Absolute Dental Group, LLC was the subject of a data breach notification filed with the OR Attorney General. The AG filing was recorded on August 26, 2025. The breach or discovery date reported in the filing is February 19, 2025.
Data Exposed
Absolute Dental Group, LLC was the subject of a data breach notification filed with the OR Attorney General. The AG filing was recorded on August 26, 2025. The breach or discovery date reported in the filing is February 19, 2025.
Absolute Dental Group, LLC operates within the healthcare and dental services sector, providing comprehensive oral healthcare, preventive treatments, orthodontics, and specialized surgical procedures to patients across the Pacific Northwest. Because modern dental practices maintain exhaustive patient profiles to coordinate care, process insurance claims, and manage billing, Absolute Dental Group routinely collects and stores vast amounts of sensitive information. This operational reality requires the collection of not only basic contact details but also detailed clinical histories, diagnostic radiographs, financial records, and government-issued identification numbers, making the practice a repository for highly confidential personal data. In 2025, Absolute Dental Group, LLC reported a significant data security incident to the Oregon Attorney General, thrusting patient privacy concerns into the spotlight. While investigations into healthcare breaches often point toward sophisticated cyberattacks such as ransomware deployments, unauthorized network intrusions, or vulnerabilities within third-party administrative and electronic health record vendors, the fundamental issue remains a breakdown in digital perimeter defenses. In the healthcare sector, threat actors aggressively target administrative databases specifically because they house unencrypted files that can be easily monetized on illicit dark web markets or leveraged for targeted phishing schemes. Compromised data stemming from a dental practice breach typically exposes a dangerous combination of Protected Health Information (PHI) and Personally Identifiable Information (PII). When patient names, dates of birth, Social Security numbers, health insurance identifiers, and specific treatment or diagnostic records are exposed, the resulting risks are severe and long-lasting. Unlike a compromised credit card that can be cancelled, core identifiers like Social Security numbers and detailed medical histories cannot be easily replaced. This exposure leaves victims vulnerable to medical identity theft—where unauthorized parties fraudulently obtain care under a victim's name—as well as tax fraud, insurance fraud, financial account takeovers, and relentless targeted phishing campaigns designed to extract further information. As a healthcare provider handling sensitive patient data, Absolute Dental Group, LLC was bound by strict legal and regulatory frameworks, most notably the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and Oregon state consumer protection statutes. These laws mandate the implementation of robust administrative, physical, and technical safeguards, including data encryption, rigorous access controls, network monitoring, and regular risk assessments. The occurrence of a data breach strongly suggests a failure to meet these foundational regulatory standards, indicating that vulnerabilities in the network infrastructure were left unaddressed or that security protocols were inadequate to repel modern cyber threats. Receiving a data breach notification letter from Absolute Dental Group, LLC is a formal acknowledgment that your private information was compromised due to corporate negligence. Legally, the receipt of this notice establishes the concrete injury and legal standing required to participate in a class action lawsuit against the organization. Plaintiffs do not need to prove that they have already suffered actual financial loss or direct medical identity theft to seek accountability; the increased, imminent risk of future harm is sufficient under modern jurisprudence. Our law firm is actively investigating this breach on a contingency fee basis, meaning affected individuals pay nothing out of pocket, and legal fees are only recovered if a successful settlement or judgment is secured on your behalf.
Based on the data types reported, affected individuals face:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
What the Oregon Consumer Information Protection Act and federal statutes entitle you to recover:
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
HIPAA violations carry civil penalties between $100 and $50,000 per violation. Where a healthcare organization's negligence led to the exposure of protected health information, class members may recover statutory damages in addition to actual losses.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
Several state data breach laws provide for statutory minimum damages — fixed amounts recoverable per affected individual regardless of actual loss. These provisions exist specifically to make legal action viable for victims who have not yet experienced direct harm.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Oregon Consumer Information Protection Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
If Absolute Dental Group, LLC is a covered healthcare entity or business associate under HIPAA, affected patients have additional rights — including the right to an HHS complaint. These HIPAA violations also strengthen civil damages claims. Consult an attorney to understand your full remedies.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
Statutes of limitations for data breach claims vary by state but typically run 2–4 years. Depending on when you learned of the breach, you may still have time. Contact our office for a free eligibility review — there is no cost to find out.
Accepting free credit monitoring from Absolute Dental Group, LLC does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Received a notification letter from Absolute Dental Group, LLC?
What it means and what to do next.
Absolute Dental Group, LLC breach?
Free case review · No fee unless you win