Home Blog TX Dental Ransomware 2026

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →
Threat Intelligence Brief — June 2026

Texas Dental Practice Ransomware: Why Your Patients' Data Is the Payday in 2026

Henry Schein. Change Healthcare. Pecan Tree Dental, Grand Prairie TX. Three incidents, two supply-chain collapses, and one TX-specific breach that hit 13,300 patients in January 2026. TX dental practices are in the ransomware crosshairs — and the attack surface has never been wider.

8.9M
MCNA Dental records — largest dental breach on record (LockBit, Mar 2023)
$2.457B
Change Healthcare total impact — 40% of all TX dental claims disrupted
207-day
avg dwell time before a dental practice detects a breach
HIPAA TSBDE TX HB 300 LockBit ALPHV/BlackCat INC Ransom Dentrix Eaglesoft

Research verified across 49 source citations including HHS OCR enforcement data, ADA HPI workforce data, HIPAA Journal breach records, ADA News incident reports, and TSBDE licensee data. Last updated June 27, 2026. CoreRecon — TX SOC, SDVOSB, 30-min SLA.

Why TX Dental Practices Are Primary Targets in 2026

Texas has over 30,000 actively practicing dentists — the third-largest dental workforce in the United States — across a population of 30+ million. The Texas State Board of Dental Examiners (TSBDE) governs this population through the Dental Practice Act and Rule 104 (24 CE hours per biennium). This is a large, dispersed, and largely under-secured vertical.

Dental practices are HIPAA covered entities — every patient record, insurance claim, billing entry, and clinical note is protected health information (PHI). This makes them high-value targets for ransomware operators who know: (a) HIPAA breach notification requirements create pressure to pay, (b) encrypted patient records create a patient-care emergency that accelerates decision-making, and (c) most TX practices have neither a dedicated IT security team nor a documented incident response plan.

The DSO consolidation is creating enterprise-scale attack surfaces

As of 2024, 16.1% of U.S. dentists are DSO-affiliated, up from roughly 8% in 2015 — more than doubling in under a decade, per the ADA Health Policy Institute. Major metros in Texas — DFW, Houston, San Antonio, Austin — are primary DSO consolidation targets. DFW alone has hundreds of DSO-affiliated practices. Houston's medical industry cluster accelerates DSO entry. A compromise at a DSO management vendor exposes every affiliated location simultaneously, as seen in the Professional Dental Alliance breach via North American Dental Management in 2024.

The regulatory enforcement environment has shifted

HHS OCR's 2025 enforcement record is the clearest signal yet: the average enforcement fine for a healthcare data breach is now $486,000. Of 14 OCR breach investigations in 2025, 8 involved ransomware. OCR's Risk Analysis Initiative (launched October 2024) has made failure to conduct an accurate and thorough risk analysis the leading cause of enforcement action — 12 of 14 recent cases cited this gap. The proposed 2024 HIPAA Security Rule updates (finalization expected 2026) will mandate MFA, network segmentation, vulnerability scanning, and encryption as baseline requirements.

Healthcare ransomware surged 58% in 2025, per Compudent Systems research. IBM's Cost of a Data Breach Report 2025 confirms healthcare as the most expensive sector for breach remediation — $7.42 million average — for the 14th consecutive year. A TX dental practice with 8–25 endpoints is not exempt from these trends. The Pecan Tree Dental incident in Grand Prairie, TX (Sinobi ransomware, January 2026, 13,300 affected individuals, HHS OCR confirmed) confirms this is not a large-practice problem.

Download the Full Threat Brief

Print-ready PDF with full source citations, compliance crosswalk, and 30/60/90-day roadmap.

Get the PDF Brief →

Named Incidents: The Supply Chain Is the Attack Vector

TX dental practices need to understand that the three most damaging incidents in recent memory were not attacks on individual practices — they were attacks on the infrastructure those practices depend on. Understanding these incidents is the foundation of effective defense.

Henry Schein — BlackCat/ALPHV Ransomware (October–November 2023)

On October 14, 2023, BlackCat/ALPHV infiltrated Henry Schein's network, exfiltrated 35 terabytes of data including payroll, shareholder data, and supplier bank accounts, and deployed ransomware across manufacturing and distribution systems. Henry Schein — the largest dental distributor globally and provider of Dentrix practice management software — took systems offline. BlackCat re-encrypted the network a second time in November 2023 after ransom negotiations collapsed. BlackCat claimed $150 million in lost revenue. By December 2023, law enforcement disrupted BlackCat's infrastructure via DOJ operation.

The Maine AG breach notification confirmed 166,432 individuals were affected in the Henry Schein incident. The total estimated cost reached $2.87 billion when benchmarked against the Change Healthcare 2024 incident that followed. TX practices relying on Henry Schein's eCommerce and telesales channels experienced supply disruptions. More importantly, the incident demonstrated that a PMS vendor compromise creates exposure across every connected practice simultaneously.

Change Healthcare — ALPHV Ransomware (February 2024)

Change Healthcare processes roughly 40% of all U.S. medical and dental insurance claims. In February 2024, the company suffered a catastrophic ransomware attack. The attacker gained access through a remote login portal without multi-factor authentication (MFA). The attack encrypted systems and exfiltrated data affecting 192+ million individuals — one of the largest healthcare data breach events ever recorded.

TX dental practices were immediately cut off from electronic claims submission, eligibility verification, and payment processing. Many TX practices reported cash flow disruptions of $50,000+ while claims backed up. The Texas Dental Association issued guidance on alternative processing routes. The downstream effect on TX Medicaid dental programs — through MCNA Dental's role as the TX Medicaid/CHIP administrator — compounded the disruption.

MCNA Dental — LockBit Ransomware (March 2023)

MCNA Dental, the largest dental insurer for government-sponsored Medicaid and CHIP programs covering 8 states, was breached by LockBit. Attackers exfiltrated ~700GB of data and published it when MCNA refused the $10 million ransom. Over 8.9 million individuals were affected — the largest dental-sector breach on record.

TX Medicaid dental programs were affected via downstream impacts on provider networks and member data. The MCNA incident also illustrates the speed of double-extortion: attackers don't just encrypt data — they steal it first, so paying the ransom doesn't prevent publication.

TX-Specific Incidents: The Pattern Is Local

🚨
Pecan Tree Dental, Grand Prairie TX — Sinobi Ransomware, January 2026 Up to 13,300 individuals affected. Reported to HHS OCR. Sinobi ransomware group added the practice to its dark-web leak site. Grand Prairie sits in the DFW metro — one of the highest-density DSO consolidation zones in Texas. HIPAA Journal | Becker's Dental.
🚨
West Texas Oral Facial Surgery, Lubbock — INC Ransom, June 2025 11,151+ individuals affected. INC Ransom added the practice to its data leak site on June 18, 2025. Individual notifications mailed July 31, 2025. West Texas rural healthcare provider — Lubbock-based oral surgery and dental specialist. HIPAA Journal.
🚨
Central Texas Pediatric Orthopedics — Hacking Incident, March 2025 140,000 patients affected. Breach reported to Texas AG (March 2025) and HHS OCR (April 2025). 90,000+ Texas residents confirmed in TX AG notification. Pediatric dental/oral health specialty provider — TX residency confirmed. HIPAA Journal.

The FBI issued a credible threat advisory specifically to dental practices in May 2024 via ADA News. This was not generic guidance — it was a confirmed intelligence report indicating active targeting.

The PMS and Imaging Attack Surface: Where Dentrix, Eaglesoft, and Carestream Create Exposure

The practice management system as single point of failure

The practice management system — typically Dentrix (Henry Schein), Eaglesoft (Patterson), Open Dental, Curve Dental, CareStack, or tab32 — is a single database running the entire business: scheduling, clinical notes, billing, insurance claims, and treatment planning. Encrypting it stops production immediately. Attackers specifically target PMS vendors because they know practices cannot bill, treat, or look up a patient until the system is restored.

The 2019 PerCSoft/DDS Safe incident (REvil ransomware, 400+ dental practices) demonstrated that a single PMS cloud backup vendor compromise affects hundreds of practices simultaneously — not one-by-one. HIPAA Journal | ZDNet. Absolute Dental (Nevada, 1.2M patient records) was compromised via MSP. The Professional Dental Alliance breach compromised thousands of affiliated practices through North American Dental Management. Paubox.

CBCT and imaging systems on flat networks

CBCT scanners, intraoral cameras, and digital imaging workstations run on the same network as front-desk PCs in most TX practices. These devices often run embedded Windows, receive irregular firmware updates, and cannot run EDR agents. Siotek 2026 dental cybersecurity research confirms the imaging layer as a critical gap. A compromise of a receptionist's workstation can reach the CBCT server and encrypt imaging archives — making clinical care impossible even if the PMS is spared.

Common imaging products in TX practices include Carestream, DEXIS Imaging Suite, and Dentsply imaging systems. CBCT systems typically run on flat VLANs with the rest of the practice network. Network segmentation of imaging VLANs is a specific HIPAA Security Rule control and a TSBDE record retention enabler — encrypted imaging archives mean the practice cannot access diagnostic records, creating a patient care problem that extends the breach notification clock.

RDP on front-desk workstations without MFA

Remote Desktop Protocol (RDP) exposed to the internet without MFA is a primary attack vector for dental practices. A single unpatched or poorly configured RDP instance on a reception workstation gives attackers direct network access. From there, they move laterally using credentials cached on the system. MedicalITG 2026 healthcare ransomware research confirms RDP as the leading initial access vector for healthcare ransomware in 2026.

Credential stuffing and password reuse

Criminals maintain large databases of leaked credentials from unrelated data breaches (LinkedIn, streaming services, retail breaches) and systematically try these credentials against dental software portals, insurance company logins, and Microsoft 365 accounts. If front-desk staff used the same password for their personal email and the practice management portal, that credential pair is in a criminal database right now. Medix Dental 2026 IT scams research.

In 2024, 88% of healthcare workers opened phishing emails, per Compudent Systems. The high-volume, high-urgency nature of dental front-desk work — insurance claims, patient attachments, billing inquiries — creates a perfect phishing environment. A single fake claims attachment clicked at 9am on Monday gives attackers access to the full network by 9:15am.

The Triple-Jeopardy Compliance Stack: HIPAA, TSBDE, and TX HB 300

TX dental practices face enforcement from three directions simultaneously. Understanding each layer is the first step toward building a defensible security posture.

HIPAA — Federal framework, accelerating enforcement

Dental practices are HIPAA covered entities via standard electronic transactions: 837D dental claims, 270/271 eligibility inquiries, and NCPDP SCRIPT for e-prescribing. HIPAA applies to all PHI — patient records, insurance data, imaging, billing. HHS OCR enforcement agreements confirm this applies to dental practices of every size.

Key enforcement actions relevant to TX dental practices:

Entity Amount Reason
Westend Dental (Indiana) $350,000 Ransomware + delayed breach notification; patient complaint to OAG led to discovery
Elgon Information Systems $80,000 Ransomware; failure to conduct required HIPAA risk analysis
MMG Fusion (dental software vendor) $10,000 15M individuals affected; vendor essentially out of business
Concentra Inc. $112,500 HIPAA Right of Access — 54th OCR enforcement under this initiative (Dec 2025)

Sources: Workplace Privacy Report | FaxSIPIt HIPAA statistics | DataBreachToday

Texas HB 300 — Stricter than HIPAA in key areas

The Texas Medical Records Privacy Act (TMRPA, codified under Texas HB 300) extends HIPAA-style protections beyond HIPAA's covered entities, applying to any individual or organization handling PHI for commercial, financial, or professional purposes. TMRPA imposes several requirements stricter than HIPAA:

