All Breaches
July 28, 2025 Verified Healthcare

Tieu Dental (South Bay Oral Surgery) 2025 Data Breach

The 2025 Tieu Dental data breach involved unauthorized access to the network of the oral and maxillofacial surgery organization operating as South Bay Oral & Maxillofacial Surgery between July 28 and July 29, 2025. The organization's official notice says certain files may have been accessed and removed from the network.

The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as a hacking/information-technology incident involving a network server and reported 8,918 affected individuals.

Verified Incident Timeline

The forensic investigation determined that the unauthorized party accessed the network between July 28 and July 29, 2025. Review of the affected files was completed on January 11, 2026, and notifications began in March 2026.

The public documents do not identify the initial access method, a specific vulnerability, or the responsible party. This entry therefore does not add an unverified attack technique or threat group.

What Information May Have Been Affected?

The sample notice confirms that full names were among the information involved and that personal and/or health information may have been affected. Because the fields differed by person, recipients should use their own notification letter to confirm their specific scope.

Names and health information can make phishing attempts more convincing when a message refers to a real treatment or insurance detail. Recipients should not provide a password, verification code, additional health information, or payment details in an unexpected message.

The 8,918-Person Total

The HHS record reports 8,918 affected individuals. This is the incident total, but the public documents do not provide counts by data field, so it does not mean that every person had the same information involved.

What Should Affected People Do?

Tieu Dental says eligible individuals were offered a one-year Experian IdentityWorks membership. Notice recipients should confirm the activation deadline in their letter and monitor credit reports, health-insurance explanation-of-benefits statements, and medical bills for an unfamiliar transaction or service.

8.9 Thousand
Affected People
2
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

2
Names
Protected health information

Additional Information