How to Evaluate the Security Posture of Your Dental RCM Partner?
Dental practices and DSOs increasingly worry about what happens to patient records once they leave the front desk and reach a billing vendor. Ransomware groups now target dental billing companies directly, and a breach at your revenue cycle management partner becomes your breach too. HIPAA requires every billing vendor to sign a Business Associate Agreement and apply administrative, technical, and physical safeguards to protect electronic patient records during transfer and storage.
This guide explains what those requirements mean in practice, the red flags that signal a vendor is cutting corners, and the questions to ask about monitoring, backups, and incident-response timelines before signing a contract. It also covers recent ransomware attacks on dental billing vendors, including the 2026 incident involving eAssist Dental Solutions, and what a security-first billing partnership looks like when a vendor works with a dedicated cybersecurity firm.
Every claim your practice submits, every patient balance you collect, and every insurance verification you run passes through a chain of vendors outside your four walls. When you outsource dental RCM services, that chain gets longer, and so does the list of places a hacker can get in, if your data isn’t handled securely.
This is something that happened on September 6, 2026, when the ransomware group DireWolf listed eAssist Dental Solutions, one of the largest outsourced dental billing companies in the country and majority-owned by Henry Schein, on its dark web leak site. Two days later, eAssist notified customers it was investigating a potential security incident and had brought in outside forensic experts. As of this writing, the company has not confirmed what data was accessed, and no entry for the incident appears yet on the federal breach portal, but the listing alone sent practices scrambling to check their own exposure.
That scramble is the point of this guide. Security posture used to be a line item on a vendor questionnaire that nobody read closely. It’s now the deciding factor in which RCM partner gets your contract, because a billing company that mishandles Social Security numbers, insurance IDs, and treatment histories makes your practice prone to notification letters, the fines, and the phone calls from anxious patients. Below, we cover what HIPAA requires from a billing vendor, the red flags that separate a well-run RCM company from a liability, and what to look for in monitoring, backups, and incident response before you sign anything.
Why Does Security Posture Now Decide Which RCM Partner You Choose?
The numbers explain the shift. The Department of Health & Human Services (HHS)’s Office for Civil Rights has watched large healthcare breach reports climb every year since 2018. Reports increased 102% between 2018 and 2023, and the number of people affected jumped more than 1,000% over the same period, driven mostly by hacking and ransomware. In 2023, 167 million individuals were affected, and 2025 broke the record with 772 large breaches reported to OCR, the highest annual total since the agency began tracking breaches in 2009.
Billing vendors make up a growing share of that total. In the first half of 2026, business associates, the HIPAA term for vendors like billing companies, were involved in 43% of large healthcare breaches reported to federal regulators, up from an average of about 20% between 2009 and 2017, as per HIPAA Journal’s analysis. Verizon’s 2026 Data Breach Investigations Report found third-party breaches in healthcare rose 60% year over year, highlighting the growing security exposure created by external vendors.
Dental practices specifically saw a 45% increase in cyberattacks between 2022 and 2024, according to Ponemon Institute research, with breach costs averaging more than $9 million once legal fees, notifications, and recovery are factored in. A vendor’s security posture is no longer a formality. It’s the biggest factor that determines whether your practice ends up in that data.
What are the HIPAA Compliance Requirements Your Billing Partner Must Meet?
What Makes a Billing Company a “Business Associate”
The HIPAA Security Rule's Current and Coming Baseline
The HIPAA Security Rule has always required administrative, physical, and technical safeguards: risk analysis, workforce training, access controls, audit logging, and encryption. In December 2024, HHS’s Office for Civil Rights proposed the first major update to the Security Rule since 2013. The proposed rule removes the old distinction between “addressable” and “required” safeguards, meaning a vendor can no longer skip a control simply by documenting a reason why it isn’t feasible.
- Encryption of ePHI at rest and in transit, with only limited, documented exceptions
- Multi-factor authentication for any system that stores or accesses patient data
- Network segmentation to keep systems that touch ePHI isolated from the rest of the network
- Vulnerability scans at least every six months and penetration testing at least annually
- Written incident response and disaster recovery plans built to restore critical systems within 72 hours
- An annual technology asset inventory, network map, and documented review of each business associate’s security practices
The comment period closed in March 2025 with nearly 5,000 submissions, and a coalition of more than 100 healthcare organizations asked HHS to withdraw the rule in December 2025, citing an estimated $9 billion first-year compliance cost across the industry. The final rule is still pending. Whatever its ultimate form, these proposals describe what OCR already considers baseline practice, so a billing partner meeting this bar today is ahead of the requirement.
What's Required Today vs. What's Proposed vs. What to Look For
| Security issue | Current HIPAA requirement | Proposed Security Rule (NPRM) | Recommended vendor standard |
|---|---|---|---|
| Risk analysis | Required, existing specification | More detailed, data-flow and asset-inventory based | Current and thorough, updated at least yearly |
| Multi-factor authentication | Not specifically required; only general person/entity authentication | Required for systems accessing ePHI, limited exceptions | Yes, on every account with access to patient data |
| Encryption (at rest and in transit) | Addressable, not mandatory under current rule | Required, with limited documented exceptions | Yes, on all systems and backups |
| Network segmentation | Not specifically mandated | Required | Yes |
| Vulnerability scanning | Not specified by frequency | Required at least every 6 months | Yes, on a documented schedule |
| Penetration testing | Not specifically required | Required at least annually | Yes, with a summary you can review |
| Backup and disaster-recovery planning | Required contingency plan, risk-based | More prescriptive, tested restoration plans | Yes, with documented, tested restores |
| 72-hour system restoration target | Not a current requirement | Proposed as a benchmark for critical systems | Useful benchmark to request contractually |
| Business Associate Agreement | Required for any covered entity/business associate relationship | Unchanged as a requirement; adds annual verification of a BA's security practices | Yes, reviewed annually, not just signed once |
| Breach notification timeline | Required, up to 60 days | Unchanged, 60-day outer limit | Faster contractual notification (24-72 hours) is reasonable to request |
What a Business Associate Agreement Must Cover?
A Business Associate Agreement (BAA) is the contract that makes a billing vendor legally accountable under HIPAA. A properly written BAA:
- Specifies the permitted and required uses of patient data
- Commits the vendor to implement appropriate safeguards
- Sets out how and when the vendor must report a breach or security incident to your practice
- Requires any subcontractor to agree to the same restrictions
- Obligates the vendor to return or destroy patient data when the relationship ends
Keep in mind that a BAA doesn’t eliminate the need for the covered entity to perform appropriate vendor oversight and risk management. Practices should use the agreement, security documentation, assessments, and contractual audit or verification rights to understand how the vendor protects PHI.
Which are the Recent Ransomware Incidents in Dental RCM?
Dental billing has become a repeat target for ransomware incidents. The incidents below illustrate how the risk plays out across billing vendors of every size, from national outsourcers to single-location practices.
MCNA Dental (2023)
Change Healthcare (2024)
The February 2024 attack on Change Healthcare by the BlackCat/ALPHV group froze claims processing for dental, medical, and pharmacy billing across the country for weeks. As noted in an article by Wired and referenced by the Congress in April 2024, Change Healthcare paid $22 million in bitcoin to the attackers, and a second group, RansomHub, leaked contracts and patient records anyway, a reminder that paying a ransom never guarantees the data stays private.
TriZetto Provider Solutions (2024-2026 disclosure)
DentaQuest (2026)
In May 2026, a cybercriminal group ShinyHackers hacked dental and vision benefits administrator DentaQuest’s systems, gaining unauthorized access to sensitive data, which included details like email addresses, health insurance information, names, phone numbers, physical addresses, and much more. Initially reported to be a data theft of over 2.6 million records, the numbers have since reached to 15-23 million records according to varying estimates.
ShinyHackers blackmailed DentaQuest to either pay a certain amount in extortion or see the data leaked. Refusal to meet the demands led ShinyHackers to publish over 234GB of company and individual data on a dark web site.
eAssist Dental Solutions (2026)
On September 6, 2026, DireWolf added eAssist Dental Solutions to its dark web leak site, claiming to have stolen roughly 26 gigabytes of data spanning 12.8 million rows. eAssist provides outsourced billing, insurance verification, and administrative staffing to dental practices nationwide. Two days later, the company notified its clients it was investigating a potential information security incident and had engaged outside forensic experts.
Speaking of DireWolf, it’s a double-extortion group that first appeared in May 2025. It steals data before encrypting systems so it can keep pressuring a victim even after backups make the encryption itself recoverable. Practices that work with eAssist were advised to review access logs, rotate credentials, and confirm their BAA covers breach-notification timelines.
Smaller Practices Are Targets Too
A Nevada-based DSO disclosed a breach affecting roughly 1.22 million patients in early 2025, exposing dates of birth, insurance details, and financial identifiers.
The same was the case with a single-location Philadelphia practice, which reported a breach affecting 11,273 patients in November 2025 after an intruder locked its internal server.
Both these cases demonstrate that practice size doesn’t determine whether a practice becomes a target. All systems that don’t implement proactive security measures are vulnerable to ransomware attacks and data breaches that come with legal risks and data breaches.
Choose a Billing Partner that Provides Encryption and Complete Data Protection with HIPAA-Compliant Solutions
What are the Red Flags that Signal a Dental RCM Partner Isn't Secure?
Here are the red flags that help identify if a dental billing company isn’t reliable enough to provide secure solutions:
- No BAA offered upfront, or a generic template the vendor won’t customize or discuss line by line
- Vague or evasive answers about where patient data is hosted and who can access it
- No multi-factor authentication on staff logins or on the portal your team uses to check claims
- No documented incident response plan, or no named contact for a security event
- No recent third-party security assessment, penetration test, or audit result to share
- Backups that have never been tested, or a vendor that can’t describe its restore process
- Subcontractors the vendor won’t name, meaning your data may be touched by companies you’ve never vetted
How Can Your Dental Practice Verify a Billing Vendor's Security Claims?
A trustworthy RCM vendor should be able to produce documentation, not just reassurance, when a practice asks about security. Request the following, as applicable to the vendor’s size and setup:
- A current security risk assessment or independent audit report
- A SOC 2 report, if the vendor maintains one
- ISO 27001 certification, if applicable
- A penetration-test summary from within the past 12 months
- A written vulnerability-management policy
- Disaster-recovery and business-continuity documentation
- Evidence that backups have actually been tested and restored, not just taken
- A written incident-response policy
- Breach-notification procedures, including timelines
- A list of relevant subcontractors who may touch patient data
- A data-flow diagram showing how PHI moves through the vendor’s systems
- Documented encryption standards for data at rest and in transit
- Access-control and multi-factor authentication policies
- Records showing employees have completed security training
A vendor saying it’s HIPAA compliant is not the same thing as demonstrating how its security program actually operates. Compliance is a claim. Documentation is proof, and a vendor confident in its program will hand it over without hesitation.
Where Is Your Patient Data Stored?
Outsourcing dental billing and coding means patient data leaves your premises, and where it lands is as important as much as how it’s protected. Before signing a contract, confirm:
- Where PHI is physically or logically hosted, including whether any of the hosting system is located outside the United States
- Which cloud provider or data center the vendor uses
- Where backups are stored, and whether that location is separate from the primary system
- Where disaster-recovery systems are located and how quickly they can take over if the primary system fails
- How remote access into the vendor’s systems is secured, and by whom
- Whether any offshore staff or contractors can access PHI, and under what controls
- Which subcontractors have access to your data and where they operate from
- How long the vendor retains your data after the contract ends, and under what terms
HIPAA doesn’t prohibit hosting or accessing PHI outside the United States, but the same BAA obligations and safeguards have to extend to anyone handling that data, wherever they’re located. If a vendor can’t answer these questions clearly, that uncertainty becomes your liability the moment something goes wrong.
Least Privilege and Credential Management
A billing partner connects into more of your practice than most vendors do: practice-management software, clearinghouses, payer portals, EHR systems, banking and payment platforms, email, and remote-access tools. Every one of those connections is a potential entry point. The DireWolf listing against eAssist referenced specific staff accounts and remote-access tools among the data it claimed to have taken, a reminder that ransomware groups increasingly go after credentials directly rather than only network vulnerabilities.
- Who at the vendor has access to which of your systems?
- Is access role-based, limited to what each employee’s job actually requires?
- Is multi-factor authentication required on every account with access to PHI?
- Are inactive or departed-employee accounts disabled promptly?
- Does each employee use unique credentials rather than shared logins?
- Are privileged or administrative accounts separated from everyday accounts and monitored more closely?
