September 8th, 2026
eAssist Data Breach: What Dental Practices Need to Know
Industry Research — Dental Cybersecurity, News
A ransomware group put a dental billing vendor on its leak site last weekend. The vendor has not commented publicly since.
On September 6, 2026, a ransomware group called DireWolf listed eAssist Dental Solutions as a victim on its dark web leak site. eAssist is one of the largest outsourced dental billing companies in the country, and it is majority owned by Henry Schein. As of this writing the company has not confirmed the incident, denied it, or commented publicly, and neither has Henry Schein. As of September 8, 2026 there is no notice on the eAssist website and no eAssist entry turns up in a search of the federal breach portal, and federal reporting deadlines run from a breach being discovered rather than from a leak site post, so an absence this early tells you little either way.
That leaves dental practices and DSOs in an awkward spot. The claim comes from a criminal group with an obvious incentive to exaggerate, the vendor is silent, and the pages ranking for this story are mostly law firms recruiting plaintiffs and threat feeds republishing the listing. None of them tell an operator what to do.
The short answer: the eAssist data breach is an unconfirmed claim, not a confirmed incident. A ransomware group named eAssist on its leak site on September 6, 2026. eAssist and Henry Schein have not commented publicly, no eAssist entry appears in a search of the federal breach portal as of September 8, 2026, and no independent source has verified what was taken. If your practice sends data to eAssist, the useful response is not to wait for confirmation but to inventory and tighten that vendor’s access to your systems this week.
What is actually known about the eAssist breach claim
Strip out the speculation and the confirmed facts fit in a short list.
DireWolf published a listing naming eAssist Dental Solutions and its domain, dentalbilling.com, on September 6, 2026. Threat intelligence trackers including Ransomware.live, RedPacket Security and BrinzTech indexed the posting. What those trackers establish is that the listing exists, not that an attack occurred. Every detail in circulation, including every figure below, traces back to that single attacker-authored page.

What has not happened matters just as much. eAssist has issued no public statement. Henry Schein has issued no public statement. No lawsuit has been filed, though several plaintiff firms have already opened investigations.
None of that means the claim is false. It means the claim is unverified, and those are different things.
The numbers going around are the attacker’s numbers
You may have seen specific figures attached to this story: around 26 GB of data, 213 database tables, roughly 12.8 million database rows. Every one of those came from the attacker’s own posting, which lays out a database inventory in considerable detail.
Treat them accordingly. A leak site listing is an extortion tool, written to pressure a victim and advertise to buyers. Both goals reward inflation, and there is no independent confirmation of any of it.

One detail is worth knowing about where those numbers come from. The structured field where a data volume would normally appear on a tracker record is empty for this listing, which is why the trackers indexing it show no data size. The figures being repeated were read out of the body of the posting instead, where the group published its own overview and inventory of what it says it holds. The only source for the scale of this alleged theft is the party with the most to gain from making it sound large.
None of it changes what you should do. We tell the groups we work with to treat attacker figures as an unverified claim rather than a measurement, and to act on their own exposure instead, because your exposure is a fact you can establish today without anyone’s cooperation.
Who eAssist is, and why this vendor matters
eAssist sells outsourced dental billing and revenue cycle management: insurance claims, patient billing, insurance verification, credentialing. Henry Schein acquired a 70% ownership position in June 2021, and eAssist’s own website says it serves more than 3,000 dental practices.
A remote billing service cannot do its job without reaching into your systems. That typically means access to your practice management software, a route into your claims and patient ledgers, and credentials for the payer portals your claims flow through. The whole value of the service is that someone outside your building can work inside your systems.
That is why this claim is worth your attention even unconfirmed. The concern is not one company’s servers. It is that a billing vendor is, by design, holding keys to a lot of practices at once.
As for who DireWolf is, the short version is the part that matters to you. The group surfaced in May 2025 and runs a double extortion model, encrypting systems to disrupt operations and stealing data to threaten publication. Security firm Proven Data counted 127 claimed victims as of September 7, 2026, with healthcare the largest slice at 17%. That concentration is the signal worth keeping: healthcare data stays valuable for decades, downtime is expensive, and the industry increasingly routes its data through vendors who hold many organizations’ records in one place.
What should a dental practice that uses eAssist do now?
Here is the reframe that makes this manageable. You are not deciding whether the breach happened. You are deciding whether your exposure to that vendor is acceptable, and that is a question you can answer today with no help from anyone.
Every step below is worth doing regardless of how this particular claim resolves. That is the test we apply to any unconfirmed incident. Work that only pays off if the claim is true is a bet. Work that pays off either way was already overdue.
1. Write down what you actually send them
Most practices cannot answer this quickly, which is itself the finding. List what data leaves your practice for the vendor, what comes back, and how. Claims files, patient demographics, insurance details, ledgers, imaging attachments. Not what the contract says. What actually moves.
2. Find every way they can get in
Inventory the live connections: remote access into your practice management software, any interface between their platform and your systems, file transfer accounts, shared drives. Vendor access tends to accumulate quietly. Someone set it up during onboarding years ago and nobody has looked since.
3. Rotate the credentials attached to those pathways
Change the passwords tied to vendor access, especially any shared account. Coordinate it with the vendor and your own team first, because rotating a credential that an active integration depends on can interrupt claims work. Done in order it is one of the cheapest ways to close a path between a vendor compromise and your practice.
