[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSL1HWd_pQAl7JX6KxrTXRJ_u3pHef8xHzKMbbdmbM4g":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":25,"source":26,"isVerified":4,"isSpamList":27,"isSensitive":4,"severity":28,"processingStatus":29,"logoUrl":30,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66f42d7440216073d3046e","CureDental2025","Cure Dental 2025 Data Breach","cure-dental-2025","curedentalbeltontx.com",{"name":12,"sector":13,"country":14,"website":10},"Cure Dental","Healthcare","United States","2025-06-25T00:00:00.000Z","2026-07-27T06:01:17.257Z",878,[19,20,21,22,23,24],"Personal information","Names","Addresses","Dates of birth","Social Security numbers","Driver's license numbers","\u003Cp>\u003Cstrong>The Cure Dental 2025 data breach\u003C\u002Fstrong> was discovered when the dental practice in Belton, Texas detected an unauthorized cyber intrusion on June 25, 2025. Its official patient notice says the event potentially affected personally identifiable information belonging to up to 878 current and former patients; the patient-record platform was restored quickly and archive data was not affected.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights lists the Cure Dental event as a Hacking\u002FIT Incident affecting 878 people. LeakData imported no patient or person rows, and importedRecordCount is zero. This entry presents only verified event metadata from the official notice and a reliable second source.\u003C\u002Fp>\n\u003Ch2>How Was the Cure Dental Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is Cure Dental's Website Notice to Patients on its own domain. The practice directly explains the discovery date, technical response, possible personal-data fields, its finding that patient PHI was not affected, and identity-protection steps recommended to patients.\u003C\u002Fp>\n\u003Cp>The second confirmation is HHS OCR's breach report, which identifies Cure Dental as a healthcare provider, classifies the event as a hacking\u002FIT incident involving a network server, reports 878 individuals, and gives a June 23, 2026 submission date. Claim Depot independently reports the same count, discovery date, and data categories using the official page and HHS record.\u003C\u002Fp>\n\u003Ch2>What Happened on June 25, 2025?\u003C\u002Fh2>\n\u003Cp>After detecting unauthorized cyber access, the practice immediately locked down its network, terminated external connections, disabled accounts with remote-desktop web access, and forced an office-wide password reset. Its cybersecurity platform detected and effectively stopped the movement of malicious activity across the network.\u003C\u002Fp>\n\u003Cp>The official text describes what appeared to be a ransomware attack but does not identify an attacker or group. The intruder later contacted the office several times and demanded that staff manually activate malware files left on the system; staff did not comply and the attempts stopped. LeakData adds no unverified group attribution.\u003C\u002Fp>\n\u003Ch2>Which Systems and Data May Have Been Affected?\u003C\u002Fh2>\n\u003Cp>The investigation found that the patient-record platform, although restricted, was restored quickly and archive data was not affected. Still, the practice determined that some personal information associated with patients may have been accessed during the event. The sources do not disclose an exact file count, download volume, or access duration.\u003C\u002Fp>\n\u003Cp>The breachDate field uses June 25, 2025, the verified detection date, without presenting it as the first day of access. The official notice says information may have been accessed but does not confirm that it was published or sold. The HHS submission date roughly one year later is a regulatory-reporting step, not the incident date.\u003C\u002Fp>\n\u003Ch2>What Personal Information Was at Risk?\u003C\u002Fh2>\n\u003Cp>Potentially affected fields include a name, address, date of birth, Social Security number, and driver's-license number. This combination creates substantial exposure to fraudulent account opening, impersonation, credit fraud, and targeted social engineering. The practice also reported that one patient received a call from someone posing as an information-technology professional.\u003C\u002Fp>\n\u003Cp>The patient immediately ended the call and informed the practice, and Cure Dental reported no additional suspicious activity. The official page does not say every field was present for all 878 people or provide field-level counts. LeakData therefore does not assume every person's SSN or license number was involved or add passwords, cards, or bank accounts absent from the source.\u003C\u002Fp>\n\u003Ch2>Was Protected Health Information Affected?\u003C\u002Fh2>\n\u003Cp>Cure Dental expressly said the incident did not affect patient Protected Health Information such as treatment and payment information. It also said the patient-record platform was restored and archive data was not affected. Diagnosis, treatment, prescription, insurance, billing, and medical-record content are therefore not added to this entry.\u003C\u002Fp>\n\u003Cp>Association with a dental practice may still matter for privacy, but the available sources do not confirm exposure of health information beyond that relationship. LeakData preserves this distinction between identity data and PHI and does not treat HHS's healthcare-provider classification as proof that medical records were involved.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>Potentially affected people should obtain free reports from the three major credit bureaus, review unfamiliar accounts and inquiries, and consider a fraud alert or free credit freeze. Identity information should never be shared with callers claiming to represent Cure Dental; verification should be initiated through a contact channel on the practice's official website.\u003C\u002Fp>\n\u003Cp>The practice published the toll-free 888-766-1488 number for incident questions. Evidence of an unfamiliar account, credit inquiry, or impersonation call should be preserved and reported to the relevant organization and, when appropriate, law enforcement. LeakData does not host, distribute, or make searchable patient lists, SSNs, driver's-license numbers, or attack files.\u003C\u002Fp>","Official Cure Dental patient notice confirming unauthorized cyber intrusion and potential PII access",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fcuredentalbeltontx_com.png"]