Requirement HIPAA Standard TMRPA (Texas HB 300)
EHR access request response 30 days 15 business days
Employee privacy training "Reasonable period" after hire 90 days after hire
Refresher training Flexible Every 2 years
Breach reporting to TX AG 500+ individuals (HHS threshold) 250+ individuals

Sources: Censinet TMRPA guide | HIPAA Journal TX privacy | Patient Protect TX dentists

TSBDE — Record retention creates second-order ransomware exposure

The Texas State Board of Dental Examiners requires record retention under the Dental Practice Act — typically 7–10 years post-last-encounter (longer for minors). Ransomware that encrypts practice records without a clean backup creates a TSBDE compliance problem in addition to the HIPAA breach. This is a second-order consequence most generalist IT providers don't connect: if your backup is encrypted along with your PMS, you may not be able to demonstrate TSBDE compliance for the required retention period — even if you restore operations.

TSBDE Rule 104 sets CE requirements (24 hours/biennium), and the board has issued guidance on cybersecurity awareness as part of practice management CE. The TSBDE public license database confirms active oversight of 30,000+ TX licensees — enforcement capacity exists.

TDPSA — Exempt for HIPAA-covered PHI, not irrelevant

The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, explicitly exempts entities governed by HIPAA for protected health information. Dental practices are generally exempt for PHI under TDPSA. However, TDPSA clarifies HIPAA as the applicable framework for dental PHI — it does not reduce the HIPAA obligations. Accountable TDPSA analysis.

The proposed HIPAA Security Rule updates: what changes in 2026

OCR's proposed 2024 HIPAA Security Rule updates will, when finalized, mandate specific technical controls that most TX dental practices do not currently have: mandatory MFA for all ePHI systems, network segmentation requirements, documented vulnerability scanning, and encryption of ePHI at rest. DrBicuspid HIPAA Security Rule analysis. Practices that are not already implementing these controls will face a compliance cliff when the rule is finalized.

The Ransomware Playbook Against Dental Practices: How It Actually Runs

Understanding how ransomware operators approach a dental practice is the best defense against becoming one. The playbook has four stages, each with specific indicators and defense opportunities.

1

Initial Access — Phishing, RDP, Credential Stuffing, or Vendor Compromise

Attackers gain foothold through one of four vectors: (a) a phishing email clicked by front-desk or billing staff — fake insurance claims attachment, fakeChange Healthcare notification, fake supplier invoice; (b) exposed RDP on a workstation — direct network entry with no MFA barrier; (c) credential stuffing using leaked credentials from unrelated breaches — front-desk staff reuse the same password for Netflix and the PMS portal; (d) supply chain via a PMS vendor, clearinghouse, or lab communication tool that has been compromised. Obsidian Ridge 2026 dental ransomware research.

2

Reconnaissance and Dwell — 207 Days of Patience

Once inside, attackers don't rush. The IBM/Ponemon healthcare breach data confirms an average 207-day dwell time before detection in healthcare. During this period, attackers map the network, identify the PMS database location, find backup systems, identify the imaging VLAN, and determine the scope of PHI. They exfiltrate data for weeks or months before deploying encryption. HIPAA Journal 2025 healthcare breach analysis | IBM Cost of Data Breach 2025. For a dental practice, 207 days is enough time for the attacker to have copied every patient record in the PMS.

3

Encryption and Double-Extortion — The Kill Shot

When attackers are ready, they deploy ransomware across the network simultaneously — encrypting the PMS, the imaging servers, the backup systems, and any mapped network drives. INC Ransom (West Texas Oral Facial Surgery, June 2025), Sinobi (Pecan Tree Dental Grand Prairie TX, January 2026), LockBit (MCNA Dental), and BlackCat/ALPHV (Henry Schein, Change Healthcare) are the named threat actors currently targeting TX dental practices. Double-extortion means data is exfiltrated before encryption — paying the ransom does not prevent publication of patient records.

