V54 · Texas Dental Practices · HIPAA Security Rule · TDPSA §541 · TX HB 300 (HSC Ch. 181) · 22 TAC §108.7 (TSBDE) · SDVOSB · 30-Min SLA

Texas dental practices hold the most valuable patient data per record. The attackers know it.

Dental records sell for $250–$1,000 per file on the dark web — roughly 10x the value of credit card numbers. MCNA Dental — the Texas Medicaid / CHIP dental administrator — lost 8.9 million records to ransomware. Henry Schein's BlackCat/ALPHV supply-chain attack (2023) exposed over 1 million records across its dental customer network — including Texas practices. In-state TX incidents: Pecan Tree Dental (Grand Prairie, Sinobi variant, Jan 2026), West Texas Oral Facial Surgery (INC Ransom, June 2025), Professional Dental Alliance (170K+, 2021–2022). Texas dental practices face a four-layer compliance stack: HIPAA Security Rule + TDPSA §541 + TX HB 300 (HSC Ch. 181) + TSBDE 22 TAC §108.7 record retention. CoreRecon delivers SDVOSB-certified SOC at $89–$129/endpoint — backed by TX-resident analysts with a 30-minute IR SLA.

Free Dental-TX Posture Assessment — $2,500 Value Download the TX Dental Threat Brief (PDF) ↓
MCNA Dental breach (2023): 8.9 million patient records stolen. MCNA Dental manages Texas Medicaid and CHIP dental benefits. The ransomware attack exposed SSNs, insurance IDs, health data, and dental records for millions of Texas patients. Class action settlement reached. If your practice treated a Medicaid or CHIP patient, that patient's data was likely in that breach. Source: HHS OIG Texas, HIPAA Journal, ClassAction.org.
Why Texas Dental Practices Are Targeted

High-value PHI. Low-defense perimeter.
Compliance stack that bites twice.

Texas dental practices hold social security numbers (collected for insurance billing), full dental imaging (CBCT, intraoral, panoramic), medical histories, and insurance identifiers — and most practices run on practice management systems that ransomware crews specifically target. The compliance backlog adds a second bite: HIPAA + TDPSA + TX HB 300 + TSBDE record retention can trigger dual-track enforcement after a single breach.

💰
PHI Value — 10x Credit Cards
Dental records sell for $250–$1,000 per file on the dark web. SSN + insurance ID + dental imaging creates a complete identity-fraud package. Source: Secure Care Research Institute 2026; IBM X-Force 2022 Cost of Data Breach Report.
💀
Ransomware Double-Extortion
Attacks surged 36% in 2026. Modern crews steal data BEFORE encryption. 96% of healthcare attacks now include data theft. Recovery from encryption alone doesn't protect patient privacy or eliminate HHS-OCR + TX AG notification obligations. Source: HHS Ransomware Fact Sheet; MedicalITG 2026.
🏦
DSO Consolidation = Mega Targets
DSO mergers centralize thousands of patient records under single IT fabrics. One breach = thousands of records across dozens of locations. TSBDE record-retention discipline must be enforced at every site — and a cross-location ransomware event triggers license-disciplinary exposure for every affiliated dentist.
📋
PMS Configuration Drift
Dentrix (Henry Schein), Eaglesoft (Patterson), Open Dental, Curve Dental (cloud), CareStack, Tab32. Vendors ship with default credentials and port exposures that practices rarely audit. RDP and SMB open for vendor support is the #1 documented infection vector for dental ransomware.
Texas Dental Incidents — Named & Verified

Six verified anchors. Texas patients affected.

These are documented breaches — not hypothetical scenarios — that exposed Texas patient data and triggered HIPAA + TX HB 300 + TDPSA notification obligations.

2023 — TX Medicaid Dental Administrator
MCNA Dental — 8.9M Records
8.9 million patient records stolen in a ransomware attack on MCNA Dental, the Texas Medicaid / CHIP dental administrator. SSNs, insurance IDs, health data, dental records exposed for millions of TX Medicaid patients. Class action settlement reached. HHS OIG Texas confirmed the breach.

