Greater St. Louis Oral & Maxillofacial Surgery PC Data Breach
Email System Breach at St. Louis Oral Surgery Practice
What happened in the Greater St. Louis Oral & Maxillofacial Surgery PC data breach?
The Greater St. Louis Oral & Maxillofacial Surgery PC data breach was reported on December 4, 2025 and affected 501 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Missouri. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Greater St. Louis Oral & Maxillofacial Surgery PC Breach Details
Greater St. Louis Oral & Maxillofacial Surgery PC Email Breach Report
Opening Summary
Greater St. Louis Oral & Maxillofacial Surgery PC, a dental surgical practice based in Missouri, experienced a data breach involving unauthorized access to its email system. The breach was reported to the U.S. Department of Health and Human Services on December 4, 2025, affecting 501 individuals. The unauthorized access to the email infrastructure created potential exposure of protected health information (PHI) that may have been stored in or transmitted through email communications. This incident represents a significant security event for the practice and its patient population, as email systems in healthcare settings frequently contain sensitive clinical and administrative information.
Discovery and Response Timeline
The specific discovery date and investigation timeline were not detailed in the breach submission, though the December 4, 2025 submission date indicates the breach was reported within the required HIPAA notification window. Upon discovery of the unauthorized email access, Greater St. Louis Oral & Maxillofacial Surgery PC initiated an investigation to determine the scope of the breach, identify which patient records may have been compromised, and assess what information was accessible to unauthorized parties. The organization was required under HIPAA Breach Notification Rule to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The practice also had obligations to notify the HHS Office for Civil Rights and, depending on the number of affected individuals and media coverage, potentially the media.
Technical Details of the Breach
The breach involved a hacking or IT incident targeting the organization's email system. Email-based breaches typically occur through one or more vectors: compromised credentials (username and password), phishing attacks that trick users into revealing login information, exploitation of unpatched email server vulnerabilities, or compromise of email backup systems. Once attackers gain access to an email system, they can potentially view, copy, or exfiltrate all messages and attachments stored on the system, including those containing patient health information, appointment details, insurance information, and clinical notes. The fact that this breach was categorized as a hacking/IT incident rather than a loss or theft suggests the unauthorized access was likely remote and deliberate rather than the result of a lost device or physical theft. Email systems are particularly vulnerable because they often contain years of accumulated communications and are frequently less rigorously monitored than other clinical databases.
Organizational Context
Greater St. Louis Oral & Maxillofacial Surgery PC is a specialized dental surgical practice located in Missouri, focusing on oral and maxillofacial surgery services. Oral and maxillofacial surgeons perform complex surgical procedures including tooth extractions, jaw reconstruction, dental implant placement, and treatment of oral pathology. As a surgical specialty practice, the organization maintains detailed patient records including medical histories, surgical plans, imaging results, anesthesia records, and post-operative care instructions. The practice operates as a private entity without involvement of a business associate in this particular breach, meaning the organization itself was responsible for the security of patient data and the breach response. The 501 affected individuals represent the practice's patient population whose information was potentially exposed through the compromised email system.
Patient Impact and Notification
Approximately 501 patients of Greater St. Louis Oral & Maxillofacial Surgery PC were notified of the breach. These individuals may have had various types of protected health information accessible through the compromised email system. Patients likely received breach notification letters explaining what information may have been exposed, the date range of potential access, steps the organization was taking to secure the system, and recommended actions to protect themselves. Under HIPAA requirements, the notification must include a description of the breach, the types of information involved, steps patients should take to protect themselves, what the organization is doing to investigate and prevent future breaches, and contact information for questions. The practice was required to maintain documentation of all notification efforts and provide copies to HHS.
HIPAA Compliance and Industry Context
This breach highlights the ongoing vulnerability of email systems in healthcare settings despite decades of HIPAA requirements. The HIPAA Security Rule mandates that covered entities implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). Email systems should ideally be encrypted both in transit and at rest, access should be restricted through strong authentication mechanisms, and user activity should be monitored for suspicious access patterns. However, email remains one of the most frequently breached communication channels in healthcare because it balances accessibility with security challenges. According to healthcare breach statistics, email-based incidents consistently represent a significant portion of reported breaches, often due to the human element—phishing attacks succeed because users are tricked into voluntarily providing credentials. The 501-individual impact in this case is relatively modest compared to large-scale healthcare breaches, but represents a meaningful exposure for a specialized surgical practice. The breach underscores the importance of email security measures including multi-factor authentication, employee security awareness training, email encryption, and regular security audits of email infrastructure.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Greater St. Louis Oral & Maxillofacial Surgery PC Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements from your insurance provider and monitor your healthcare accounts for unauthorized services or claims; contact your insurance company immediately if you identify suspicious activity
Change your password for any online accounts associated with Greater St. Louis Oral & Maxillofacial Surgery PC and use a strong, unique password; enable multi-factor authentication if available
Be vigilant against phishing emails and calls claiming to be from the practice or related organizations; verify any requests for information by calling the practice directly using a phone number from your records rather than numbers provided in unsolicited communications
Consider enrolling in complimentary credit monitoring or identity theft protection services if offered by the practice; document all breach-related communications for your records
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Missouri Breaches
Search all breaches reported in Missouri