4

Breach Notification Clock — 60 Days, TSBDE, and TX HB 300

HIPAA Breach Notification Rule requires 60-day notification to HHS OCR and affected individuals for breaches affecting 500+. TX HB 300 requires notification to the Texas AG for breaches affecting 250+ individuals. TSBDE record retention requirements mean encrypted records may create a compliance gap even after systems are restored. HHS OCR Breach Portal tracks all reported breaches — Pecan Tree Dental and Central Texas Pediatric Orthopedics are both confirmed in this portal.

The average cost of a healthcare data breach in 2025 was $7.42 million — the highest of any industry for the 14th consecutive year. For a small TX dental practice (8–25 endpoints), the direct costs of a single incident typically run $125,000–$500,000 when you include ransom, downtime, forensics, OCR fines, state AG fines, legal fees, and class action exposure. AI.dentist ransomware recovery planning | Compudent Systems 2026 research.

What a 30-Minute SLA Actually Buys You vs. a Generic MSP Response

Most TX dental practices have an MSP that handles their IT — someone they call when the server goes down or a workstation crashes. That relationship works fine for hardware failures. It is categorically inadequate for a ransomware attack. Here's the math.

The response time gap

A typical MSP responds to after-hours incidents within 4–8 hours — if they have after-hours support at all. Many smaller MSPs serving dental practices only offer business-hours coverage. A receptionist clicking a phishing link at 10pm on a Saturday generates a network-wide ransomware deployment that will have encrypted the PMS, backup systems, and imaging servers within 30–90 minutes. AI.dentist incident response research.

CoreRecon's 30-minute response SLA means a trained HIPAA-aligned SOC analyst is actively working to contain the threat while the practice owner is still on the phone with their IT provider trying to figure out what happened. Every minute of delay in ransomware containment increases the scope of encryption, the volume of exfiltrated data, and the cost of recovery.

The downtime cost math

Healthcare organizations lose an average of $7,900 per minute during EHR downtime, per IBM. A dental practice that cannot bill for 3 days while the PMS is being restored — assuming a clean backup exists and the restore is tested — loses $2.5M in potential billing time per minute metric. The real-world calculation: a 15-operatory practice billing $3,000–$5,000/day in claims cannot process electronic claims, cannot verify insurance eligibility, cannot look up patient records. Three days of downtime at $3,500/day = $10,500 in cash flow disruption — before any forensics, ransom, or OCR fine. Siotek 2026 dental cybersecurity.

The billing model misalignment

Generalist MSPs bill by the hour ($150–$250/hr). A ransomware incident that requires 200 hours of recovery work generates $30,000–$50,000 in MSP labor alone — before any ransom payment, before any OCR fine, before any legal fees. The MSP has a financial incentive to be reactive (more hours = more revenue) and no financial incentive to prevent incidents in the first place.

CoreRecon's published flat-rate pricing ($89–$129/endpoint/month) aligns incentives: the better the prevention, the less reactive work required. A 15-endpoint practice pays $1,335–$1,935/month — $16,020–$23,220/year — vs. the potential $125,000–$500,000 cost of a single incident. The math is unambiguous.

The CoreRecon Approach: Built Specifically for TX Dental Practices

CoreRecon is a purpose-built cybersecurity solution for HIPAA-covered dental practices in Texas. SDVOSB (Service-Disabled Veteran-Owned Small Business) certified. TX-based SOC. Published flat-rate pricing. No surprise hourly billing.

24/7 HIPAA-Aligned SOC

CoreRecon analysts are trained in HIPAA Security Rule requirements and dental practice workflows. The 24/7/365 SOC monitors endpoints, email, and network traffic across your practice — not just the server room. Average detection-to-containment for critical alerts: under 30 minutes.

TX Residency — Texas SOC, Corpus Christi

CoreRecon's SOC operates from Corpus Christi, TX. Analysts understand the TX regulatory environment — TSBDE requirements, TX HB 300 thresholds, TX AG breach reporting for 250+ individuals, and the specific threat landscape facing TX dental practices. You can reach a human analyst, not a ticket queue, during business hours and after.

HIPAA-Aligned Incident Response Playbooks

CoreRecon maintains documented IR playbooks specifically for dental practices covering: ransomware detection and containment (isolate PMS first), breach notification clock management (60-day OCR requirement), TMRPA 250+ TX AG threshold assessment, TSBDE record retention confirmation during downtime, EHR/PMS recovery prioritization (billing first, clinical records second, imaging third), and PHI exfiltration assessment (double-extortion scenario). OCR enforcement data confirms IR plan gaps are a leading factor in breach investigations.

Published Flat-Rate Pricing

CoreRecon pricing is published: $89–$129/endpoint/month, flat-rate. No hourly billing, no surprise charges, no nickel-and-dime on incidents. The flat rate covers SOC monitoring, patching, backup testing, and incident response. See the full pricing page.

SDVOSB Certification

CoreRecon is SDVOSB certified — service-disabled veteran-owned small business. This certification may provide procurement advantages for government-adjacent dental practices, FQHC affiliates, and large DSO clients that prioritize vendor diversity in their security partnerships.

Next Steps: What TX Dental Practices Need to Do Now

This checklist is designed for an 8–25 endpoint TX dental practice with no dedicated IT security staff. Complete in order.

Week 1: Visibility (Days 1–7)

  • Day 1–2: Enable MFA on Microsoft 365 admin accounts and practice management software login. This single step blocks 90%+ of initial access attacks. ADA ransomware guidance.
  • Day 3–4: Audit all remote access points (VPN, RDP, any vendor remote support tools). Close or password-protect any exposed RDP. Require MFA for all remote access. This is the most common initial access vector for healthcare ransomware in 2026.
  • Day 5–7: Confirm Business Associate Agreements are signed and current for: Dentrix/Eaglesoft/Open Dental vendor, imaging software vendor, clearinghouse (Change Healthcare), cloud backup provider. Missing or expired BAAs are a leading OCR enforcement gap.

Week 2: Detection (Days 8–14)

  • Day 8–10: Deploy or confirm EDR (endpoint detection and response) on every workstation and server — not just antivirus. EDR detects ransomware behavior (mass file encryption, suspicious PowerShell, lateral movement) and can isolate the endpoint automatically.
  • Day 11–12: Confirm backup schedule and test one restore. Ask your IT provider: "When did we last successfully restore from backup? Can you show me the last restore test log?" If they can't answer in 30 seconds, your backups are unproven.
  • Day 13–14: Get a HIPAA security risk analysis done. OCR's #1 enforcement priority is the risk analysis. If you don't have a documented, current risk analysis, you are already non-compliant.

Week 3: Network Segmentation (Days 15–21)

  • Day 15–17: Document the network topology — specifically, is the CBCT/imaging system on the same VLAN as the front-desk workstations? If yes, request a network segmentation plan.
  • Day 18–21: Disable auto-run for USB devices (prevents ransomware delivered via infected USB keys from imaging reps or equipment vendors). Restrict software installation rights — only administrators can install software.

Week 4: Response Readiness (Days 22–28)

  • Day 22–24: Ask your IT provider for a copy of your incident response plan. Does it mention HIPAA breach notification timelines? Does it assign a specific person to manage the breach notification process? If no, request one.
  • Day 25–26: Document all PHI data flows: where patient records are stored, who has access, how backups are stored, who your business associates are. This is the foundation of a HIPAA risk analysis.
  • Day 27–28: Phishing training. Send a simulated phishing test to your front-desk and billing staff. Track click rates. If more than 15% click, schedule training immediately.

Free Security Posture Assessment

30-minute assessment covering MFA, EDR, backup testing, network segmentation, and HIPAA risk analysis gaps. TX-based team. No obligation. Results in 5 business days.

Book Free Assessment →

TX Dental Practices Are Being Targeted.
You're Not Imagining It.

Three confirmed incidents in 2025–2026. 49 verified source citations. HIPAA, TSBDE, TX HB 300 triple-stack exposure. Pecan Tree Dental, Grand Prairie TX was hit January 2026. The next one is not a hypothetical.

SDVOSB Certified TX SOC — Corpus Christi 30-min SLA Published Pricing