Hawaii Dental Group, Inc., which does business as Hawaii Family Dental, is notifying patients of a data breach. The practice runs 12 offices across Oʻahu, Maui, Kauaʻi and the Big Island. It says an unauthorized person used a compromised account to reach patient information on July 19 and 20, 2026. Its filing with the HHS Office for Civil Rights, submitted August 21, lists 45,853 affected individuals, according to HIPAA Journal and two law firms tracking the portal. The Qilin ransomware and extortion group claimed the attack on its leak site. Hawaii Family Dental has not named an attacker or described the incident as ransomware, and nobody has independently verified Qilin's claim.
What Happened
In a press release dated August 26, the practice says it found the intrusion on July 20, 2026. The unauthorized access ran from July 19 to July 20. It says the affected account was secured the same day it was discovered, and that its IT and security team then began investigating and working out who was affected. HIPAA Journal and DentalGoodNews describe the investigation as forensic and say the attacker reached systems where patient information was stored.
The timeline across sources:
- July 19–20, 2026: Unauthorized access window, per the practice's notice.
- July 20, 2026: Suspicious activity found and the account secured, per the practice.
- July 31, 2026: Qilin lists Hawaii Family Dental on its leak site, according to Medix Dental IT and Almeida Law Group.
- August 21, 2026: Breach report submitted to HHS OCR, classified as "Hacking/IT Incident" involving email, per Almeida Law Group and Federman & Sherwood.
- August 26, 2026: Public press release. Patients are being notified by mail.
Hawaii Family Dental says it has no evidence that any of the data has been misused. Qilin, according to HIPAA Journal, says it exfiltrated sensitive data.
What Was Taken
The practice's notice says the information that may have been accessed includes patient names, dates of birth, phone numbers, email addresses, mailing addresses, dental insurance information, parts of medical information, and dental treatment information. The notice explicitly states that Social Security numbers and financial account information were not involved.
On the numbers: HIPAA Journal and the law firms citing the HHS filing agree on 45,853 individuals. Paubox also reports 45,853 in its story, but its headline says "40k". Treat 45,853 from the regulator filing as the authoritative count. Almeida Law Group puts the practice's total patient base at more than 57,000, which would mean most patients were affected. That figure comes from a single source and has not been confirmed.
Conflicting account: Federman & Sherwood's generic list of data that "may" have been exposed includes Social Security numbers. That contradicts the practice's own notice. The same firm also says the HHS filing does not specify which data types were affected. The victim's statement should take precedence here.
There is no public evidence yet about whether Qilin has published any of the data or what it contains.
Why It Matters
This fits the pattern that has defined healthcare extortion for several years: a regional provider holding tens of thousands of PHI records, compromised through one identity. Treatment and insurance data can't be reissued the way a card number can. Even without SSNs, it is well suited to targeted phishing and insurance fraud. The practice's advice to patients points the same way: be wary of unexpected emails or calls that mention dental care.
The two accounts of the incident also don't fully line up. The practice describes a single compromised account (an email account, according to the HHS classification) that was secured the same day. Qilin normally runs double extortion: it steals data and encrypts systems. Paubox reports that the group has about 2,311 victims since it appeared in 2022 and that it chooses targets by opportunity rather than design. Whether this was a limited email compromise that Qilin is exploiting for extortion, or a deeper intrusion, can't be settled from public sources. Accounts differ, and Medix Dental IT argues the two stories should be kept separate.
The Attack Technique
Public details point to account compromise, not an exploited perimeter vulnerability:
- The practice's notice says an unauthorized person "used a compromised account."
- The HHS OCR filing classifies the incident as a Hacking/IT Incident with email as the breach location, as reported by Almeida Law Group and Federman & Sherwood.
- HIPAA Journal describes access to "its computer network" and systems storing patient information, which is broader wording.
No source says how the credentials were obtained, whether MFA was in place, or whether encryption took place.
Context, not attribution: Separately, Inception Security reports that Cisco Talos observed a cluster (UAT-11988) whose tactics are consistent with Qilin affiliates. That cluster exploited Cisco Secure Firewall Management Center flaws (CVE-2026-20079, which is on CISA's KEV list, and CVE-2026-20316) and used reverse-SSH tunnels toward Active Directory. Nothing links that campaign to Hawaii Family Dental. It's included here only because it shows that Qilin affiliates use several different ways in, from stolen credentials to exploiting edge devices.
What Organizations Should Do
- Enforce phishing-resistant MFA on all email and remote access accounts, especially shared front-desk and billing mailboxes that routinely handle PHI.
- Reduce the PHI sitting in mailboxes. Set retention limits, move patient files out of email and into access-controlled systems, and use DLP to flag bulk attachments of treatment or insurance data.
- Watch for account takeover signals: impossible-travel logins, new inbox forwarding rules, OAuth app grants, and mailbox exports. Alert on them rather than just logging them.
- Monitor extortion leak sites for your organization's name so a claim like Qilin's July 31 posting doesn't catch you off guard in the middle of an investigation.
- Patch and hunt on management-plane devices. If you run Cisco FMC, apply the hotfixes for CVE-2026-20079 and CVE-2026-20316 and check for home.jsp, /var/tmp/license.tmp and socks5.py artifacts. A patched build does not prove the device was never compromised.
- Prepare patient-facing anti-fraud messaging in advance. Breached PHI tends to lead to targeted phishing, so tell patients clearly which channels you will never use to ask for sensitive data.
Sources: Qilin claims 40k data breach at Hawaii Dental Group | Hacking Incident Affects 46,000 Hawaii Family Dental Patients | Hawaii Family Dental Notifies Patients of Cyberattack - PR.com | Hawaii Family Dental Data Breach: What It Means for Dental Practice... | Hawaii Dental Group, Inc DBA Hawaii Family Dental Data Breach Inves... | Hawaii Dental Group, Inc. DBA Hawaii Family Dental Data Breach – In... | Approximately 46,000 patients’ health information breached, U.S. de... | Hunt Cisco FMC: home.jsp, license.tmp, socks5