Absolute Dental Group, LLC Data Breach Notice (Oregon Attorney General)
If you received a notice from Absolute Dental Group, LLC, here’s what the filing says was exposed, and what to do about it.
Absolute Dental Group, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on August 26, 2025. The filing puts the incident itself on February 19, 2025.
The February 19, 2025 breach at Absolute Dental Group, LLC placed the personal information of 1,223,635 people at risk. The company filed its formal notice with the Oregon Department of Justice on August 26, 2025 — 188 days later.
That six-and-a-half-month gap is the single most striking fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, the interval is long enough to matter to anyone whose records were involved.
What the Filing Actually Disclosed
The record lists only one category: personal information. No passwords, no financial account numbers, no Social Security numbers, and no medical identifiers beyond what falls under the broad “personal information” label are named. The absence of those more sensitive fields is genuine good news. It means the breach does not carry the automatic, high-velocity identity-theft risk that comes with a full set of government identifiers or payment details.
Still, names combined with addresses, dates of birth, or internal dental-patient identifiers remain valuable on the underground market. Criminals can use them for targeted phishing, insurance fraud, or as building blocks in larger identity profiles that develop over years.
The Value That Does Not Expire
Unlike a credit card, personal information tied to a dental patient cannot be cancelled or reissued. Once it is out, it stays out. The people whose records were included now carry a permanent, low-level increase in fraud risk that will not disappear when the news cycle moves on.
Because the filing uses a single generic category, you cannot assume every exposed record contained the same fields. Your own notification letter — if you received one — is the only document that can tell you exactly what applied to you.
How to Know Whether This Concerns You
Absolute Dental Group is required to notify affected individuals directly, usually by mail to the last known address. If you have not received a letter, it is likely your records were not part of this incident. However, if you have moved since February 19, 2025, or changed addresses without updating the practice, contact Absolute Dental Group directly to confirm whether you were on the affected list.
What Remains in Your Control
Even without exposed government IDs or account credentials, vigilance still matters. The exposure gives attackers more credible personal details to weave into convincing messages that appear to come from your dental provider, insurer, or even the IRS.
Watch for unsolicited communications that reference your dental history, recent visits, or billing information. Treat any request for additional verification or personal data with suspicion, even if it looks legitimate. Verify by calling the practice using a number you locate yourself rather than one provided in an email or text.
Continue monitoring your Explanation of Benefits statements from your dental insurer. Unexpected claims or services you did not receive are often the first visible sign of medical identity fraud. Report them immediately.
Place a fraud alert with the three major credit bureaus. While no credit card or banking data was listed, the alert adds a useful extra layer that forces lenders to verify your identity before opening new accounts in your name. It is free, lasts one year, and can be renewed.
Consider freezing your credit if you do not expect to apply for new loans or lines of credit soon. A freeze is more restrictive than a fraud alert but provides stronger protection against new-account fraud.
The Long View
This incident does not involve credential exposure, so there is no need to change any passwords related to Absolute Dental Group. The account itself was not compromised in a way that grants login access. The risk sits entirely in the non-revocable personal details that were taken.
That distinction matters. Many people instinctively reach for password changes after reading breach news; here that step would be wasted effort. The work that actually helps is the quieter, ongoing discipline of watching for misuse of the information that cannot be replaced.
The 188-day interval between the incident and the filing leaves open questions about when the company became aware and how quickly it could investigate. The record itself is silent on those details, as most breach filings are. What is certain is the number of people affected and the category of information involved.
For the 1,223,635 Oregon residents named in this notice, the practical outcome is a modest but permanent elevation in identity-related risk. The letter in your mailbox — or its absence — remains the clearest signal of whether that risk applies to you. If uncertainty lingers after checking with the practice, the credit tools and monitoring habits described above are the most effective steps available.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…