Skip to main content

E-Assist Data Breach – Take Action Now!

By Olivia Wann

eAssist Dental Solutions has been the target of a ransomware attack claimed by the DireWolf threat actor group although full details and the extent of the data breach is yet under investigation.

eAssist is one of the largest third-party dental insurance billing companies in the country.  As of date, the breach is an unconfirmed claim.  However, what we do know is that DireWolf published a listing naming eAssist Dental Solutions.  Neither eAssist or majority interest owner, Henry Schein, has issued a statement yet.

Should you just wait and see what happens if you were a customer of eAssist?  What should you do?

The Office for Civil Rights (OCR) publishes HIPAA breaches that are currently under investigation at U.S. Department of Health & Human Services – Office for Civil Rights.  eAssist does not yet appear as of the date of this article.

Take action now!  Suggested steps include:

In compliance with HIPAA, maintain a security-incident procedure and documentation:

  • Date you became aware of the reports
  • Where you learned about the alleged incident
  • Your relationship with eAssist
  • Your current BAA with eAssist
  • What types of PHI eAssist receives
  • What systems/accounts eAssist can access
  • Communications with eAssist
  • Your investigation and mitigation steps – see provided checklist

Review your BAA with eAssist.  HIPAA requires a business associate to report security incident sand breaches to the covered entity, and the BAA may impose more specific reporting requirements. 

Specifically look for the following information on the BAA:

  • Security incident notification
  • Breach notification
  • Time limits for notification
  • Cooperation with investigations
  • Access to forensic information
  • Data return/destruction
  • Subcontractor requirements
  • Indemnification
  • Cybersecurity requirements
  • Termination rights

Don’t assume that because eAssist handles the breach, the dental practice has no responsibility.

Contact eAssist in writing and inquire:

___  Has eAssist experienced a cybersecurity incident?

___  Is the September 2026 ransomware claim legitimate?

___  When was the incident discovered?

___  When did the unauthorized access allegedly occur?

___  What systems were accessed?

___  Was the practice’s data involved?

___  Was ePHI involved?

___  What categories of PHI were potentially accessed?

___  How many patients may be affected?

___  Was data exfiltrated?

  • Was ransomware deployed?
  • Has law enforcement been notified?
  • Has eAssist engaged an independent forensic firm?
  • Has eAssist notified its cyber-insurance carrier?
  • Has eAssist notified HHS/OCR?
  • When will affected customers receive a formal breach report?
  • What containment and remediation measures have been implemented?

Discuss with your IT/cybersecurity team what eAssist had access to that relates to your data base:

What does eAssist have access to?

For example:

  • Practice management system
  • EHR
  • Patient demographics
  • Insurance information
  • Claims
  • Payment information
  • Account balances
  • Treatment information
  • Social Security numbers, if applicable
  • Driver’s license information, if applicable
  • Banking information
  • Provider credentials
  • Patient portals
  • Remote-access accounts

Then determine whether eAssist has ongoing access.

If unnecessary access exists, restrict it.

HHS emphasizes access controls, audit controls, encryption, incident response, and risk analysis as important Security Rule safeguards

Review your audit logs.

Ask your IT vendor to review:

  • eAssist user activity
  • Remote logins
  • Failed login attempts
  • Privileged-account activity
  • Downloads/export activity
  • Unusual after-hours activity
  • Bulk patient-record access
  • Changes to banking/payment information
  • Changes to user permissions

Preserve the logs. Don’t simply delete or overwrite them.

Update your HIPAA Security Risk Analysis.

This is especially important given OCR’s current emphasis on risk analysis.

Your risk analysis should now address the risk associated with your third-party billing/business-associate relationship with eAssist.

Document:

Threat: Cyberattack against business associate handling practice ePHI

Vulnerability: Reliance upon external vendor’s cybersecurity controls

Potential impact: Unauthorized access, disclosure, alteration, destruction, or unavailability of ePHI

Existing controls: BAA, encryption, access controls, MFA, audit logging, vendor due diligence

Additional mitigation: Written incident inquiry, access review, enhanced monitoring, contingency planning, vendor reassessment

HHS specifically states that covered entities and business associates must conduct risk analyses addressing threats and vulnerabilities to the confidentiality, integrity and availability of ePHI.

Can you Afford to Pay a $552,250 Settlement for HIPAA Violations? 

by Olivia Wann, JD

Another ransomware enforcement action sends a clear message to health care providers: A HIPAA risk analysis must be accurate, thorough, and capable of identifying the organization’s actual cybersecurity risks.

On July 29, 2026, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with OSF HealthCare System and its affiliated covered entities, marking OCR’s 21st ransomware enforcement action. OSF agreed to pay $552,250 and comply with a corrective action plan that will be monitored by OCR for two years.

The case arose from a 2021 ransomware attack involving the Nephilim ransomware variant. OSF discovered evidence of ransomware on April 23, 2021. During its investigation, OSF determined that threat actors had stolen the protected health information (PHI) of 53,907 individuals.

What Did OCR Find?

OCR’s investigation identified several areas of concern under the HIPAA Privacy, Security, and Breach Notification Rules.

According to the Resolution Agreement, OCR determined that OSF:

  • Failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to its electronic protected health information (ePHI);
  • Impermissibly disclosed the PHI of 53,907 individuals as a result of the stolen data;
  • Failed to provide timely notification to affected individuals; and
  • Failed to provide timely notification to the HHS Secretary regarding the breach affecting more than 500 individuals.

The settlement itself does not constitute an admission of liability by OSF. The parties entered into the agreement to resolve the OCR investigation.

The Corrective Action Plan Is Particularly Important

For health care organizations, the corrective action plan may be more instructive than the settlement amount.

OSF must conduct an accurate and thorough risk analysis addressing security threats and vulnerabilities involving its ePHI. The analysis must incorporate electronic equipment, data systems, programs, applications, off-site data storage, and other technology that creates, receives, maintains, or transmits ePHI.

OSF must also develop and implement an enterprise-wide risk management plan addressing the risks and vulnerabilities identified through its risk analysis. The plan must include processes and timelines for implementing, evaluating, and revising remediation activities.

The corrective action plan goes beyond simply completing a risk assessment and putting it in a file. OSF is required to conduct annual assessments during the two-year compliance period and report its compliance to OCR.

Workforce Compliance Is Also Under the Microscope

Another significant component of the corrective action plan involves workforce compliance.

If OSF determines that a workforce member failed to comply with its existing Privacy, Security, or Breach Notification policies and procedures, OSF must investigate the matter and, when appropriate, report the event to OCR. The report must describe the event, the policies involved, and the corrective and preventive measures taken—including appropriate sanctions when warranted.

OSF must also submit annual reports to OCR that include an attestation regarding completion of required HIPAA training by its workforce.

What Does This Mean for Dental Practices?

While OSF is a large health care system, the lesson is highly relevant to dental practices of every size.

OCR’s ransomware enforcement actions demonstrate that cybersecurity compliance is not limited to having antivirus software, firewalls, backups, or a written HIPAA policy. A practice must be able to demonstrate that it has identified its actual risks to ePHI and has taken reasonable steps to address those risks.

For a dental practice, that risk analysis should consider the technology and systems actually used by the practice, including:

  • Practice management and electronic health record systems;
  • Cloud-based software and storage;
  • Email systems;
  • Patient portals;
  • Computers, laptops, and mobile devices;
  • Backup systems;
  • Dental imaging and radiography systems;
  • Remote access;
  • Third-party vendors and business associates;
  • Cybersecurity protections and vulnerabilities;
  • Workforce access to ePHI; and
  • Emerging technologies, including artificial intelligence (AI) tools.

A generic HIPAA risk assessment that does not accurately reflect the practice’s current technology, vendors, workflows, and vulnerabilities may not be enough.

The Takeaway

The OSF settlement is another reminder that HIPAA compliance must be an ongoing process—not a binder on a shelf.

A strong HIPAA Security Rule compliance program should include a current and thorough risk analysis, a documented risk management plan, appropriate policies and procedures, workforce training, vendor oversight, incident response procedures, and documentation demonstrating that identified risks are actually being addressed.

OCR’s ransomware enforcement actions continue to reinforce one important point:

If your practice cannot identify its cybersecurity risks, it cannot effectively manage them. And if you cannot demonstrate your compliance efforts, you may have difficulty defending your program when OCR comes knocking.

The complete OSF HealthCare System Resolution Agreement and Corrective Action Plan is available from HHS OCR. Read the OSF Resolution Agreement and Corrective Action Plan

Source: U.S. Department of Health and Human Services, Office for Civil Rights, July 29, 2026.

The Power of a Handshake: Why Human Connection Still Matters in Dentistry

By Olivia Wann

In a world filled with emails, text messages, video meetings, and social media, there is one simple gesture that continues to leave a lasting impression—a handshake.

Recently I was travelling to the Association of Dental Safety annual conference. A large group of us made reservations at a nearby restaurant.  The waitress was running frantically attending to everyone’s request. She went the extra mile assuring that everyone was taken care of in her seating area. On leaving, I extended my hand to shake hers. Initially she appeared shocked. “Why is this businesswoman shaking my hand?” she probably thought. And then her face glowed with a large smile as I thanked her for working hard to make our dinner amazing. I treated her with the same level of respect as I would another professional.

I always shake the hand of my Uber driver and thank them for getting me to my destination safely. One of the drivers remarked that he deals with people from all over the world, but not many that took the time to shake his hand.

Do you introduce yourself to your new patient?  Does it include a handshake?

During the COVID-19 pandemic, handshakes virtually disappeared. We became accustomed to waving from a distance, bumping elbows, or avoiding physical contact altogether. While those precautions served an important purpose during a public health crisis, many people never returned to one of the oldest forms of greeting.

Perhaps it’s time we did.

A firm handshake accompanied by eye contact and a genuine smile communicates something technology never can. It says, “I’m happy to meet you. You have my full attention.” It establishes trust, confidence, and respect in just a few seconds.

Whether you are welcoming a new patient, interviewing a job candidate, or introducing yourself at a networking event with other dental professionals, personal interaction matters. People may forget what was said during a conversation, but they often remember how they felt. A warm greeting can make someone feel valued before a single word is spoken.

The dental and legal professions are built on relationships. Clients and patients are often experiencing uncertainty or stress. They want to know they are more than a file, a chart, or a case number. A handshake—when appropriate—helps bridge that gap and reminds people they are interacting with another human being who genuinely cares.

Of course, good hand hygiene remains important.  Most dental offices have hand sanitizer located throughout the dental office.  We are all well versed in how to wash our hands properly.  I have hand sanitizer in my office, in my purse and in my car. These simple precautions allow us to enjoy the benefits of personal connection while remaining mindful of health and safety.

As our society becomes increasingly digital and artificial intelligence handles more routine tasks, authentic human interaction becomes even more valuable. No software can replace empathy, kindness, or the confidence conveyed through a sincere greeting.

So the next time you meet someone, don’t underestimate the impact of extending your hand. That brief moment of connection may be the beginning of a trusted relationship, a lifelong client, a meaningful friendship, or simply someone’s brighter day.

Sometimes the most powerful communication requires no words at all.

Should a Teenage Minor Bring a Younger Sibling to the Dentist Without a Parent or Legal Guardian?

By Olivia Wann

It is not uncommon for busy families to ask an older teenage child to bring a younger sibling to a dental appointment. While this may seem like a practical solution, dental practices should carefully consider the legal and ethical implications before treating a minor patient without a parent or legal guardian present.

In general, a minor cannot provide legal consent for another minor’s dental treatment. Parents and legal guardians have the legal authority to make healthcare decisions for their children unless a specific law provides otherwise. An older sibling—even one who is 16 or 17 years old—is typically not authorized to consent to examinations, radiographs, restorative treatment, extractions, or other dental procedures on behalf of a younger sibling.

Unless the older sibling has been appointed as the younger child’s legal guardian or has another legally recognized authority to make healthcare decisions, the dental practice should not rely on the teenager’s permission to proceed with treatment.

What About Routine Hygiene Appointments?

Even for what appears to be a routine preventive visit, unexpected findings may require additional treatment or decisions. During an examination, the dentist may discover:

  • Dental decay requiring restorative treatment
  • A fractured tooth
  • An abscess or infection
  • The need for radiographs beyond those anticipated
  • An orthodontic concern
  • An urgent condition requiring immediate care

Without an authorized decision-maker available, the practice may have to postpone recommended treatment or obtain parental authorization before proceeding.

