Dark dental office desk with a monitor showing a compromised IT vendor account connected to a fleet of computers

Most breach stories end with a lesson about employee training. This one points somewhere most practices have never looked.

The Absolute Dental data breach affected 1,223,635 individuals, and the way it happened should give pause to every practice owner and DSO leader who outsources their IT. Absolute Dental is a Nevada group with more than 50 locations. According to the company’s breach notice, the attacker got in through the execution of a malicious version of a legitimate software tool, run through an account associated with the group’s managed services provider. Read that again. Not a hacked firewall. Ordinary IT software, running under an account the network had every reason to trust. The notice stops there, and so will I. But it raises a question worth asking about your own practice: if your IT provider’s account can reach every machine you own, then that access is part of your attack surface, whether you have ever thought about it that way or not.

What happened in the Absolute Dental breach

Absolute Dental identified suspicious activity on February 26, 2025. The company’s notice puts the unauthorized access window at February 26 to March 5, 2025, while plaintiffs in the resulting litigation allege it began a week earlier, on February 19. Either way, the aftermath took far longer than the intrusion. The file review was not completed until July 28, 2025, and notification letters did not reach affected individuals until August 26, 2025, six months to the day after the activity was spotted. An initial report filed with federal regulators in May 2025 listed a placeholder figure of 501 individuals. The real number, more than 1.2 million, did not surface until August.

The detail that matters is the entry point. The notice states the initial access came through the execution of a malicious version of a legitimate software tool, run through an account associated with the group’s managed services provider. Read that carefully, because the notice does not say the MSP itself was breached, and it does not say who ran the tool. What it establishes is narrower and, honestly, more useful: a weaponized copy of ordinary IT software reached the network through a trusted vendor account, and it looked enough like routine remote administration to work. Absolute Dental has not publicly named the MSP or the tool, and neither will I, because that was never disclosed. The exposed data was extensive: names, contact information, dates of birth, Social Security numbers, driver’s license and state ID numbers, other government IDs, and health and treatment information, with financial or payment-card details for a smaller subset. This affected employees as well as patients. A proposed class-action settlement of $3.3 million received preliminary approval in March 2026, and the court scheduled a final-approval hearing for July 30, 2026.

Why your IT vendor is your attack surface

Almost every practice and mid-size DSO hands an outside IT provider deep, standing access to the whole environment. That access is the entire point of the relationship. The MSP needs to reach every machine to patch it, monitor it, and fix it at 7 a.m. before the schedule loads. But that same reach means anything that gets in through a vendor account is not a foothold in one workstation. It is a foothold in everything, all at once, wearing a uniform your systems already trust. That is true whether the vendor was compromised, an employee was tricked into running something, or a credential leaked. The account is the exposure, regardless of how it gets misused.

This is why a vendor account is a different problem from a hijacked front-desk mailbox. When a front-desk account gets phished, the attacker inherits that one person’s access. When something reaches the network through a vendor’s administrative account, it inherits control designed to touch every device in the practice. And your security tools are built to flag the outsider. They are far worse at flagging trusted software running under a trusted account, which is exactly what a malicious version of a legitimate management tool looks like from the inside.

For a DSO, the math is worse. One MSP account often spans every location. The same standing access that lets a vendor manage 50 offices efficiently is the same standing access that, once turned, reaches 50 offices worth of patient data before anyone notices.

What practices and DSOs should do now

You cannot audit an attacker, but you can change how much your IT vendor is allowed to do and how closely that access is watched. You also do not need to be technical to start. Here are four questions to ask your IT provider, and what a good answer actually sounds like:

  • “Do you have full admin access to everything, all the time?” Most providers do, because it is convenient. The better arrangement is access granted for a specific task and taken back when the task is done (the industry terms are “least privilege” and “just-in-time access”). A good answer explains how and when their access is elevated and removed. A bad answer is “we need it to support you,” with no further detail.
  • “How do your technicians log in to our systems, exactly?” You are listening for a physical security key or an app that makes them match a number on screen, not a texted code and not a push notification they can approve by reflex. Those accounts can reach every machine you own, so they deserve your strongest login protection, not your weakest. A good answer names the method without being asked twice.
  • “If your remote-support software ran against every one of our computers at 2 a.m., would anyone notice?” This is the Absolute Dental question. The attack hid inside ordinary IT software running under an account the network already trusted. A good answer describes logging and alerting on who runs remote-support tools, from where, and against how many machines at once. If the answer is “that would never happen,” you have your answer.
  • “What in our contract actually requires any of this?” Go pull the agreement. Your business associate agreement and vendor contract should name specific obligations: multi-factor authentication on their accounts, a deadline for notifying you of a breach, and your right to review their controls. “We take security seriously” on a sales page is not a control. A clause you can enforce is. If your provider will not put it in writing, that itself is the finding.

The trusted-vendor blind spot

Read enough of these incidents and a specific blind spot keeps showing up. Practices spend their security budget defending against the outside world, the phishing email, the ransomware attachment, the stranger at the perimeter. Then the breach walks in through the vendor everyone already trusts by default, and the tools that would have caught a stranger wave it right through. Absolute Dental sits alongside cases like this in our roundup of the biggest dental data breaches, and the trusted-third-party pattern is one of the most common threads across the entire list. The recent DentaQuest breach shows the same lesson from the software-vendor side of the chain.

The uncomfortable truth for owners is that outsourcing IT does not outsource the risk. You can hand a vendor the keys, but the patients whose data walks out the door are still yours, and so is the notification letter, the settlement, and the phone call at the front desk.

I will be straight about the hard part, because most articles like this skip it. If you run three practices, you may not have much leverage over the provider you rely on. Asking a small local vendor to give up standing admin access and sign audit rights can get you a shrug or a bigger invoice. Ask anyway. What you are really testing is whether your provider treats security as part of the job or as an upsell, and the answer tells you a great deal about the relationship. If you run a group with several providers across locations, the harder problem is inconsistency: one vendor may do this well and another may never have been asked, and you will not know which until someone checks. That is the work, and it is worth doing before an incident does it for you.

This is what we do for the groups we protect at Medix Dental IT. We scope what an outside provider can reach, watch how that access gets used, and hold the people with the master keys to the highest standard in the building rather than the lowest. If you have never actually looked at what your IT vendor can touch, start with the four questions above. If the answers make you uneasy, our cybersecurity assessment exists to turn that unease into a specific list. Prevention is always cheaper than panic.

Posted in Dental Cybersecurity, News

Filter By: