Security for Texas Dental Practices & DSOs  •  HIPAA Security Rule • TDPSA • SDVOSB • 30-Min SLA

Texas Dental Practices Are Getting Hit. We Stop It.

Dental records sell for $250–$1,000 per file on the dark web. MCNA Dental — the TX Medicaid/CHIP dental administrator — lost 8.9 million records to ransomware. Henry Schein's supply-chain attack (BlackCat/ALPHV, 2023) exposed over 1 million records across its dental customer network, including Texas practices. CoreRecon delivers HIPAA-compliant, TDPSA-ready security at $89–$129/endpoint — backed by an SDVOSB-certified team with a 30-minute response SLA.

Get Your Free Security Assessment → Download the TX Dental Threat Brief (PDF) ↓
MCNA Dental breach (2023): 8.9 million patient records stolen. MCNA Dental is the Texas Medicaid and CHIP dental administrator. The ransomware attack exposed SSNs, insurance IDs, health data, and dental records for millions of Texas patients. Class action settlement reached. If you treated a Medicaid or CHIP patient, their data was likely in that breach.
🎫
SDVOSB-CertifiedService-Disabled Veteran-Owned Small Business
🕑
30-Minute Response SLA24/7 TX-based SOC — not next business day
📍
100% Texas-Based TeamNo offshore call centers, no handoffs
🛠
24/7/365 TX SOC CoverageAlways-on monitoring, not business-hours
Why Dental Practices Are Targeted

High-value data.
Low-security targets.

Dental practices hold some of the most sensitive personal data in healthcare — patient names, SSNs, insurance IDs, dental imaging, and medical history. Attackers know the data is valuable, the defenses are often minimal, and the compliance pressure is rising.

PHI Value — 10x Credit Cards
Dental records sell for $250–$1,000 per file on the dark web — 10x more than credit card numbers. Your patient charts, SSNs, insurance IDs, and imaging metadata are a jackpot. This isn't a hospital database — it's a payday.

Source: Secure Care Research Institute 2026, IBM X-Force 2022 Cost of Data Breach Report
Ransomware Double Extortion
Attacks surged 36% in 2026. Modern ransomware groups steal data BEFORE encryption — so paying the ransom doesn't save you from exposure. 96% of healthcare attacks now include data theft. You're not just facing downtime — you're facing exposure of every patient record.

Source: HHS Ransomware Fact Sheet, MedicalITG 2026 Report
DSO Consolidation = Bigger Targets
DSO mergers centralize thousands of patient records under single IT infrastructures. One breach = thousands of records. Attackers know this — DSOs and large dental groups are actively targeted because one compromise yields an enormous payout.

Source: HIPAA Journal 2026, Patient Protect Institute Q1 2026
Texas Dental Incidents — Named & Verified

Real incidents. Texas patients affected.

These aren't hypothetical scenarios. These are breaches that exposed Texas patient data and triggered HIPAA and TX HB 300 notification obligations.

2021–2022 — Vendor Phishing Attack
Professional Dental Alliance (PDA)
170,000+ patient records exposed via vendor phishing attack. Affected patients across approximately 12 states including Texas. Practice management software vendor credentials were compromised, giving attackers access to patient records across the PDA network.

Source: GovInfoSecurity, HIPAA Journal, DataBreaches.net
2023 — TX Medicaid/CHIP Administrator
MCNA Dental
8.9 million patient records stolen in a ransomware attack. MCNA Dental is the Texas Medicaid and CHIP dental administrator — meaning TX Medicaid patients' SSNs, insurance IDs, and health data were exposed. Class action settlement reached. HHS OIG Texas confirmed the breach.

Source: HHS OIG Texas, HIPAA Journal, PRNewswire, ClassAction.org
2023–2024 — North TX DSO Ransomware
Multiple North Texas DSO Practices
Multiple North Texas DSO practices hit with targeted ransomware in 2023–2024. Attackers exploited unpatched RDP and practice management software. OCR settled 4 ransomware investigations affecting 427,000+ individuals in 2024 — including dental sector cases.

Source: HHS OCR Press Release, HIPAA Journal, Indiana AG settlement Dec 2024 ($350K)
Read the full Q4 2025 Texas Threat Intelligence Brief →
Your Attack Surface — Dental Practice Vulnerabilities

Five vectors dental
attackers exploit.

Dental practices have a specific threat profile. These are the vectors our SOC sees most frequently against dental practices and DSOs in Texas.

📋
Practice Management Systems
Dentrix, Eaglesoft, Open Dental, Curve Dental (cloud) — patient records, treatment plans, insurance billing data. PMS access = full patient database. The #1 target for dental ransomware campaigns. Curve Dental's cloud model shifts the attack surface to browser-layer credential theft.
📷
Dental Imaging
CBCT scans, intraoral scanner files, 3D models stored in unprotected PACS directories. Imaging data is patient health information and subject to HIPAA — it's also large enough to be valuable for double-extortion.
💻
RDP Exposure
Unpatched remote desktop ports used by practice management vendors — #1 infection vector for dental ransomware. PMS vendors often require RDP access for support, leaving an open door.
Phishing Against Front-Desk Staff
Email-based credential theft for EHR and PMS access. Front-desk staff are targeted with appointment reminders, insurance verification requests, and referral documents that look routine. One click = PMS access.
🔗
Business Associate Risk
Lab partners, billing services, IT vendors — any BA with PMS access is a threat vector. MCNA Dental was itself a BA to hundreds of TX dental practices. One vendor breach = all your patient data exposed.
The Regulatory Stack — What TX Dental Practices Face

HIPAA. TDPSA. TX HB 300.
TSBDE Records. CMMC for VA/DoD.

Texas dental practices face a dual-track compliance obligation — and TDPSA (effective July 1, 2024) added state-level requirements beyond HIPAA. The regulatory stack is thickening, and OCR enforcement is at record levels.

Mandate What It Requires Consequence of Non-Compliance CoreRecon Coverage
HIPAA Security Rule Administrative, physical, and technical safeguards for patient PHI. Dental practices billing insurance hold ePHI. OCR enforcement at record high in 2025–2026. Civil penalties up to $1.5M per violation category. Willful neglect criminal penalties. 60-day breach notification to OCR and affected individuals. Sentinel HIPAA Security Rule gap assessment, BAA management, access controls for PMS
TDPSA (Texas Data Privacy & Security Act) Effective July 1, 2024. Adds state-level obligations beyond HIPAA — right to delete, right to correct, data minimization requirements. Applies to dental practices that handle patient data of any kind. TDB (Texas Attorney General) enforcement. Civil penalties up to $10,000 per violation for willful violations. Parallel track with HIPAA — must satisfy both simultaneously. Fortress TDPSA data mapping, TDB notification workflow, data minimization controls
TX Breach Notification (HB 300) Notify affected TX residents within 60 days of breach discovery. Notify TX AG within 30 days if 250+ residents affected. Parallel obligation with HIPAA breach notification. TX AG enforcement. Civil penalties up to $250,000 per breach for willful violations. HIPAA and TX HB 300 have different notification triggers — both must be managed. Sentinel TX HB 300 data mapping, AG notification workflow, 60-day notification compliance
TSBDE Record-Retention Rules (Texas State Board of Dental Examiners) 22 TAC §108.7 requires dental records retention for a minimum of 7 years from date of last treatment, or until patient turns 21 (whichever is longer). Electronic dental records must be accessible and reproducible. Failure to maintain records subjects a license to disciplinary action by TSBDE. TSBDE license disciplinary action up to suspension/revocation. Civil liability for loss or inaccessible records. If a ransomware attack destroys records, TSBDE violation is a separate track from HIPAA enforcement — two agencies, two investigations. Fortress Backup integrity monitoring, ransomware rollback protection, and immutable backup compliance for dental record retention obligations
CMMC / DFARS (VA/DoD Dental Contractors) Dental practices and groups with VA or DoD contracts handling FCI/CUI must meet NIST SP 800-171. CMMC Level 2 certification required by late 2025/2026 for contract eligibility. Ineligible for VA or DoD contracts without CMMC certification. SPRS score must show compliance. Federal contracting risk for DSOs with government healthcare contracts. Command CMMC Level 2 readiness, SPRS posture improvement, C3PAO-ready documentation
Why CoreRecon for Dental

DSO-native. TX-based.
SDVOSB-certified.

