discovery and Response Timeline
The specific date of breach discovery was not disclosed in the available submission data, though the March 14, 2025 submission date indicates the entity reported the incident within the required timeframe under HIPAA regulations. Upon discovery of unauthorized access to their email systems, the organization initiated an investigation to determine the scope of the breach, identify affected individuals, and assess what protected health information (PHI) may have been accessed. Standard breach response protocols typically include forensic analysis of email systems, review of access logs, notification to affected individuals, and coordination with regulatory authorities. The entity's response included formal notification to the Tennessee Department of Health as required under state breach notification laws and HIPAA's Breach Notification Rule, which mandates notification without unreasonable delay and no later than 60 calendar days after discovery of a breach.
Technical Details of Email System Compromise
Email system breaches represent a particularly significant threat vector in healthcare organizations because email serves as a central repository for clinical communications, appointment scheduling, billing information, and administrative records. Unauthorized access to email systems may have exposed patient names, contact information, dates of birth, insurance details, treatment records, and potentially financial information. Email-based breaches typically occur through methods such as credential compromise (phishing, weak passwords, credential stuffing), exploitation of unpatched email server vulnerabilities, or compromise of email service provider infrastructure. The fact that this breach involved email systems rather than a centralized database suggests the compromise may have been more diffuse, potentially affecting multiple mailboxes across the organization. Email breaches are particularly concerning because they often go undetected for extended periods, as unauthorized access may not trigger the same alerts as database intrusions. The scope of 173,430 affected individuals suggests the breach may have affected email systems used across multiple dental facilities or administrative departments within the Chord Specialty Dental Partners network.
Organizational Context and Operations
Chord Specialty Dental Partners, operating through CDHA Management, LLC and Spark DSO, LLC, is a dental services organization (DSO) providing specialized dental services across Tennessee. DSOs typically manage multiple dental practices, coordinate clinical operations, handle billing and insurance processing, and maintain centralized administrative functions. The organization's size, as evidenced by the 173,430 affected individuals, indicates it operates a substantial network of dental facilities or has accumulated patient records from multiple locations over an extended period. Dental practices, while often perceived as lower-risk than hospitals or large medical centers, maintain comprehensive patient health records including treatment histories, radiographic images, medical histories, and insurance information. The centralized nature of DSO operations means that a single breach of core IT infrastructure can affect patient populations across numerous individual practices.
Patient Population Impact and Notification
Approximately 173,430 individuals had their personal and health information potentially exposed through the email system compromise. This substantial patient population reflects either a large multi-practice dental organization or accumulated records from years of patient care. Affected individuals likely include current and former patients of Chord Specialty Dental Partners facilities throughout Tennessee. The compromised information may have included names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers (if used for insurance verification or billing), insurance information, dental treatment records, medical histories, and potentially financial account information. Under HIPAA requirements, the organization was obligated to notify all affected individuals of the breach, the types of information compromised, steps the organization is taking to investigate and prevent future breaches, and resources available to affected individuals. Notification typically occurs through written correspondence, though some organizations supplement this with credit monitoring services or identity theft protection resources.
HIPAA and Industry Context
This breach falls under HIPAA's Breach Notification Rule, which requires covered entities and business associates to notify affected individuals, the media (if more than 500 residents of a state are affected), and the U.S. Department of Health and Human Services (HHS) of breaches of unsecured PHI. With 173,430 individuals affected, this breach clearly exceeds the 500-person threshold for media notification in Tennessee, making it a matter of public record and regulatory scrutiny. Email-based breaches have become increasingly common in healthcare, with the HHS Office for Civil Rights reporting that email compromise and phishing attacks represent significant vectors for healthcare data breaches. The healthcare industry has experienced a notable increase in email-targeted attacks, particularly those exploiting remote work infrastructure and cloud-based email services. Dental practices, while sometimes perceived as lower-priority targets than hospitals, maintain valuable patient data and financial information that makes them attractive to threat actors. The scale of this breach—affecting over 170,000 individuals—places it among the larger healthcare breaches reported in recent years and underscores the importance of strong email security controls, including multi-factor authentication, encryption, and advanced threat detection systems.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the CDHA Management, LLC and Spark DSO, LLC dba Chord Specialty Dental Partners Breach
Monitor credit reports and consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent unauthorized account opening. Obtain free annual credit reports at annualcreditreport.com and review them for suspicious activity.
Enroll in any complimentary credit monitoring or identity theft protection services offered by Chord Specialty Dental Partners or through the breach notification process. These services typically provide monitoring for 12-24 months and may include identity theft insurance.
Change passwords for all online accounts, particularly email, banking, insurance, and healthcare portals. Use strong, unique passwords (minimum 12-16 characters with mixed case, numbers, and symbols) and enable multi-factor authentication wherever available.
Be vigilant against phishing emails and social engineering attempts. Do not click links or download attachments from unsolicited emails claiming to be from Chord Specialty Dental Partners, financial institutions, or insurance companies. Contact organizations directly using phone numbers from official websites.
Review medical and dental records for accuracy and unauthorized treatment. Contact Chord Specialty Dental Partners and your insurance provider if you notice any claims or treatments you did not authorize.
Monitor financial accounts and credit card statements regularly for unauthorized charges. Report any suspicious activity immediately to your financial institution and consider placing a fraud alert with your bank.
Document all communications related to the breach, including notification letters and any identity theft incidents. Keep records of credit monitoring enrollment and any fraudulent activity discovered.
Consider filing a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you experience identity theft or fraud as a result of this breach. This creates an official record that may assist in dispute resolution.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Tennessee Breaches
Search all breaches reported in Tennessee
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits