Add TransDontics as a preferred
source on Google
Security Posture

How to Evaluate the Security Posture of Your Dental RCM Partner?

Dental practices and DSOs increasingly worry about what happens to patient records once they leave the front desk and reach a billing vendor. Ransomware groups now target dental billing companies directly, and a breach at your revenue cycle management partner becomes your breach too. HIPAA requires every billing vendor to sign a Business Associate Agreement and apply administrative, technical, and physical safeguards to protect electronic patient records during transfer and storage.

This guide explains what those requirements mean in practice, the red flags that signal a vendor is cutting corners, and the questions to ask about monitoring, backups, and incident-response timelines before signing a contract. It also covers recent ransomware attacks on dental billing vendors, including the 2026 incident involving eAssist Dental Solutions, and what a security-first billing partnership looks like when a vendor works with a dedicated cybersecurity firm.

Every claim your practice submits, every patient balance you collect, and every insurance verification you run passes through a chain of vendors outside your four walls. When you outsource dental RCM services, that chain gets longer, and so does the list of places a hacker can get in, if your data isn’t handled securely.

This is something that happened on September 6, 2026, when the ransomware group DireWolf listed eAssist Dental Solutions, one of the largest outsourced dental billing companies in the country and majority-owned by Henry Schein, on its dark web leak site. Two days later, eAssist notified customers it was investigating a potential security incident and had brought in outside forensic experts. As of this writing, the company has not confirmed what data was accessed, and no entry for the incident appears yet on the federal breach portal, but the listing alone sent practices scrambling to check their own exposure.

That scramble is the point of this guide. Security posture used to be a line item on a vendor questionnaire that nobody read closely. It’s now the deciding factor in which RCM partner gets your contract, because a billing company that mishandles Social Security numbers, insurance IDs, and treatment histories makes your practice prone to notification letters, the fines, and the phone calls from anxious patients. Below, we cover what HIPAA requires from a billing vendor, the red flags that separate a well-run RCM company from a liability, and what to look for in monitoring, backups, and incident response before you sign anything.

Why Does Security Posture Now Decide Which RCM Partner You Choose?

The numbers explain the shift. The Department of Health & Human Services (HHS)’s Office for Civil Rights has watched large healthcare breach reports climb every year since 2018. Reports increased 102% between 2018 and 2023, and the number of people affected jumped more than 1,000% over the same period, driven mostly by hacking and ransomware. In 2023, 167 million individuals were affected, and 2025 broke the record with 772 large breaches reported to OCR, the highest annual total since the agency began tracking breaches in 2009.

Billing vendors make up a growing share of that total. In the first half of 2026, business associates, the HIPAA term for vendors like billing companies, were involved in 43% of large healthcare breaches reported to federal regulators, up from an average of about 20% between 2009 and 2017, as per HIPAA Journal’s analysis. Verizon’s 2026 Data Breach Investigations Report found third-party breaches in healthcare rose 60% year over year, highlighting the growing security exposure created by external vendors.

Dental practices specifically saw a 45% increase in cyberattacks between 2022 and 2024, according to Ponemon Institute research, with breach costs averaging more than $9 million once legal fees, notifications, and recovery are factored in. A vendor’s security posture is no longer a formality. It’s the biggest factor that determines whether your practice ends up in that data.

What are the HIPAA Compliance Requirements Your Billing Partner Must Meet?

What Makes a Billing Company a “Business Associate”

Under the Health Insurance Portability and Accountability Act (HIPAA), any vendor that creates, receives, maintains, or transmits protected health information on behalf of a dental practice is a business associate. These business associates are directly bound by the HIPAA Security Rule and Privacy Rule, not just their client’s policies. That covers outsourced dental billing support, clearinghouses, RCM platforms, and any subcontractor those companies use to process claims or verify eligibility.

