Many dental practices across the country utilize eAssist Dental Solutions for dental billing and revenue cycle management services. Reports have recently surfaced that eAssist is investigating a potential information security incident following claims made by a ransomware group. According to industry reports, the company has acknowledged that it is investigating the matter and has engaged cybersecurity experts to determine the nature and scope of the incident.
At this time, there has been no public confirmation regarding whether patient information was compromised, the extent of any data involved, or the total number of individuals potentially affected. The investigation remains ongoing.
Why This Matters
Dental practices entrust third-party vendors with sensitive information needed for insurance claims processing, billing, and collections. Depending on the services utilized, information maintained by a billing vendor may include:
- Patient names and contact information
- Insurance details
- Treatment and claim information
- Financial and payment data
- Employee and provider information
While there is currently no confirmed report regarding the specific data involved in this incident, the situation serves as an important reminder that vendor cybersecurity events can impact dental practices and their patients.
Recommended Actions for Dental Practices
If your practice works with eAssist, consider taking the following precautionary steps:
- Monitor Communications
Carefully review any communications received directly from eAssist regarding the investigation, findings, or recommended response measures.
- Change Passwords
As a precaution, review and update passwords associated with:
- Practice management software
- Insurance carrier portals
- Clearinghouse accounts
- Billing platforms
- Remote access systems
Industry reporting indicates that eAssist recommended changing system passwords and removing inactive user accounts while the investigation proceeds.
- Review User Access
Evaluate employee access rights and promptly disable inactive accounts. Limiting unnecessary access helps reduce cybersecurity risk regardless of the ultimate findings of the investigation.
- Strengthen Security Controls
Consider implementing or reviewing:
- Multi-factor authentication (MFA)
- Password management policies
- Employee cybersecurity awareness training
- Vendor risk assessment procedures
- Compliance with HIPPA Security Rule & Incident response plans
- Monitor your bank accounts
- Consider a credit freeze
- Reach out to your IT company
Immediate Actions an IT company can take:
- Conduct a rapid risk assessment
- Help you reset and harden credentials
- Audit user access
- Help you review system logs
- Monitor suspicious activity
- Scan for malware
- HIPPA and compliance support
- Review disaster recovery procedures
- Perform vendor security review
- Conduct staff awareness training
- Consult Legal and Compliance Advisors
If future findings indicate that protected health information (PHI) was affected, practices may have obligations under HIPAA and applicable state privacy laws. Work with your attorney, compliance consultant, or cybersecurity advisor to understand any responsibilities that may arise.
A Good Reminder for All Dental Practices
Even if a cybersecurity incident originates with a third-party vendor, it can still create operational, financial, and reputational challenges for a dental practice. Regular vendor reviews, strong password controls, multi-factor authentication, and cyber liability insurance remain important safeguards in today’s environment.
We encourage our clients to stay alert to updates from eAssist Dental Solutions and their cybersecurity team as additional information becomes available.
Disclaimer
This article is based on publicly available information as of September 10, 2026. The reported incident remains under investigation, and facts may change as additional information becomes available.
