Michael Bilikas DDS Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Michael Bilikas DDS disclosed a data breach on July 29, 2025, that exposed the personal information of 23,517 individuals. The breach occurred on May 18, 2025; anyone who received services from the practice should review the official notice and consider placing a fraud alert or credit freeze.
A dental practice has told Oregon authorities that tens of thousands of people may have had personal information exposed in a cyber incident earlier this year. Michael Bilikas DDS reported the matter to the Oregon Department of Justice on July 29, 2025, stating that the incident itself occurred on May 18, 2025, and that 23,517 people were affected. For patients and others whose records may be involved, the practical concern is straightforward: personal information that a dental office routinely holds can be reused for identity theft, account takeover, or targeted scams once it leaves the organization’s control.
Public detail beyond the official notice remains limited. The filing describes the exposed material only as personal information and does not publish a fuller technical account of how the incident unfolded. That leaves affected individuals needing clear, calm steps rather than speculation.
Inside the incident
According to the breach notice filed with the Oregon Attorney General’s office, Michael Bilikas DDS experienced a data incident on May 18, 2025. The organization later notified Oregon residents and submitted its report on July 29, 2025. The filing states that 23,517 people were affected.
The notice characterizes the exposed data as personal information. It does not, in the summary available from the state filing, describe the technical method of intrusion, the systems involved, whether ransomware or another form of unauthorized access was used, how long any access lasted, or whether data was confirmed exfiltrated versus merely accessed. Those operational details are undisclosed in the public record summarized here. What is established is the date of the incident, the date of the regulatory filing, the headcount of people the practice identified as affected, and the broad category of data named in the notification.
How a breach like this happens
Incidents that lead to notices like this typically begin with an attacker gaining a foothold in an organization’s network or cloud services. Common entry paths in healthcare and small-practice environments include compromised email accounts, stolen or weak remote-access credentials, unpatched software on practice-management systems, or malicious attachments that deploy further tools. Once inside, an adversary may move laterally to locate patient databases, billing systems, imaging archives, or backup stores that contain concentrated personal data.
In many cases the goal is to copy records quietly, encrypt systems for leverage, or both. Detection can lag days or weeks, which is one reason notification filings often appear well after the stated incident date. None of this general pattern identifies a specific threat group or technique for the Michael Bilikas DDS event; no actor is attributed in the Oregon filing summary, and none should be assumed. The description above is background on how similar incidents commonly unfold, not a reconstruction of this one.
About Michael Bilikas DDS
Michael Bilikas DDS is a dental practice. Organizations of this type provide clinical dental care and, as a routine part of that work, collect and retain information needed to identify patients, coordinate treatment, submit insurance claims, and maintain medical and billing histories. That operational reality makes dental offices attractive targets: the data they hold is both sensitive and relatively stable over time, and many smaller practices operate with limited dedicated cybersecurity staff compared with large hospital systems.
A breach at a dental practice is consequential because the same records that support ordinary care—identity details, contact information, and related personal data—can be misused outside the clinical setting. Even when clinical notes or full medical charts are not confirmed as exposed, the personal information category alone can enable fraud. The Oregon notice places this practice among the set of healthcare-related entities that have had to inform residents and regulators after discovering unauthorized access or acquisition of data.
What data was at risk
The breach notification names the exposed material as personal information. The public summary does not itemize further fields such as Social Security numbers, driver’s license numbers, financial account data, insurance identifiers, or clinical details. Because those specifics are not disclosed in the facts available from the filing, they remain unconfirmed.
Dental practices typically maintain names, addresses, dates of birth, contact numbers, insurance information, and treatment-related records. Some also store payment details or government identifiers collected for billing and identity verification. It is accurate to say that organizations of this kind hold data that can be sensitive; it is not accurate, on the present record, to assert that any particular field beyond the stated “personal information” was involved in this incident. Readers should treat the exact contents as limited to what the notice itself reports.
What's at stake
For individuals, the main risks are misuse of personal information: fraudulent account openings, tax or benefits fraud, phishing that appears more credible because it references real personal details, and long-term identity monitoring burdens. Even when a practice cannot confirm that every record was stolen, the fact of unauthorized access to systems that hold personal data is enough to warrant caution. The scale reported—23,517 people—means the impact is not limited to a handful of local patients; a substantial number of individuals may need to watch for unusual activity.
For the organization, consequences include regulatory notification duties, potential follow-on inquiries, the cost of investigation and patient outreach, and erosion of trust among patients who expect clinical and administrative data to remain confidential. None of those outcomes requires a finding of negligence to matter; they follow from the simple fact that personal information left the expected protective boundary. Public reporting so far does not assign fault or describe security controls that failed; it records that an incident occurred and that notice was given.
Were you affected?
If you have been a patient of Michael Bilikas DDS or otherwise provided personal information to the practice, treat the notice as a prompt to act rather than a reason to panic. Review any letter or email you may have received from the practice for specific guidance, including any offer of credit monitoring. Place fraud alerts with the major credit bureaus if you are concerned about new-account fraud, and monitor bank, credit-card, and insurance statements for unfamiliar activity. Change passwords on related accounts if you reused credentials tied to the practice’s patient portal or email communications, and be skeptical of unexpected calls or messages that cite the breach and ask for further personal data.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets elsewhere. That check does not replace official notice from the practice, but it can help you see whether your information is circulating more widely and decide what additional monitoring is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.