Henry Schein, Inc. Data Breach Notice (Oregon Attorney General)
If you received a notice from Henry Schein, Inc., here’s what the filing says was exposed, and what to do about it.
Henry Schein, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 23, 2024. The filing puts the incident itself on September 27, 2023.
The personal information of 166,432 people was exposed in a breach at Henry Schein, Inc. that occurred on September 27, 2023. The company filed its notification with the Oregon Department of Justice on October 23, 2024 — 392 days later.
A Long Delay Between Incident and Notification
This 13-month gap between the incident date and the public filing is the most striking detail in the record. While notification deadlines vary by state and depend on when an investigation concludes, the interval here is unusually extended. The filing itself provides no discovery date, so it is not possible to determine how long the company knew about the breach before notifying affected individuals.
What the Filing Actually Lists as Exposed
The record names only one broad category: personal information. It does not specify further details such as Social Security numbers, dates of birth, addresses, or financial data. Because the filing uses this single generic term, it is not possible to state with certainty which exact data elements were taken. No passwords, no login credentials, and no permanent government identifiers are listed as exposed.
This absence of credential data is genuinely good news. There is no evidence that Henry Schein customer accounts themselves were compromised. You do not need to change any password connected to this incident.
What This Exposure Means for Identity Theft Risk
Personal information, even when described only in general terms, retains long-term value to identity thieves. Names combined with other details can be used to attempt new account fraud, tax refund fraud, or medical identity theft. Unlike a credit card number that can be canceled, once personal information leaves a company’s control it cannot be recalled or reissued.
The scale — more than 166,000 individuals — makes this one of the larger notifications filed in Oregon in recent years. The volume alone increases the chance that the data will appear on dark web markets or be used in automated fraud attempts over the coming months and years.
How to Determine Whether You Were Affected
Henry Schein is required to notify affected individuals directly, usually by mail to the last known address. If you have not received a letter from the company, it is likely that your records were not part of this incident. However, anyone who has moved since September 27, 2023 should contact Henry Schein directly to confirm whether their information was included.
The Limits of What This Filing Tells Us
The notification does not disclose how the breach occurred, whether data was exfiltrated, or what security measures were in place. It also does not name any specific subtypes of personal information beyond the single generic category. These details remain unknown to the public. The record is limited to who filed, when the incident occurred, when the filing was made, how many people were affected, and the broad category of data involved.
Why the Delay Matters to You
A 392-day interval between the breach date and the notification date gives any data that was taken a long head start. Criminals may have already had time to test, package, and sell the information. This does not mean every person named in the filing will become a victim, but it does mean the risk window is already open and will remain open for years.
Practical Steps That Address This Specific Exposure
- Place a fraud alert or credit freeze with the three major credit bureaus. This is the single most effective step you can take when personal information has been exposed. It forces lenders to verify your identity before opening new accounts.
- Monitor your credit reports and bank statements for unexpected activity. Review reports from Equifax, Experian, and TransUnion at least once per quarter for the next 24 months.
- File your taxes early and watch for IRS rejection notices. Tax-related identity theft is a common consequence when personal information is exposed; submitting your return before fraudsters do can prevent fraudulent filings in your name.
- Be extremely cautious with unsolicited calls, emails, or texts claiming to be from Henry Schein or government agencies. Scammers often use breach data to make their approaches more convincing.
- Contact Henry Schein customer service if you moved after September 2023 and have not received a notification letter. Only the company can confirm whether your specific records were in the affected group.
The exposure cannot be undone, but its practical impact remains within your control. Acting quickly on credit monitoring and alerts reduces the chance that this incident becomes a long-term problem.
Report details & sourcing
Related breaches
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…
Castle Management, LLC Data Breach Notice (Vermont Attorney General)
Castle Management, LLC notified Vermont residents of a data breach in a filing reported to the Vermo…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…