[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNSYV7Yxhz1umXGhTCqOEZf8J2CJjLuXvJLsXQzpAUTU":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":18,"dataClasses":19,"description":28,"source":29,"isVerified":4,"isSpamList":30,"isSensitive":4,"processingStatus":31,"logoUrl":32,"contentUpdatedAt":17,"hasEnglishDescription":4,"severity":33},"6a677206fcf739cebd54b1d2","TotemLakeFamilyDentistry2025","Totem Lake Family Dentistry 2025 Data Breach","totem-lake-family-dentistry-2025","totemlakefamilydentistry.com",{"name":12,"sector":13,"country":14,"website":10},"Totem Lake Family Dentistry","Healthcare","United States","2025-05-28T00:00:00.000Z","2026-07-27T14:58:14.312Z","2026-07-27T16:11:14.710Z",3464,[20,21,22,23,24,25,26,27],"Full names","Dates of birth","Social Security numbers","Medical records","Treatment plans","Patient numbers","Prescriptions","Health insurance information","\u003Cp>\u003Cstrong>The Totem Lake Family Dentistry 2025 data breach\u003C\u002Fstrong> involved unauthorized access to one employee email account at the dental practice in Kirkland, Washington. The practice said it detected the activity on or about June 2, 2025, and that its investigation found some files may have been accessed by an unauthorized individual between May 28 and June 2, 2025.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights portal lists 3,464 affected people for Totem Lake Family Dentistry. The federal row classifies the event as an email-based Hacking\u002FIT Incident. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.\u003C\u002Fp>\u003Ch2>How Was the Totem Lake Incident Verified?\u003C\u002Fh2>\u003Cp>The primary source is the “Notice of Data Security Incident” PDF dated April 30, 2026 and hosted on the practice's own totemlakefamilydentistry.com domain. It describes the unauthorized email access, incident dates, investigation, possible information types, response measures, misuse status, and the 1-833-877-4013 assistance line.\u003C\u002Fp>\u003Cp>The second source is the HHS\u002FOCR federal row reported April 30, 2026 for 3,464 people. The third is ClaimDepot's incident summary, which matches the entity, dates, and count and links to the official notice and HHS.\u003C\u002Fp>\u003Ch2>Incident Timeline\u003C\u002Fh2>\u003Cp>According to the official notice, an unauthorized person accessed one employee email account between May 28 and June 2, 2025. The incident date is based on the earliest technical activity that can be verified from public sources.\u003C\u002Fp>\u003Cp>The practice says it contained and secured the email environment, eradicated the threat, and investigated with third-party cybersecurity professionals. A detailed review of potentially impacted files concluded on March 31, 2026 that protected health information may have been present. The April 30, 2026 public notice date is not the attack start.\u003C\u002Fp>\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\u003Cp>According to Totem Lake's notice, files may have contained a full name combined, depending on the person, with a date of birth or Social Security number. Health-related categories include medical records, treatment plans, patient numbers, prescriptions, and health insurance information. The source describes these fields as possible contents of the affected files.\u003C\u002Fp>\u003Cp>The document specifically says some files “may have been accessed” and that the information combination varied by individual. It should not be assumed that every field belonged to all 3,464 people or was definitely viewed by the actor. Addresses, passwords, payment cards, bank accounts, and other categories absent from the official list were not added.\u003C\u002Fp>\u003Ch2>How Should the Affected-Person Count Be Interpreted?\u003C\u002Fh2>\u003Cp>3,464 is the affected-person count published by HHS\u002FOCR for Totem Lake Family Dentistry in Washington; it is not a number of emails, files, prescriptions, or medical records. The federal portal identifies the event within the health-data notification system as an email-based hacking\u002FIT incident. This official person figure is used without estimation.\u003C\u002Fp>\u003Cp>When an official individual notice is available, its listed data categories and protection options should guide the assessment of personal exposure.\u003C\u002Fp>\u003Ch2>Identity and Medical Privacy Risks\u003C\u002Fh2>\u003Cp>A combination of name, date of birth, and Social Security number can increase new-account fraud and targeted phishing risk. Recipients can review credit reports, watch for unfamiliar inquiries, and consider a fraud alert or credit freeze when appropriate. Requests invoking the practice should be verified through its known website or assistance line.\u003C\u002Fp>\u003Cp>Medical records, treatment plans, patient numbers, prescriptions, and insurance information create medical identity-theft and privacy risks. Users can review insurance explanations for services they did not receive, unfamiliar prescriptions, and incorrect patient records. Suspicious activity should be reported directly to the healthcare provider and insurer.\u003C\u002Fp>\u003Ch2>Organization Response and Steps for Individuals\u003C\u002Fh2>\u003Cp>Totem Lake Family Dentistry said it secured the email environment, eradicated the threat, conducted a scope review with specialists, and continued evaluating its practices and internal controls. Its April 30, 2026 document says there was no evidence that information had been misused as a direct result of the incident and does not name a specific actor.\u003C\u002Fp>\u003Cp>People who did not receive a letter but believe they may be affected can call 1-833-877-4013 between 9:00 a.m. and 9:00 p.m. Eastern Time on weekdays. Users should follow the protective steps in their letter and monitor unusual credit or healthcare activity. If a suspicious message or account event appears, it should be verified through the organization’s current official contact channel without using links in the message. When an individual notification letter is available, it is the primary source for the person-specific data scope and protection options offered.\u003C\u002Fp>","Official Totem Lake Family Dentistry notice, HHS\u002FOCR breach report, and ClaimDepot",false,"completed","\u002Fuploads\u002Flogo\u002Ftotemlakefamilydentistry_com.svg","Low"]