Dental records sell for $250–$1,000 per file on the dark web — roughly 10x the value of credit card numbers. MCNA Dental — the Texas Medicaid / CHIP dental administrator — lost 8.9 million records to ransomware. Henry Schein's BlackCat/ALPHV supply-chain attack (2023) exposed over 1 million records across its dental customer network — including Texas practices. In-state TX incidents: Pecan Tree Dental (Grand Prairie, Sinobi variant, Jan 2026), West Texas Oral Facial Surgery (INC Ransom, June 2025), Professional Dental Alliance (170K+, 2021–2022). Texas dental practices face a four-layer compliance stack: HIPAA Security Rule + TDPSA §541 + TX HB 300 (HSC Ch. 181) + TSBDE 22 TAC §108.7 record retention. CoreRecon delivers SDVOSB-certified SOC at $89–$129/endpoint — backed by TX-resident analysts with a 30-minute IR SLA.
Texas dental practices hold social security numbers (collected for insurance billing), full dental imaging (CBCT, intraoral, panoramic), medical histories, and insurance identifiers — and most practices run on practice management systems that ransomware crews specifically target. The compliance backlog adds a second bite: HIPAA + TDPSA + TX HB 300 + TSBDE record retention can trigger dual-track enforcement after a single breach.
These are documented breaches — not hypothetical scenarios — that exposed Texas patient data and triggered HIPAA + TX HB 300 + TDPSA notification obligations.
Texas dental practices are not subject to one regulatory framework — they are subject to four overlapping ones, each with its own enforcement arm and its own penalty structure. A single breach can trigger three parallel notification tracks running simultaneously.
| Mandate | What It Requires | Consequence of Non-Compliance | CoreRecon Coverage |
|---|---|---|---|
| HIPAA Security Rule | Administrative, physical, and technical safeguards for patient PHI. Dental practices billing insurance hold ePHI. OCR enforcement at record highs in 2025–2026. | Civil penalties up to $1.5M per violation category. Willful neglect criminal penalties. 60-day breach notification clock. | Sentinel HIPAA gap assessment + BAA + PMS access controls |
| TDPSA (TX Data Privacy & Security Act) | Effective July 1, 2024. Sensitive PI enumeration. Right to delete / correct. Data minimization. Breach notification §521.053. | TX AG enforcement. Civil penalties up to $10,000 per violation for willful violations. Parallel track to HIPAA — must satisfy both simultaneously. | Fortress TDPSA data mapping + breach notification dual-track |
| TX HB 300 (HSC Ch. 181) | Notify affected TX residents within 60 days of breach discovery. Notify TX AG within 30 days if 250+ residents affected. | TX AG enforcement. Civil penalties up to $250,000 per breach for willful violations. HIPAA and TX HB 300 have different notification triggers — both must be managed. | Sentinel TX HB 300 data mapping + AG notification workflow + 60-day notification compliance |
| TSBDE 22 TAC §108.7 | Dental records retention for minimum 7 years from date of last treatment (or until patient turns 21, whichever is longer). Electronic records must be accessible and reproducible throughout retention period. | TSBDE license disciplinary action up to suspension/revocation. Civil liability if records lost. If ransomware destroys records, TSBDE violation is a SEPARATE track from HIPAA enforcement — two agencies, two investigations. | Fortress Immutable backup + ransomware rollback + TSBDE 7-year retention |
Generic EDR misses the Texas dental attack surface because the workflow-specific risks don't exist in any other sector. The unique surface area:
These eight controls close the gap between a generic MSSP and a HIPAA / TDPSA / TX HB 300 / TSBDE-compliant dental SOC. Each maps to a specific compliance track or attack surface.
SDVOSB certification counts toward federal contracting set-aside goals on any TX DSO procurement that flows federal dollars (VA dental programs, DoD dental TRICARE networks, IHS dental contracts, federal prison dental contracts). When a Texas DSO bundles CoreRecon managed SOC into their procurement, the spend counts toward SDVOSB utilization goals, dental-payer compliance, and quarterly review transparency.
This roadmap assumes a typical 10–100 endpoint Texas dental practice or DSO with existing PMS infrastructure and partial HIPAA documentation. Adjust for your actuals — the sequencing (identity → backup → dual-track notification) is the pattern most TX dental practices follow.
| Phase | Focus | Key Deliverables |
|---|---|---|
| Day 1–30 | Identity & PMS Hardening | Phishing-resistant MFA on PMS (Dentrix / Eaglesoft / Open Dental / Curve) + practice SaaS (Weave / Demandforce / Lighthouse 360); admin account inventory; vendor-default credential scan on PMS + imaging servers + SaaS admin; HIPAA Security Rule gap assessment + BAA documentation. |
| Day 31–60 | Backup + TSBDE Retention + Imaging Hardening | Immutable backup snapshot every 4 hours with 7-year retention per TSBDE 22 TAC §108.7; quarterly restore tests; DEXIS / Patterson imaging file server ACL review + PHI metadata tagging; PACS access logging + SOC retention; patient-comms SaaS session monitoring. |
| Day 61–90 | HHS OCR + TX HB 300 + TDPSA Dual-Track Notification + DSO BA Management | HHS OCR + TX AG + patient notification workflow drafted + tested; HIPAA + TDPSA + TX HB 300 dual-track narrative templates pre-loaded; DSO multi-location shared-AD segmentation (where applicable); BA agreement inventory centralized; annual tabletop exercise calendared. |
10-endpoint minimum. Month-to-month. No 3-year lock-ins. A 2-dentist practice (8–12 endpoints) knows their maximum monthly spend on the first call. Practice owners can approve it in one meeting.
Healthcare ransomware kill-chain window is 45–90 minutes per CrowdStrike 2024 Global Threat Report. The TSBDE record-retention clock doesn't pause during encryption — if your records are inaccessible for 1 week, you may need to notify every patient whose record retention window is still open. A 30-min containment SLA closes the gap before encryption spreads AND before HHS OCR + TX AG + patient notification clocks all start at the same time.
We assess your PMS (Dentrix / Eaglesoft / Open Dental / Curve) credential posture, HIPAA Security Rule gap, TDPSA data mapping, TX HB 300 breach notification workflow, TSBDE 22 TAC §108.7 backup retention, and DSO multi-location exposure. Identify the gaps most likely to cost you patients, HHS OCR fines, or TSBDE license standing. No credit card. SDVOSB-certified. TX-resident analysts. 14-day delivery from contract start.
Free Dental-TX Posture Assessment — $2,500 Value →Delivered within 14 days • SDVOSB-certified • DSO-native specialists • TX-resident SOC