The HIPAA Security Rule's Current and Coming Baseline

The HIPAA Security Rule has always required administrative, physical, and technical safeguards: risk analysis, workforce training, access controls, audit logging, and encryption. In December 2024, HHS’s Office for Civil Rights proposed the first major update to the Security Rule since 2013. The proposed rule removes the old distinction between “addressable” and “required” safeguards, meaning a vendor can no longer skip a control simply by documenting a reason why it isn’t feasible.

  • Encryption of ePHI at rest and in transit, with only limited, documented exceptions
  • Multi-factor authentication for any system that stores or accesses patient data
  • Network segmentation to keep systems that touch ePHI isolated from the rest of the network
  • Vulnerability scans at least every six months and penetration testing at least annually
  • Written incident response and disaster recovery plans built to restore critical systems within 72 hours
  • An annual technology asset inventory, network map, and documented review of each business associate’s security practices
 

The comment period closed in March 2025 with nearly 5,000 submissions, and a coalition of more than 100 healthcare organizations asked HHS to withdraw the rule in December 2025, citing an estimated $9 billion first-year compliance cost across the industry. The final rule is still pending. Whatever its ultimate form, these proposals describe what OCR already considers baseline practice, so a billing partner meeting this bar today is ahead of the requirement.

What's Required Today vs. What's Proposed vs. What to Look For

It’s easy to blur legally required safeguards with proposed ones and with good vendor practice. The table below separates the three, so you know exactly what a billing vendor must already meet, what regulators have proposed, and what’s worth requiring in a contract regardless of how the rulemaking ends.
Security issueCurrent HIPAA requirementProposed Security Rule (NPRM)Recommended vendor standard
Risk analysisRequired, existing specificationMore detailed, data-flow and asset-inventory basedCurrent and thorough, updated at least yearly
Multi-factor authenticationNot specifically required; only general person/entity authenticationRequired for systems accessing ePHI, limited exceptionsYes, on every account with access to patient data
Encryption (at rest and in transit)Addressable, not mandatory under current ruleRequired, with limited documented exceptionsYes, on all systems and backups
Network segmentationNot specifically mandatedRequiredYes
Vulnerability scanningNot specified by frequencyRequired at least every 6 monthsYes, on a documented schedule
Penetration testingNot specifically requiredRequired at least annuallyYes, with a summary you can review
Backup and disaster-recovery planningRequired contingency plan, risk-basedMore prescriptive, tested restoration plansYes, with documented, tested restores
72-hour system restoration targetNot a current requirementProposed as a benchmark for critical systemsUseful benchmark to request contractually
Business Associate AgreementRequired for any covered entity/business associate relationshipUnchanged as a requirement; adds annual verification of a BA's security practicesYes, reviewed annually, not just signed once
Breach notification timelineRequired, up to 60 daysUnchanged, 60-day outer limitFaster contractual notification (24-72 hours) is reasonable to request

What a Business Associate Agreement Must Cover?

A Business Associate Agreement (BAA) is the contract that makes a billing vendor legally accountable under HIPAA. A properly written BAA:

  • Specifies the permitted and required uses of patient data
  • Commits the vendor to implement appropriate safeguards
  • Sets out how and when the vendor must report a breach or security incident to your practice
  • Requires any subcontractor to agree to the same restrictions
  • Obligates the vendor to return or destroy patient data when the relationship ends
 

Keep in mind that a BAA doesn’t eliminate the need for the covered entity to perform appropriate vendor oversight and risk management. Practices should use the agreement, security documentation, assessments, and contractual audit or verification rights to understand how the vendor protects PHI.

Which are the Recent Ransomware Incidents in Dental RCM?

Dental billing has become a repeat target for ransomware incidents. The incidents below illustrate how the risk plays out across billing vendors of every size, from national outsourcers to single-location practices.

MCNA Dental (2023)

A ransomware attack on Managed Care of North America Dental exposed personal and dental records for 8.9 million individuals over ten days in early 2023, still the largest breach recorded against a dental-focused organization. The stolen data included names, addresses, Social Security numbers, and treatment histories related to Medicaid dental plans across several states.

