Gentle Dentistry Group
Disclosed Sep 26, 20188 years ago831 affectedConfirmed
A workforce member of the covered entity (CE), Gentle Dentistry Group, emailed a product promotion to 831 patients, disclosing recipients’ email addresses to each other. The CE provided breach notification to HHS, the media, and the affected individuals, including any required substitute notice to the affected individuals. Following the breach, the CE updated its practices to prohibit sending an email to multiple patients, provided a refresher training to its workforce regarding its email protocols, and sanctioned the workforce member responsible for the breach incident. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to conduct a risk analysis and implement a corresponding remediation plan.
What is known
| People affected | 831 (as reported to HHS) |
|---|---|
| Disclosed | Sep 26, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Gentle Dentistry Group (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 26, 2018 | 831 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.