Hawaii Family Dental Data Breach Exposes Patient Health and Insurance Information

Published: 14 September 2026
Healthcare data breach illustration
Breach Discovery: July 2026Breach Notification: September 2026

Hawaii Family Dental discovered a hacking incident in July 2026 that exposed personal and health information for 45,853 patients, including names, contact details, dates of birth, and dental treatment and insurance information. Social Security numbers and financial data were not involved. Affected patients should monitor insurance statements and watch for phishing attempts referencing their dental care.

CompanyHawaii Family Dental
IndustryHealthcare
Data Types ExposedNames, Phone Numbers, Home Addresses, Email Addresses, Dates of Birth, Medical and Dental Treatment Information, Health Insurance Information
People Affected45,853 individuals
Attack MethodHacking/Data Theft
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Hawaii Family Dental Data Breach?

Hawaii Family Dental, which operates a dozen dental clinics across Hawaii, has begun notifying patients about a serious cybersecurity incident. The company discovered unauthorized activity within its computer network in July 2026. This discovery triggered an immediate internal review to determine what had happened and whether patient data was at risk.

According to the investigation, an unauthorized third party gained access to Hawaii Family Dental’s systems over a short window in July 2026. During that time, the intruder reached systems that stored patient information. As a result, files containing personal and health details may have been viewed or copied.

A forensic investigation followed the initial discovery to determine the scope of the intrusion. While Hawaii Family Dental did not publicly name the group behind the attack, the Qilin data theft and extortion gang claimed responsibility. Qilin stated that it removed sensitive data from the network, a claim consistent with the company’s own findings.

Because this was a hacking incident rather than a simple internal error, the response required careful technical review. Investigators worked to confirm exactly which systems were touched and which files were exposed. This process is standard after any confirmed intrusion of this kind, since organizations must verify the full extent of unauthorized access before notifying patients.

Who was affected?

The breach affects patients of Hawaii Family Dental’s clinic network throughout Hawaii. In total, the company is notifying 45,853 individuals whose information was involved in the incident. This makes the breach one of the larger healthcare data exposures reported in the state this year.

Because Hawaii Family Dental serves families across its twelve locations, the affected population likely includes patients of all ages, including children who received dental care at these clinics. The breach notice does not specify separate categories for adults and minors. However, given the practice’s family-oriented services, parents should assume their children’s records may also be part of the exposure.

The company has not indicated that the breach extended beyond patients to include employees or other groups. Still, anyone who received treatment at a Hawaii Family Dental location should treat this notification seriously. This is true even for patients who visited only occasionally or years ago, since older records may have remained stored on the affected systems.

What Information Was Potentially Exposed?

The investigation found that several categories of personal and health information were stored on the compromised systems. Hawaii Family Dental confirmed that files containing this data were accessible to the attacker and potentially copied during the intrusion.

  • Full names
  • Phone numbers
  • Home addresses
  • Email addresses
  • Dates of birth
  • Medical and dental treatment information
  • Health insurance information

Importantly, Hawaii Family Dental has stated that Social Security numbers and financial account information were not involved in this incident. This distinction matters because it narrows, though does not eliminate, the risk patients face going forward.

Even without financial account numbers, exposed contact details and treatment information carry real risk. For example, scammers often use stolen names, birth dates, and health details to craft convincing phishing emails or phone calls. Because the messages reference real treatment history, they can appear far more legitimate than a generic scam attempt.

In addition, health insurance information can be misused to submit fraudulent claims or obtain medical services under someone else’s identity. This type of fraud, known as medical identity theft, can be difficult to detect until an insurance statement or bill looks unfamiliar. Therefore, patients should review insurance communications carefully in the coming months.

What is the company doing?

After identifying the suspicious activity, Hawaii Family Dental launched a forensic investigation to determine what happened and which patients were affected. Once the review confirmed the scope of the exposure, the company began sending notification letters to all 45,853 affected individuals.

In response to the incident, Hawaii Family Dental says it is reviewing and strengthening its data privacy and security safeguards. This includes evaluating existing network protections to reduce the chance of a similar intrusion happening again. The company has not detailed every technical measure it plans to implement, but it has committed to ongoing security improvements.

Hawaii Family Dental has also encouraged patients to stay alert for signs of misuse involving their personal information. Because the breach notice does not mention a specific credit monitoring or identity protection offer, affected patients should rely on their own vigilance alongside any guidance provided directly in their notification letter.

What Should Affected Individuals Do?

Monitor Your Credit Reports Regularly

Even though Social Security numbers were not exposed, it remains wise to check your credit reports periodically. Identity thieves sometimes combine breached contact information with data from other sources to attempt fraud. As a result, monitoring adds an extra layer of protection.

You can request free credit reports from each of the three major credit bureaus once a year through the official government-authorized site. Reviewing these reports allows you to spot unfamiliar accounts or inquiries quickly. If you notice anything unusual, report it to the bureau immediately.

Watch for Phishing Attempts Referencing Your Dental Care

Because names, contact details, and treatment information were exposed, scammers may attempt to impersonate Hawaii Family Dental or your insurance provider. These messages might reference real appointment dates or services to appear credible. Consequently, patients should treat unexpected emails or calls about dental care with caution.

Never click links or provide personal details in response to unsolicited messages. Instead, contact Hawaii Family Dental directly using a verified phone number if you want to confirm any communication. This simple step can prevent a convincing phishing attempt from succeeding.

Guard Against Medical Identity Theft

Since health insurance information was part of the exposure, patients should review upcoming insurance statements closely. Look for claims, services, or providers you do not recognize. Medical identity theft can lead to inaccurate health records and unexpected bills.

If you spot a discrepancy, contact your insurance provider right away to dispute the charge. In addition, request a copy of your insurance claims history periodically. This habit helps catch fraudulent activity before it causes lasting damage to your coverage or medical records.

Consider a Fraud Alert as an Extra Precaution

Although financial account numbers were not exposed in this breach, some patients may still choose to place a fraud alert with the credit bureaus out of caution. A fraud alert requires businesses to take extra steps to verify your identity before opening new credit in your name. This is a low-cost, low-effort safeguard.

Fraud alerts are free and typically last one year, with renewal options available. Because this breach involved sensitive personal details, some individuals prefer this added layer of security even without direct financial data exposure. If you are unsure whether this step applies to your situation, a data breach attorney can help evaluate your options during a free case review.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →