Azle Cube Smiles patient data breach: who was affected, what to do
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Azle Cube Smiles, a dental practice in Azle, Texas, confirmed that a May 2026 cyberattack may have exposed patient names, home addresses, dates of birth, driver’s license and other government ID numbers, and medical information. The Texas Attorney General was told 2,940 Texas residents were affected. Payment information and details of dental treatment were not involved.
Azle Cube Smiles PLLC, a general dentistry practice in Azle, Texas, confirmed a cyberattack on the systems staff used to log in from outside the office. On 26 May 2026, its IT support spotted unusual activity on those remote-access systems. The practice cut off outside access, shut down the remote-access accounts, and reset passwords across the office. Patient records were restored quickly, and archived data was not affected.
Investigators concluded that some patient information may have been viewed or copied. The practice’s own public notice says that information could include names, home addresses, dates of birth, driver’s license numbers, other government-issued ID numbers, and medical information. Payment and financial information were not involved, and neither were the details of the dental care provided. The practice notified the Texas Attorney General and federal health officials, mailed letters to affected patients, posted a website notice, and offered free identity-protection monitoring. The Texas Attorney General listing, as reported on 21 September 2026, shows 2,940 Texas residents affected. That number is a Texas-resident count, not a nationwide total.
Why “no payment data” is the wrong headline for patients
Coverage of this incident keeps leading with what was not taken: no card numbers, no bank accounts, no chart of which tooth was treated. That is what the practice said, and it is true. It is also the least useful fact if you were a patient there.
What may have been copied is the set of details used to impersonate someone in the real world: your name, where you live, when you were born, and the numbers on a driver’s license or other government ID, along with some medical information. That combination is how a stranger opens accounts, talks their way through a call center, or files paperwork in your name. Cancelling a card you once used at the dentist does not touch any of that. The practice was careful to separate “medical information” from “details of the dental care provided,” so this is not a story about someone knowing your treatment. It is a story about someone possibly holding the identity file that sat next to that chart.
Two other points get blurred. “Potentially accessed or copied” is not proof a file left the building, and it is not proof nothing left either — treat the data as exposed. And lawsuit ads that add Social Security numbers, payment cards, or health-insurance details are reading broad boxes on a regulator form. They do not match what the practice itself said was involved. Do not shrug this off because of the “no financial data” line, and do not assume extra categories just because an advertisement listed them.
What to actually expect
- If the practice treated you as affected, the signal is a letter from Azle Cube Smiles offering free identity-protection monitoring. Public reporting of the incident appeared around 21 September 2026; the exact mailing date of individual letters has not been confirmed. No letter is not proof you were spared, especially if you live outside Texas — the 2,940 figure is only the Texas-resident count the state requires.
- You will see class-action ads citing 2,940 people and extra data types the practice did not confirm. Those pages are not a second investigation, and they are not a notice that you were included.
- Expect follow-up phishing that pretends to be the dental office or the monitoring service: a message asking you to “enroll,” “verify your driver’s license,” or “confirm your records after the breach.” The practice already has the data it needs to mail you; it does not need you to type that data into a link.
- The fraud pattern that fits this data is new-account and impersonation fraud over the coming months — credit, utilities, fake IDs — not mystery charges on a card you used to pay for a visit. Payment information was not involved.
What you can and cannot fix
If your name, home address, date of birth, driver’s license or other government ID number, or medical information was in the data that may have been copied, that copy cannot be pulled back. No company, website, or lawyer can delete it from whoever has it. An address that is out is out. A license or national ID number that is out is out. Nothing undoes the leak itself.
- If you received a letter from the practice, enroll in the complimentary monitoring it offered. That is the help tied to this incident. It will not recall the data; it may flag new accounts opened in your name.
- Place a credit freeze with the major credit bureaus, or at least a fraud alert. Name, address, date of birth, and a driver’s license number are enough to apply for credit. A freeze is the step that actually blocks that, and it is the highest-leverage move you can make with this particular mix of data.
- Watch the DMV and tax side, not just your bank app. A government ID number paired with your date of birth is useful for impersonation that never touches a credit card.
- Shrink the public trail that makes a leaked record dangerous. A bare file of name, address, and date of birth becomes much easier to use when people-search sites bolt on relatives, phone numbers, employers, and previous addresses. Those listings, unlike the stolen copy, can actually be removed. Opting out of them does not erase the breach. It does stop a stranger from turning one dental-office record into a full map of your life. A people-search result or a generic “breach check” also cannot tell you whether you were in this incident — that list is not something those tools search — so do not treat a clean result as proof you were spared.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Azle Cube Smiles.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Gyazo data breach: 23.6 million records leaked — what it means for you
On 11 September 2026 attackers broke into Gyazo and took about 23.62 million user records plus hundr…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
PayPal SSN Exposure Lasting Six Months — February 2026
A code change at PayPal allowed unauthorized access to Social Security Numbers and account details f…