The Bayside Dental 2026 data breach involved unauthorized access to the network of the dental practice in Anacortes, Washington and the possibility that certain files were removed. Bayside Dental said it detected unauthorized access on or about January 5, 2026, secured its network, and began a thorough investigation with external cybersecurity professionals.
The U.S. Department of Health and Human Services Office for Civil Rights portal lists 10,216 total affected people for Bayside Dental. A secondary source summarizing the Washington filing reports 9,683 Washington residents; that state subset is not added to the total. importedRecordCount is zero because no raw patient data was obtained.
How Was the Bayside Dental Incident Verified?
The primary source is the Bayside Dental letter published through the Washington Attorney General's notification system. It describes the January 5 detection, possible access or removal of files, the March 13 data-review conclusion, possible information fields, credit-monitoring services, and the organization's response.
The second source is the HHS/OCR federal row reported April 17, 2026 for 10,216 people, classifying the event as a network-server Hacking/IT Incident. The third is ClaimDepot's summary comparing Washington, Massachusetts, New Hampshire, and HHS filings. The production search found no matching record for the entity, domain, likely slugs, or 2026 period.
Incident Timeline
According to the official letter, Bayside Dental detected unauthorized access to its network on or about January 5, 2026. The investigation found that some files may have been accessed or removed by an unauthorized individual that day. breachDate, dateOccurred, and dateDiscovered use this verified date.
The practice then reviewed potentially affected data to identify the information categories and related people. On March 13, 2026, it determined that the files may have contained personal health information. The HHS April 17 report date is a notification time and is not presented as the attack start.
What Information May Have Been Involved?
According to Bayside Dental's letter, possible fields include a full name, date of birth, Social Security number, patient number, and dates of service. Health-related information includes health insurance information, health-plan beneficiary information, medical treatment information, and medical diagnostic information.
The document says files “may have been accessed or removed” and that the combination varied by person. It should not be assumed that every field was present or definitely taken for all 10,216 people. Passwords, payment cards, prescriptions, bank accounts, and categories absent from the official letter were not added.
10,216 Total and 9,683 Washington Residents
10,216 is the total affected-person count published by HHS/OCR for Bayside Dental and is used for pwnCount and totalRecords. ClaimDepot's 9,683 figure, based on the Washington regulator filing, is the state-resident subset. The two figures do not describe separate breaches and are not added together.
importedRecordCount 0 means LeakData did not receive raw patient records containing names, Social security numbers, or medical information. The incident volume displayed to users is 10,216 people, while the number of searchable person-level records is zero. Zero imports do not make the event unreal or mean no one was affected.
Identity and Medical Privacy Risks
A combination of name, date of birth, and Social Security number can support identity fraud and targeted phishing. People whose Social security numbers were involved were offered 12 months of single-bureau credit monitoring, a credit report, credit score, and proactive fraud assistance through Cyberscout. This record does not claim a service period beyond the letter.
Patient numbers, dates of service, treatment, diagnosis, and insurance information create medical identity-theft risk. Users should review insurance explanations for services they did not receive, unfamiliar claims, and incorrect medical records. Suspicious activity should be reported directly to the healthcare provider and insurer.
Organization Response and Steps for Individuals
Bayside Dental said it secured the network, investigated with external specialists, and continually evaluated its information-security practices and internal controls. At the time of the official letter, it had no evidence that personal information had been used for financial fraud or identity theft. The organization nevertheless notified people as a precaution.
Recipients should use the Cyberscout enrollment code in their letter within the stated 90-day period and monitor credit reports and insurance statements. This record was prepared by comparing the Washington Attorney General letter, HHS/OCR row, and an independent incident summary while keeping the total and state subset separate.