7 to 7 Dental & Orthodontics, a dental practice with multiple locations across San Antonio, Texas, notified the Texas Attorney General’s office of a data security incident affecting approximately 3,526 individuals. Companies that store patient and financial information have a responsibility to protect that data from unauthorized access, and a breach at a healthcare provider can leave affected individuals vulnerable to fraud and identity theft.
7 to 7 Dental & Orthodontics’s Data Breach Investigation
According to the report filed with the Texas Attorney General, 7 to 7 Dental & Orthodontics experienced a data security incident that has affected approximately 3,526 individuals. The filing does not specify the cause of the incident or the exact category of information involved, listing the affected data only as falling under a general “other” classification. As of the filing date, the notice indicates that consumer notice had not yet been provided, meaning affected patients may not yet know their information was involved.
Dental and healthcare practices have become a frequent target for data security incidents in recent years. These practices typically maintain detailed patient records that combine personal identifiers, insurance information, and payment details in a single system, which makes them an attractive target for anyone seeking to exploit that data for financial gain. Smaller, multi-location practices like 7 to 7 Dental & Orthodontics often rely on shared practice-management software and centralized scheduling and billing systems across their offices, meaning an incident affecting one part of that infrastructure can potentially touch patient records tied to any of the practice’s locations.
When a healthcare provider files a data security incident report with a state regulator, it typically means state law requires the business to notify affected residents once it has determined the scope of what happened. In many cases, the investigation into exactly what data was accessed and by whom continues even after the initial regulatory filing, which is one reason the specific categories of exposed information are not always available at the time a report first becomes public. It is common for a company to update its filing or send more detailed notification letters to affected individuals as the investigation progresses.
Because dental and medical records often combine several types of sensitive information, including full names, dates of birth, insurance details, and sometimes Social Security numbers or payment card data, incidents involving healthcare providers can expose individuals to a broad range of follow-on risks, from medical identity theft to routine financial fraud. Patients who receive a notification letter from a dental or medical provider should treat it seriously and review it carefully once it arrives, even before all the details of an incident are fully public.
Regulatory filings like the one made by 7 to 7 Dental & Orthodontics are also often the first public sign that a review is underway, well before individual notification letters go out to patients. Affected individuals are encouraged to watch for official communication directly from the practice regarding this incident and to be cautious of unsolicited messages claiming to be related to the breach, since scammers sometimes use news of a real data breach to launch phishing attempts targeting the same population.
State data breach notification laws generally require businesses to notify residents within a set window after discovering an incident, though the exact timeline can vary depending on how long it takes to determine which individuals and records were affected. It is not unusual for a company to file an initial regulatory notice indicating that consumer notification is still pending, as this filing does, while the underlying investigation into the scope and cause of the incident continues in the background. Patients should not assume that the absence of a detailed public explanation means the incident was minor; it may simply mean the company is still working through the process of confirming exactly whose information was involved.
Data security incidents affecting healthcare and dental practices can also carry consequences beyond the immediate financial risk. Medical identity theft, in which a bad actor uses stolen personal information to obtain medical services or prescriptions under someone else’s name, can be more difficult to detect and unwind than ordinary financial fraud, since it may not show up on a standard credit report. Individuals who receive notice of this incident should pay close attention not only to their financial accounts but also to any unfamiliar medical bills, insurance statements, or explanation-of-benefits notices that could indicate their information was misused.
When Did This Breach Occur?
7 to 7 Dental & Orthodontics reported this incident to the Texas Attorney General on September 17, 2026. The company has not yet publicly disclosed the specific dates on which the underlying incident occurred, was discovered, or was reported to the company.
What Information Was Breached?
The Texas Attorney General filing lists the type of information affected only under a general “other” category, and 7 to 7 Dental & Orthodontics has not publicly specified which categories of personal or health information were involved. The filing also indicates that consumer notice had not yet been provided as of the report date.
What You Can Do
Because the specific information involved in this incident has not yet been publicly disclosed, affected individuals should watch for an official notification letter from 7 to 7 Dental & Orthodontics and consider the following general precautions in the meantime:
- Monitor bank and credit card statements for unauthorized transactions
- Review your credit reports for unfamiliar accounts or inquiries
- Consider placing a fraud alert or credit freeze with the major credit bureaus
- Be cautious of unsolicited calls, texts, or emails referencing this incident
- Contact 7 to 7 Dental & Orthodontics directly with any questions once a notification letter is received
File a Data Breach Lawsuit Against 7 to 7 Dental & Orthodontics
Individuals whose personal information may have been exposed in this incident may have legal options worth exploring. An attorney experienced in data breach litigation can help evaluate whether affected patients have grounds to pursue compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.