Cyber Incident Victim: Smith Dental
Date:
Nov 2017
Location:
United States of America
Summary
A ransomware attack targeted a Tennessee dental practice's internal servers, potentially compromising clinical, demographic, and financial information of approximately 1,500 patients. While no evidence indicated protected health information was accessed or exfiltrated, the entity implemented additional physical and technical safeguards to prevent future incidents. Affected individuals were advised to consider credit monitoring services and provided a contact number for inquiries, though details regarding direct patient notifications remained unclear. The incident was reported to federal health authorities following delayed public disclosure via the practice's website.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Smith Dental, a dental practice in Tennessee, experienced a ransomware attack targeting its internal computer servers in November 2017. The incident was reported to the U.S. Department of Health and Human Services (HHS) on January 22, 2023, over five years after the attack occurred. The HHS breach report classified the event as a hacking/IT incident affecting approximately 1,500 patients. While the practice stated it found no evidence that protected health information was accessed, copied, or distributed, it acknowledged the potential compromise of clinical, demographic, and financial information belonging to patients. The delayed notification timeline and absence of immediate public disclosure raised questions about incident response protocols.

The practice eventually posted a notice on its website's About section, though the exact publication date remained unclear as of February 2023. This notice advised patients to consider securing their credit profiles or enrolling in commercial credit monitoring services, shifting responsibility for protective measures to affected individuals. Smith Dental provided a dedicated phone number (877-480-0566) for patient inquiries but did not confirm whether formal breach notification letters were mailed to impacted individuals. The practice implemented additional physical and technical safeguards following the attack, expressing confidence in preventing future incidents. Multiple attempts by media outlets to obtain clarification regarding notification methods and mitigation support received no substantive response beyond automated acknowledgments.
