Skip to content
Back to Blog
low severity July 29, 2025 · 3 min read

Michael Bilikas DDS Data Breach Notice (Oregon Attorney General)

If you received a notice from Michael Bilikas DDS, here’s what the filing says was exposed, and what to do about it.

Michael Bilikas DDS notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 29, 2025. The filing puts the incident itself on May 18, 2025.

Michael Bilikas DDS Data Breach Notice (Oregon Attorney General)

The filing from Michael Bilikas DDS shows that personal information belonging to 23,517 people was exposed in an incident on May 18, 2025. The practice notified the Oregon Department of Justice on July 29, 2025 — 72 days later.

If you received a letter, your records were part of this group

The organisation is required to notify affected individuals directly, usually by post. If you have not received anything, it is likely your information was not included. However, if you have moved since May 18, 2025, contact the dental practice directly to confirm whether your records were affected.

What personal information actually means here

The record lists only “personal information” as exposed. It does not name Social Security numbers, driver’s license numbers, financial details, medical records beyond basic identifiers, or any other specific category. No passwords were exposed. No permanent government identifiers such as Social Security numbers appear in the filing.

This is important. Without those stronger identifiers, the immediate risk of new account fraud or tax-related identity theft is lower than in many breaches. The exposed data still carries long-term value for identity thieves who combine it with information obtained elsewhere. Names, addresses, dates of birth, and phone numbers do not expire. Once they are out, they remain useful for years in phishing, impersonation, or building a fuller profile.

The 72-day gap between incident and notification

The breach occurred on May 18 and the filing reached the state on July 29. That interval is the most notable fact in the record. Notification timelines vary by when an investigation concludes and by state requirements, so the gap alone does not prove fault. It does, however, mean that anyone whose information was taken had it circulating for more than two months before official notice began.

Why this exposure still matters even without SSNs

Personal information from a dental practice almost always includes details tied to your health history and contact information. Thieves can use accurate name-plus-date-of-birth combinations to answer security questions, impersonate you with insurers, or craft convincing spear-phishing emails that reference recent appointments or procedures. The absence of passwords is genuinely good news — you do not need to change any credentials for this incident — but the remaining data still gives attackers a foundation for fraud that can take months or years to appear.

What you can still control

Because no passwords or login credentials were exposed, this incident does not put any of your online accounts at direct risk from this breach. The real ongoing concern is the durability of the personal details now outside the practice’s control.

Place a fraud alert with the three major credit bureaus if you have not done so in the past year. It forces lenders to verify your identity before opening new accounts in your name and lasts 90 days, after which you can renew it. This step is especially useful when only partial personal information has been lost.

Review your Explanation of Benefits statements from your dental insurer for any claims you do not recognise. While the filing does not list full medical records as exposed, basic treatment information is often attached to personal identifiers in dental offices. Early detection of fraudulent claims protects both your credit and your insurance history.

Be wary of unsolicited calls, texts, or emails that reference dental work, appointments, or billing. Scammers now have enough accurate personal context to sound legitimate. Hang up on unexpected requests for verification codes, payment details, or additional personal information.

Consider whether you need to update your contact details with the practice itself. If you have moved or changed phone numbers since May 2025, outdated records increase the chance that future legitimate communications from them could be misdirected.

Finally, monitor your credit reports for free once per week at AnnualCreditReport.com. Look for accounts or inquiries you do not recognise. The 72-day delay means suspicious activity could have begun weeks before you were notified.

The record contains no information about how the breach occurred, whether the system was internet-facing, or what security measures were in place. Those details remain unknown outside the investigation. What is known is that 23,517 individuals had their personal information exposed, and the notification arrived more than two months after the incident date.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed July 29, 2025
Last reviewed July 22, 2026
Affected 23517
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email