Many dental practices ask parents to complete written authorization forms allowing another adult, such as a grandparent, babysitter, or family friend, to accompany a child to an appointment. These forms may authorize the office to communicate with that adult and, depending on state law and the language of the authorization, permit consent for limited routine care.

However, simply sending a younger child with an older teenage sibling is different. A signed note from a parent may not be sufficient to authorize a minor sibling to make healthcare decisions. Dental offices should consult state law and legal counsel regarding what types of delegation are legally recognized.

Emergencies Present Additional Challenges

Suppose a child experiences a medical emergency, allergic reaction, or other unexpected complication during the visit. Having a parent or legal guardian readily available is important to discuss treatment options, provide medical history, and authorize necessary care if time permits.

Best Practice for Dental Offices

To reduce legal risk and protect patients, dental practices should consider implementing a written policy that addresses who may accompany a minor patient and who is authorized to consent to treatment. The policy should include procedures for:

  • Verifying the identity of the parent or legal guardian.
  • Obtaining appropriate consent before treatment.
  • Documenting telephone consent when permitted by law and office policy.
  • Identifying situations in which treatment should be postponed until a parent or legal guardian is available.
  • Training staff on the office’s consent procedures.

When a parent cannot attend an appointment, it is often preferable to have another authorized adult accompany the child rather than an older teenage sibling.

The Bottom Line

While allowing an older sibling to bring a younger child to the dentist may be convenient, convenience should never outweigh proper consent procedures. Every dental office should have clear policies that comply with applicable state law and protect both the patient and the practice.

When in doubt, obtain consent from the parent or legal guardian before providing treatment. A few extra minutes spent confirming authorization can help avoid misunderstandings, reduce liability, and ensure that the child’s best interests remain the primary focus of care.

Disclaimer: This article is intended for educational purposes only and is not legal advice. Dental practices should consult legal counsel regarding state-specific laws governing consent for the treatment of minors.

Why Every Dental Practice Needs an Artificial Intelligence Policy

by Olivia Wann

Artificial intelligence (AI) is rapidly transforming the health care landscape. Dental professionals are increasingly using AI-powered tools to assist with administrative tasks, patient communications, clinical documentation, treatment planning, marketing, and operational efficiency. While these technologies offer significant benefits, they also introduce new privacy, security, compliance, and ethical risks that many dental practices have not yet fully addressed.

Continue reading

Why Should Instruments Remain Packaged Until Point of Use?

By Olivia Wann

In every dental practice, infection prevention depends on more than running instruments through a sterilizer. Proper handling after sterilization is equally important. Once instruments have been sterilized and sealed in approved sterilization pouches, they should remain packaged until the exact moment they are needed for patient treatment. Opening pouches ahead of time defeats an important layer of protection and increases the risk of contamination.

Continue reading

Safety Squints?

by Caitlin Denison, BS, RDH, CHPC

When many of us think of eye protection, we think of safety glasses worn by nail-gun-wielding construction workers, or the goggles worn by chemical-mixing scientists. What our imagination often fails to offer up are images of a hygienist whose prophy angle is spraying polish about, or the dentist using a high-speed drill to excavate-and possibly fling- decay, or even the dental assistant peering into the mouth of a patient whose salivary glands threaten to spray without notice (see the recent TikTok phenomenon of ‘gleeking’.)

Continue reading

Ten Reasons to Choose a Lawyer Familiar with Dentistry to Draft Your Buy-Sell Agreement

by Olivia Wann

Thirty-four percent of dentist owners plan to retire within six years according to Dental Post’s 2025 Dental Salary Survey Report. If you are interested in selling a practice or buying a practice, there are important legal considerations. Selecting a lawyer who understands the many facets of dentistry to prepare or review a buy-sell agreement is to the dentist’s advantage.  Here’s my top ten reasons why:

Continue reading

How a Specialty Dentist Can Plan a Successful Continuing Education Event for Referring Dentists

by Olivia Wann, JD

Specialty dentists such as oral surgeons, periodontists, orthodontists, and endodontists depend heavily on relationships with general dentists who refer patients for treatment. Hosting a continuing education (CE) event is one of the most effective ways to strengthen those relationships while providing genuine value to the referring community. A well-planned CE program positions the specialist as a trusted resource, encourages collaboration, and keeps colleagues informed about evolving clinical techniques.

Continue reading