Azle Cube Smiles, a dental practice located in Azle, Texas, has reported a data security incident to the Texas Attorney General involving the personal and medical information of thousands of its patients. Businesses that handle sensitive medical, financial, and identification information have a responsibility to protect that data from unauthorized access, and patients affected by this incident deserve a clear explanation of what happened.
Azle Cube Smiles’s Data Breach Investigation
According to a filing submitted to the Texas Attorney General’s Data Security Breach Reports portal, published on September 11, 2026, Azle Cube Smiles disclosed a data security incident affecting 2,940 Texas residents. The filing lists the categories of information involved as names, addresses, Social Security numbers, driver’s license numbers, government-issued identification numbers, financial account information, medical information, health insurance information, and dates of birth. As of this notice’s publication, Azle Cube Smiles has not released additional public information about the incident beyond what appears in the state filing, including the specific date the breach occurred, how unauthorized parties gained access, or whether the incident involved ransomware, a phishing attack, or another method of intrusion.
Dental practices, like many other healthcare-adjacent businesses, have become increasingly attractive targets for cybercriminals because of the breadth of sensitive information they routinely store. A dental office’s records often include not just clinical treatment history, but also insurance details, billing and payment information, and government identification used to verify a patient’s identity. This combination of medical, financial, and identity data makes healthcare providers a single point of compromise that can expose multiple categories of a patient’s personal life at once, which is part of why the healthcare sector consistently ranks among the most frequently targeted industries in data breach reporting nationwide.
Texas law generally requires businesses to notify affected residents and the Attorney General within a reasonable window once a breach is discovered and its scope understood, though the precise discovery and containment dates for this particular incident were not included in the public filing reviewed for this article. The gap between when a breach actually occurs and when it becomes public can sometimes span weeks or months, since organizations typically need time to investigate the scope of unauthorized access, determine which individuals were affected, and prepare legally required notifications before any information becomes public. This is a normal part of the regulatory process rather than evidence of wrongdoing, but it does mean affected individuals may not learn of an incident until well after it actually happened.
The specific combination of data types reportedly involved in this incident, Social Security numbers, driver’s license numbers, government-issued identification numbers, and financial account information, together with medical and health insurance information, is particularly valuable to identity thieves. Social Security numbers and government-issued IDs can be used to open new lines of credit, file fraudulent tax returns, or apply for loans in a victim’s name. Financial account information can enable direct unauthorized transactions. Medical and health insurance information can be used to commit medical identity theft, in which a criminal uses someone else’s insurance information to receive treatment, order medical equipment, or submit fraudulent insurance claims. This can lead to inaccurate entries in a victim’s own medical records and unexpected bills or collection notices for care they never received, complications that can be difficult and time-consuming to untangle even after the fraud is discovered.
Because the full scope of how this information may be used is not always immediately apparent to affected individuals, cybersecurity and consumer protection experts generally recommend that anyone notified of a breach involving this combination of data types take proactive steps to monitor their accounts and credit files for signs of misuse, rather than waiting for a specific incident of fraud to occur before acting.
When Did This Breach Occur?
Azle Cube Smiles’s data breach notification was published to the Texas Attorney General’s Data Security Breach Reports portal on September 11, 2026. The filing did not specify the date the breach itself occurred or the date it was discovered, information that is sometimes omitted from these public disclosures depending on what the reporting business chooses to include.
What Information Was Breached?
Per the filing, the categories of information involved include names, addresses, Social Security numbers, driver’s license numbers, government-issued identification numbers, financial account information, medical information, health insurance information, and dates of birth for 2,940 Texas residents.
What You Can Do
If you received a notice from Azle Cube Smiles or believe you may have been affected by this breach, consider taking the following steps:
- Monitor your bank and credit card statements closely for any unauthorized transactions.
- Consider placing a fraud alert or security freeze on your credit files with the three major credit bureaus.
- Watch for suspicious activity related to your health insurance, including unfamiliar claims or explanation-of-benefits statements.
- Be cautious of unsolicited calls, emails, or texts referencing this breach, as scammers sometimes exploit public breach notices to run phishing schemes.
- Keep any notification letter you receive, along with records of any suspicious activity, in case you need them later.
File a Data Breach Lawsuit Against Azle Cube Smiles
If your personal information was exposed in the Azle Cube Smiles data breach, you may have legal options available to you. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.