Menu
Browse

Cyber Incident Victim: Smith Dental

Date:

Nov 2017

Location:

United States of America

Summary

A ransomware attack targeted a Tennessee dental practice's internal servers, potentially compromising clinical, demographic, and financial information of approximately 1,500 patients. While no evidence indicated protected health information was accessed or exfiltrated, the entity implemented additional physical and technical safeguards to prevent future incidents. Affected individuals were advised to consider credit monitoring services and provided a contact number for inquiries, though details regarding direct patient notifications remained unclear. The incident was reported to federal health authorities following delayed public disclosure via the practice's website.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Smith Dental, a dental practice in Tennessee, experienced a ransomware attack targeting its internal computer servers in November 2017. The incident was reported to the U.S. Department of Health and Human Services (HHS) on January 22, 2023, over five years after the attack occurred. The HHS breach report classified the event as a hacking/IT incident affecting approximately 1,500 patients. While the practice stated it found no evidence that protected health information was accessed, copied, or distributed, it acknowledged the potential compromise of clinical, demographic, and financial information belonging to patients. The delayed notification timeline and absence of immediate public disclosure raised questions about incident response protocols.

Cyber Incident Image

The practice eventually posted a notice on its website's About section, though the exact publication date remained unclear as of February 2023. This notice advised patients to consider securing their credit profiles or enrolling in commercial credit monitoring services, shifting responsibility for protective measures to affected individuals. Smith Dental provided a dedicated phone number (877-480-0566) for patient inquiries but did not confirm whether formal breach notification letters were mailed to impacted individuals. The practice implemented additional physical and technical safeguards following the attack, expressing confidence in preventing future incidents. Multiple attempts by media outlets to obtain clarification regarding notification methods and mitigation support received no substantive response beyond automated acknowledgments.

Sources
Sources available to members
1 source