Great Expressions Dental Centers Data Breach
Great Expressions Dental Centers Network Server Breach
What happened in the Great Expressions Dental Centers data breach?
The Great Expressions Dental Centers data breach was reported on May 12, 2023 and affected 528 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Michigan. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Great Expressions Dental Centers Breach Details
Great Expressions Dental Centers Data Breach Report
Incident Overview
Great Expressions Dental Centers, a dental healthcare provider operating in Michigan, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was reported to the U.S. Department of Health and Human Services on May 12, 2023, affecting 528 individuals. The incident involved a hacking or IT-related compromise of the organization's network server systems, which typically serve as centralized repositories for patient records, appointment scheduling systems, billing information, and other sensitive healthcare data. This type of breach represents a direct compromise of the organization's core information technology infrastructure rather than a physical theft or loss of devices.
Discovery and Response Timeline
The specific discovery date and investigation timeline were not detailed in the breach submission, though the May 12, 2023 submission date indicates the organization had completed its investigation and notification process by that time. Upon discovery of the unauthorized network access, Great Expressions Dental Centers initiated standard breach response protocols, including a forensic investigation to determine the scope of the compromise, identification of affected individuals, and preparation of breach notifications required under the Health Insurance Portability and Accountability Act (HIPAA). The organization's response did not involve a business associate, indicating the breach was contained within Great Expressions' own IT infrastructure and systems. This suggests the organization managed the investigation and notification process independently.
Technical Breach Details
Specific Details
Network server breaches typically occur through one or more common attack vectors including credential compromise, unpatched software vulnerabilities, phishing attacks targeting employee credentials, or direct exploitation of internet-facing systems. When a network server is compromised, attackers gain access to centralized data repositories that may contain multiple years of patient information. The location designation of "Network Server" indicates the breach affected backend infrastructure rather than individual workstations or portable devices. This type of compromise is particularly concerning because network servers typically contain consolidated patient data across multiple patients and multiple data types, creating a single point of failure for large volumes of protected health information (PHI). The fact that 528 individuals were affected suggests the attackers may have accessed specific patient records or a particular subset of the organization's database rather than the entire patient population, though the exact scope depends on the nature of the compromise and what data was actually exfiltrated versus merely accessed.
Organizational Context
Great Expressions Dental Centers operates as a dental healthcare provider in Michigan, offering preventive, restorative, and cosmetic dental services to patients throughout the state. Dental practices maintain comprehensive patient records including personal identifiers, insurance information, treatment histories, and clinical notes. As a dental healthcare organization, Great Expressions Dental Centers is a covered entity under HIPAA and is required to maintain appropriate safeguards for all patient protected health information. The breach of 528 patients represents a significant incident for a dental practice, though the organization's size and number of total locations were not specified in the breach submission. Dental practices typically maintain detailed patient records including contact information, insurance details, and clinical information spanning years of treatment, making them attractive targets for healthcare data breaches.
Patient Impact and Notifications
Number of People Affected
A total of 528 individuals were affected by the network server breach at Great Expressions Dental Centers. These individuals likely include current and former patients whose records were stored on the compromised network server. The notification process required by HIPAA mandates that affected individuals be notified without unreasonable delay and no later than 60 calendar days after discovery of the breach. Given the May 12, 2023 submission date, notifications to affected patients should have been completed by mid-July 2023. Affected individuals should have received written notification detailing the nature of the breach, the types of information compromised, steps the organization is taking to address the breach, and recommended actions patients should take to protect themselves.
Personal Information Involved
Based on typical dental practice data systems, the compromised network server likely contained multiple categories of protected health information including patient names, dates of birth, addresses, telephone numbers, email addresses, insurance information including policy numbers and group numbers, Social Security numbers (if used for patient identification), dental treatment records and clinical notes, appointment histories, payment and billing information, and potentially medical history information relevant to dental treatment. The specific data elements exposed depend on what information was actually accessed by the attackers and what data the organization's network server contained. Dental records are particularly sensitive because they contain identifiable information linked to specific individuals' healthcare conditions and treatment histories.
Industry Context and HIPAA Implications
Network server breaches represent one of the most common categories of healthcare data breaches, accounting for a significant percentage of reported incidents across the healthcare industry. According to HHS breach notification data, hacking and IT incidents consistently rank among the top causes of healthcare data breaches, often affecting larger numbers of individuals than physical theft or loss incidents. HIPAA requires covered entities to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI), including access controls, encryption, audit controls, and integrity controls. Network server breaches often indicate potential gaps in one or more of these safeguard categories, such as inadequate access controls, insufficient encryption of data at rest or in transit, unpatched systems, or weak authentication mechanisms. The breach notification rule requires covered entities to notify affected individuals, the media (if more than 500 residents of a state are affected), and the Secretary of HHS. Since this breach affected fewer than 500 individuals in Michigan, media notification was not required, though the organization was required to notify affected individuals and maintain documentation of the breach response.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Great Expressions Dental Centers Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for suspicious activity and consider placing a fraud alert or credit freeze to prevent unauthorized account opening
Review explanation of benefits (EOB) statements from your dental insurance and other health insurance carriers for unauthorized claims or services you did not receive
Change passwords for any online accounts associated with Great Expressions Dental Centers or your dental insurance, using strong, unique passwords that are not reused across other accounts
Monitor financial accounts and credit card statements for unauthorized charges, and consider requesting new payment cards from your financial institutions if payment information was exposed
Be cautious of unsolicited communications claiming to be from Great Expressions Dental Centers, your insurance company, or financial institutions, as attackers may use exposed information to craft convincing phishing emails or phone calls
Consider enrolling in credit monitoring or identity theft protection services if offered by Great Expressions Dental Centers as part of their breach response
Report any suspicious activity or suspected identity theft to the Federal Trade Commission at IdentityTheft.gov and to local law enforcement
Request a copy of your dental records from Great Expressions Dental Centers to verify the accuracy of information maintained about you
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Michigan Breaches
Search all breaches reported in Michigan