Least-privilege access won’t stop every attack, but it limits how far a single compromised login can reach into your practice’s systems and data.
Continuous Monitoring: What to Ask a Billing Vendor
A vendor’s security posture shouldn’t rely on catching problems after the fact. Ask whether the vendor runs continuous monitoring of its network and systems, not periodic checks. That includes:
- Centralized logging
- Automated alerts for unusual login activity or data transfers
- Monitoring for credentials that show up in breach dumps or dark web listings
- Regular review of who has accessed patient billing portals and when the right billing partner is the one who can explain how security alerts are monitored outside normal business hours and how incidents are escalated when they occur.
What are the Backup and Disaster Recovery Standards to Expect?
Backups determine whether a ransomware attack becomes a bad day or a bad year. Look for immutable backups that ransomware can’t encrypt or delete, nightly backup cycles, geographically separate storage, and documented, regularly tested restores, instead of using a new backup system which has never been used before to recover anything.
The proposed HIPAA Security Rule update ties disaster recovery planning to a 72-hour restoration target for critical systems. Whether or not that becomes final, it’s a reasonable benchmark to hold any billing vendor to today.
Incident-Response SLAs: What “Fast” Actually Means
HIPAA’s Breach Notification Rule gives covered entities up to 60 days to notify affected individuals after discovering a breach. That is a legal ceiling, not a realistic operating standard for a business relationship.
Your contract with a billing vendor should set a tighter internal clock: written notification to your practice within 24 to 72 hours of a confirmed incident, a named point of contact available outside business hours, a documented containment and forensics process, and evidence that the vendor runs incident-response exercises at least once a year, instead of waiting for something to go wrong and act after that.
What Happens When You Leave the Vendor?
A BAA should already require a vendor to return or destroy PHI at the end of the relationship, but a security-minded practice confirms the mechanics before signing, not after giving notice. Ask how the vendor handles:
- Termination of user accounts and logins tied to your practice
- Revocation of API keys and system credentials
- Removal of remote-access connections into your network
- Removal of access to payer portals and clearinghouses
- Return or export of your practice’s data in a usable format
- Destruction of the vendor’s copies of your data, including backups
- Backup retention and deletion timelines after offboarding
- Written confirmation of destruction, not just a verbal assurance
- A defined transition process if you’re moving to another RCM provider
An offboarding process you never discussed is one you’ll be improvising during a stressful transition. Get it in writing while you still have the leverage to ask.
How Do TransDontics and MOATiT Deliver a Secure Billing Partnership?
TransDontics, a Texas-based dental RCM company, built its dental billing ecosystem on infrastructure secured by MOATiT, an Idaho-based managed IT and cybersecurity company that has served healthcare and dental practices across Idaho, Utah, and Wyoming since 2013. MOATiT’s healthcare practice runs HIPAA-conscious networks, hosts and backs up EMR and EHR systems on a nightly schedule, and applies encryption and access controls to data in transit and at rest.
Through this collaborative support, TransDontics provides:
- Immutable, nightly-tested backups designed so ransomware cannot take patient billing data hostage
- HIPAA security risk assessments and staff training performed by an in-house HIPAA compliance team
- Encrypted, access-controlled networks built specifically around medical and dental practice workflows
- Local, fixed-fee support with response inside one business hour
This partnership puts documented, independently maintained infrastructure behind every claim TransDontics processes. Practices working with the company get a security posture they don’t have to take on faith and a paper trail they can hand to an auditor, a payer, or a patient who asks how their records are protected.
Partner with a billing team backed by dedicated cybersecurity experts to protect your data and RCM
Final Takeaway
A signed Business Associate Agreement (BAA) is mandatory for any dental billing vendor under HIPAA, but its real value only emerges when you can actually verify compliance through documentation or audit rights.
The threat landscape has shifted dramatically, ransomware attacks like the 2026 eAssist incident prove that billing companies are now prime targets, not just collateral damage. As a result, encryption, multi-factor authentication, and network segmentation are becoming mandatory under the forthcoming HIPAA Security Rule update.
Beyond those basics, immutable and tested backups, plus a written incident-response SLA with a 72-hour window, carry far more weight than any vendor’s marketing claims. A billing partner that has a dedicated cybersecurity firm behind it, such as TransDontics working with MOATiT, offers your practice documented and verifiable protection.