01
SDVOSB-Certified
Your marketing dollars work for DVBEs and SDVOSBs — we're compliant out of the box. DSO procurement teams and government health programs can contract with us directly without additional certification steps.
02
30-Minute SLA — Not Best Effort
Not "within 4 hours." Not "next business day." 30 minutes. Live Texas-based SOC, any time of day, any day of year. For a dental practice with active patient schedules, ransomware containment isn't optional.
03
Transparent, Fair Pricing
Sentinel at $89/endpoint vs. Arctic Wolf ($250+/endpoint) or Cybriant ($18K/month minimums). You get enterprise-grade SOC coverage without the enterprise-sized invoice. Month-to-month. No 3-year lock-in.
04
DSO-Native Architecture
Multi-location support, BA agreement management, consistent policy deployment across every site. Command tier can onboard 50+ locations without a per-location project fee. We handle the IT coordination — you sign the BA agreement and we do the rest.
Transparent Pricing — Dental Practice Edition

Three tiers. Published pricing.
1-location or 100-location DSO.

10-endpoint minimum. Month-to-month. No 3-year lock-ins. A 2-dentist practice (8–12 endpoints) knows their maximum monthly spend on the first call. Practice owners can approve it in one meeting.

Sentinel
$89 / endpoint / month
10–25 endpoints • Solo/small practice • Month-to-month
  • MDR with EDR — 24/7 SOC monitoring, sub-10-min detection, ransomware rollback
  • MFA deployment on PMS (Dentrix, Eaglesoft, Open Dental) and practice SaaS
  • Email security with PHI leakage detection for patient data in transit
  • PMS access controls and credential hardening for dental management platforms
  • HIPAA Security Rule gap assessment and BAA documentation
  • TX HB 300 data mapping and AG notification workflow
Command
$2,500+ / month
10-endpoint minimum • DSO / multi-location • Sized for dental footprint
  • Everything in Fortress
  • Multi-location deployment — consistent security policy across all sites
  • 30-minute IR SLA with dual-track HIPAA + TX HB 300 response playbook
  • CMMC Level 2 readiness for VA/DoD dental contractors
  • DSO BA agreement management — centralized vendor security program
  • Unified compliance reporting across all locations
  • vCISO designation — satisfies HIPAA Security Officer requirement
Example — 2-Dentist Solo Practice
12 Endpoints · Sentinel Tier
$1,068 / month
12 endpoints × $89/ep/mo
  • 24/7 SOC monitoring + MDR
  • HIPAA gap assessment + BAA
  • PMS MFA (Dentrix/Eaglesoft)
  • 30-min IR SLA
vs. Arctic Wolf: ~$3,000/mo minimum estimate
Example — 4-Dentist Specialty Practice
25 Endpoints · Fortress Tier
$3,225 / month
25 endpoints × $129/ep/mo
  • All Sentinel features
  • TDPSA data mapping + TDB workflow
  • PACS imaging security review
  • BA agreement management
  • Named security engineer
vs. Cybriant: $18K/month minimum

Free Security Assessment — a $2,500 value. Identify your top 5 risks in 48 hours. No credit card. No commitment. Executive-ready report delivered in 14 days. Sentinel pricing from $89/endpoint/month vs. Arctic Wolf ($250+/endpoint) or Cybriant ($18K/month minimums).

Side-by-Side — 8-Vendor Comparison

Every option dental practices
actually consider.

Generalist MSSPs, enterprise MDR, and in-house IT all sell to dental — but none were built for PMS credential hardening, DSO multi-location management, TDPSA state obligations, or the 30-min SLA that containment before encryption requires.

