On May 26, 2026, Mysa Dental became aware of irregularities related to remote access session hosts, indicating a cyberattack. The company's IT team secured the systems and restored the patient record platform.
An investigation revealed that personal information of 3,394 patients in Texas may have been accessed. The exposed data includes names, addresses, driver’s license numbers, government-issued ID numbers, medical information, health insurance information, and dates of birth. Payment information was not impacted.
Mysa Dental reported the incident to the Texas Attorney General and the U.S. Department of Health and Human Services on July 28, 2026, and notified affected patients.