
Aldrich Pediatric Dentistry 2026 Data Breach (5.9 Thousand People Affected)
The 2026 Aldrich Pediatric Dentistry data breach involved an employee email account compromised through a phishing attack on January 16, 2026. The practice says it learned of the incident on February 24, secured the account, and ended the attacker's access.
The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as a hacking/information-technology incident involving email and reported 5,900 affected individuals.
Verified Incident TimelineAccording to the official notice, the employee account was compromised on January 16, 2026. The practice learned of the incident on February 24, required password changes, and implemented additional safeguards against future phishing attempts.
The practice says it found no evidence that the attacker was seeking patient information or accessed that information in the account. The public documents do not describe the phishing message or identify the responsible party.
What Information May Have Been Affected?The email account contained names, addresses, email addresses, telephone numbers, dates of service, procedures, and insurance information. The official notice expressly says the patient information did not include Social Security numbers or financial account numbers.
Medical-service and insurance details can make a fraudulent message more convincing when it refers to a real appointment or payment. Recipients should not provide additional health information, a password, a verification code, or payment details in an unexpected communication.
The 5,900-Person TotalThe HHS record reports 5,900 affected individuals. The public documents do not provide counts by data field, so this total does not mean that every person had the same information involved.
What Should Affected People Do?Notice recipients should monitor health-care accounts, insurance claims, and explanation-of-benefits statements for an unfamiliar transaction or service. If something looks suspicious, contact the insurer or health-care provider through a verified channel rather than a link in the message.