Dental records sell for $250–$1,000 per file on the dark web. MCNA Dental — the TX Medicaid/CHIP dental administrator — lost 8.9 million records to ransomware. Henry Schein's supply-chain attack (BlackCat/ALPHV, 2023) exposed over 1 million records across its dental customer network, including Texas practices. CoreRecon delivers HIPAA-compliant, TDPSA-ready security at $89–$129/endpoint — backed by an SDVOSB-certified team with a 30-minute response SLA.
Dental practices hold some of the most sensitive personal data in healthcare — patient names, SSNs, insurance IDs, dental imaging, and medical history. Attackers know the data is valuable, the defenses are often minimal, and the compliance pressure is rising.
These aren't hypothetical scenarios. These are breaches that exposed Texas patient data and triggered HIPAA and TX HB 300 notification obligations.
Dental practices have a specific threat profile. These are the vectors our SOC sees most frequently against dental practices and DSOs in Texas.
Texas dental practices face a dual-track compliance obligation — and TDPSA (effective July 1, 2024) added state-level requirements beyond HIPAA. The regulatory stack is thickening, and OCR enforcement is at record levels.
| Mandate | What It Requires | Consequence of Non-Compliance | CoreRecon Coverage |
|---|---|---|---|
| HIPAA Security Rule | Administrative, physical, and technical safeguards for patient PHI. Dental practices billing insurance hold ePHI. OCR enforcement at record high in 2025–2026. | Civil penalties up to $1.5M per violation category. Willful neglect criminal penalties. 60-day breach notification to OCR and affected individuals. | Sentinel HIPAA Security Rule gap assessment, BAA management, access controls for PMS |
| TDPSA (Texas Data Privacy & Security Act) | Effective July 1, 2024. Adds state-level obligations beyond HIPAA — right to delete, right to correct, data minimization requirements. Applies to dental practices that handle patient data of any kind. | TDB (Texas Attorney General) enforcement. Civil penalties up to $10,000 per violation for willful violations. Parallel track with HIPAA — must satisfy both simultaneously. | Fortress TDPSA data mapping, TDB notification workflow, data minimization controls |
| TX Breach Notification (HB 300) | Notify affected TX residents within 60 days of breach discovery. Notify TX AG within 30 days if 250+ residents affected. Parallel obligation with HIPAA breach notification. | TX AG enforcement. Civil penalties up to $250,000 per breach for willful violations. HIPAA and TX HB 300 have different notification triggers — both must be managed. | Sentinel TX HB 300 data mapping, AG notification workflow, 60-day notification compliance |
| TSBDE Record-Retention Rules (Texas State Board of Dental Examiners) | 22 TAC §108.7 requires dental records retention for a minimum of 7 years from date of last treatment, or until patient turns 21 (whichever is longer). Electronic dental records must be accessible and reproducible. Failure to maintain records subjects a license to disciplinary action by TSBDE. | TSBDE license disciplinary action up to suspension/revocation. Civil liability for loss or inaccessible records. If a ransomware attack destroys records, TSBDE violation is a separate track from HIPAA enforcement — two agencies, two investigations. | Fortress Backup integrity monitoring, ransomware rollback protection, and immutable backup compliance for dental record retention obligations |
| CMMC / DFARS (VA/DoD Dental Contractors) | Dental practices and groups with VA or DoD contracts handling FCI/CUI must meet NIST SP 800-171. CMMC Level 2 certification required by late 2025/2026 for contract eligibility. | Ineligible for VA or DoD contracts without CMMC certification. SPRS score must show compliance. Federal contracting risk for DSOs with government healthcare contracts. | Command CMMC Level 2 readiness, SPRS posture improvement, C3PAO-ready documentation |
10-endpoint minimum. Month-to-month. No 3-year lock-ins. A 2-dentist practice (8–12 endpoints) knows their maximum monthly spend on the first call. Practice owners can approve it in one meeting.
Free Security Assessment — a $2,500 value. Identify your top 5 risks in 48 hours. No credit card. No commitment. Executive-ready report delivered in 14 days. Sentinel pricing from $89/endpoint/month vs. Arctic Wolf ($250+/endpoint) or Cybriant ($18K/month minimums).