Change Healthcare (2024)

The February 2024 attack on Change Healthcare by the BlackCat/ALPHV group froze claims processing for dental, medical, and pharmacy billing across the country for weeks. As noted in an article by Wired and referenced by the Congress in April 2024, Change Healthcare paid $22 million in bitcoin to the attackers, and a second group, RansomHub, leaked contracts and patient records anyway, a reminder that paying a ransom never guarantees the data stays private.

TriZetto Provider Solutions (2024-2026 disclosure)

TriZetto, a claims and revenue cycle clearinghouse used by thousands of providers, reported a breach affecting 3.43 million individuals in the first half of 2026, one of the two largest healthcare breaches of the year. 2026’s largest breaches so far happened at business associates rather than at hospitals or dental offices directly, underscoring the risk that comes through partnering with vendors processing claims.

DentaQuest (2026)

In May 2026, a cybercriminal group ShinyHackers hacked dental and vision benefits administrator DentaQuest’s systems, gaining unauthorized access to sensitive data, which included details like email addresses, health insurance information, names, phone numbers, physical addresses, and much more. Initially reported to be a data theft of over 2.6 million records, the numbers have since reached to 15-23 million records according to varying estimates.

ShinyHackers blackmailed DentaQuest to either pay a certain amount in extortion or see the data leaked. Refusal to meet the demands led ShinyHackers to publish over 234GB of company and individual data on a dark web site.

eAssist Dental Solutions (2026)

On September 6, 2026, DireWolf added eAssist Dental Solutions to its dark web leak site, claiming to have stolen roughly 26 gigabytes of data spanning 12.8 million rows. eAssist provides outsourced billing, insurance verification, and administrative staffing to dental practices nationwide. Two days later, the company notified its clients it was investigating a potential information security incident and had engaged outside forensic experts.

Speaking of DireWolf, it’s a double-extortion group that first appeared in May 2025. It steals data before encrypting systems so it can keep pressuring a victim even after backups make the encryption itself recoverable. Practices that work with eAssist were advised to review access logs, rotate credentials, and confirm their BAA covers breach-notification timelines.

Smaller Practices Are Targets Too

A Nevada-based DSO disclosed a breach affecting roughly 1.22 million patients in early 2025, exposing dates of birth, insurance details, and financial identifiers.

The same was the case with a single-location Philadelphia practice, which reported a breach affecting 11,273 patients in November 2025 after an intruder locked its internal server.

Both these cases demonstrate that practice size doesn’t determine whether a practice becomes a target. All systems that don’t implement proactive security measures are vulnerable to ransomware attacks and data breaches that come with legal risks and data breaches.

Choose a Billing Partner that Provides Encryption and Complete Data Protection with HIPAA-Compliant Solutions

What are the Red Flags that Signal a Dental RCM Partner Isn't Secure?

Here are the red flags that help identify if a dental billing company isn’t reliable enough to provide secure solutions:

  • No BAA offered upfront, or a generic template the vendor won’t customize or discuss line by line
  • Vague or evasive answers about where patient data is hosted and who can access it
  • No multi-factor authentication on staff logins or on the portal your team uses to check claims
  • No documented incident response plan, or no named contact for a security event
  • No recent third-party security assessment, penetration test, or audit result to share
  • Backups that have never been tested, or a vendor that can’t describe its restore process
  • Subcontractors the vendor won’t name, meaning your data may be touched by companies you’ve never vetted

How Can Your Dental Practice Verify a Billing Vendor's Security Claims?

A trustworthy RCM vendor should be able to produce documentation, not just reassurance, when a practice asks about security. Request the following, as applicable to the vendor’s size and setup:

  • A current security risk assessment or independent audit report
  • A SOC 2 report, if the vendor maintains one
  • ISO 27001 certification, if applicable
  • A penetration-test summary from within the past 12 months
  • A written vulnerability-management policy
  • Disaster-recovery and business-continuity documentation
  • Evidence that backups have actually been tested and restored, not just taken
  • A written incident-response policy
  • Breach-notification procedures, including timelines
  • A list of relevant subcontractors who may touch patient data
  • A data-flow diagram showing how PHI moves through the vendor’s systems
  • Documented encryption standards for data at rest and in transit
  • Access-control and multi-factor authentication policies
  • Records showing employees have completed security training
 

A vendor saying it’s HIPAA compliant is not the same thing as demonstrating how its security program actually operates. Compliance is a claim. Documentation is proof, and a vendor confident in its program will hand it over without hesitation.

Where Is Your Patient Data Stored?

Outsourcing dental billing and coding means patient data leaves your premises, and where it lands is as important as much as how it’s protected. Before signing a contract, confirm:

  • Where PHI is physically or logically hosted, including whether any of the hosting system is located outside the United States
  • Which cloud provider or data center the vendor uses
  • Where backups are stored, and whether that location is separate from the primary system
  • Where disaster-recovery systems are located and how quickly they can take over if the primary system fails
  • How remote access into the vendor’s systems is secured, and by whom
  • Whether any offshore staff or contractors can access PHI, and under what controls
  • Which subcontractors have access to your data and where they operate from
  • How long the vendor retains your data after the contract ends, and under what terms
 

HIPAA doesn’t prohibit hosting or accessing PHI outside the United States, but the same BAA obligations and safeguards have to extend to anyone handling that data, wherever they’re located. If a vendor can’t answer these questions clearly, that uncertainty becomes your liability the moment something goes wrong.

Least Privilege and Credential Management

A billing partner connects into more of your practice than most vendors do: practice-management software, clearinghouses, payer portals, EHR systems, banking and payment platforms, email, and remote-access tools. Every one of those connections is a potential entry point. The DireWolf listing against eAssist referenced specific staff accounts and remote-access tools among the data it claimed to have taken, a reminder that ransomware groups increasingly go after credentials directly rather than only network vulnerabilities.

  • Who at the vendor has access to which of your systems?
  • Is access role-based, limited to what each employee’s job actually requires?
  • Is multi-factor authentication required on every account with access to PHI?
  • Are inactive or departed-employee accounts disabled promptly?
  • Does each employee use unique credentials rather than shared logins?
  • Are privileged or administrative accounts separated from everyday accounts and monitored more closely?
 

Least-privilege access won’t stop every attack, but it limits how far a single compromised login can reach into your practice’s systems and data.

Continuous Monitoring: What to Ask a Billing Vendor

A vendor’s security posture shouldn’t rely on catching problems after the fact. Ask whether the vendor runs continuous monitoring of its network and systems, not periodic checks. That includes:

  • Centralized logging
  • Automated alerts for unusual login activity or data transfers
  • Monitoring for credentials that show up in breach dumps or dark web listings
  • Regular review of who has accessed patient billing portals and when the right billing partner is the one who can explain how security alerts are monitored outside normal business hours and how incidents are escalated when they occur.

What are the Backup and Disaster Recovery Standards to Expect?

Backups determine whether a ransomware attack becomes a bad day or a bad year. Look for immutable backups that ransomware can’t encrypt or delete, nightly backup cycles, geographically separate storage, and documented, regularly tested restores, instead of using a new backup system which has never been used before to recover anything.

The proposed HIPAA Security Rule update ties disaster recovery planning to a 72-hour restoration target for critical systems. Whether or not that becomes final, it’s a reasonable benchmark to hold any billing vendor to today.

Incident-Response SLAs: What “Fast” Actually Means

HIPAA’s Breach Notification Rule gives covered entities up to 60 days to notify affected individuals after discovering a breach. That is a legal ceiling, not a realistic operating standard for a business relationship.

Your contract with a billing vendor should set a tighter internal clock: written notification to your practice within 24 to 72 hours of a confirmed incident, a named point of contact available outside business hours, a documented containment and forensics process, and evidence that the vendor runs incident-response exercises at least once a year, instead of waiting for something to go wrong and act after that.

What Happens When You Leave the Vendor?

A BAA should already require a vendor to return or destroy PHI at the end of the relationship, but a security-minded practice confirms the mechanics before signing, not after giving notice. Ask how the vendor handles:

  • Termination of user accounts and logins tied to your practice
  • Revocation of API keys and system credentials
  • Removal of remote-access connections into your network
  • Removal of access to payer portals and clearinghouses
  • Return or export of your practice’s data in a usable format
  • Destruction of the vendor’s copies of your data, including backups
  • Backup retention and deletion timelines after offboarding
  • Written confirmation of destruction, not just a verbal assurance
  • A defined transition process if you’re moving to another RCM provider
 

An offboarding process you never discussed is one you’ll be improvising during a stressful transition. Get it in writing while you still have the leverage to ask.

How Do TransDontics and MOATiT Deliver a Secure Billing Partnership?

TransDontics, a Texas-based dental RCM company, built its dental billing ecosystem on infrastructure secured by MOATiT, an Idaho-based managed IT and cybersecurity company that has served healthcare and dental practices across Idaho, Utah, and Wyoming since 2013. MOATiT’s healthcare practice runs HIPAA-conscious networks, hosts and backs up EMR and EHR systems on a nightly schedule, and applies encryption and access controls to data in transit and at rest.

Through this collaborative support, TransDontics provides:

  • Immutable, nightly-tested backups designed so ransomware cannot take patient billing data hostage
  • HIPAA security risk assessments and staff training performed by an in-house HIPAA compliance team
  • Encrypted, access-controlled networks built specifically around medical and dental practice workflows
  • Local, fixed-fee support with response inside one business hour
 

This partnership puts documented, independently maintained infrastructure behind every claim TransDontics processes. Practices working with the company get a security posture they don’t have to take on faith and a paper trail they can hand to an auditor, a payer, or a patient who asks how their records are protected.

Partner with a billing team backed by dedicated cybersecurity experts to protect your data and RCM

Final Takeaway

A signed Business Associate Agreement (BAA) is mandatory for any dental billing vendor under HIPAA, but its real value only emerges when you can actually verify compliance through documentation or audit rights.

The threat landscape has shifted dramatically, ransomware attacks like the 2026 eAssist incident prove that billing companies are now prime targets, not just collateral damage. As a result, encryption, multi-factor authentication, and network segmentation are becoming mandatory under the forthcoming HIPAA Security Rule update.

Beyond those basics, immutable and tested backups, plus a written incident-response SLA with a 72-hour window, carry far more weight than any vendor’s marketing claims. A billing partner that has a dedicated cybersecurity firm behind it, such as TransDontics working with MOATiT, offers your practice documented and verifiable protection.

Frequently Ask Questions (FAQs)

What does HIPAA require from a dental billing vendor?

Any vendor handling patient data on your behalf must sign a Business Associate Agreement and follow HIPAA’s Security Rule safeguards, covering encryption, access controls, and breach notification. This applies to billing companies, clearinghouses, and their subcontractors.
HIPAA holds covered entities responsible for confirming a vendor’s safeguards through a signed BAA and ongoing oversight, even when the vendor caused the breach.
Look for written commitment to notify you within 24 to 72 hours of a confirmed incident, not HIPAA’s 60-day outer limit, along with a named contact and a documented containment process.
Backups should be tested on a regular schedule, not just stored. Ask for documented restore tests and confirmation that backups are immutable so ransomware cannot encrypt them along with live data.
No BAA offered upfront, vague answers about encryption or data hosting, no named incident-response process, and no recent third-party security assessment are all signs to walk away.
It depends on the vendor. A billing partner with documented safeguards, like encrypted infrastructure and tested backups, often reduces risk compared to managing everything in-house without dedicated security staff.
Asad Aleem

Asad Aleem

Dental Billing Specialist & RCM Expert

Grow your practice with our custom billing solutions.

We improve finances by settling claims fast and maximizing collections

Your Trusted
Dental Billing Partner

Get In Touch