Smile Doctors of Arizona, P.C. d/b/a Grinz Orthodontics ("Grinz Orthodontics") Data Breach
Grinz Orthodontics Desktop Computer Theft Exposes 1,034 Patients
What happened in the Smile Doctors of Arizona, P.C. d/b/a Grinz Orthodontics ("Grinz Orthodontics") data breach?
The Smile Doctors of Arizona, P.C. d/b/a Grinz Orthodontics ("Grinz Orthodontics") data breach was reported on May 9, 2023 and affected 1,034 individuals. The breach type was Theft involving Desktop Computer. This breach occurred in Arizona. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Smile Doctors of Arizona, P.C. d/b/a Grinz Orthodontics ("Grinz Orthodontics") Breach Details
Breach Overview
Smile Doctors of Arizona, P.C., operating under the name Grinz Orthodontics, experienced a data breach involving the theft of a desktop computer containing patient health information. The breach was reported to the Arizona Attorney General on May 9, 2023, affecting 1,034 individuals. The stolen desktop computer contained unencrypted or inadequately protected patient records, including protected health information (PHI) typically maintained by orthodontic practices. This incident represents a common but preventable breach vector in healthcare settings where physical security controls may not adequately protect devices containing sensitive patient data.
Company Response
Upon discovery of the theft, Grinz Orthodontics initiated an investigation to determine the scope of the breach and identify which patient records were stored on the affected desktop computer. The organization notified affected individuals of the breach in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. The entity also filed the required notification with the Arizona Attorney General's office, as required by state law for breaches affecting Arizona residents. The investigation determined that the theft occurred at the physical location where the desktop computer was maintained, and that patient data had been accessible on the device.
Specific Details
The breach involved the physical theft of a desktop computer—a stationary device typically located in an office, clinical workspace, or administrative area. Desktop computer thefts in healthcare settings often occur due to inadequate physical security measures, such as lack of cable locks, absence of access controls to equipment storage areas, or insufficient monitoring of valuable IT assets. Unlike portable devices such as laptops or mobile phones, desktop computer thefts may indicate either opportunistic theft or targeted removal of equipment. The fact that the device contained patient data suggests that Grinz Orthodontics may not have implemented adequate data minimization practices (storing only necessary data on individual workstations) or encryption protocols that would have rendered the data inaccessible to unauthorized parties. Desktop computers in healthcare settings should typically be configured with full-disk encryption, access controls, and regular security audits to prevent such incidents.
Organizational Context
Smile Doctors of Arizona, P.C., d/b/a Grinz Orthodontics, is an orthodontic practice providing dental and orthodontic services in Arizona. Orthodontic practices are covered entities under HIPAA and must comply with the Privacy, Security, and Breach Notification Rules. As a dental specialty practice, Grinz Orthodontics maintains comprehensive patient records including treatment plans, clinical notes, radiographic images, and financial information. The organization operates as a healthcare provider subject to HIPAA's administrative, physical, and technical safeguards requirements. The breach of a desktop computer suggests potential gaps in the organization's physical security safeguards, which are required under HIPAA's Security Rule to protect electronic information systems and related facilities from unauthorized physical access.
Patient Impact and Notifications
Approximately 1,034 individuals were affected by this breach. These patients had received orthodontic treatment or services at Grinz Orthodontics and had their personal health information stored on the stolen desktop computer. Affected individuals were notified of the breach through written notification letters sent by the organization, as required by HIPAA regulations. The notification letters typically included information about the nature of the breach, the types of information involved, steps the organization was taking to investigate and prevent future incidents, and recommended actions patients should take to protect themselves. Patients were advised to monitor their accounts and credit reports for signs of identity theft or fraud, and to consider placing fraud alerts or credit freezes with credit reporting agencies if they were concerned about potential misuse of their information.
Industry Context and HIPAA Implications
Physical theft of computing devices containing patient data remains a significant source of healthcare data breaches. According to breach notification data, theft accounts for a substantial percentage of healthcare breaches, particularly in smaller healthcare organizations and specialty practices that may have limited IT security resources. The HIPAA Security Rule requires covered entities to implement physical safeguards including facility access controls, workstation use policies, workstation security, and device and media controls. These requirements mandate that healthcare organizations implement measures such as cable locks for desktop computers, restricted access to areas where computing devices are stored, inventory management of IT assets, and secure disposal of devices containing patient data. The breach at Grinz Orthodontics illustrates the importance of these physical security controls, which are often overlooked in favor of network-based security measures. Healthcare organizations are increasingly required to implement comprehensive security programs that address both digital and physical threats to patient information. The notification of this breach to the Arizona Attorney General and affected patients demonstrates the organization's compliance with state and federal breach notification requirements, though the incident itself indicates that preventive physical security measures may have been insufficient prior to the theft.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Smile Doctors of Arizona, P.C. d/b/a Grinz Orthodontics ("Grinz Orthodontics") Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider obtaining free annual credit reports at annualcreditreport.com and reviewing them carefully for suspicious activity.
Place a fraud alert with at least one of the three major credit bureaus, which will require creditors to verify your identity before opening new accounts. You can also consider a credit freeze to prevent unauthorized access to your credit file.
Monitor financial accounts, credit card statements, and insurance explanations of benefits (EOBs) for unauthorized charges or claims. Report any suspicious activity to your financial institutions and insurance providers immediately.
Watch for suspicious communications claiming to be from healthcare providers, insurance companies, or financial institutions. Be cautious of phishing emails or calls attempting to obtain additional personal information, and verify any requests directly with the organization.
Consider placing a security freeze with the three major credit bureaus if you are concerned about identity theft risk. This prevents new credit accounts from being opened without your explicit authorization.
Document the breach notification and keep records of any communications from Grinz Orthodontics regarding the incident for your records and potential future reference.
If you notice any signs of identity theft or fraud, file a report with the Federal Trade Commission (FTC) at identitytheft.gov and contact local law enforcement.
Review your orthodontic and dental records with Grinz Orthodontics to ensure accuracy and request confirmation that your information is being properly secured going forward.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Arizona Breaches
Search all breaches reported in Arizona