Updated September 9, 2026

Legend Networking alert graphic on the unconfirmed eAssist ransomware claim, marked unconfirmed and action required

A ransomware group has named eAssist Dental Solutions as an alleged victim of a cyberattack. For dental practices, the useful question is not whether every attacker claim is true. It is whether your organization knows exactly what access an outside billing vendor has and how quickly that access could be contained if necessary.

On September 6, 2026, the DireWolf ransomware group listed eAssist Dental Solutions on its leak site. As of this review, Legend Networking has not identified a public statement from eAssist or majority owner Henry Schein confirming the ransomware group's allegations, the systems allegedly involved, whether information was actually exfiltrated, or whether any dental practices or patients were affected.

The HHS Office for Civil Rights breach portal also does not currently show an eAssist entry. The absence of an entry this early should not be interpreted as evidence that a breach did or did not occur.

The short version: this is an unconfirmed ransomware claim, not a confirmed breach. If your practice uses eAssist, do not panic. Audit your own exposure.

What Is Claimed vs. What Is Verified

Claimed by the ransomware groupVerified as of September 9, 2026
Database access and alleged data theftDireWolf publicly listed eAssist on September 6
Alleged practice, dentist, portal and billing-related recordsThreat-intelligence trackers recorded that the listing exists
Specific quantities and database figures circulated onlineeAssist / Henry Schein had not publicly confirmed the alleged incident at the time of review
Potential access to sensitive informationNo authoritative public list of affected dental practices was identified

Important: A ransomware leak-site posting is an assertion from a criminal organization. It is not an independent forensic report, regulatory filing or customer notification.

Why This Vendor Matters to Dental Practices

eAssist provides outsourced dental billing and revenue-cycle services. Henry Schein acquired a 70% ownership position in eAssist in 2021. A remote billing service may need legitimate access to practice-management workflows, claims, patient ledgers, payer portals and other systems required to perform its work.

That is why the broader cybersecurity issue matters even if this particular claim remains unconfirmed: a trusted third party can sit outside your walls while still holding important keys to your practice. Ongoing managed dental cybersecurity services exist to keep those pathways visible and controlled.

The Question Every Dental Practice Should Ask

Exactly what can each vendor access?

Trust and cybersecurity controls are not the same thing. A reputable vendor can still experience a security incident. Your practice should know who has access, how they authenticate, what they can reach, whether activity is logged, and how quickly access can be revoked.

8 Things Dental Practices Should Audit Right Now

1. Identify Every Vendor With Access

List every outside organization that can access your technology environment or sensitive information, and document how each one connects.

2. Eliminate Shared Accounts Whenever Possible

Use named identities whenever supported so access can be disabled, MFA enforced, activity reviewed and former users removed cleanly.

3. Verify Multi-Factor Authentication

Review MFA for Microsoft 365, administrative accounts, remote access, payer portals, cloud dental software, backup administration, password managers, vendor portals and financial applications. Secure dental email and Microsoft 365 solutions make that enforcement consistent across the team.

4. Apply Minimum Necessary Access

Give each vendor only the permissions required for its role, location and business purpose. This is especially important for multi-location DSO IT support.

5. Find Saved Passwords

Review billing and administrative workstations for credentials stored in browsers or local password files. Use a managed credential strategy.

6. Review Login and Security Logs

Look for unusual locations, after-hours logins, new administrators, unexpected remote-support tools, changed email forwarding rules, MFA changes, unfamiliar devices and unusual bulk access.

7. Review Business Associate Agreements

Know which vendors have BAAs, where they are stored, who owns the relationship, notification obligations and the vendor security contact. A BAA does not replace technical safeguards, which is why HIPAA compliance support and technical controls belong together.

8. Know How to Shut Vendor Access Off

A mature offboarding process covers identities, active sessions, shared credentials, remote access, privileges, email, cloud applications, local software, logs and documentation.

Schedule Your Free Dental IT & Vendor Access Assessment

Schedule Your Free Dental IT & Vendor Access Assessment Call 800-794-1588

Legend Dental Vendor Risk Score

Give your practice 10 points for each control that is fully documented and working today:

  • Complete vendor inventory
  • Named individual accounts
  • MFA on supported systems
  • Least-privilege permissions
  • Centralized login / security monitoring
  • Managed credential storage
  • Current BAA and security contact
  • Controlled remote-access methods
  • Documented vendor offboarding
  • Incident-response procedure for third-party events

90 to 100: Strong
70 to 89: Improvements Recommended
Below 70: Vendor Access Review Recommended

For DSOs, Vendor Risk Multiplies With Every Acquisition

Every acquired practice can arrive with a different IT provider, billing company, imaging vendor, practice-management system, remote-access tool, backup platform, Microsoft 365 environment and set of administrative accounts. Without standardization, group leadership may not have a complete picture of every third party capable of accessing sensitive systems.

Legend recommends maintaining a centralized vendor register:

Vendor Service Locations Systems Data Access Method Named Users MFA BAA Internal Owner Termination Procedure

Five steps for dental practices using eAssist: map vendor access, reset vendor passwords, turn on MFA, review access logs, confirm your BAA
Five practical steps, in order. Map access before changing anything.

What Dental Practices Using eAssist Should Do Now

Document the relationship. Identify which eAssist services your practice uses, what data moves in each direction and how the workflow connects to your systems.

Identify associated accounts. Find eAssist-related users, shared credentials, payer portal accounts, stored passwords and remote-access pathways.

Verify MFA. Confirm MFA on sensitive systems connected to the workflow wherever the platform supports it.

Review access activity. Ask your dental IT support provider to review relevant authentication and administrative logs for unusual activity.

Locate contracts and BAAs. Know where the agreements are and understand the process for security incident notification.

Ask for authoritative updates. Preserve any incident communication and coordinate with legal, compliance, insurance and cybersecurity resources as appropriate.

Make controlled changes. Map dependencies first, then rotate or revoke access in a controlled sequence.

What Dental Practices Should Not Do

  • Do not assume your practice was affected.
  • Do not assume PHI was stolen.
  • Do not repeat threat-actor allegations as verified facts.
  • Do not ignore vendor security simply because the incident remains unconfirmed.

Your Vendor's Cybersecurity Is Part of Your Cybersecurity

Modern dentistry is interconnected. Practices depend on software companies, billing services, imaging vendors, cloud providers, insurance portals, dental phone systems and IT providers. Those relationships create efficiency, but they also create access pathways.

The answer is not to stop working with outside vendors. The answer is to know who has access, what they can access, how they authenticate, whether activity can be monitored, and how quickly access can be removed. Tested dental backup and disaster recovery remains the control that protects the practice when a third party is compromised.

Diagram showing a dental practice at the centre connected to billing vendor, practice software, payer portals, email and patient data
Every vendor connection is an access path into the practice.

Who Has Access to Your Dental Practice?

Legend Networking has specialized in dental technology since 2004, helping dental practices, startups and multi-location organizations build and manage the technology behind their operations.

A Free Dental IT & Vendor Access Assessment can help identify network security risks, remote access, administrative accounts, vendor access, endpoint protection, backup strategy, firewall configuration, Microsoft 365 security, MFA gaps, technology documentation and multi-location standardization.

Know where your vulnerabilities are before an attacker finds them.

Schedule Your Free Dental IT & Vendor Access Assessment

Schedule Your Free Dental IT & Vendor Access Assessment Call 800-794-1588

Frequently Asked Questions

Has eAssist confirmed a data breach?

As of September 9, 2026, DireWolf has publicly claimed eAssist Dental Solutions as a victim. Legend Networking has not identified an authoritative public confirmation from eAssist or Henry Schein. The situation should therefore be described as an unconfirmed ransomware claim.

Was patient data exposed?

There is not enough independently verified public information to conclude that patient information or PHI was stolen. Threat-actor allegations about data categories and quantities should not be presented as confirmed facts.

Is eAssist listed on the HHS breach portal?

As of this review, an eAssist entry was not identified in the HHS Office for Civil Rights breach portal. The absence of a listing at this early stage does not establish whether a breach occurred.

Should my dental practice stop using eAssist?

The currently available verified information does not provide a factual basis for Legend Networking to recommend terminating eAssist solely because of the ransomware group's claim.

Does having a BAA mean a dental vendor is secure?

No. A BAA establishes contractual obligations involving PHI but does not replace MFA, endpoint protection, access controls, monitoring, secure backups and incident response.

What should I do if a vendor confirms an incident?

Preserve the notification and involve the appropriate legal, compliance, insurance and cybersecurity resources. Determine what systems and information were involved and follow applicable incident-response and HIPAA processes.

Technical Review

Reviewed by Jim Bennett, Chief Technology Officer, Legend Networking.

Legend Networking provides this article for cybersecurity education and general informational purposes. It is not legal advice. Threat intelligence surrounding an active or alleged cybersecurity incident can change quickly.

Last reviewed: September 9, 2026