Supply chain ⛓ Supply Chain

HHS OCR $10K HIPAA Fine — Dental Practice Software Vendor, 15 Million Records Breach

📅 2026-03-06
Primary Source ↗

Incident Details

The US Department of Health and Human Services Office for Civil Rights (HHS OCR) issued a $10,000 civil monetary penalty to a dental practice management software vendor responsible for a breach affecting approximately 15 million patient records. The nominal penalty ($10,000 for 15 million affected individuals — less than $0.001 per person) reflects the vendor’s small size and limited financial resources, as HIPAA penalties are scaled based on the organization’s financial capacity. The case highlights the tension in HIPAA enforcement between accountability and deterrence — small healthcare IT vendors handling massive datasets face penalties that may be insufficient to incentivize adequate investment in security. The dental practice software market serves tens of thousands of dental offices nationwide.

Technical Details

Initial Attack Vector
A dental practice management software vendor suffered a data breach exposing protected health information for approximately 15 million dental patients
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2026-03-06 Breach occurred
  2. 2026-03-06 Publicly disclosed