E-Assist Data Breach – Take Action Now!

By Olivia Wann
eAssist Dental Solutions has been the target of a ransomware attack claimed by the DireWolf threat actor group although full details and the extent of the data breach is yet under investigation.
eAssist is one of the largest third-party dental insurance billing companies in the country. As of date, the breach is an unconfirmed claim. However, what we do know is that DireWolf published a listing naming eAssist Dental Solutions. Neither eAssist or majority interest owner, Henry Schein, has issued a statement yet.
Should you just wait and see what happens if you were a customer of eAssist? What should you do?
The Office for Civil Rights (OCR) publishes HIPAA breaches that are currently under investigation at U.S. Department of Health & Human Services – Office for Civil Rights. eAssist does not yet appear as of the date of this article.
Take action now! Suggested steps include:
In compliance with HIPAA, maintain a security-incident procedure and documentation:
- Date you became aware of the reports
- Where you learned about the alleged incident
- Your relationship with eAssist
- Your current BAA with eAssist
- What types of PHI eAssist receives
- What systems/accounts eAssist can access
- Communications with eAssist
- Your investigation and mitigation steps – see provided checklist
Review your BAA with eAssist. HIPAA requires a business associate to report security incident sand breaches to the covered entity, and the BAA may impose more specific reporting requirements.
Specifically look for the following information on the BAA:
- Security incident notification
- Breach notification
- Time limits for notification
- Cooperation with investigations
- Access to forensic information
- Data return/destruction
- Subcontractor requirements
- Indemnification
- Cybersecurity requirements
- Termination rights
Don’t assume that because eAssist handles the breach, the dental practice has no responsibility.
Contact eAssist in writing and inquire:
___ Has eAssist experienced a cybersecurity incident?
___ Is the September 2026 ransomware claim legitimate?
___ When was the incident discovered?
___ When did the unauthorized access allegedly occur?
___ What systems were accessed?
___ Was the practice’s data involved?
___ Was ePHI involved?
___ What categories of PHI were potentially accessed?
___ How many patients may be affected?
___ Was data exfiltrated?
- Was ransomware deployed?
- Has law enforcement been notified?
- Has eAssist engaged an independent forensic firm?
- Has eAssist notified its cyber-insurance carrier?
- Has eAssist notified HHS/OCR?
- When will affected customers receive a formal breach report?
- What containment and remediation measures have been implemented?
Discuss with your IT/cybersecurity team what eAssist had access to that relates to your data base:
What does eAssist have access to?
For example:
- Practice management system
- EHR
- Patient demographics
- Insurance information
- Claims
- Payment information
- Account balances
- Treatment information
- Social Security numbers, if applicable
- Driver’s license information, if applicable
- Banking information
- Provider credentials
- Patient portals
- Remote-access accounts
Then determine whether eAssist has ongoing access.
If unnecessary access exists, restrict it.
HHS emphasizes access controls, audit controls, encryption, incident response, and risk analysis as important Security Rule safeguards
Review your audit logs.
Ask your IT vendor to review:
- eAssist user activity
- Remote logins
- Failed login attempts
- Privileged-account activity
- Downloads/export activity
- Unusual after-hours activity
- Bulk patient-record access
- Changes to banking/payment information
- Changes to user permissions
Preserve the logs. Don’t simply delete or overwrite them.
Update your HIPAA Security Risk Analysis.
This is especially important given OCR’s current emphasis on risk analysis.
Your risk analysis should now address the risk associated with your third-party billing/business-associate relationship with eAssist.
Document:
Threat: Cyberattack against business associate handling practice ePHI
Vulnerability: Reliance upon external vendor’s cybersecurity controls
Potential impact: Unauthorized access, disclosure, alteration, destruction, or unavailability of ePHI
Existing controls: BAA, encryption, access controls, MFA, audit logging, vendor due diligence
Additional mitigation: Written incident inquiry, access review, enhanced monitoring, contingency planning, vendor reassessment
HHS specifically states that covered entities and business associates must conduct risk analyses addressing threats and vulnerabilities to the confidentiality, integrity and availability of ePHI.