Molalla Family Dental
Disclosed Jul 16, 201214 years ago4,354 affectedConfirmed
The CE did not control access to the electronic protected health information (ePHI) of 4,354 individuals which was contained in the CE’s network-attached storage. Specifically, the CE’s firewall was set to allow access to a port that permitted anyone outside of CE’s firewall to access patient information. The ePHI involved in the breach included names, addresses, email addresses, dates of birth, patient intake sheets, invoices, dental charts, photos, x-rays, insurance information, credit card numbers, dates of birth, and social security numbers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE closed access to the unsecured port, encrypted ePHI, upgraded operating system software on all workstations, implemented new firewall rules, installed a new server, set up automatic software patching and spyware removal, and deployed new virus and spam filters. The CE also retrained employees and implemented extensive policies and procedures, including new backup procedures for ePHI. OCR obtained assurances that the corrective actions were taken.
What is known
| People affected | 4,354 (as reported to HHS) |
|---|---|
| Disclosed | Jul 16, 2012 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Molalla Family Dental (Healthcare Provider, OR)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 16, 2012 | 4,354 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.