Skip to content
Back to Blog
low severity October 23, 2024 · 4 min read

Henry Schein, Inc. Data Breach Notice (Oregon Attorney General)

If you received a notice from Henry Schein, Inc., here’s what the filing says was exposed, and what to do about it.

Henry Schein, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 23, 2024. The filing puts the incident itself on September 27, 2023.

Henry Schein, Inc. Data Breach Notice (Oregon Attorney General)

The personal information of 166,432 people was exposed in a breach at Henry Schein, Inc. that occurred on September 27, 2023. The company filed its notification with the Oregon Department of Justice on October 23, 2024 — 392 days later.

A Long Delay Between Incident and Notification

This 13-month gap between the incident date and the public filing is the most striking detail in the record. While notification deadlines vary by state and depend on when an investigation concludes, the interval here is unusually extended. The filing itself provides no discovery date, so it is not possible to determine how long the company knew about the breach before notifying affected individuals.

What the Filing Actually Lists as Exposed

The record names only one broad category: personal information. It does not specify further details such as Social Security numbers, dates of birth, addresses, or financial data. Because the filing uses this single generic term, it is not possible to state with certainty which exact data elements were taken. No passwords, no login credentials, and no permanent government identifiers are listed as exposed.

This absence of credential data is genuinely good news. There is no evidence that Henry Schein customer accounts themselves were compromised. You do not need to change any password connected to this incident.

What This Exposure Means for Identity Theft Risk

Personal information, even when described only in general terms, retains long-term value to identity thieves. Names combined with other details can be used to attempt new account fraud, tax refund fraud, or medical identity theft. Unlike a credit card number that can be canceled, once personal information leaves a company’s control it cannot be recalled or reissued.

The scale — more than 166,000 individuals — makes this one of the larger notifications filed in Oregon in recent years. The volume alone increases the chance that the data will appear on dark web markets or be used in automated fraud attempts over the coming months and years.

How to Determine Whether You Were Affected

Henry Schein is required to notify affected individuals directly, usually by mail to the last known address. If you have not received a letter from the company, it is likely that your records were not part of this incident. However, anyone who has moved since September 27, 2023 should contact Henry Schein directly to confirm whether their information was included.

The Limits of What This Filing Tells Us

The notification does not disclose how the breach occurred, whether data was exfiltrated, or what security measures were in place. It also does not name any specific subtypes of personal information beyond the single generic category. These details remain unknown to the public. The record is limited to who filed, when the incident occurred, when the filing was made, how many people were affected, and the broad category of data involved.

Why the Delay Matters to You

A 392-day interval between the breach date and the notification date gives any data that was taken a long head start. Criminals may have already had time to test, package, and sell the information. This does not mean every person named in the filing will become a victim, but it does mean the risk window is already open and will remain open for years.

Practical Steps That Address This Specific Exposure

  • Place a fraud alert or credit freeze with the three major credit bureaus. This is the single most effective step you can take when personal information has been exposed. It forces lenders to verify your identity before opening new accounts.
  • Monitor your credit reports and bank statements for unexpected activity. Review reports from Equifax, Experian, and TransUnion at least once per quarter for the next 24 months.
  • File your taxes early and watch for IRS rejection notices. Tax-related identity theft is a common consequence when personal information is exposed; submitting your return before fraudsters do can prevent fraudulent filings in your name.
  • Be extremely cautious with unsolicited calls, emails, or texts claiming to be from Henry Schein or government agencies. Scammers often use breach data to make their approaches more convincing.
  • Contact Henry Schein customer service if you moved after September 2023 and have not received a notification letter. Only the company can confirm whether your specific records were in the affected group.

The exposure cannot be undone, but its practical impact remains within your control. Acting quickly on credit monitoring and alerts reduces the chance that this incident becomes a long-term problem.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed October 23, 2024
Last reviewed July 22, 2026
Affected 166432
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email