Menu
Browse

Cyber Incident Victim: Dental Health Associates, P.A.

Date:

Oct 2020

Location:

United States of America

Summary

Dental Health Associates, P.A. had protected health information exposed when threat actors affiliated with the REvil (Sodinokibi) ransomware group attacked a dental hygienists' association and dumped over 70,000 files containing the entity's documents and letterhead on a dedicated leak site. The incident, involving unauthorized access to sensitive patient data, was part of a broader pattern of ransomware attacks targeting medical sector entities, with multiple healthcare providers experiencing similar breaches and subsequent data leaks by various threat actor groups when ransom demands went unmet.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

The incident involving Dental Health Associates, P.A. occurred in the context of a ransomware attack against the New Jersey Dental Hygienists’ Association (NJDHA) by the REvil (Sodinokibi) threat actor group. The attack was initiated on or shortly after October 20, 2020. REvil operators exfiltrated and subsequently dumped over 70,000 files from NJDHA systems onto their dedicated leak site. Forensic analysis of the leaked data revealed numerous files containing Dental Health Associates, P.A.’s name and letterhead, indicating that their protected information was compromised during the breach of NJDHA. This collateral exposure occurred despite no direct evidence that REvil targeted Dental Health Associates’ own infrastructure. The threat actors employed ransomware tactics typical of REvil operations, involving data encryption, exfiltration, and extortion through the threat of public data disclosure.

Cyber Incident Image

The compromised Dental Health Associates records exposed through NJDHA’s breach included unspecified sensitive information, though the exact data categories and patient impact volume were not publicly disclosed. No evidence indicated Dental Health Associates independently detected or reported a breach of their systems, suggesting the compromise originated solely through their association with NJDHA. As of the article’s publication date, Dental Health Associates had not issued public statements, breach notifications to patients, or submissions to HHS’s breach portal regarding this incident. The absence of documented containment actions or communications left the full scope of impacts on Dental Health Associates’ patients unverified. REvil’s data dump remained publicly accessible, perpetuating ongoing risks of misuse of the exposed dental health information.

Sources
Sources available to members
1 source