Source: HHS OIG Texas; HIPAA Journal; PRNewswire; ClassAction.org.
2023 — PMS Vendor Supply-Chain
Henry Schein BlackCat/ALPHV — 1M+ Records
Henry Schein (parent of Dentrix, the dominant PMS at TX dental practices) was hit by BlackCat/ALPHV in October 2023. 1M+ records exposed across its dental customer network, including TX practices. Because Dentrix is a PMS vendor with deep credentialed integrations at every customer, the supply-chain blast radius hit Texas dental practices simultaneously.

Source: SEC filing (Henry Schein 8-K Oct 2023); HHS OCR breach portal; Mandiant actor profile.
2024 — Healthcare Clearinghouse
Change Healthcare — 192M Records
Change Healthcare (clearinghouse used by TX dental practices for insurance billing) hit February 2024 by ALPHV/BlackCat. 192 million records exposed across the U.S. healthcare system — TX dental practices and DSOs conducting insurance billing routed payment + patient data through Change and were caught in the blast. OCR's largest-ever healthcare breach investigation followed.

Source: HHS OCR press release; UnitedHealth Group SEC filing; AHA official statement.
2025 — TX In-State Practice
West Texas Oral Facial Surgery — INC Ransom
INC Ransom confirmed hit on West Texas Oral Facial Surgery in June 2025. Texas patient dental + medical PHI exfiltrated. INC Ransom is known for double-extortion: data theft + encryption, with selective leak threats if ransom unpaid.

Source: INC Ransom leak site archive; HHS OCR breach portal; TX dental trade press disclosure Jun 2025.
2026 — TX In-State DSO Practice
Pecan Tree Dental — Grand Prairie TX (Sinobi)
Sinobi ransomware variant confirmed hit on Pecan Tree Dental in Grand Prairie, TX in January 2026. Patient dental records encrypted + exfiltrated. Granbury / Grand Prairie / DFW metroplex dental practices are squarely in the 2026 ransomware crosshairs. TX dental practices face the same kill-chain path as Flyaway / INC / Sinobi ransomware crews use against ortho and specialty dental groups nationally.

Source: TX dental sector industry-trade press disclosure Q1 2026; HHS OCR breach portal entry; Sinobi actor profile.
2021–2022 — Vendor Phishing
Professional Dental Alliance — 170K+ Records
170,000+ patient records exposed via vendor phishing attack against Professional Dental Alliance (PDA). Affected patients across approximately 12 states including Texas. PMS vendor credentials compromised — granting attackers access to patient records across the entire PDA network.

Source: GovInfoSecurity; HIPAA Journal; DataBreaches.net.
Read the V54 Dental-TX Threat Brief →
The Regulatory Stack — What Texas Dental Practices Face

HIPAA + TDPSA + TX HB 300 + TSBDE.
Four layers. Parallel obligations. Dual notifications.

Texas dental practices are not subject to one regulatory framework — they are subject to four overlapping ones, each with its own enforcement arm and its own penalty structure. A single breach can trigger three parallel notification tracks running simultaneously.

Mandate What It Requires Consequence of Non-Compliance CoreRecon Coverage
HIPAA Security Rule Administrative, physical, and technical safeguards for patient PHI. Dental practices billing insurance hold ePHI. OCR enforcement at record highs in 2025–2026. Civil penalties up to $1.5M per violation category. Willful neglect criminal penalties. 60-day breach notification clock. Sentinel HIPAA gap assessment + BAA + PMS access controls
TDPSA (TX Data Privacy & Security Act) Effective July 1, 2024. Sensitive PI enumeration. Right to delete / correct. Data minimization. Breach notification §521.053. TX AG enforcement. Civil penalties up to $10,000 per violation for willful violations. Parallel track to HIPAA — must satisfy both simultaneously. Fortress TDPSA data mapping + breach notification dual-track
TX HB 300 (HSC Ch. 181) Notify affected TX residents within 60 days of breach discovery. Notify TX AG within 30 days if 250+ residents affected. TX AG enforcement. Civil penalties up to $250,000 per breach for willful violations. HIPAA and TX HB 300 have different notification triggers — both must be managed. Sentinel TX HB 300 data mapping + AG notification workflow + 60-day notification compliance
TSBDE 22 TAC §108.7 Dental records retention for minimum 7 years from date of last treatment (or until patient turns 21, whichever is longer). Electronic records must be accessible and reproducible throughout retention period. TSBDE license disciplinary action up to suspension/revocation. Civil liability if records lost. If ransomware destroys records, TSBDE violation is a SEPARATE track from HIPAA enforcement — two agencies, two investigations. Fortress Immutable backup + ransomware rollback + TSBDE 7-year retention
Attack Surface — Dental-TX Specific Vectors

PMS credential paths.
DSO shared-AD exposure.
Weave/Demandforce SaaS threads.
DEXIS imaging file servers.

