Bonita Orthodontics Data Breach Exposes Patient and Minor Health Records

Published: 22 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

A ransomware group called incransom attacked Bonita Orthodontics and claims to have stolen and leaked private patient files, potentially including records belonging to minor patients. The exact number of affected people and full data categories have not been publicly disclosed. Affected patients and parents should monitor credit reports, consider a credit freeze, and watch for phishing attempts immediately.

CompanyBonita Orthodontics
IndustryHealthcare
Data Types ExposedPatient Names and Contact Information, Dates of Birth, Dental and Orthodontic Treatment Records, Insurance Information, Billing and Payment Details, Guardian or Parent Contact Information
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Bonita Orthodontics Data Breach?

Bonita Orthodontics, an orthodontic practice run by Dr. Maryann Kriger, has confirmed it was targeted in a ransomware attack. A threat actor group known as incransom claims responsibility for the intrusion. As a result, patient information may have been stolen and posted online.

According to the threat actor’s own public statements, incransom attempted to contact the practice multiple times before publishing any stolen files. The group claims it warned the practice that the exposed data included private information belonging to minors. Despite these warnings, the messages reportedly went unanswered, and the group ultimately released the stolen data.

The exact breach discovery date has not been publicly disclosed. Similarly, the date the practice notified affected individuals, if it has done so, remains unknown. Because ransomware groups typically publish stolen files only after failed extortion attempts, the timeline suggests the attack occurred well before the leak became public.

At this stage, it is unclear whether an independent forensic investigation has been completed or announced. However, incidents involving ransomware groups that publish stolen data typically indicate that files were both accessed and removed from internal systems. This distinguishes the case from a simple network intrusion with no confirmed data theft.

Who was affected?

The breach appears to primarily affect patients of Bonita Orthodontics. Because the practice provides orthodontic treatment, including services like Invisalign, its patient base likely includes a significant number of minors. This raises particular concern, since children’s personal and health information generally carries long-term identity theft risks.

The exact number of affected individuals has not been publicly disclosed. It is also unclear whether the breach extended to employee records, in addition to patient files. Given the nature of orthodontic practices, the affected population likely includes both current and former patients, as well as their parents or guardians who provided contact and insurance details during treatment.

Because the practice appears to operate in a single location, the geographic scope of affected individuals is likely regional. Nevertheless, patients who have since moved to other states could also be impacted, since breached records are typically retained long after treatment ends.

What Information Was Potentially Exposed?

The specific categories of data exposed have not been fully itemized in public statements. However, based on the nature of the incident and the type of practice involved, the following categories of information are commonly present in orthodontic patient files and may be at risk.

  • Patient names and contact information
  • Dates of birth
  • Dental and orthodontic treatment records
  • Insurance information
  • Billing and payment details
  • Guardian or parent contact information for minor patients

If accurate, this combination of data creates real risk for identity theft. For example, a child’s personal information combined with a date of birth can be used to open fraudulent accounts that go unnoticed for years. This is because most parents do not monitor their child’s credit until much later in life.

In addition, exposed insurance details could be used for medical identity theft. Someone could use stolen insurance information to receive treatment or file fraudulent claims under a patient’s name. As a result, victims may face billing disputes or incorrect entries in their medical history that are difficult to correct.

What is the company doing?

It is not currently known what formal remediation steps Bonita Orthodontics has taken since the attack was discovered. However, organizations facing a confirmed ransomware and data theft incident typically begin by isolating affected systems and engaging cybersecurity specialists to assess the scope of compromise.

The practice has not publicly detailed whether it plans to offer credit monitoring or identity protection services to affected patients. Additionally, no information is currently available about whether law enforcement has been formally engaged, though ransomware incidents involving confirmed data theft are frequently reported to federal authorities.

Affected individuals should watch for official notification letters from the practice. These letters typically explain what happened, what data was involved, and what protective steps, if any, are being offered.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals, and parents of affected minors, should request free copies of their credit reports. Regularly checking for unfamiliar accounts or inquiries can help catch fraud early, before significant damage occurs.

Because minors rarely have existing credit files, any credit activity tied to a child’s Social Security number is a strong warning sign. Parents should specifically request a manual credit check for their children, since automated alerts typically will not exist for minors without a credit history.

Consider a Credit Freeze or Fraud Alert

A credit freeze prevents new creditors from accessing your credit report, which makes it much harder for identity thieves to open new accounts. This step is especially useful for families concerned about their children’s exposed information.

To place a freeze, contact each of the three major credit bureaus directly. This step is free and can be lifted temporarily whenever you need to apply for credit yourself.

Protect Against Medical Identity Theft

Because dental and treatment records may have been exposed, patients should closely review any insurance statements or billing notices for unfamiliar charges. Medical identity theft can result in incorrect information appearing in your health records, which may affect future care.

If you notice unfamiliar claims or treatments listed on an insurance explanation of benefits, contact your insurer immediately. Correcting these errors early helps prevent long-term complications with future coverage or claims processing.

Stay Alert for Phishing Attempts

Following a data breach, scammers often use stolen contact information to send convincing phishing emails or text messages. These messages may impersonate the practice, an insurer, or a credit monitoring service.

Therefore, never click on links or provide personal information in response to unsolicited messages. Instead, contact the organization directly using a verified phone number or website to confirm whether any communication is legitimate.

Consult a Data Breach Attorney

Given the reported involvement of minors’ private health information, affected families may want to understand their legal options. A data breach attorney can review the details of your situation and explain whether you may qualify for compensation.

Many attorneys offer free consultations for data breach cases, so there is generally little risk in seeking a professional opinion. This is particularly worthwhile if your child’s health or personal information was included in the leaked files.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

See the latest data breaches we're tracking →