
Another major dental-related breach just hit the headlines — and it’s a reminder that the weakest link in cybersecurity often isn’t a firewall… it’s an inbox.
Delta Dental of Virginia (DDVA), the largest dental benefits carrier in Virginia, has announced a data breach affecting 145,918 individuals after an employee email account was accessed by an unauthorized party. The HIPAA Journal
While DDVA isn’t a dental practice, incidents like this matter to every practice and DSO because they show exactly how attackers are getting in — and what kinds of data they’re after.
DDVA detected suspicious activity in an employee’s email account on April 23, 2025. A forensic investigation confirmed that the account had been accessed by an unauthorized third party starting March 21, 2025, with access continuing until the account was secured on April 23. The HIPAA Journal
Emails and attachments in that account may have been viewed or taken during that window. Notification letters began going out on November 21, 2025. The HIPAA Journal
The potentially compromised information is exactly what cybercriminals want for identity theft and insurance fraud, including:
In other words: a full identity + healthcare profile.
This wasn’t a server hack. It wasn’t ransomware.
It was email compromise — still the #1 doorway into healthcare environments.
Here’s why you should care:
After confirming the breach, DDVA says it implemented stronger email security safeguards and delivered more security awareness training. They’re offering affected members credit and identity monitoring services for 12 months. The HIPAA Journal
That’s a solid response — but the bigger lesson is prevention.
If you want to avoid becoming the next breach notice:
✅ Lock down email with modern security controls
✅ Run phishing simulations + real training
Phishing emails now look like Open Dental notices, supply invoices, and internal messages. Training needs to stay current.
✅ Monitor logins for abnormal behavior
We regularly detect “impossible travel,” suspicious IPs, and token theft patterns before damage spreads.
✅ Assume every inbox contains PHI
Because in dentistry, it usually does. That means email needs HIPAA-grade protection, not “good enough.”
Delta Dental of Virginia’s breach is a giant neon sign for the dental industry:
Email compromise is still one of the fastest ways into sensitive dental data.
If you’re not sure how protected your email environment is, we’ll help you find out.
📍 Want an email security and HIPAA risk check?
Darkhorse Tech can run a fast, no-fluff assessment and show you where the gaps are — before hackers do.
We understand that caring for your patients is your top priority. Dealing with a computer issue, slow IT response time or HIPAA compliance requirements just aren’t high on your list of to-do’s. That’s where Darkhorse Dental Tech comes in. Our team of Dental IT specialists are experts when it comes to running a great, secure and successful practice —and so much more. Whether you’re looking for IT services for startups, or existing support and security services for your practice, Darkhorse can do it all for you, so you can get back to your patients.
Have questions? Looking for ideas? Just want to talk teeth? Drop us a line at sales@darkhorsetech.com to get the conversation started! Or head to our Contact page to send us a message. Don’t forget to follow us on Instagram!
Dental IT Support, Dental Startups, Dental IT Support New York, Dental IT Support Texas, Dental IT Support North Carolina, Dental IT Support Raleigh, Dental IT Support Charlotte, Dental IT Support Wake Forest, Dental IT Support Florida, Dental IT Support California, Dental IT Support Pennsylvania, Dental IT Support New Jersey, Cloud Dental Solutions, Dental Technology.
Don’t hesitate to drop us a line, we look forward to connecting with you soon.
You can schedule an intro meeting online! Find a time on our calendar that works for you.
schedule today!