[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgSAmVuFIX_UocAr-uezh7fuWlGKX_0rVSRInlMD75ew":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":18,"dataClasses":19,"description":29,"source":30,"isVerified":4,"isSpamList":31,"isSensitive":4,"processingStatus":32,"logoUrl":33,"contentUpdatedAt":17,"hasEnglishDescription":4,"severity":34},"6a67759e3a4efcd35a7ffd10","BaysideDental2026","Bayside Dental 2026 Data Breach","bayside-dental-2026","baysidedentalwa.com",{"name":12,"sector":13,"country":14,"website":10},"Bayside Dental","Healthcare","United States","2026-01-05T00:00:00.000Z","2026-07-27T15:13:34.881Z","2026-07-27T16:11:12.197Z",10216,[20,21,22,23,24,25,26,27,28],"Full names","Dates of birth","Social Security numbers","Health insurance information","Health plan beneficiary information","Medical treatment information","Medical diagnostic information","Patient numbers","Dates of service","\u003Cp>\u003Cstrong>The Bayside Dental 2026 data breach\u003C\u002Fstrong> involved unauthorized access to the network of the dental practice in Anacortes, Washington and the possibility that certain files were removed. Bayside Dental said it detected unauthorized access on or about January 5, 2026, secured its network, and began a thorough investigation with external cybersecurity professionals.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights portal lists 10,216 total affected people for Bayside Dental. A secondary source summarizing the Washington filing reports 9,683 Washington residents; that state subset is not added to the total.\u003C\u002Fp>\u003Ch2>How Was the Bayside Dental Incident Verified?\u003C\u002Fh2>\u003Cp>The primary source is the Bayside Dental letter published through the Washington Attorney General's notification system. It describes the January 5 detection, possible access or removal of files, the March 13 data-review conclusion, possible information fields, credit-monitoring services, and the organization's response.\u003C\u002Fp>\u003Cp>The second source is the HHS\u002FOCR federal row reported April 17, 2026 for 10,216 people, classifying the event as a network-server Hacking\u002FIT Incident. The third is ClaimDepot's summary comparing Washington, Massachusetts, New Hampshire, and HHS filings.\u003C\u002Fp>\u003Ch2>Incident Timeline\u003C\u002Fh2>\u003Cp>According to the official letter, Bayside Dental detected unauthorized access to its network on or about January 5, 2026. The investigation found that some files may have been accessed or removed by an unauthorized individual that day. The incident date is based on the earliest technical activity that can be verified from public sources.\u003C\u002Fp>\u003Cp>The practice then reviewed potentially affected data to identify the information categories and related people. On March 13, 2026, it determined that the files may have contained personal health information. The HHS April 17 report date is a notification time and is not presented as the attack start.\u003C\u002Fp>\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\u003Cp>According to Bayside Dental's letter, possible fields include a full name, date of birth, Social Security number, patient number, and dates of service. Health-related information includes health insurance information, health-plan beneficiary information, medical treatment information, and medical diagnostic information.\u003C\u002Fp>\u003Cp>The document says files “may have been accessed or removed” and that the combination varied by person. It should not be assumed that every field was present or definitely taken for all 10,216 people. Passwords, payment cards, prescriptions, bank accounts, and categories absent from the official letter were not treated as confirmed.\u003C\u002Fp>\u003Ch2>10,216 Total and 9,683 Washington Residents\u003C\u002Fh2>\u003Cp>The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person. ClaimDepot's 9,683 figure, based on the Washington regulator filing, is the state-resident subset. The two figures do not describe separate breaches and are not added together.\u003C\u002Fp>\u003Cp>When an official individual notice is available, its listed data categories and protection options should guide the assessment of personal exposure.\u003C\u002Fp>\u003Ch2>Identity and Medical Privacy Risks\u003C\u002Fh2>\u003Cp>A combination of name, date of birth, and Social Security number can support identity fraud and targeted phishing. People whose Social Security numbers were involved were offered 12 months of single-bureau credit monitoring, a credit report, credit score, and proactive fraud assistance through Cyberscout. Public sources do not establish a service period beyond the letter.\u003C\u002Fp>\u003Cp>Patient numbers, dates of service, treatment, diagnosis, and insurance information create medical identity-theft risk. Users should review insurance explanations for services they did not receive, unfamiliar claims, and incorrect medical records. Suspicious activity should be reported directly to the healthcare provider and insurer.\u003C\u002Fp>\u003Ch2>Organization Response and Steps for Individuals\u003C\u002Fh2>\u003Cp>Bayside Dental said it secured the network, investigated with external specialists, and continually evaluated its information-security practices and internal controls. At the time of the official letter, it had no evidence that personal information had been used for financial fraud or identity theft. The organization nevertheless notified people as a precaution.\u003C\u002Fp>\u003Cp>Recipients should use the Cyberscout enrollment code in their letter within the stated 90-day period and monitor credit reports and insurance statements. If a suspicious message or account event appears, it should be verified through the organization’s current official contact channel without using links in the message. When an individual notification letter is available, it is the primary source for the person-specific data scope and protection options offered. Dates and data categories should be interpreted only to the extent supported by public sources; undisclosed details should not be treated as confirmed. Regular review of credit, financial, and healthcare accounts can help identify possible misuse early.\u003C\u002Fp>","Washington Attorney General notice, HHS\u002FOCR breach report, and ClaimDepot",false,"completed","\u002Fuploads\u002Flogo\u002Fbaysidedentalwa_com.jpg","Medium"]