I’ve spent years assessing security posture for Department of Defense systems. The work involves classified networks, adversarial threat modeling, and the kind of rigorous controls that assume a breach is always possible.

And then I look at a typical dental practice’s IT setup - and I lose sleep.

Not because dentists are careless. Because nobody has ever told them what they’re actually protecting, who wants it, or what it costs when things go wrong.

I hold both CISSP and CISM certifications and hold AI certificates from Johns Hopkins. I’ve built systems designed to withstand nation-state attacks. And I’m telling you: your dental practice is a more appealing target than you probably realize.

Here’s why - and what to do about it.


Your Patient Data Is Worth More Than a Credit Card Number

Most people assume cybercriminals are after credit card numbers. Steal the card, use it, done.

A patient record from a dental practice is worth far more on the dark web. It contains full name, date of birth, Social Security number, insurance information, and detailed health history. That combination enables identity theft, insurance fraud, and medical fraud - all at once, from a single record.

That’s why healthcare has been the most expensive industry for data breaches for 14 consecutive years, according to IBM’s 2024 Cost of a Data Breach Report. The average healthcare breach cost $9.77 million in 2024. (Source: IBM Security / HIPAA Journal)

Dental practices aren’t exempt from that number. They’re part of it.


Dental Practices Are Being Targeted - Right Now

The threat is documented. Here are four real cases from the past two years:

MCNA Dental. The LockBit ransomware group hit MCNA Dental - one of the largest dental insurance administrators in the United States - and stole data on 9 million individuals. Social Security numbers, driver’s licenses, health and insurance details. All of it. This wasn’t a small practice. It was a large, resourced organization with an IT team. (Source: HIPAA Journal)

First Choice Dental (Wisconsin, October 2023). A network of 12 dental clinics suffered a ransomware attack. They sent breach notifications to affected patients nine months after the attack - raising serious questions about their detection and response capabilities. The practice settled the resulting lawsuit for $1.2 million. (Source: HIPAA Journal)

Absolute Dental (Nevada, February 2025). A 50-plus-location dental group discovered a breach that exposed data on 1.2 million people. They had security measures in place. The breach happened anyway. (Source: Paubox)

Westend Dental (Indiana). A ransomware attack exposed patient records. Then the practice compounded the problem by posting x-rays and patient information publicly while responding to Google reviews. The Indiana Attorney General’s office investigated. The settlement: $350,000 - plus mandatory remediation. (Source: Indiana Lawyer)

The pattern is consistent: attack, delayed discovery, expensive aftermath. IBM’s 2024 Cost of a Data Breach Report puts the global mean time to identify a breach at 194 days. By the time you know something is wrong, the attacker has been inside your systems for more than six months.


What Your IT Vendor Isn’t Telling You

Most dental practices outsource IT to a local managed service provider or rely on their practice management system vendor for “support.” That’s not security. That’s tech maintenance.

A CISSP doesn’t evaluate your security by asking whether your software is up to date. We evaluate your attack surface - every place an attacker could get in - and your security posture - how well you could detect, contain, and recover from a breach.

Here’s what checkbox compliance looks like versus what actual security looks like:

Checkbox ComplianceActual Security Posture
”We have antivirus installed.”Endpoint detection with behavioral monitoring and response capability.
”Our vendor is HIPAA-certified.”Reviewed your Business Associate Agreement and verified their subprocessor chain.
”We back up our data.”Tested restoration from backup. Confirmed backups are air-gapped and ransomware-resistant.
”Our staff completed security training.”Phishing simulation run in the last 90 days with measurable results.
”We’re on the cloud.”Verified access controls, encryption at rest and in transit, and audit logging on all cloud systems.

Most dental IT vendors live in the left column. They’re not being dishonest - HIPAA compliance and operational security are genuinely different disciplines. But the distinction matters when an attacker shows up.

