Were you recently affected by a data breach?

Tarboro Family Dentistry Data Breach

Tarboro Family Dentistry notified patients that a network security incident may have exposed their names, Social Security numbers, and medical and health insurance information.

Tarboro Family Dentistry
Date of Breach: June 1, 2026
CAU logo

Who was affected:

Clients of Tarboro Family Dentistry

Impacted Data:

Names, addresses, Social Security numbers, medical treatment information, health insurance information

Tarboro Family Dentistry, a dental practice operating under Gray Bailey, D.M.D., P.A. in Tarboro, North Carolina, has notified patients that their personal information may have been exposed in a data security incident. Dental and medical practices maintain some of the most sensitive records a patient has, and patients trust that this information will be kept secure.

Tarboro Family Dentistry’s Data Breach Investigation

According to the notification letter sent to affected individuals, Tarboro Family Dentistry (“TFD”) detected and stopped a network security incident on or around June 1, 2026. TFD has stated that an unauthorized party gained access to its network and may have acquired certain files from its systems. Upon discovering the incident, TFD says it promptly began taking steps to secure its systems and engaged third-party forensic specialists to investigate the scope of the intrusion and to conduct a comprehensive review of the potentially affected records.

TFD’s investigation concluded on July 31, 2026. Through that review, the practice determined that some patients’ personal information was contained in the files an unauthorized party may have accessed. TFD reported the incident to appropriate authorities and says it has implemented additional measures to further secure its network environment going forward. As of the date of the notification letter, TFD stated it had not received any reports that a patient’s information had actually been misused as a result of the incident.

Data security incidents at healthcare providers are a significant and ongoing concern because the records involved typically combine core identity information with sensitive medical history, making them especially valuable to identity thieves and considerably harder for victims to fully remediate than a typical financial account breach. Dental and medical offices, in particular, have become frequent targets for network intrusions in recent years. These practices often store detailed patient records, insurance billing information, and payment data on networked systems, but many smaller healthcare providers operate with more limited cybersecurity resources than larger hospital systems, which can leave gaps that unauthorized actors are able to exploit.

When a dental or medical practice experiences a network intrusion, patients are often left facing months of uncertainty about how their Social Security number, insurance details, and treatment history may ultimately be used. Unlike a stolen credit card, which can simply be cancelled and reissued, a compromised Social Security number or medical record cannot be replaced, and the exposure can create a lasting risk of identity theft, medical identity fraud, and targeted phishing attempts that reference a patient’s actual treatment history to appear more credible. Because the specific type of intrusion and the identity of the unauthorized party involved in this incident have not been publicly detailed beyond what TFD disclosed in its notification letter, affected patients are encouraged to take the protective steps outlined below rather than wait for additional information to be released.

TFD has offered affected individuals twenty-four months of complimentary single-bureau credit monitoring, credit report, and credit score services through Cyberscout, a TransUnion company that specializes in fraud assistance and remediation. Patients who received a notification letter are encouraged to enroll in these services before the enrollment deadline stated in their letter, and to remain alert for any signs that their information has been used without their permission, even after that monitoring period ends. Healthcare providers that collect and store sensitive patient data bear a responsibility to safeguard it, and patients affected by a breach like this one deserve a clear accounting of what happened and meaningful support in protecting themselves going forward.

State and federal notification laws generally require an entity that experiences a data security incident to notify affected individuals and the relevant state Attorney General once an investigation confirms that personal information was compromised, which is why there is often a gap of several weeks or months between when an incident is detected and when patients actually receive a letter in the mail. That gap can leave affected individuals unaware that their information is at risk during the exact window when it would be most useful to monitor their accounts and credit files closely. This is one reason consumer advocates and regulators alike encourage anyone who works with a healthcare provider, financial institution, or other business handling sensitive personal information to check periodically for breach notifications rather than assuming no news means no risk.

When Did This Breach Occur?

TFD detected and stopped the network security incident on or around June 1, 2026. The practice’s investigation into which records were affected concluded on July 31, 2026, at which point TFD determined that patient personal information had been contained in the impacted files. Notification letters to affected individuals were dated September 29, 2026.

What Information Was Breached?

The information potentially involved varies by individual but may include name, address, Social Security number, medical treatment information, and health insurance information. TFD has stated it is not aware of any reports of identity theft or fraud connected to this incident as of the date of its notification letter.

What You Can Do

If you received a notification letter from Tarboro Family Dentistry, consider taking the following steps:

  • Enroll in the complimentary 24-month credit monitoring service offered through Cyberscout before the deadline in your letter.
  • Place a fraud alert or security freeze on your credit file with Equifax, Experian, and TransUnion.
  • Request and review a free copy of your credit report at annualcreditreport.com.
  • Monitor your financial and insurance statements closely for any unauthorized activity.
  • Report any suspected identity theft to your state Attorney General and the Federal Trade Commission.

File a Data Breach Lawsuit Against Tarboro Family Dentistry

If you received a data breach notification letter from Tarboro Family Dentistry, you may be entitled to compensation. Companies that collect and store sensitive medical and financial information have a responsibility to keep it secure, and when that trust is broken, affected individuals deserve answers and accountability.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed
Date of Breach: December 2-18, 2025
Date of Breach: December 2-18, 2025
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.