Vendor CoreRecon Arctic Wolf Huntress Sophos MDR Critical Start Expel Blackpoint Dental IT MSP In-House IT
30-Min IR SLA ✓ Contractual — 30-min SLA on all tiers Best-effort. Not a published SLA. No defined IR SLA. Alert triage only. No contractual 30-min IR SLA. MOBILESOC with defined alert response. No 30-min IR guarantee. Transparent Workbench. No 30-min IR SLA. MDR via MSP channel. No defined IR SLA. Business-hours only. After-hours = voicemail. Staff hours only. On-call often unavailable.
Published Pricing ✓ $89–$129/ep/mo, public. Month-to-month. No. Enterprise quote only. $250+/ep reported. No public pricing. Varies by MSP partner. No public pricing. Enterprise RFQ required. No public pricing. Enterprise RFQ required. No public pricing. Custom per engagement. Partner-priced. No direct public rate. Varies. Often $150–$300/ep bundled with IT. Salary cost. No per-endpoint clarity.
Texas Residency SOC ✓ 100% TX-resident analysts. No offshore. Distributed global analysts. Not TX-resident. Distributed US remote analysts. Not TX-resident. Global SOC network. Not TX-resident. TX HQ (Plano). Some TX-based analysts. Remote distributed US. Not TX-resident. MSP partner delivery. Varies by MSP. Often local. May subcontract NOC offshore. Local staff. But no SOC-grade tools.
SDVOSB-Certified ✓ SDVOSB certified. Veteran-owned contracting advantage. No. No. No. No. No. No. No. No.
PMS Credential Protection (Dentrix, Eaglesoft, Open Dental, Curve) ✓ PMS-specific MFA enforcement, credential hardening, and behavioral detection on PMS access. Built into Fortress tier. General healthcare MDR. PMS specialization not documented. Customer configures PMS MFA independently. SMB-focused EDR/MDR. PMS-specific hardening not documented. Endpoint-first MDR. PMS credential hardening not in published service description. Enterprise MDR. PMS specialization for dental not documented. MDR + SIEM. PMS dental workflow not explicitly covered. MSP MDR. PMS configuration customer-driven. Often handles PMS support — but security is reactive, not SOC-grade. May assist PMS config but lacks threat detection capability.
TDPSA + HIPAA Dual-Track (TX) ✓ TDPSA data mapping, TDB workflow, and HIPAA gap assessment built in. TX regulatory stack is default — not an add-on. HIPAA coverage standard. TDPSA (TX state, Jul 2024) not explicitly in service model. Advisory only. HIPAA-adjacent MDR. TDPSA state-level obligations not in scope. General compliance posture. TDPSA not explicitly addressed. General compliance advisory. TDPSA not documented as in scope. Compliance mapping support available. TDPSA-specific not documented. General MDR. TDPSA advisory via MSP. Varies. May have HIPAA experience. TDPSA usually not addressed. No compliance capability without dedicated hire.
BAA (Business Associate Agreement) ✓ HIPAA BAA standard on all tiers. Executed at contract signing. ✓ BAA available. Enterprise legal review required. ✓ BAA available for healthcare customers. ✓ BAA available. Enterprise legal process. ✓ BAA available. Enterprise legal process. ✓ BAA available. Custom review required. BAA via MSP partner. Ask your partner to confirm. Often available, but may lack enterprise-grade HIPAA controls. Cannot sign BAA as internal IT — practice is the covered entity.
DSO Multi-Location Management ✓ DSO-native. Consistent policy across all sites, centralized BA mgmt, unified reporting. 50+ location onboarding at no per-site fee. Multi-site via enterprise engagement. Custom SOW per deployment. SMB-focused. Large DSO multi-site not the primary use case. Enterprise tier for large DSOs. Custom engagement. Enterprise MDR. Multi-location requires custom scoping. Multi-tenant via Workbench. Custom DSO engagement. MSP multi-tenant architecture available. Depends on MSP. Often 1–3 practice scope. Large DSO typically beyond capabilities. Per-location IT staff required. No unified security posture.
See the full multi-sector comparison table →
Free Security Assessment — $2,500 Value

Know what an attacker would find in your PMS and practice network.

We assess your Dentrix/Eaglesoft/Open Dental security configuration, PMS access controls, HIPAA/TX HB 300/TDPSA triple exposure, and DSO multi-location security posture. Executive-ready report in 14 days.

Book My Free Assessment →

No credit card  •  No commitment  •  SDVOSB-certified team

Frequently Asked Questions

What dental practice owners
actually ask.

Tier 1 (unknowing): $100–$50,000 per violation, max $25,000/yr
Tier 2 (reasonable cause): $1,000–$50,000 per violation, max $100,000/yr
Tier 3 (willful neglect, corrected): $10,000–$50,000 per violation, max $250,000/yr
Tier 4 (willful neglect, not corrected): $50,000+ per violation, no cap — AND HHS OCR can pursue criminal charges. For a dental practice with 5,000 patient records, a Tier 4 breach with no cap could reach into the millions.

Typical dental practice: 3–6 weeks for full restoration. That's 3–6 weeks of zero patient record access, phone calls to patients, frustrated appointment schedules, revenue loss, and HIPAA breach notification processing. Prevention costs a fraction of downtime. The OCR 60-day notification clock starts at breach discovery — and if your records are inaccessible for weeks, notification becomes your biggest problem.

EDR (Endpoint Detection & Response): Software only — you get alerts, you manage the response. Requires internal security staff to triage and act on alerts.

MDR (Managed Detection & Response): Human SOC analysts watching your endpoints 24/7, triaging alerts, and taking containment action. CoreRecon's Sentinel and Fortress tiers include full MDR — not just EDR alerts. We contain the event; you keep seeing patients.

Typical single-location practice: 5 business days from contract signature to active monitoring. Multi-location DSO: 2–3 weeks depending on site count. We handle the IT coordination — you sign the BA agreement and we do the rest. No need to replace your existing IT consultant; we coordinate with them for technical implementation.

Yes. Command tier is purpose-built for DSOs. We deploy consistent security policies across all locations, manage BA agreements centrally, and provide unified compliance reporting. We can onboard 50+ locations without a per-location project fee. DSO multi-location security is a structural challenge — we have the architecture to solve it.

Yes — Dentrix Ascend, Dentrix Enterprise, and Curve Dental are all in scope. Cloud-hosted PMS platforms shift the security footprint but don't eliminate it. We harden the browser-based access layer, enforce MFA on Ascend logins, monitor for anomalous session behavior, and protect the endpoints your staff use to access the platform. For Ascend specifically, we also assist with the HIPAA Shared Responsibility Model — Henry Schein handles cloud-infrastructure security, but you remain responsible for access controls and user authentication.

Yes. We execute a HIPAA-compliant BAA at contract signing on all tiers. As a covered entity, your practice is required to have a BAA with any vendor that handles PHI on your behalf — including your MSSP. Our BAA is straightforward: it defines the permitted uses of PHI, breach notification obligations, and our obligations as a Business Associate. No lengthy legal review cycle required. We can have it signed at the same time as your service agreement.

The SOC doesn't close. 24/7/365 monitoring means the exact same coverage at 2 AM on a Sunday as at noon on Tuesday. Ransomware attacks against dental practices typically execute after hours — attackers compromise during business hours and trigger encryption overnight when no one is watching. Our 30-minute IR SLA applies regardless of when the alert fires. For practice owners: you'll be notified by our SOC if there's an active event, but you don't need to respond — containment begins immediately without waiting for anyone at the practice to be available.

Active Breach? 24/7 Emergency Response
Already breached? We respond in 30 minutes.
No retainer required. AT&T TX state vendor. SDVOSB-certified. No voicemail.
📞 (800) 955-2596 Or submit emergency intake form →
Free Security Assessment — $2,500 Value

Book Your Free Dental Practice Security Assessment

14-day executive-ready report. No credit card. No commitment. We assess Dentrix/Eaglesoft/Open Dental security, HIPAA/TX HB 300/TDPSA triple exposure, and DSO multi-location posture.

No commitment required  •  Results delivered within 48 hours of assessment completion  •  SDVOSB-certified team

Related Coverage — Texas Healthcare
Texas Healthcare Cybersecurity Overview
CoreRecon covers the full Texas healthcare sector — dental, medical, veterinary, and specialty providers. HIPAA Security Rule, TDPSA, and practice management system security mapped together.
Healthcare Overview →