The Rhysida ransomware group has listed a dental practice on its leak site, claiming it walked off with the full patient database and health records of the entire practice.
Threat trackers logged the Fairview Dental Group listing on August 21. The leak post says the stolen material includes the complete patient database, patient X-rays, scanned forms, consents, and invoices, plus health records that were stored unencrypted. Rhysida gave an estimated attack date of August 21.
Fairview Dental Group provides family dentistry, cosmetic treatments, dental implants, and invisible braces. The practice has not publicly confirmed an intrusion, and trackers flag the claim as unverified.
The listing fits Rhysida’s pattern of going after smaller medical and dental providers. The group previously claimed records from Melbourne clinics in Australia, and dental offices are attractive targets because they hold insurance data and clinical imaging alongside payment details, often with leaner security budgets.
For dental practices, the claim is a reminder that patient X-rays and scanned consent forms are protected health information under HIPAA and should be encrypted at rest. Even an unverified leak post can trigger OCR scrutiny, state breach reporting duties, and patient notification obligations. Practices should inventory where imaging and scanned documents live, confirm encryption is on, and review vendor and backup access paths.