Bright Smile Dental Care, Ltd. Data Breach Exposes Social Security Numbers and Health Records

Published: 30 September 2026
Healthcare data breach illustration
Breach Discovery: August 2026Breach Notification: Not Publicly Disclosed

Bright Smile Dental Care, an Indiana dental practice, discovered ransomware on its network in August 2026 that may have exposed patient names, birth dates, contact details, insurance information, health records, and Social Security numbers for some patients. The practice reports a low likelihood the data was actually viewed but is notifying patients and offering free credit monitoring. Affected individuals should enroll in monitoring and watch their credit reports closely.

CompanyBright Smile Dental Care, Ltd.
IndustryHealthcare
Data Types ExposedFull Names, Dates of Birth, Home Addresses, Email Addresses, Phone Numbers, Insurance Information, Health Information, Social Security Numbers
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Bright Smile Dental Care Data Breach?

Bright Smile Dental Care, Ltd., a dental practice based in Fishers, Indiana, found ransomware on its computer server. The practice discovered this intrusion in August 2026. This server handled essential daily functions, including patient records, insurance processing, and dental imaging.

As soon as staff identified the threat, the practice disconnected the affected systems from its network. This step aimed to stop further damage. Bright Smile Dental Care then brought in outside forensic experts to dig into the incident and figure out exactly what happened.

The investigation found that attackers had encrypted files on the server. Because the data was locked rather than left open, the practice believes there’s a low chance the intruder actually viewed or copied patient information. However, ransomware groups often claim they stole data before encrypting it, using that threat to pressure victims into paying. Bright Smile Dental Care has stated it has no evidence of actual misuse of patient data so far.

Despite the low likelihood of data viewing, the practice chose to notify patients anyway. This cautious approach follows standard practice under state and federal breach notification laws. Dental and medical offices often become targets for cybercriminals precisely because they store so much sensitive information in one place.

Who Was Affected?

The breach affects patients of Bright Smile Dental Care. This includes anyone whose personal or health information sat on the compromised server. The exact number of affected individuals has not been publicly disclosed.

Because dental practices often treat patients across age groups, it’s possible that minors are among those affected, particularly if family insurance plans or dependent information were stored together. The practice’s notice specifically mentions that information about dependents may have been involved, suggesting that family members connected to patient accounts could also face exposure.

Given the practice’s location in Fishers, Indiana, most affected individuals are likely local patients. However, dental records and insurance data can sometimes include out-of-state family members or former patients who moved away, so the geographic reach may extend beyond Indiana.

What Information Was Potentially Exposed?

According to Bright Smile Dental Care, several categories of sensitive information may have been stored on the affected server. The practice has confirmed the following types of data could be involved:

  • Full names
  • Dates of birth
  • Home addresses
  • Email addresses
  • Phone numbers
  • Insurance information
  • Information about dependents
  • Health information
  • Social Security numbers (for some individuals)

This combination of data creates multiple avenues of risk for affected patients. For example, Social Security numbers combined with dates of birth and addresses give criminals nearly everything needed to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. Even though the practice reports a low likelihood the data was actually viewed, patients whose Social Security numbers appear in the affected systems should still take the situation seriously.

Beyond financial fraud, the exposure of health and insurance information creates a separate category of risk: medical identity theft. This happens when someone uses a stolen identity to receive medical care, prescriptions, or dental treatment, potentially resulting in false entries on the victim’s own medical records. In addition, detailed health and insurance data can make phishing attempts far more convincing, since scammers can reference real details about a patient’s dental history or coverage to appear legitimate.

What Is the Company Doing?

After discovering the ransomware, Bright Smile Dental Care worked with forensic specialists to assess the scope of the incident. Once that review was complete, the practice began mailing written notices to patients whose information may have been involved. As a result, affected individuals should watch their mail for a formal notice describing their specific situation.

In response to the incident, the practice says it is adding new security measures to reduce the chances of a similar event happening again. For patients whose Social Security numbers may have been exposed, Bright Smile Dental Care is offering complimentary credit monitoring as a protective measure. Patients who believe they were affected but never received a notice have been told to contact the practice directly to confirm their status.

What Should Affected Individuals Do?

Review Your Notice and Enroll in Credit Monitoring

If you receive a letter from Bright Smile Dental Care, don’t set it aside. This notice may contain account-specific details and any deadlines for enrolling in the free credit monitoring service. Reading it carefully helps you understand exactly what information was involved in your case.

Because the practice is only offering credit monitoring to patients whose Social Security numbers were affected, enrolling promptly matters. This service can alert you to new accounts opened in your name or unusual credit inquiries. Acting quickly gives you the best chance of catching fraud before it spreads.

Place a Fraud Alert or Credit Freeze

Since Social Security numbers may have been exposed for some patients, consider placing a fraud alert or full credit freeze with the three major credit bureaus. A fraud alert requires lenders to verify your identity before approving new credit. A freeze goes further, blocking most new credit applications entirely until you lift it.

Both options are free and relatively simple to set up. Because identity thieves sometimes wait months or years before using stolen data, maintaining a freeze or alert for an extended period offers stronger long-term protection than a one-time check.

Monitor Insurance Statements and Medical Records

Because health and insurance information may have been exposed, review your insurance statements and patient portal activity regularly. Look for claims for treatments you never received or providers you’ve never visited. Medical identity theft can be harder to detect than financial fraud, so this step deserves extra attention.

If you spot anything unfamiliar, report it to your insurance provider and to Bright Smile Dental Care right away. Correcting inaccurate medical records early helps prevent complications with future treatment or insurance claims. Keep copies of any disputes you file for your own records.

Watch for Phishing Attempts

Scammers often use breach notices as an opportunity to send fake follow-up messages. Be cautious of unsolicited calls, texts, or emails asking you to confirm your Social Security number, insurance details, or portal password. Bright Smile Dental Care will not ask for sensitive information this way.

If you receive a suspicious message claiming to be from the practice, contact them directly using a verified phone number instead of replying. This simple habit can prevent you from accidentally handing over information to a scammer posing as a legitimate organization.

Check Your Credit Reports Regularly

In addition to any monitoring service offered, request your free credit reports from Equifax, Experian, and TransUnion through AnnualCreditReport.com. Review each report for accounts, inquiries, or addresses you don’t recognize. Doing this every few months, rather than just once, increases your odds of catching fraud early.

If you find suspicious activity, dispute it with the relevant credit bureau immediately. Keeping detailed records of your review process, along with your breach notice, may also prove useful if you later decide to consult an attorney about your legal options.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

See the latest data breaches we're tracking →