All Breaches
May 28, 2025 Verified Sensitive Record Healthcare

Totem Lake Family Dentistry 2025 Data Breach

The Totem Lake Family Dentistry 2025 data breach involved unauthorized access to one employee email account at the dental practice in Kirkland, Washington. The practice said it detected the activity on or about June 2, 2025, and that its investigation found some files may have been accessed by an unauthorized individual between May 28 and June 2, 2025.

The U.S. Department of Health and Human Services Office for Civil Rights portal lists 3,464 affected people for Totem Lake Family Dentistry. The federal row classifies the event as an email-based Hacking/IT Incident. The affected-person total is recorded in pwnCount and totalRecords, while importedRecordCount is zero because no raw patient data was obtained.

How Was the Totem Lake Incident Verified?

The primary source is the “Notice of Data Security Incident” PDF dated April 30, 2026 and hosted on the practice's own totemlakefamilydentistry.com domain. It describes the unauthorized email access, incident dates, investigation, possible information types, response measures, misuse status, and the 1-833-877-4013 assistance line.

The second source is the HHS/OCR federal row reported April 30, 2026 for 3,464 people. The third is ClaimDepot's incident summary, which matches the entity, dates, and count and links to the official notice and HHS. The production duplicate search covered the entity name, domain, likely slugs, and 2025 date range and found no existing matching record.

Incident Timeline

According to the official notice, an unauthorized person accessed one employee email account between May 28 and June 2, 2025. breachDate and dateOccurred use May 28, the earliest known access date. dateDiscovered is June 2 because that is when the organization detected the unauthorized access.

The practice says it contained and secured the email environment, eradicated the threat, and investigated with third-party cybersecurity professionals. A detailed review of potentially impacted files concluded on March 31, 2026 that protected health information may have been present. The April 30, 2026 public notice date is not the attack start.

What Information May Have Been Involved?

According to Totem Lake's notice, files may have contained a full name combined, depending on the person, with a date of birth or Social Security number. Health-related categories include medical records, treatment plans, patient numbers, prescriptions, and health insurance information. The source describes these fields as possible contents of the affected files.

The document specifically says some files “may have been accessed” and that the information combination varied by individual. It should not be assumed that every field belonged to all 3,464 people or was definitely viewed by the actor. Addresses, passwords, payment cards, bank accounts, and other categories absent from the official list were not added.

3,464 People Versus Zero Imports

3,464 is the affected-person count published by HHS/OCR for Totem Lake Family Dentistry in Washington; it is not a number of emails, files, prescriptions, or medical records. The federal portal identifies the event within the health-data notification system as an email-based hacking/IT incident. This official person figure is used without estimation.

importedRecordCount 0 means LeakData did not receive raw patient records containing names, Social security numbers, or medical information. The incident volume presented to users is 3,464 people, while the number of searchable person-level records in the system is zero. Zero imports do not mean zero affected people or make the incident unreal.

Identity and Medical Privacy Risks

A combination of name, date of birth, and Social Security number can increase new-account fraud and targeted phishing risk. Recipients can review credit reports, watch for unfamiliar inquiries, and consider a fraud alert or credit freeze when appropriate. Requests invoking the practice should be verified through its known website or assistance line.

Medical records, treatment plans, patient numbers, prescriptions, and insurance information create medical identity-theft and privacy risks. Users can review insurance explanations for services they did not receive, unfamiliar prescriptions, and incorrect patient records. Suspicious activity should be reported directly to the healthcare provider and insurer.

Organization Response and Steps for Individuals

Totem Lake Family Dentistry said it secured the email environment, eradicated the threat, conducted a scope review with specialists, and continued evaluating its practices and internal controls. Its April 30, 2026 document says there was no evidence that information had been misused as a direct result of the incident and does not name a specific actor.

People who did not receive a letter but believe they may be affected can call 1-833-877-4013 between 9:00 a.m. and 9:00 p.m. Eastern Time on weekdays. Users should follow the protective steps in their letter and monitor unusual credit or healthcare activity. This record was prepared by comparing the practice's official PDF, the HHS/OCR row, and an independent incident summary.

3.5 Thousand
Affected Accounts
8
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

8
Full names
Dates of birth
Social security numbers
Medical records
Treatment plans
Patient numbers
Prescriptions
Health insurance information

Additional Information

Added DateJuly 27, 2026
Breach DateMay 28, 2025
Domaintotemlakefamilydentistry.com
SourceOfficial Totem Lake Family Dentistry notice, HHS/OCR breach report, and ClaimDepot
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information