Cyber Incident Victim: North American Dental Management
Date:
Mar 2021
Location:
United States of America
Summary
A cyber-attack via email phishing compromised a vendor supporting a network of dental practices, leading to unauthorized access to email accounts containing patient information. The incident exposed protected health details including names, addresses, contact information, dental and insurance records, Social Security Numbers, and financial account data for over 125,000 patients across multiple states. The affected vendor secured the breached accounts, initiated an investigation, and confirmed no evidence of data misuse. Impacted individuals were offered complimentary credit monitoring and identity theft protection services for two years following regulatory reporting.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 31, 2021, unauthorized individuals gained access to email accounts belonging to North American Dental Management (NADM), a vendor providing administrative and technical support services for Professional Dental Alliance (PDA) dental offices. The breach persisted until April 1, 2021, stemming from a phishing attack that compromised employee credentials. NADM secured the affected email accounts upon discovery and initiated an investigation to determine the scope. PDA, notified by its vendor, subsequently determined that protected health information stored within those email accounts might have been accessed. The incident was attributed to credential harvesting through phishing, with no evidence suggesting broader system infiltration beyond the compromised email accounts. Grove Dental Associates, a PDA affiliate, publicly disclosed that the attacker's identity remained partially unknown as NADM's investigation continued.

Exposed patient information potentially included names, addresses, email addresses, phone numbers, dental treatment details, insurance information, Social Security Numbers, and financial account numbers. The breach impacted 125,760 patients across dental practices in ten U.S. states, prompting PDA to file a report with the Department of Health and Human Services' Office for Civil Rights. While no actual misuse of data was confirmed, PDA offered affected individuals two years of complimentary credit monitoring and identity theft protection services. NADM reinforced email security measures following containment, though specific technical enhancements were not detailed in public statements. Notification letters were distributed to patients without delay once the compromised data types and affected population were identified through forensic analysis.
