Agave Dental, a dental practice in Floresville, Texas, recently notified patients that their personal information may have been accessed following a cybersecurity incident involving the practice’s remote access systems. Dental practices and other healthcare providers handle highly sensitive patient information, and a breach like this one highlights the responsibility such practices carry to protect the personal data entrusted to them.
Agave Dental’s Data Breach Investigation
According to a notification letter sent to patients dated July 16, 2026, Agave Dental was informed by its IT support company on May 26, 2026 that irregularities had been identified related to remote access session hosts. The practice’s IT team quickly determined that an attack had occurred and moved to lock down external access to its remote desktop web services, disabling all accounts with remote access and forcing an office-wide password reset. According to the letter, the patient record platform was restored quickly and the practice’s archived data was not affected by the incident.
Agave Dental’s investigation determined that certain patient personal information may have been accessed, including names, addresses, dates of birth, Social Security numbers, and driver’s license numbers. The letter specifically states that the incident did not affect Protected Health Information (PHI) such as treatment and payment records. Agave Dental reported that it has notified the Texas Attorney General and the U.S. Department of Health and Human Services (HHS) of the incident, and stated it is not aware of any additional suspicious activity since the incident occurred, though the practice’s IT support company has continued to monitor its systems.
Healthcare providers, including dental practices, remain frequent targets of cyberattacks because they store a combination of identity and financial information, such as Social Security numbers and driver’s license numbers, that is highly valuable on the black market even when clinical treatment records are not directly compromised. The exposure of a Social Security number alongside a name and date of birth is particularly concerning because that combination is often sufficient on its own to open new credit accounts, file fraudulent tax returns, or apply for government benefits in a victim’s name.
The roughly seven-week gap between Agave Dental’s detection of the incident on May 26, 2026 and patient notification on July 16, 2026 is consistent with the time many organizations require to investigate the scope of a security incident, determine which individuals were affected, and prepare legally compliant notifications under state and federal law. Texas’s Identity Theft Enforcement and Protection Act requires notification to affected residents and the state Attorney General without unreasonable delay once a breach involving sensitive personal information is confirmed.
When Did This Breach Occur?
Agave Dental’s IT support company identified irregularities on May 26, 2026, and the practice determined shortly thereafter that an attack had occurred. Patients were notified by letter dated July 16, 2026.
What Information Was Breached?
According to Agave Dental’s notification letter, the affected information may have included patients’ names, addresses, dates of birth, Social Security numbers, and driver’s license numbers. The letter states that treatment and payment information (PHI) was not affected.
What You Can Do
If you received a notice from Agave Dental, consider taking the following steps:
- Place a fraud alert with one of the three major credit bureaus (Equifax, Experian, or TransUnion) — this will automatically notify the other two.
- Review your credit reports closely for accounts you did not open.
- Enroll in the complimentary identity protection monitoring Agave Dental is offering to affected patients.
- Monitor your financial accounts and tax filings for signs of fraud.
- Keep your notification letter and any related correspondence for your records.
File a Data Breach Lawsuit Against Agave Dental
If you received a notice about the Agave Dental data breach, you may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.