Skip to content
OSHA Review toll free phone number 800-555-6248

Ransomware Cyberattack Strikes Large US Dental Referral Firm

Many dental news outlets are reporting a significant cyberattack against 1-800-Dentist, a popular dental referral and marketing service used by dental practices across the United States. On June 28, 2026, the Qilin ransomware gang — a Russian-linked cybercriminal group — published on its dark web victim blog that it had stolen a cache of personal information files potentially linked to millions of people and dental practices connected to 1-800-Dentist.

This post is part of our Dental Bytes eNewsletter 2026 hub, where you can access each monthly issue.

What Happened

The Qilin ransomware group is a sophisticated cybercriminal organization with ties to Russian-speaking threat actors. Ransomware attacks involve unauthorized actors infiltrating a network, stealing or encrypting sensitive data, and demanding a ransom payment in exchange for restoring access or agreeing not to release stolen information publicly.

In this case, the group publicly claimed responsibility for the attack on 1-800-Dentist and alleged it had obtained a large volume of personal data files. 1-800-Dentist connects patients with dental providers nationwide and maintains information about both patients and the dental practices in its network. The full scope of the breach — including exactly what data was accessed and how many individuals may be affected — was under investigation at the time of reporting.

Why This Matters for Dental Practices

Dental practices that participate in referral networks, marketing platforms, or third-party patient management services should be aware that their data — and their patients’ data — may be held by those vendors. Under HIPAA, dental practices have an obligation to ensure that any Business Associate that handles protected health information (PHI) on their behalf has appropriate safeguards in place.

Key points dental practices should understand:

  • Business Associate Agreements (BAAs) are required. If 1-800-Dentist or any referral service handles PHI on behalf of your practice, a signed BAA must be in place. If a breach occurs, you need documentation that your vendor relationship was properly structured.
  • Vendor breaches can trigger your notification obligations. If a business associate experiences a breach of your patients’ PHI, you may have reporting obligations under the HIPAA Breach Notification Rule.
  • Your practice may be asked to notify patients. Depending on the data involved, affected practices may need to communicate with patients whose information was potentially compromised.

What Dental Practices Should Do Now

This incident is a timely reminder for all dental practices to review their cybersecurity posture and vendor relationships:

  • Confirm you have signed BAAs with all vendors who access, store, or transmit patient PHI — including referral platforms, marketing services, and patient communication tools.
  • Review your practice’s HIPAA Security Risk Analysis. Practices are required to conduct a risk analysis and update it regularly. OCR has increasingly cited failure to conduct a risk analysis as a primary violation in enforcement actions.
  • Monitor communications from 1-800-Dentist and any other affected vendors for guidance on the scope of the breach and any recommended steps for affiliated practices.
  • Ensure staff receive regular HIPAA security training so they can recognize phishing attempts and social engineering tactics that often accompany large-scale breaches.
  • Review your incident response plan so your team knows exactly what to do if your practice is notified of a breach involving your patients’ data.

Cyberattacks on dental referral services and dental support organizations highlight that the risk is not limited to direct attacks on individual offices. Vendor security is an extension of your practice’s own security obligations.

Quick Summary

  • The Qilin ransomware gang claimed a June 2026 attack on 1-800-Dentist, alleging theft of personal data affecting millions of patients and dental practices.
  • Dental practices using third-party referral or marketing services must have BAAs in place with vendors who handle PHI.
  • A vendor breach may trigger your practice’s HIPAA breach notification obligations.
  • Now is a good time to review your HIPAA Security Risk Analysis, vendor agreements, and incident response plan.

Related OSHA Review Resources


About OSHA Review, Inc.
Since 1992, OSHA Review, Inc. has supported dental professionals with regulatory compliance resources, infection control guidance, continuing education, sterilizer monitoring, surface disinfectant products, and dosimetry monitoring services. For more information, visit oshareview.com or call 800-555-6248.

This post is part of the Dental Bytes eNewsletter 2026 series. Visit the hub to access all monthly updates.

Morgan Lawson is the Chief Operations Officer and Managing Editor at OSHA Review, Inc., where he has led dental compliance education and operations since 1999. With over 25 years of experience in OSHA regulations, infection control standards, and dental practice compliance, Morgan oversees the development of content, training programs, and compliance resources trusted by dental practices nationwide.

Back To Top
Search