The Three Vectors That Hit Dental Practices Most

1. Phishing. A staff member gets an email that looks like it’s from your practice management vendor, your bank, or a patient. They click. The attacker has a foothold. Dental practices often have limited user security training and no email filtering. This is the single most common entry point across healthcare. (Source: Tricerat)

2. Unpatched practice management systems. Eaglesoft, Dentrix, and similar systems run on local servers at many practices. Legacy software versions go unpatched for months or years - sometimes because upgrading requires downtime, sometimes because no one is tracking it. Every unpatched vulnerability is an open door. The ADA specifically flags unpatched software as a primary ransomware vector for dental offices. (Source: ADA Ransomware Guide)

3. Vendor compromise. Your practice management vendor, your billing company, your imaging software provider - each one has access to your systems. If their systems are breached, yours can be too. Multi-tenant SaaS platforms are especially vulnerable here: one breach at the vendor level can expose every practice on the platform.


What Solas AI Does Differently

When I designed Solas AI’s architecture, I made one foundational decision: no shared infrastructure.

Every Solas AI client runs on their own dedicated server. Not a shared cloud platform where your data sits alongside hundreds of other practices. Not a multi-tenant SaaS product where a single breach cascades across everyone.

Your automation workflows, your patient communication systems, your integrations - they all run on infrastructure that belongs to your practice. Solas AI configures it, monitors it, and supports it. But it’s yours.

That means:

  • Data isolation. A breach at another dental practice using Solas AI cannot touch your records.
  • Audit control. You can see exactly what your systems are doing, when, and why.
  • Vendor risk reduction. Solas AI signs your BAA, documents subprocessors, and gives you real answers when you ask security questions.

This isn’t just good policy. It’s what a CISSP would build.

Solas AI handles the behind-the-scenes work - missed call automation, appointment reminders, patient reviews - while keeping your data where it belongs: under your control.


HIPAA AI Automation: What Compliance Actually Requires

As dental practices adopt AI automation for patient communication and scheduling, HIPAA compliance requirements follow those tools wherever they go.

Any AI system that touches protected health information (PHI) requires a signed Business Associate Agreement, data encryption, access logging, audit controls, and a documented incident response procedure.

Most “HIPAA AI automation” tools on the market are built for the checkbox: they provide a BAA and call it done. A security-first approach asks harder questions:

  • Where does patient data go when a message is processed?
  • Who at the vendor can access it?
  • What happens to that data if you cancel the service?
  • How would you know if the vendor was breached?

These aren’t trick questions. They’re the questions every practice should be asking before connecting any third-party tool to their patient management system. At Solas AI, the answer to each is straightforward - because the system was built to be answerable from the start.

If you want to understand how AI automation fits into a HIPAA-compliant dental practice, this post on reducing no-shows without creating new compliance risk covers the operational side in detail.


7 Things You Can Audit in Your Practice This Week

You don’t need to hire a security consultant to start improving your posture. Here’s a practical starting point:

1. Pull your Business Associate Agreements. Every vendor with access to patient data should have a signed BAA on file. If you can’t find the signed copy, that’s a gap.

2. Ask when your practice management system was last updated. If the answer is “I’m not sure” - that’s your answer. Log in and check. Unpatched local servers are one of the most common entry points for ransomware.

3. Test your backup. Don’t just check that backups are running. Restore a test file. If you’ve never done a restoration test, you don’t actually know if your backups work.

4. Review your admin access list. Who has administrative access to your practice management system? If former staff still have credentials, disable them today.

5. Send a phishing test. Services like KnowBe4 and Proofpoint offer simulated phishing campaigns. Run one. You’ll learn how your team actually responds, not how they think they’d respond.

6. Review what your IT vendor actually covers. Ask them in writing: what happens if you detect ransomware at 2am? Do they have 24/7 monitoring? What’s their incident response procedure? If they can’t answer clearly, you need a clearer agreement.

7. Confirm your cyber insurance. General liability doesn’t cover a HIPAA breach. Review your coverage. Know your limits. Know what triggers the policy.

These seven steps won’t make your practice impenetrable - no checklist can. But they close the most common gaps and give you a real picture of where you stand.


The Bottom Line

Dental practices sit at the intersection of two things attackers love: valuable personal data and limited security resources. That combination makes them targets.

The practices that avoid the headline-making breaches don’t avoid them by luck. They avoid them by treating security as an ongoing responsibility, not a one-time software purchase.

You’ve spent years building a practice patients trust with their health and their personal information. That trust deserves a security posture that can actually protect it.

If you want to understand where your practice stands - without jargon, without sales pressure - visit solasai.net to schedule a free security posture review. I’ll give you a straightforward look at your actual risk and a practical path forward.

Less grind. More growth.


Sources: