Data breaches have been announced by Soniva Dental Care in Texas, Optalis Management Solutions in Michigan, CareCloud in New Jersey, and Hudson Valley Medical Billing & Credentialing in New York. Soniva Dental Care Soniva Dental Care, a San Antonio, Texas-headquartered provider of dental services, orthodontics, and cosmetic dentistry across 14 locations, has recently disclosed a cybersecurity incident affecting patients of several of its practices.
On May 26, 2026, Soniva Dental Care was informed by its IT support company about suspicious remote access sessions. It rapidly became apparent that its remote desktop web services infrastructure was under attack, and IT resources were shifted to containing the incident, terminating all external communications, disabling accounts with remote desktop access, and locking down its infrastructure.
Soniva Dental Care said its patient record system was quickly restored and its archive data was unaffected. While the incident was rapidly detected and contained, it was not possible to rule out unauthorized access to patient data. Files exposed in the incident were reviewed and found to contain names, addresses, dates of birth, driver’s license numbers, government-issued IDs, and medical information.
Soniva Dental Care said its incident response was effective, and it has not identified any further suspicious activity. While Soniva Dental Care is unaware of any instances of data misuse, the affected individuals have been advised to place a fraud alert on their accounts with any of the three major credit bureaus. Security inspections are being conducted by its IT support company, which will continue to monitor for unauthorized activity.
Regulators have been notified about the data breach, but the incident is not yet shown on the HHS Office for Civil Rights breach portal. The Texas Attorney General was informed that up to 30,000 Texas residents were potentially affected. Affected practices include, but may not be limited to, Agave Dental Floresville, Allwyn Dental, Azle Smiles, Kashi Dental, Mysa Dental, and Wilson Dental.
A ransomware-as-a-service group called TheGentlemen claimed responsibility for the attack. The group is currently one of the most prolific ransomware groups, having attracted affiliates from other groups by offering a 90% split on ransom payments. Optalis Management Solutions Optalis Management Solutions, a Michigan-based operations management company specializing in the management of senior living and healthcare facilities, has reported a data breach to the HHS Office for Civil Rights involving the protected health information of 13,723 individuals.
Suspicious activity was identified within its computer network on or around April 19, 2025. The forensic investigation confirmed unauthorized access between April 14, 2025, and April 19, 2025, and on June 10, 2025, it was confirmed that files had been exfiltrated from its network. The review of the affected data has recently been completed, confirming that the following types of information were compromised in the incident: full names, Social Security numbers, driver’s license/state ID numbers, credit/debit card information, financial account information, diagnosis and treatment information, and health insurance information.
Notification letters started to be mailed to the affected individuals on June 29, 2026. While no evidence has been found to indicate any actual or attempted misuse of the stolen data, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services. CareCloud CareCloud Inc.
, a Somerset, New Jersey-based provider of cloud-based and AI-powered EHR, RCM, PM, and clinical documentation solutions, has determined that data was exfiltrated from its systems in a recent security incident. CareCloud said it experienced a network disruption on March 16, 2026, that impacted one of its electronic health record environments. Third-party cybersecurity experts were engaged to assist with the investigation, who determined that the impacted AWS environment was accessed by an unauthorized third party between March 10 and March 16, 2026.
The threat actor claimed to have exfiltrated databases from that environment. The data was reviewed, and on June 24, 2026, CareCloud confirmed the data types involved. The affected individuals are now being notified, and the individual notification letters state the exact types of data involved.
Complimentary identity theft protection services have been offered to the affected individuals. The data breach is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected. Hudson Valley Medical Billing & Credentialing Hudson Valley Medical Billing & Credentialing, LLC, a New York-based provider of patient billing and accounts receivable services, has identified unauthorized access to computer systems containing the protected health information of 5,459 patients of its healthcare clients.
The intrusion was first identified on March 6, 2026, and immediate action was taken to contain the incident and terminate the unauthorized access. The investigation was unable to determine whether patient data was accessed or copied, so notification letters have been mailed to individuals who have potentially been affected. The company said it has enhanced its technical safeguards to strengthen system security, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services.
The exact data types involved are detailed in the individual notification letters. The post Soniva Dental Care Data Breach Affects At Least 30,000 Patients appeared first on The HIPAA Journal .
Originally published at hipaajournal.com