Henry Schein, Inc. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Henry Schein, Inc. disclosed a data breach to the Oregon Attorney General on October 23, 2024, affecting 166,432 individuals whose personal information was exposed. Anyone who received notice or believes they may have been impacted should review their account statements and consider placing a fraud alert or credit freeze.
Data breaches involving large healthcare-adjacent suppliers remain a persistent feature of the current threat landscape, where attackers target organisations that sit between manufacturers, clinics and patients and often hold broad contact and identity records. Henry Schein, Inc. has disclosed a data breach affecting a substantial number of individuals, with formal notice filed with Oregon authorities more than a year after the underlying incident.
According to the Oregon Attorney General filing reported on October 23, 2024, Henry Schein notified Oregon residents of a breach whose incident date is given as September 27, 2023. The notice states that 166,432 people were affected and that personal information was involved. Public detail beyond those points is limited; the filing does not expand on method, full scope of systems involved, or a complete inventory of every data element.
Breaking down the breach
The available record is the data-breach notice associated with the Oregon Department of Justice, dated October 23, 2024. That filing places the incident itself on September 27, 2023. Henry Schein, Inc. is identified as the organisation, and the notice reports 166,432 people affected. The data types named as exposed are described as personal information, per the breach notification. No further technical narrative—such as how access was obtained, how long unauthorised activity continued, which systems were involved, or whether data was exfiltrated in bulk—appears in the facts provided. The gap between the stated incident date and the Oregon reporting date is part of the public record; reasons for that interval are not detailed in the disclosure summary used here.
Because the notice is framed as notification to Oregon residents, the 166,432 figure is the count given in that context. Whether the same event affected residents of other states in additional numbers is not specified in these facts. No threat actor is named, and no leak-site claim or ransom demand is part of the supplied record.
How a breach like this happens
Incidents described only as involving “personal information” at a large commercial organisation typically follow familiar patterns, though none of the following should be read as a confirmed account of this case. Attackers often gain an initial foothold through stolen or phished credentials, unpatched remote-access services, compromised third-party software, or malware delivered by email. Once inside, they may move laterally, locate databases or file shares containing customer, employee or partner records, and copy data for later use in fraud or resale. Detection can lag if logging is incomplete or alerts are missed. Organisations then investigate, determine what was accessed, and issue notices under state laws that require reporting when personal information may have been compromised. The precise path in any single event remains unknown unless the organisation or investigators publish it; here, that level of detail is undisclosed.
Who is Henry Schein, Inc.?
Henry Schein, Inc. is a major distributor of products and services to dental and medical practitioners, clinics and related healthcare settings. Companies in this sector commonly maintain records needed to sell and ship supplies, manage accounts, support practices, and communicate with professionals and sometimes patients or practice staff. That role places them adjacent to the healthcare ecosystem even when they are not a hospital or insurer. A breach at such an organisation matters because the same identity and contact data used for legitimate business can be reused for impersonation, billing fraud or targeted phishing against clinics and individuals. The Oregon notice establishes that a large number of people were drawn into the notification obligation for this event; broader operational impact on customers or partners is not described in the facts given.
What data was at risk
The breach notification names personal information as the exposed category. It does not, in the facts supplied, list every field—such as specific combinations of names, addresses, dates of birth, Social Security numbers, financial account details or clinical identifiers. For an organisation of Henry Schein’s type, personal information in business systems can include names, postal and email addresses, phone numbers, account or customer identifiers, and other data collected in the ordinary course of distribution and practice support. Exact contents for this incident remain unconfirmed beyond the notification’s reference to personal information. Readers should treat any more granular claim as unverified unless it appears in an official notice they receive directly.
What's at stake
For affected individuals, exposure of personal information raises concrete risks: fraudulent account opening, tax- or benefits-related identity misuse, convincing phishing that references a real supplier relationship, and long-term reuse of static identifiers. Even when clinical records are not confirmed as part of a notice, contact and identity data alone can support social-engineering attacks against dental or medical offices. For the organisation, consequences can include regulatory follow-up, notification and support costs, contractual questions with customers, and reputational strain—none of which are quantified in the Oregon filing summary used here. The 166,432 figure indicates scale large enough that many people may need to monitor credit and accounts for an extended period. No dollar loss, ransomware payment, or confirmed misuse statistics are stated in the available facts.
What to do if you're exposed
If you receive a notice from Henry Schein or believe you may be included, keep the letter or email and follow any official instructions for credit monitoring or identity-protection services if they are offered. Place fraud alerts or credit freezes with the major consumer reporting agencies if appropriate for your situation, and watch bank, credit-card and tax accounts for unfamiliar activity. Be cautious of unexpected calls or messages that claim to be from a dental or medical supplier and ask for passwords, payment details or remote access. Change passwords on related accounts and enable multi-factor authentication where available. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets, which can help you prioritise further monitoring without replacing official notices from the company itself.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Stiiizy Inc. Data Breach Notice (Oregon Attorney General)Norwex USA, Inc. Data Breach Notice (Oregon Attorney General)American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General)Oregon Reproductive Medicine, LLC Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.