Full Report
Bright Smile Dental Care, Ltd. (“Bright Smile”) recently became aware of a security incident that may have involved the personal information of some patients. While we have no evidence that any of our patients’ information was misused, we are providing this notice to explain the incident, the types of information involved, our investigation and response, and recommendations to help individuals protect their information. On August 3, 2026, Bright Smile discovered ransomware on its server which affected its practice management and patient record software and its dental imaging software. Bright Smile immediately engaged cybersecurity consultants to assess the nature of the incident and mitigate its impact. Despite the ransomware, our investigation determined that the threat actor would likely not have been able to view or acquire any of the data, as all data on the server was encrypted. Therefore, while we are providing this notice out of an abundance of caution, we believe that there is a low likelihood that any of the data was viewed or otherwise compromised.
Analysis Summary
# Incident Report: Bright Smile Dental Care Ransomware Incident
## Executive Summary
On August 3, 2026, Bright Smile Dental Care discovered ransomware on its server that affected its practice management, patient record, and dental imaging software. Cybersecurity consultants were immediately engaged to investigate and mitigate the impact, determining that because the data on the server was encrypted, there is a low likelihood that any data was viewed or compromised by the threat actor. Out of caution, the organization is implementing additional safeguards, notifying consumer reporting agencies, and offering credit monitoring services to individuals whose Social Security numbers may have been involved.
## Incident Details
- **Discovery Date:** August 3, 2026
- **Incident Date:** Not disclosed
- **Affected Organization:** Bright Smile Dental Care, Ltd.
- **Sector:** Healthcare / Dental Care
- **Geography:** Fishers, Indiana, USA
## Timeline of Events
### Initial Access
- **Date/Time:** Not disclosed
- **Vector:** Not disclosed
- **Details:** Not disclosed
### Lateral Movement
- Not disclosed
### Data Exfiltration/Impact
- Ransomware was deployed on the server, impacting the practice management software, patient record software, and dental imaging software.
- Patient data potentially involved included names, dates of birth, addresses, email addresses, phone numbers, insurance information, details about dependents, health information, and in some cases, Social Security numbers. Financial information was not impacted.
- The investigation determined that the data on the server was encrypted, and there is no indication the threat actor possessed the encryption keys, meaning the attacker was likely unable to view or acquire the data.
### Detection & Response
- **August 3, 2026:** Bright Smile Dental Care discovered the ransomware on its server.
- **Post-Discovery:** The organization immediately hired cybersecurity consultants to assess the incident and mitigate impact. Bright Smile began mailing written notices to affected individuals, notifying national consumer reporting agencies, implementing additional safeguards, and updating internal data privacy and security policies.
## Attack Methodology
- **Initial Access:** Not disclosed
- **Persistence:** Not disclosed
- **Privilege Escalation:** Not disclosed
- **Defense Evasion:** Not disclosed
- **Credential Access:** Not disclosed
- **Discovery:** Not disclosed
- **Lateral Movement:** Not disclosed
- **Collection:** Not disclosed
- **Exfiltration:** Not disclosed (Investigation indicates a low likelihood that any data was acquired due to server-side encryption)
- **Impact:** Ransomware deployment affecting server software (practice management, patient records, and dental imaging)
## Impact Assessment
- **Financial:** Not disclosed (Direct costs not provided; however, the organization is providing free TransUnion credit monitoring for certain affected individuals)
- **Data Breach:** Low likelihood of data compromise due to data encryption on the server. Potentially exposed categories include name, date of birth, address, email, phone number, insurance details, dependent info, health records, and some Social Security numbers. Financial data was not compromised.
- **Operational:** Disruption to practice management software, patient record software, and dental imaging software.
- **Reputational:** Public notification issued; national consumer reporting agencies notified.
## Indicators of Compromise
- **Network indicators:** None disclosed
- **File indicators:** None disclosed
- **Behavioral indicators:** None disclosed
## Response Actions
- **Containment measures:** Engaged cybersecurity consultants immediately to assess the nature of the incident and mitigate its impact.
- **Eradication steps:** Not disclosed
- **Recovery actions:** Implementing additional safeguards, reviewing and updating internal policies and procedures related to privacy and security, notifying national consumer reporting agencies, mailing written notices to affected individuals, and offering free TransUnion credit monitoring services to individuals whose Social Security numbers were potentially involved.
## Lessons Learned
- Maintaining strong data encryption on servers can effectively prevent threat actors from viewing or acquiring sensitive files even if ransomware successfully targets the system.
- Ongoing review and adjustment of internal security policies and technical safeguards are required to sustain data privacy and security posture.
## Recommendations
- Implement the planned additional technical safeguards to further protect personal and health information.
- Complete the review and updates of internal security and privacy policies and procedures.
***
*Note: Defanged links and contact info associated with this incident notice:*
- *brightsmiledentalcare[.]net*
- *brightsmiledentalcare@hotmail[.]com*
- *www[.]ftc[.]gov/idtheft*
- *www[.]experian[.]com*
- *www[.]equifax[.]com*
- *www[.]transunion[.]com*
- *www[.]annualcreditreport[.]com*
- *doctorsinternet[.]com*