2026 Azle Smiles — remote desktop attack May 26; patient PHI/IDs (Texas AG / HHS notice)
Data compromised
Names, addresses, dates of birth, driver’s license numbers, government-issued IDs, and medical information; Texas AG reporting also notes health insurance information may have been exposed. Payment information not affected per practice.
Technical writeup
Verified — Azle Smiles (Texas dental practice) patient website notice and Texas Attorney General data-security breach report (posted ~July 28, 2026). On May 26, 2026 the practice’s IT support identified irregularities on remote access session hosts; external remote-desktop access was locked down, accounts disabled, and an office-wide password reset forced. Investigation found certain patient personal information might have been accessed (names, addresses, DOB, DL/government IDs, medical information); payment card data and clinical care delivery were not affected per the notice. Practice notified the Texas AG and HHS. Complimentary identity monitoring offered; helpline (844) 473-3900. No public total count in the notice; recordsAffected 0 pending attestation.
Root cause
Attack on remote desktop web services / remote access session hosts; IT support locked down external access and forced password resets (practice notice)