Mary H. Makhlouf, DMD, MS, PA Data Breach
NC Dental Practice Hit by Network Server Breach
What happened in the Mary H. Makhlouf, DMD, MS, PA data breach?
The Mary H. Makhlouf, DMD, MS, PA data breach was reported on March 22, 2024 and affected 1,797 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in North Carolina. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Mary H. Makhlouf, DMD, MS, PA Breach Details
Healthcare Data Breach Report: Mary H. Makhlouf, DMD, MS, PA
Incident Overview
On March 22, 2024, Mary H. Makhlouf, DMD, MS, PA, a dental practice located in North Carolina, reported a significant data breach affecting 1,797 patients. The breach resulted from unauthorized access to the practice's network server infrastructure, compromising protected health information (PHI) stored within their clinical and administrative systems. This incident represents a hacking or IT-related security compromise rather than physical theft or loss of records, indicating that attackers gained unauthorized entry into the practice's digital systems.
Discovery and Response Timeline
The dental practice discovered the unauthorized access to their network server and initiated an investigation into the scope and nature of the compromise. Following discovery, the practice took steps to secure their systems, investigate the breach, and comply with HIPAA Breach Notification Rule requirements. The submission date of March 22, 2024, indicates when the breach was formally reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), which typically occurs after the entity has completed its investigation and determined the scope of affected individuals. The practice likely notified affected patients within the 60-day window required by HIPAA regulations, though specific notification dates were not provided in the breach submission data.
Technical Details of the Breach
Network server breaches typically occur through various attack vectors including but not limited to: exploitation of unpatched software vulnerabilities, weak or compromised credentials, phishing attacks targeting staff members, inadequate firewall configurations, or insufficient access controls. The location designation of "Network Server" indicates that the breach occurred at the infrastructure level rather than affecting individual workstations or portable devices. This suggests that attackers may have gained access to centralized systems where patient records, appointment data, billing information, and clinical notes are stored. Network server compromises are particularly concerning because they can potentially expose large volumes of data simultaneously and may indicate a more sophisticated attack than isolated device theft. The fact that no business associate was involved suggests the practice maintained its own IT infrastructure rather than outsourcing to a third-party vendor, meaning the practice bears direct responsibility for security controls.
Organizational Context
Mary H. Makhlouf, DMD, MS, PA, operates as a dental practice in North Carolina. The credentials "DMD, MS, PA" indicate the practice is led by a dentist with advanced education (Doctor of Dental Medicine and Master of Science) and operates as a professional association. Dental practices, while smaller than hospital systems, maintain comprehensive patient records including personal identifiers, insurance information, treatment histories, and potentially medical conditions relevant to dental care. The practice's patient population of 1,797 affected individuals suggests a mid-sized dental practice serving a local or regional patient base within North Carolina. Dental practices are covered entities under HIPAA and must maintain appropriate safeguards for electronic protected health information (ePHI), including administrative, physical, and technical security measures.
Patient Impact and Affected Information
Approximately 1,797 patients of Mary H. Makhlouf, DMD, MS, PA, were affected by this breach. While the specific data elements compromised were not detailed in the breach submission, network server breaches at dental practices typically expose multiple categories of protected health information. Patients should assume that their records may have included: names, addresses, telephone numbers, email addresses, dates of birth, Social Security numbers, insurance information (including policy numbers and group numbers), dental treatment records and clinical notes, medical history information relevant to dental care, payment and billing records, and potentially emergency contact information. The exposure of this combination of data elements creates significant risk for identity theft, insurance fraud, and targeted phishing attacks.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of breaches of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery of the breach. The practice was also required to notify prominent media outlets if the breach affected more than 500 residents of a state or jurisdiction, and to notify the HHS Secretary. Network server breaches represent a significant portion of healthcare data breaches reported annually, accounting for a substantial percentage of incidents affecting covered entities and business associates. According to HHS OCR data, hacking and IT incidents have become increasingly common in healthcare, reflecting the growing sophistication of cyber threats targeting healthcare providers. Dental practices, despite their smaller size compared to hospitals, are attractive targets for cybercriminals because they often have less strong cybersecurity infrastructure than larger healthcare systems while maintaining valuable patient data.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Mary H. Makhlouf, DMD, MS, PA Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze with each bureau to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements and insurance claims from your dental insurance provider for any unauthorized services or claims you did not receive
Monitor bank and credit card statements for unauthorized transactions; consider placing fraud alerts with your financial institutions and reviewing account activity regularly for the next 12-24 months
Be vigilant against phishing emails, text messages, and phone calls claiming to be from the dental practice, insurance companies, or financial institutions; verify any requests for personal information by contacting organizations directly using known phone numbers or websites
Consider enrolling in identity theft protection or credit monitoring services if offered by the practice or available through your insurance; these services can provide early warning of suspicious activity
Change passwords for any online accounts associated with the dental practice or related healthcare portals, using strong, unique passwords
Document the breach and keep records of any fraudulent activity discovered; report identity theft to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a police report if fraud occurs
Contact the dental practice directly to confirm your information was affected and inquire about specific data elements compromised and any remediation efforts being undertaken
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More North Carolina Breaches
Search all breaches reported in North Carolina