Dr. Michael Bilikas and Associates d.b.a. 32 Pearls Data Breach
32 Pearls Dental Practice Hit by Network Server Breach
What happened in the Dr. Michael Bilikas and Associates d.b.a. 32 Pearls data breach?
The Dr. Michael Bilikas and Associates d.b.a. 32 Pearls data breach was reported on July 21, 2025 and affected 23,517 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Washington. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Dr. Michael Bilikas and Associates d.b.a. 32 Pearls Breach Details
Healthcare Data Breach Report: Dr. Michael Bilikas and Associates d.b.a. 32 Pearls
Incident Overview
Dr. Michael Bilikas and Associates, operating under the business name 32 Pearls, a dental practice based in Washington State, experienced a significant data breach affecting 23,517 individuals. The breach occurred through unauthorized access to the practice's network server infrastructure, compromising patient protected health information (PHI) and personal data. The breach was formally reported to the Washington State Attorney General and affected individuals on July 21, 2025, triggering mandatory HIPAA breach notification requirements. This incident represents a substantial security failure in the practice's IT infrastructure, exposing sensitive patient records to unauthorized third parties.
Discovery and Response Timeline
The specific date of breach discovery was not disclosed in the submission materials, though the formal notification submission occurred on July 21, 2025. Upon discovery of the unauthorized network access, 32 Pearls initiated an investigation to determine the scope and nature of the compromise. The practice engaged in forensic analysis of their network systems to identify the breach vector, assess the extent of data exposure, and determine which patient records were affected. Following standard HIPAA breach notification protocols, the practice notified affected individuals, the Washington State Attorney General, and likely major credit reporting agencies. The investigation process typically involves IT security professionals examining server logs, access controls, and system vulnerabilities to reconstruct the timeline of unauthorized access and identify what information was exposed.
Technical Breach Details
The breach occurred at the network server level, indicating that attackers gained unauthorized access to centralized data storage systems rather than individual workstations or portable devices. Network server compromises typically result from one or more of the following vectors: exploitation of unpatched software vulnerabilities, weak or compromised credentials, inadequate firewall configurations, insufficient access controls, or social engineering attacks targeting staff members with system access. The fact that this breach affected over 23,000 individuals suggests the attackers accessed a significant portion of the practice's patient database, likely stored in electronic health record (EHR) systems or related administrative databases. Network-level breaches are particularly concerning because they can provide attackers with broad access to multiple data types simultaneously, rather than limiting exposure to specific patient files. The scope of this incident indicates either a prolonged period of undetected access or a single incident affecting the entire patient database.
Organizational Context
32 Pearls is a dental practice operated by Dr. Michael Bilikas and Associates in Washington State. As a dental practice, the organization maintains comprehensive patient records including clinical notes, treatment histories, radiographic images, and administrative information. Dental practices typically serve local or regional patient populations and maintain detailed records necessary for ongoing patient care, treatment planning, and billing purposes. The practice's size, as evidenced by the 23,517 affected individuals, suggests either a large multi-location practice, a long operational history with accumulated patient records, or both. Dental practices are increasingly targeted by cybercriminals because they maintain valuable personal health information while often operating with limited IT security resources compared to larger hospital systems. The breach's impact on a dental practice is particularly significant because these organizations frequently serve as primary care providers for many patients and maintain longitudinal health records.
Patient Impact and Notification
Approximately 23,517 individuals had their personal and health information potentially compromised in this breach. These affected parties include current and former patients of 32 Pearls whose records were stored on the compromised network servers. The exposed information likely includes names, addresses, dates of birth, Social Security numbers, insurance information, and detailed dental health records including treatment plans, clinical notes, and radiographic data. Some records may have also contained financial information related to billing and payment methods. Under HIPAA's Breach Notification Rule, 32 Pearls was required to notify all affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The practice was also required to notify the Washington State Attorney General and, given the number of affected individuals, likely had to notify major media outlets. Affected individuals received notification letters detailing what information was compromised, the date range of potential exposure, and recommended protective actions.
HIPAA Compliance and Industry Context
This breach represents a violation of HIPAA's Security Rule, which requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). The Security Rule specifically mandates access controls, encryption of data in transit and at rest, regular security assessments, and incident response procedures. Network server breaches of this magnitude typically indicate failures in one or more of these required safeguards, such as inadequate access controls, insufficient encryption, or delayed detection of unauthorized access. According to the U.S. Department of Health and Human Services, hacking and IT incidents remain among the most common causes of healthcare data breaches, accounting for a significant percentage of reported incidents. Dental practices have been increasingly targeted in recent years, with multiple large-scale breaches affecting thousands of patients. The 23,517 individuals affected in this incident places it among the larger dental practice breaches reported in recent years. HIPAA violations can result in civil penalties ranging from $100 to $50,000 per violation, with annual maximums reaching into the millions of dollars. Additionally, affected individuals may pursue civil litigation, and the practice may face reputational damage and loss of patient trust.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Dr. Michael Bilikas and Associates d.b.a. 32 Pearls Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze with each bureau
Review explanation of benefits (EOB) statements from your dental and health insurance providers for unauthorized claims or services you did not receive
Change passwords for any online accounts associated with 32 Pearls or your insurance provider, using strong, unique passwords for each account
Monitor financial accounts and credit card statements closely for unauthorized transactions; consider placing fraud alerts with creditors and financial institutions
Be cautious of unsolicited communications claiming to be from healthcare providers, insurance companies, or financial institutions; verify directly with organizations before providing any information
Consider enrolling in identity theft protection or credit monitoring services if offered by the practice or your insurance provider
Report any suspicious activity, unauthorized accounts, or fraudulent charges to the Federal Trade Commission (FTC) at IdentityTheft.gov and to local law enforcement
Request a free credit report from AnnualCreditReport.com and review it carefully for accounts or inquiries you do not recognize
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Washington Breaches
Search all breaches reported in Washington
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits