- State
- NV
- Covered entity type
- Business Associate
- Individuals affected
- 3,758
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
OCR notified Cambridge Dental Consulting Group (CDCG), which performs corporate functions for Boston Dental Group Management LLC (BDG) and nineteen other dental practices that form an affiliated covered entity, that it received a complaint that BDG patients’ electronic protected health information (ePHI) was accessible to the public via its website. CDCG was using a website database with a function for internal use and storage of information regarding CDCG employees and patients which had inadvertently become publicly accessible. The accessible ePHI included the clinical, demographic and financial information of 3,758 CDCG patients. CDCG notified the affected individuals and the media, and submitted a breach report to OCR on May 9, 2018. OCR provided CDCG with substantial technical assistance regarding its compliance obligations under the Privacy, Security, and Breach Notification Rules. CDCG took numerous corrective actions to remedy the incident and formalize CDCG’s compliance program, including establishing additional technical and administrative safeguards and new policies and procedures.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.