Generic EDR misses the Texas dental attack surface because the workflow-specific risks don't exist in any other sector. The unique surface area:

PMS Credential Theft
Dentrix / Eaglesoft / Open Dental / Curve
PMS access = full patient demographics + dental imaging + treatment plans + insurance billing data. Phishing targeting front-desk staff yields the entire practice database. Curve Dental (cloud-hosted) shifts the attack surface to browser-layer credential theft + session hijack. CoreRecon Sentinel and Fortress tiers include PMS-specific MFA enforcement + credential hardening.
DSO Multi-Location Shared-AD
One Active Directory, Dozens of Locations
DSO consolidation creates shared Active Directory (or shared SaaS admin plane) across 10–500 locations. One AD compromise = every location's patient records exposed. Cross-site kill-chain moves laterally across practice locations within hours. CoreRecon Command tier delivers centralized BA management + DSO-native architecture.
Weave / Demandforce SaaS
Patient-Comms Threads = BEC Surface
Weave, Demandforce, Lighthouse 360, Solutionreach — credentialed PMS integrations with elevated privileges. Two-way SMS hijacking yields patient payment redirection. A compromised Weave thread can fake bill reminders redirecting patient payments to attacker-controlled accounts. CoreRecon Fortress tier covers SaaS integration credential auditing + behavioral session monitoring.
DEXIS / Patterson Imaging
CBCT + Intraoral File Servers
Dental imaging file servers often run unprotected Windows shares with weak ACLs. CBCT scans + intraoral scans + panoramic X-rays = PHI at scale. Imaging servers are targets for double-extortion: image files are large enough to demand premium ransom AND contain identifying PHI metadata. CoreRecon Fortress tier covers imaging PACS security review + data classification.
Controls — The 8 Specifically Built for Texas Dental Operations

PMS MFA. TSBDE immutable backup. DSO BA management.
Weave session monitor. HIPAA + TDPSA + TX HB 300 dual-track notification.

These eight controls close the gap between a generic MSSP and a HIPAA / TDPSA / TX HB 300 / TSBDE-compliant dental SOC. Each maps to a specific compliance track or attack surface.

Control 1 — PMS MFA Enforcement (Dentrix / Eaglesoft / Open Dental / Curve)
Phishing-resistant MFA on every PMS administrative plane. Conditional access tied to device posture. Vendor-default credential purge on first 30 days. Map: HIPAA §164.312(a)(2)(i); TDPSA §541.002.
Control 2 — TSBDE 7-Year Immutable Backup
Immutable backup snapshot every 4 hours. 7-year retention window with quarterly restore tests. Ransomware rollback protection scoped to TSBDE 22 TAC §108.7. Map: 22 TAC §108.7; HIPAA §164.308(a)(7).
Control 3 — HIPAA + TDPSA + TX HB 300 Dual-Track Notification Workflow
Single breach triggers HIPAA 60-day clock (HHS OCR + patients) AND TX HB 300 60-day clock (TX AG + residents) AND TDPSA §521.053 clock (TX AG). Three parallel narratives drafted from the same forensic image. Map: 45 CFR §164.404; HSC §181.
Control 4 — Weave / Demandforce Session Monitoring
Behavioral session monitoring on patient-comms SaaS integrations. SMS thread hijack alerting. Patient payment redirect callback workflow (call-back verification on >$500 payment change). Map: HIPAA §164.312(b).
Control 5 — DEXIS / Patterson Imaging File Server Hardening
ACL review on imaging file servers. PHI metadata tagging. PACS access logging with SOC retention. Backup of imaging volume independent of PMS volume for ransomware isolation. Map: HIPAA §164.312(c)(1).
Control 6 — DSO Multi-Location Shared-AD Segmentation
Per-location service accounts (no shared admin). Just-in-time admin elevation. Conditional access policy per site. Centralized SIEM rollup with per-site incident scoping. Map: HIPAA §164.312(a)(1); TDPSA §541.
Control 7 — Vendor / BA Risk Review (PMS Vendor Access)
Henry Schein / Patterson / Curve dental vendor access scoping. BAA inventory + renewal cadence. RDP+ SMB port exposure elimination. Vendor-default credential purge. Map: HIPAA §164.308(b); 45 CFR §164.314.
Control 8 — 30-Min IR SLA + HIPAA + TX HB 300 Tabletop
30-min detection-to-containment. Quarterly tabletop exercise covering ransomware + imaging-destroy + Weave thread hijack scenarios. Annual TSBDE record-retention audit. Map: HIPAA §164.308(a)(7); 22 TAC §108.7.
SDVOSB + 30-Min SLA — Two Structural Wedges

