Absolute Dental Notifies 1.2 Million Individuals About Data Breach
A Nevada dental care provider has recently announced a data breach that potentially involved unauthorized access to the protected health information of more than 1.2 million individuals, making it the sixth-largest healthcare data breach to be reported this year, and the largest dental practice data breach of 2025.
Absolute Dental has more than 50 locations throughout Nevada, including Las Vegas, Reno, Minden, Sparks, and Carson City. Suspicious activity was identified within its computer systems on February 26, 2025. Third-party digital forensics experts were engaged to investigate the activity and confirmed that an unauthorized third party had access to its systems between February 19, 2025, and March 5, 2025.
“The unauthorized access appears to have originated from the inadvertent execution of a malicious version of a legitimate software tool, which occurred through an account associated with Absolute Dental’s third-party managed services provider,” explained Absolute Dental in its substitute data breach notice. Hackers often target managed services providers, as an attack on one MSP can allow the hacker to attack multiple downstream clients. The use of a legitimate tool, albeit a weaponized version, can make compromises much harder to identify.
Absolute Dental conducted a file review to identify all exposed files within its computer systems and concluded on July 28, 2025, that sensitive data had been exposed, including names, birth dates, Social Security numbers, driver’s license numbers/state ID numbers, passport or other government ID information, and health insurance information, including heath histories, diagnoses, treatment information, health insurance information, MRN numbers or patient identification numbers, and explanation of benefits. A limited number of the affected individuals may also have had payment card information and/or financial account information compromised.
Absolute Dental mailed notification letters on August 26, 2025, and has offered the affected individuals two years of credit monitoring services as a precaution, although no misuse of the affected data has been identified. The data breach is not currently listed on the HHS’ Office for Civil Rights breach portal, but state attorneys general have started adding the data breach to their websites, and one of those reports shows the incident affected 1,223,635 individuals.