This is also where a lot of dental groups discover an uncomfortable arrangement they have been living with for years. Outsourced billing frequently runs on shared payer portal logins, one account and one password used by whoever is working the claim that day. Rotating that password is the small fix. The payer portal problem underneath it is the larger one, and several carriers will issue individual logins to your team if you ask.
4. Read your access logs
Look at vendor account activity for the last several months. Logins at odd hours, from unfamiliar locations, or pulling far more records than a billing task requires. You are looking for the shape of bulk data access, not a single suspicious login.
5. Cut access down to what the work requires
A biller working claims does not need administrative rights, every patient record in your database, or access that outlives the engagement. Most vendor accounts are over-permissioned because it was faster to grant broad access than to scope it properly.
6. Pull the agreement out of the drawer
Find the signed business associate agreement and read what it obligates the vendor to do when they have an incident, including how fast they must tell you. A signed agreement is not a security control, but it is the document that governs what happens next, and the worst time to read it for the first time is after a confirmation lands. Our guide to what HIPAA breach notification actually requires covers the deadlines that would apply to you.
7. Ask the vendor directly, in writing
Contact your eAssist representative and ask for a security update in writing. You may get nothing, and a non-answer is not proof of anything on its own, since an active investigation and legal review genuinely do limit what a representative can say. Ask anyway. Whether the request is acknowledged at all is worth knowing before your next renewal conversation.
8. Tell your front desk what to expect
This one is standing hygiene rather than a response to this claim, and it is worth a two-minute huddle whenever any vendor breach is in the news. If patient details ever do circulate, the symptom that reaches your office is a convincing phone call: someone claiming to be from your practice or an insurer, armed with real information. Your team should know that a caller knowing a patient’s details does not make them legitimate. If this does become a confirmed incident, our guide on what to do after a breach walks through the sequence.
The vendor question this should actually raise
Do not let this end with eAssist. The reason an unconfirmed claim is worth this much attention is that a billing vendor sits in a position most dental groups have never risk-assessed: outside your walls, inside your systems, holding data for many practices at once.
You almost certainly have several vendors in that position. Your clearinghouse, your imaging platform, your patient communication tool, your analytics dashboard. Any of them could be next month’s leak site post, and the eight steps above would not change. It is why the biggest dental data breaches on record are mostly incidents at vendors and payers rather than at practice networks.
The groups that handle these weeks calmly are not the ones with better threat intelligence. They already know which vendors touch patient data, already scoped that access to the minimum, and already monitor for data leaving. For a DSO that work compounds, because vendor sprawl multiplies with every acquisition, and each practice you buy arrives with its own billing arrangement and its own uninventoried integrations. It is the difference between answering this question in an afternoon and spending three weeks discovering what you are connected to.
eAssist Data Breach FAQs
Has eAssist confirmed a data breach?
No. Read the public silence correctly: for a company facing an allegation like this, saying nothing until scope is established is a common and unremarkable posture rather than evidence of anything. It also means a confirmation, if one comes, can take weeks or months. Plan for a long unconfirmed window instead of refreshing the news.
Is eAssist owned by Henry Schein?
Yes, majority owned. Henry Schein announced on June 10, 2021 that it had acquired a 70% ownership position in eAssist Dental Solutions. eAssist continues to operate under its own brand.
Was patient data exposed in the eAssist breach?
There is no public, independently verified answer, and anyone stating one with confidence is guessing. DireWolf’s listing describes a database inventory, but no independent source has confirmed what was taken, and the group published no data volume in the structured field where it normally does. eAssist handles claims and billing data for dental practices, so patient information is plainly within reach of its systems, but reach is not evidence. Treat the exposure as unconfirmed and act on your own access controls rather than on an assumption in either direction.
Should we terminate eAssist over this?
Not on the basis of an unconfirmed claim, and switching billing vendors mid-cycle carries its own operational risk. The proportionate response is to tighten and verify vendor access now, ask the vendor for a written update, and watch how they communicate. How a vendor responds to a public allegation is legitimate information for a renewal conversation later. A leak site listing on its own is not grounds for an emergency exit.
Do we have to notify patients about this?
Not on today’s facts. Notification obligations run from the discovery of a breach of unsecured protected health information, and right now there is no confirmed incident, no confirmed data set, and no notification from the vendor. If eAssist was acting as your business associate and later confirms a breach, it must notify you, and your own obligation to notify patients does not disappear because the incident happened on someone else’s systems. That is the moment to involve counsel, and the reason to locate your business associate agreement this week rather than that week.
How do I know if my practice was affected by the eAssist breach?
You cannot know yet. No verified list of affected practices is public, and no customer notification from eAssist has been publicly reported. What you can establish today is your own exposure: whether you send data to eAssist, what data that is, and what access their people and systems have inside yours. If a confirmation does come, that inventory is what turns a vague worry into a specific, answerable question.
How credible is DireWolf?
Credible enough to take seriously, not credible enough to quote. A group in this business has a reason not to invent victims outright, because a listing that gets publicly disproven costs it leverage on the next target. It has an equally clear reason to inflate the value of what it took, because that is the number doing the negotiating. Treat the fact of the listing as the signal and the inventory attached to it as marketing.
Work that list and whatever comes next, a confirmation or a denial or continued silence, is a news item rather than an emergency.
That is the work we do for the dental groups and DSOs we protect at Medix Dental IT. We map every vendor and integration that can reach patient data, scope that access down to what each role actually needs, and monitor for the credential abuse and bulk data access that can follow a vendor compromise. If you want a second set of eyes on how exposed your vendor chain makes you, a cybersecurity assessment is the place to start.
Posted in Dental Cybersecurity, News