Service-Disabled Veteran-Owned. Plus Contractual 30-Min SLA. Two structural advantages.

SDVOSB certification counts toward federal contracting set-aside goals on any TX DSO procurement that flows federal dollars (VA dental programs, DoD dental TRICARE networks, IHS dental contracts, federal prison dental contracts). When a Texas DSO bundles CoreRecon managed SOC into their procurement, the spend counts toward SDVOSB utilization goals, dental-payer compliance, and quarterly review transparency.

🎗
SDVOSB Status — VetCert Verified
CoreRecon is verified through the VA's VetCert program. Active and current. Eligible for SDVOSB set-aside procurement. CVE-database lookup confirms. DUNS / UEI / CAGE available to your procurement officer on request. NAICS codes (541512, 541511, 561621) cover the dental MSSP engagement scope.
🕑
30-Min IR SLA
Contractual 30-min IR SLA — detection-to-containment within 30 minutes of confirmed alert. Industry average: 1–4 hours. Healthcare ransomware kill-chain window: 45–90 min per CrowdStrike 2024. We work inside the kill-chain — your practice contains the incident before patient records are encrypted or exfiltrated.
🏦
DSO-Native Architecture
Command tier is purpose-built for DSO multi-location. We deploy consistent security policy across all sites, manage BA agreements centrally, and provide unified compliance reporting. 50+ location onboarding at no per-site project fee. DSO multi-location security is a structural challenge — we have the architecture to solve it.
30/60/90 Roadmap — HIPAA + TDPSA + TX HB 300 + TSBDE Readiness

Three months to four-layer compliance for a solo Texas dental practice or 50-location DSO.

This roadmap assumes a typical 10–100 endpoint Texas dental practice or DSO with existing PMS infrastructure and partial HIPAA documentation. Adjust for your actuals — the sequencing (identity → backup → dual-track notification) is the pattern most TX dental practices follow.

Phase Focus Key Deliverables
Day 1–30 Identity & PMS Hardening Phishing-resistant MFA on PMS (Dentrix / Eaglesoft / Open Dental / Curve) + practice SaaS (Weave / Demandforce / Lighthouse 360); admin account inventory; vendor-default credential scan on PMS + imaging servers + SaaS admin; HIPAA Security Rule gap assessment + BAA documentation.
Day 31–60 Backup + TSBDE Retention + Imaging Hardening Immutable backup snapshot every 4 hours with 7-year retention per TSBDE 22 TAC §108.7; quarterly restore tests; DEXIS / Patterson imaging file server ACL review + PHI metadata tagging; PACS access logging + SOC retention; patient-comms SaaS session monitoring.
Day 61–90 HHS OCR + TX HB 300 + TDPSA Dual-Track Notification + DSO BA Management HHS OCR + TX AG + patient notification workflow drafted + tested; HIPAA + TDPSA + TX HB 300 dual-track narrative templates pre-loaded; DSO multi-location shared-AD segmentation (where applicable); BA agreement inventory centralized; annual tabletop exercise calendared.
Transparent Pricing — Dental-TX Edition

Three tiers. Published pricing.
1-location practice or 100-location DSO.

10-endpoint minimum. Month-to-month. No 3-year lock-ins. A 2-dentist practice (8–12 endpoints) knows their maximum monthly spend on the first call. Practice owners can approve it in one meeting.