Generalist MSSPs, enterprise MDR, and in-house IT all sell to dental — but none were built for PMS credential hardening, DSO multi-location management, TDPSA state obligations, or the 30-min SLA that containment before encryption requires.
| Vendor | CoreRecon | Arctic Wolf | Huntress | Sophos MDR | Critical Start | Expel | Blackpoint | Dental IT MSP | In-House IT |
|---|---|---|---|---|---|---|---|---|---|
| 30-Min IR SLA | ✓ Contractual — 30-min SLA on all tiers | Best-effort. Not a published SLA. | No defined IR SLA. Alert triage only. | No contractual 30-min IR SLA. | MOBILESOC with defined alert response. No 30-min IR guarantee. | Transparent Workbench. No 30-min IR SLA. | MDR via MSP channel. No defined IR SLA. | Business-hours only. After-hours = voicemail. | Staff hours only. On-call often unavailable. |
| Published Pricing | ✓ $89–$129/ep/mo, public. Month-to-month. | No. Enterprise quote only. $250+/ep reported. | No public pricing. Varies by MSP partner. | No public pricing. Enterprise RFQ required. | No public pricing. Enterprise RFQ required. | No public pricing. Custom per engagement. | Partner-priced. No direct public rate. | Varies. Often $150–$300/ep bundled with IT. | Salary cost. No per-endpoint clarity. |
| Texas Residency SOC | ✓ 100% TX-resident analysts. No offshore. | Distributed global analysts. Not TX-resident. | Distributed US remote analysts. Not TX-resident. | Global SOC network. Not TX-resident. | TX HQ (Plano). Some TX-based analysts. | Remote distributed US. Not TX-resident. | MSP partner delivery. Varies by MSP. | Often local. May subcontract NOC offshore. | Local staff. But no SOC-grade tools. |
| SDVOSB-Certified | ✓ SDVOSB certified. Veteran-owned contracting advantage. | No. | No. | No. | No. | No. | No. | No. | No. |
| PMS Credential Protection (Dentrix, Eaglesoft, Open Dental, Curve) | ✓ PMS-specific MFA enforcement, credential hardening, and behavioral detection on PMS access. Built into Fortress tier. | General healthcare MDR. PMS specialization not documented. Customer configures PMS MFA independently. | SMB-focused EDR/MDR. PMS-specific hardening not documented. | Endpoint-first MDR. PMS credential hardening not in published service description. | Enterprise MDR. PMS specialization for dental not documented. | MDR + SIEM. PMS dental workflow not explicitly covered. | MSP MDR. PMS configuration customer-driven. | Often handles PMS support — but security is reactive, not SOC-grade. | May assist PMS config but lacks threat detection capability. |
| TDPSA + HIPAA Dual-Track (TX) | ✓ TDPSA data mapping, TDB workflow, and HIPAA gap assessment built in. TX regulatory stack is default — not an add-on. | HIPAA coverage standard. TDPSA (TX state, Jul 2024) not explicitly in service model. Advisory only. | HIPAA-adjacent MDR. TDPSA state-level obligations not in scope. | General compliance posture. TDPSA not explicitly addressed. | General compliance advisory. TDPSA not documented as in scope. | Compliance mapping support available. TDPSA-specific not documented. | General MDR. TDPSA advisory via MSP. Varies. | May have HIPAA experience. TDPSA usually not addressed. | No compliance capability without dedicated hire. |
| BAA (Business Associate Agreement) | ✓ HIPAA BAA standard on all tiers. Executed at contract signing. | ✓ BAA available. Enterprise legal review required. | ✓ BAA available for healthcare customers. | ✓ BAA available. Enterprise legal process. | ✓ BAA available. Enterprise legal process. | ✓ BAA available. Custom review required. | BAA via MSP partner. Ask your partner to confirm. | Often available, but may lack enterprise-grade HIPAA controls. | Cannot sign BAA as internal IT — practice is the covered entity. |
| DSO Multi-Location Management | ✓ DSO-native. Consistent policy across all sites, centralized BA mgmt, unified reporting. 50+ location onboarding at no per-site fee. | Multi-site via enterprise engagement. Custom SOW per deployment. | SMB-focused. Large DSO multi-site not the primary use case. | Enterprise tier for large DSOs. Custom engagement. | Enterprise MDR. Multi-location requires custom scoping. | Multi-tenant via Workbench. Custom DSO engagement. | MSP multi-tenant architecture available. Depends on MSP. | Often 1–3 practice scope. Large DSO typically beyond capabilities. | Per-location IT staff required. No unified security posture. |
We assess your Dentrix/Eaglesoft/Open Dental security configuration, PMS access controls, HIPAA/TX HB 300/TDPSA triple exposure, and DSO multi-location security posture. Executive-ready report in 14 days.
Book My Free Assessment →No credit card • No commitment • SDVOSB-certified team
Tier 1 (unknowing): $100–$50,000 per violation, max $25,000/yr
Tier 2 (reasonable cause): $1,000–$50,000 per violation, max $100,000/yr
Tier 3 (willful neglect, corrected): $10,000–$50,000 per violation, max $250,000/yr
Tier 4 (willful neglect, not corrected): $50,000+ per violation, no cap — AND HHS OCR can pursue criminal charges. For a dental practice with 5,000 patient records, a Tier 4 breach with no cap could reach into the millions.
Typical dental practice: 3–6 weeks for full restoration. That's 3–6 weeks of zero patient record access, phone calls to patients, frustrated appointment schedules, revenue loss, and HIPAA breach notification processing. Prevention costs a fraction of downtime. The OCR 60-day notification clock starts at breach discovery — and if your records are inaccessible for weeks, notification becomes your biggest problem.
EDR (Endpoint Detection & Response): Software only — you get alerts, you manage the response. Requires internal security staff to triage and act on alerts.
MDR (Managed Detection & Response): Human SOC analysts watching your endpoints 24/7, triaging alerts, and taking containment action. CoreRecon's Sentinel and Fortress tiers include full MDR — not just EDR alerts. We contain the event; you keep seeing patients.
Typical single-location practice: 5 business days from contract signature to active monitoring. Multi-location DSO: 2–3 weeks depending on site count. We handle the IT coordination — you sign the BA agreement and we do the rest. No need to replace your existing IT consultant; we coordinate with them for technical implementation.
Yes. Command tier is purpose-built for DSOs. We deploy consistent security policies across all locations, manage BA agreements centrally, and provide unified compliance reporting. We can onboard 50+ locations without a per-location project fee. DSO multi-location security is a structural challenge — we have the architecture to solve it.
Yes — Dentrix Ascend, Dentrix Enterprise, and Curve Dental are all in scope. Cloud-hosted PMS platforms shift the security footprint but don't eliminate it. We harden the browser-based access layer, enforce MFA on Ascend logins, monitor for anomalous session behavior, and protect the endpoints your staff use to access the platform. For Ascend specifically, we also assist with the HIPAA Shared Responsibility Model — Henry Schein handles cloud-infrastructure security, but you remain responsible for access controls and user authentication.
Yes. We execute a HIPAA-compliant BAA at contract signing on all tiers. As a covered entity, your practice is required to have a BAA with any vendor that handles PHI on your behalf — including your MSSP. Our BAA is straightforward: it defines the permitted uses of PHI, breach notification obligations, and our obligations as a Business Associate. No lengthy legal review cycle required. We can have it signed at the same time as your service agreement.
The SOC doesn't close. 24/7/365 monitoring means the exact same coverage at 2 AM on a Sunday as at noon on Tuesday. Ransomware attacks against dental practices typically execute after hours — attackers compromise during business hours and trigger encryption overnight when no one is watching. Our 30-minute IR SLA applies regardless of when the alert fires. For practice owners: you'll be notified by our SOC if there's an active event, but you don't need to respond — containment begins immediately without waiting for anyone at the practice to be available.
14-day executive-ready report. No credit card. No commitment. We assess Dentrix/Eaglesoft/Open Dental security, HIPAA/TX HB 300/TDPSA triple exposure, and DSO multi-location posture.