Were you recently affected by a data breach?

7 to 7 Dental & Orthodontics Data Breach

7 to 7 Dental & Orthodontics, a multi-location dental practice in San Antonio, Texas, reported a data security incident to the Texas Attorney General affecting approximately 3,526 individuals. The practice has not yet publicly detailed the specific information involved or confirmed that affected patients have been notified.

7 to 7 Dental & Orthodontics
Date of Breach: Reported to the Texas Attorney General on September 17, 2026 (specific incident dates not yet publicly disclosed)
CAU logo

Who was affected:

Clients of 7 to 7 Dental & Orthodontics

Impacted Data:

The company has not publicly disclosed a specific list of the personal information types involved in this incident.

7 to 7 Dental & Orthodontics, a dental practice with multiple locations across San Antonio, Texas, notified the Texas Attorney General’s office of a data security incident affecting approximately 3,526 individuals. Companies that store patient and financial information have a responsibility to protect that data from unauthorized access, and a breach at a healthcare provider can leave affected individuals vulnerable to fraud and identity theft.

7 to 7 Dental & Orthodontics’s Data Breach Investigation

According to the report filed with the Texas Attorney General, 7 to 7 Dental & Orthodontics experienced a data security incident that has affected approximately 3,526 individuals. The filing does not specify the cause of the incident or the exact category of information involved, listing the affected data only as falling under a general “other” classification. As of the filing date, the notice indicates that consumer notice had not yet been provided, meaning affected patients may not yet know their information was involved.

Dental and healthcare practices have become a frequent target for data security incidents in recent years. These practices typically maintain detailed patient records that combine personal identifiers, insurance information, and payment details in a single system, which makes them an attractive target for anyone seeking to exploit that data for financial gain. Smaller, multi-location practices like 7 to 7 Dental & Orthodontics often rely on shared practice-management software and centralized scheduling and billing systems across their offices, meaning an incident affecting one part of that infrastructure can potentially touch patient records tied to any of the practice’s locations.

When a healthcare provider files a data security incident report with a state regulator, it typically means state law requires the business to notify affected residents once it has determined the scope of what happened. In many cases, the investigation into exactly what data was accessed and by whom continues even after the initial regulatory filing, which is one reason the specific categories of exposed information are not always available at the time a report first becomes public. It is common for a company to update its filing or send more detailed notification letters to affected individuals as the investigation progresses.

Because dental and medical records often combine several types of sensitive information, including full names, dates of birth, insurance details, and sometimes Social Security numbers or payment card data, incidents involving healthcare providers can expose individuals to a broad range of follow-on risks, from medical identity theft to routine financial fraud. Patients who receive a notification letter from a dental or medical provider should treat it seriously and review it carefully once it arrives, even before all the details of an incident are fully public.

Regulatory filings like the one made by 7 to 7 Dental & Orthodontics are also often the first public sign that a review is underway, well before individual notification letters go out to patients. Affected individuals are encouraged to watch for official communication directly from the practice regarding this incident and to be cautious of unsolicited messages claiming to be related to the breach, since scammers sometimes use news of a real data breach to launch phishing attempts targeting the same population.

State data breach notification laws generally require businesses to notify residents within a set window after discovering an incident, though the exact timeline can vary depending on how long it takes to determine which individuals and records were affected. It is not unusual for a company to file an initial regulatory notice indicating that consumer notification is still pending, as this filing does, while the underlying investigation into the scope and cause of the incident continues in the background. Patients should not assume that the absence of a detailed public explanation means the incident was minor; it may simply mean the company is still working through the process of confirming exactly whose information was involved.

Data security incidents affecting healthcare and dental practices can also carry consequences beyond the immediate financial risk. Medical identity theft, in which a bad actor uses stolen personal information to obtain medical services or prescriptions under someone else’s name, can be more difficult to detect and unwind than ordinary financial fraud, since it may not show up on a standard credit report. Individuals who receive notice of this incident should pay close attention not only to their financial accounts but also to any unfamiliar medical bills, insurance statements, or explanation-of-benefits notices that could indicate their information was misused.

When Did This Breach Occur?

7 to 7 Dental & Orthodontics reported this incident to the Texas Attorney General on September 17, 2026. The company has not yet publicly disclosed the specific dates on which the underlying incident occurred, was discovered, or was reported to the company.

What Information Was Breached?

The Texas Attorney General filing lists the type of information affected only under a general “other” category, and 7 to 7 Dental & Orthodontics has not publicly specified which categories of personal or health information were involved. The filing also indicates that consumer notice had not yet been provided as of the report date.

What You Can Do

Because the specific information involved in this incident has not yet been publicly disclosed, affected individuals should watch for an official notification letter from 7 to 7 Dental & Orthodontics and consider the following general precautions in the meantime:

  • Monitor bank and credit card statements for unauthorized transactions
  • Review your credit reports for unfamiliar accounts or inquiries
  • Consider placing a fraud alert or credit freeze with the major credit bureaus
  • Be cautious of unsolicited calls, texts, or emails referencing this incident
  • Contact 7 to 7 Dental & Orthodontics directly with any questions once a notification letter is received

File a Data Breach Lawsuit Against 7 to 7 Dental & Orthodontics

Individuals whose personal information may have been exposed in this incident may have legal options worth exploring. An attorney experienced in data breach litigation can help evaluate whether affected patients have grounds to pursue compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Between March 28, 2026, and April 12, 2026 (at vendor Ernst & Young LLP)
Date of Breach: On or about August 26, 2026
Date of Breach: On or about March 6, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.