ProSmile Holdings, LLC Data Breach
ProSmile Holdings Email Breach Affects 39,674 Patients
What happened in the ProSmile Holdings, LLC data breach?
The ProSmile Holdings, LLC data breach was reported on March 28, 2023 and affected 39,674 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in New Jersey. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
ProSmile Holdings, LLC Breach Details
ProSmile Holdings Data Breach Report
Incident Overview
ProSmile Holdings, LLC, a dental healthcare provider based in New Jersey, experienced a significant data breach involving unauthorized access to patient email systems. The breach was discovered and reported to state authorities on March 28, 2023, affecting approximately 39,674 individuals. The unauthorized access occurred through the organization's email infrastructure, a common attack vector for healthcare entities that often contain sensitive patient information including appointment details, treatment records, and personal health information. This incident represents a substantial compromise of patient privacy and triggers mandatory notification requirements under the Health Insurance Portability and Accountability Act (HIPAA).
Discovery and Response Timeline
ProSmile Holdings identified the unauthorized access to its email systems through security monitoring and investigation protocols. Upon discovery, the organization initiated a comprehensive forensic investigation to determine the scope of the breach, identify affected individuals, and assess what specific patient information may have been accessed or exfiltrated. The entity worked with cybersecurity professionals to secure the compromised systems and prevent further unauthorized access. The breach was reported to the New Jersey Attorney General's office on March 28, 2023, in compliance with state data breach notification laws. ProSmile Holdings subsequently began the process of notifying affected patients of the incident, providing them with information about the breach and recommended protective measures. The organization also coordinated with relevant regulatory bodies and, where applicable, business associates involved in the breach response.
Technical Details of the Breach
The breach involved a hacking or IT incident targeting ProSmile Holdings' email systems. Email systems are frequently targeted by threat actors because they typically contain a wealth of sensitive information and often serve as a gateway to broader organizational networks. Common attack vectors for email compromise include phishing campaigns, credential stuffing, exploitation of unpatched vulnerabilities, and brute-force attacks against weak authentication mechanisms. The fact that a business associate was involved in this breach suggests that the compromised systems may have included shared infrastructure or that patient data was accessible through third-party service providers. Email breaches of this nature typically result in unauthorized access to message contents, attachments, and metadata, potentially exposing patient names, contact information, dates of birth, insurance details, and clinical information referenced in email communications. The scale of this incident—affecting nearly 40,000 individuals—indicates either a prolonged period of unauthorized access or a broad compromise affecting multiple email accounts or distribution lists.
Organizational Context
ProSmile Holdings, LLC operates as a dental healthcare provider in New Jersey, likely managing multiple dental practices or clinics across the state. Dental practices, while often smaller than hospital systems, maintain comprehensive patient records that include personal identifiers, insurance information, and detailed clinical notes about treatments and procedures. The involvement of a business associate suggests ProSmile Holdings may utilize third-party vendors for services such as billing, claims processing, patient communication platforms, or IT infrastructure management. The organization's size and scope—serving nearly 40,000 affected patients—indicates it operates a substantial network of dental facilities or maintains a large patient population across its service area. Dental healthcare providers are subject to the same HIPAA Privacy, Security, and Breach Notification Rules as other covered entities and must maintain appropriate safeguards for protected health information (PHI).
Patient Impact and Affected Population
Approximately 39,674 individuals were affected by this breach, representing a significant portion of ProSmile Holdings' patient population. These patients had their email systems and associated communications compromised, meaning that any patient information contained within email messages, attachments, or email metadata may have been accessed by unauthorized parties. Affected individuals likely include current and former patients of ProSmile Holdings' dental practices. The compromised information may include names, addresses, phone numbers, email addresses, dates of birth, insurance information, treatment histories, appointment details, and other clinical information referenced in email communications. Patients were notified of the breach in accordance with HIPAA's Breach Notification Rule, which requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. The notification process included information about the nature of the breach, the types of information compromised, steps the organization was taking to address the incident, and recommended actions patients should take to protect themselves.
HIPAA Compliance and Industry Context
Under HIPAA's Breach Notification Rule, covered entities must notify affected individuals, the media (if more than 500 residents of a state are affected), and the U.S. Department of Health and Human Services (HHS) of breaches of unsecured PHI. Email system breaches represent a significant category of healthcare data breaches, consistently ranking among the most common breach types reported to HHS. According to HHS breach notification data, email-related incidents frequently involve either hacking of email accounts or inadvertent disclosure through misdirected messages. The involvement of a business associate in this breach underscores the importance of Business Associate Agreements (BAAs) and the requirement that covered entities ensure their business associates implement appropriate administrative, physical, and technical safeguards for PHI. ProSmile Holdings was required to conduct a risk assessment to determine whether the breach posed a significant risk of harm to affected individuals—a determination that likely resulted in the decision to notify patients given the scale of the incident and the sensitivity of dental health information. The organization must also implement corrective action plans to address the vulnerabilities that allowed the breach to occur, which may include enhanced email security controls, multi-factor authentication, employee security awareness training, and improved access controls.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the ProSmile Holdings, LLC Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review dental and medical insurance statements and explanation of benefits (EOBs) for unauthorized claims or services. Contact your insurance provider immediately if you identify suspicious activity.
Change passwords for email accounts and any online healthcare portals, using strong, unique passwords with a combination of uppercase, lowercase, numbers, and special characters. Enable multi-factor authentication where available.
Enroll in complimentary credit monitoring and identity theft protection services offered by ProSmile Holdings as part of their breach response. These services typically provide credit monitoring, dark web monitoring, and identity theft insurance for 12-24 months.
Be vigilant against phishing emails and social engineering attempts. Verify requests for personal information by contacting organizations directly using phone numbers from official websites rather than responding to unsolicited communications.
Consider placing a security freeze with credit bureaus to prevent unauthorized access to your credit file. This is a free service and provides strong protection against identity theft.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you suspect identity theft or fraudulent activity related to this breach.
Request a copy of your credit report and review it carefully for errors or unauthorized accounts. You are entitled to one free credit report annually from each bureau through AnnualCreditReport.com.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More New Jersey Breaches
Search all breaches reported in New Jersey
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits