Skip to content
Back to Blog
low severity July 22, 2024 · 3 min read

Sutton Dental Arts Data Breach Notice (Oregon Attorney General)

If you received a notice from Sutton Dental Arts, here’s what the filing says was exposed, and what to do about it.

Sutton Dental Arts notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 22, 2024. The filing puts the incident itself on April 11, 2024.

Sutton Dental Arts Data Breach Notice (Oregon Attorney General)

The April 11, 2024 breach at Sutton Dental Arts means that personal information belonging to 4,109 people is now outside the clinic’s control. The filing reached the Oregon Department of Justice on July 22, 2024 — 102 days later. That interval is the single most concrete fact in the public record.

Personal information that cannot be replaced

The notice lists personal information as exposed. Because the record names no passwords, no financial account numbers, and no permanent government identifiers such as Social Security numbers, those specific risks do not apply here. What remains is information that, once loose, stays loose.

For patients of a dental practice this typically includes name, date of birth, address, phone number, email address, and details from treatment records. Even without a Social Security number attached, that combination still enables targeted fraud attempts such as fake medical claims, insurance impersonation, or phishing that appears to come from a provider who already knows your history.

What the 102-day gap actually tells you

State law gives organisations time to investigate and contain an incident before they must notify affected residents. A three-and-a-half-month gap between the incident date of April 11 and the filing on July 22 falls within the range seen in many legitimate investigations. The record does not state when Sutton Dental Arts first discovered the breach, so it is impossible to calculate any further delay. The only dates that exist are the ones printed beside this article.

How to know whether this filing includes you

Sutton Dental Arts is required to notify every affected individual directly, usually by mail to the address they have on file. If you have not received a letter, it is likely your records were not part of the 4,109 affected. However, if you have moved since April 11, 2024, a letter may have gone to an old address. In that case contact the clinic directly to confirm whether your information was included.

The lasting risk profile of dental records

Medical and dental details do not expire. A breach that includes treatment notes, insurance information, or billing history can be used years later to build convincing social-engineering attacks or fraudulent claims. Because no passwords were exposed, your Sutton Dental Arts patient portal account itself is not at immediate risk from this incident. The exposure is about what strangers can now claim or infer about you, not about logging into the clinic’s systems.

Why the exact categories matter more than the headline number

The filing does not claim that every one of the 4,109 people had the same data exposed. Some records may have contained only contact details; others may have included clinical notes. Your own notification letter is the only document that can tell you precisely what left the clinic’s systems. The public filing simply lists the categories the incident touched.

What you can still control

Even when some information cannot be changed, your response still shapes how useful that data is to someone who should not have it. The most effective steps address the specific exposure described in this notice rather than generic breach advice.

  • Review any explanation of benefits or insurance statements for the next 12 months for claims you did not file or services you did not receive. Dental insurers sometimes catch fraudulent claims faster when patients flag them early.
  • Place a free fraud alert with the three major credit bureaus. This does not block new accounts but requires lenders to verify your identity, adding friction that stops many opportunistic applications based on personal details.
  • Monitor your bank and credit-card statements for small test charges. Dental-related scams often begin with modest transactions that test whether a card is still active.
  • Be especially wary of unsolicited calls or emails that reference your dental history, recent appointments, or insurance provider. Hang up or delete and contact the clinic or insurer using a number you look up yourself.
  • If you receive the official breach notification letter, follow the specific remediation steps it contains. Those instructions are tailored to the exact data confirmed for your record.

The breach at Sutton Dental Arts is now part of the permanent public record. The information taken cannot be retrieved, but the ways it can be weaponised can still be narrowed. Knowing exactly what was exposed, what was not, and how long the organisation took to file gives you a clearer picture than most breach announcements provide.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed July 22, 2024
Last reviewed July 22, 2026
Affected 4109
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email