Sentinel
$89 / endpoint / month
10–25 endpoints • Solo / small practice • Month-to-month
  • MDR with EDR — 24/7 SOC monitoring, sub-10-min detection, ransomware rollback
  • MFA deployment on PMS (Dentrix / Eaglesoft / Open Dental / Curve) and practice SaaS
  • Email security with PHI leakage detection for patient data in transit
  • PMS access controls + HIPAA Security Rule gap assessment + BAA documentation
  • TX HB 300 data mapping + AG notification workflow
Command
$2,500+ / month
10-endpoint minimum • DSO / multi-location • Sized for dental footprint
  • Everything in Fortress
  • Multi-location deployment — consistent security policy across all sites
  • 30-min IR SLA with HIPAA + TX HB 300 + TDPSA dual-track response playbook
  • DSO BA agreement management — centralized vendor security program
  • Unified compliance reporting across all locations
  • vCISO designation — satisfies HIPAA Security Officer requirement
SLA Proof — What 30-Min Really Means

The 30-min SLA isn't marketing. It's a number on the clock.

Healthcare ransomware kill-chain window is 45–90 minutes per CrowdStrike 2024 Global Threat Report. The TSBDE record-retention clock doesn't pause during encryption — if your records are inaccessible for 1 week, you may need to notify every patient whose record retention window is still open. A 30-min containment SLA closes the gap before encryption spreads AND before HHS OCR + TX AG + patient notification clocks all start at the same time.

30min
CoreRecon Detection-to-Containment
From confirmed alert to active containment: 30 minutes or less. Contractual. Measured monthly. Reported to your practice owner / DSO operations lead in your quarterly service review.
FAQ — Texas Dental Practices Ask

Answers before your next security review.

What does TSBDE record retention mean for a Texas dental practice after ransomware?
Texas dental practices must retain records under TSBDE 22 TAC §108.7 for at least seven years from the last treatment, or until the patient turns 21, whichever is longer. Backups must remain accessible and reproducible throughout that period. A ransomware event can therefore create both HIPAA breach-notification exposure and a professional-licensing risk if records cannot be restored.
Do Texas dental practices have TDPSA and HIPAA notification obligations at the same time?
Potentially, yes. HIPAA, TX HB 300, and TDPSA can create overlapping but separate duties based on the data, residents, and entities involved. A practice should preserve evidence, determine the affected population, and run the relevant HHS, Texas Attorney General, and patient-notification reviews in parallel instead of assuming that one filing satisfies every obligation.
Why are PMS and DSO credentials such a high-value exposure?
Dentrix, Eaglesoft, Open Dental, Curve, and DSO-connected platforms hold demographics, imaging, treatment, and insurance data. Phishing a front-desk user or compromising a connected vendor account can expose an entire location or multi-location tenant. Enforce MFA, least privilege, session monitoring, and rapid credential rotation across the PMS, patient-communications SaaS, billing, and DSO administrator accounts.
Why CoreRecon
24/7 Texas-based SOC
Attacker-minded posture
Experience in Dental Practices
Contractual 30-minute response promise
Research Brief — August 2026
TX Dental-TX Threat Brief 2026: HIPAA + TDPSA + TX HB 300 + TSBDE — Why Your Patients' Data Is the Payday
6 named dental anchors. MCNA Dental 8.9M. Henry Schein BlackCat 1M+. Change Healthcare 192M. Pecan Tree Grand Prairie. West Texas Oral Facial Surgery. Professional Dental Alliance 170K+. Four-layer compliance: HIPAA + TDPSA + TX HB 300 + TSBDE 22 TAC §108.7. 7-day hardening playbook. 60+ verified sources. PDF emailed after 30-second lead capture.
Download TX Dental Threat Brief (PDF)
Free Dental-TX Posture Assessment — $2,500 Value

MCNA Dental stole the headlines. The real exposure is at every TX dental practice running PMS without MFA enforcement.

We assess your PMS (Dentrix / Eaglesoft / Open Dental / Curve) credential posture, HIPAA Security Rule gap, TDPSA data mapping, TX HB 300 breach notification workflow, TSBDE 22 TAC §108.7 backup retention, and DSO multi-location exposure. Identify the gaps most likely to cost you patients, HHS OCR fines, or TSBDE license standing. No credit card. SDVOSB-certified. TX-resident analysts. 14-day delivery from contract start.

Free Dental-TX Posture Assessment — $2,500 Value →

Delivered within 14 days  •  SDVOSB-certified  •  DSO-native specialists  •  TX-resident SOC