Dental practice back office at night with a security dashboard on screen showing an amber unverified status ring and a vendor connection map, representing an unconfirmed breach claim against a dental billing vendor

A ransomware group put a dental billing vendor on its leak site on September 6. Two days later the vendor told its customers it was investigating, and the group’s own description of what it says it took has been circulating among dental offices ever since.

On September 6, 2026, a ransomware group called DireWolf listed eAssist Dental Solutions as a victim on its dark web leak site. eAssist is one of the largest outsourced dental billing companies in the country, and it is majority owned by Henry Schein. On September 8 eAssist notified customers that it is investigating a potential information security incident and has engaged outside experts, which the Georgia Dental Association published two days later. eAssist has not confirmed that customer or patient information was accessed or compromised, and no eAssist entry turns up in a search of the federal breach portal as of September 11, 2026. Federal reporting deadlines run from a breach being discovered rather than from a leak site post, so an absence this early tells you little either way.

Updated September 11, 2026: eAssist has told customers it is investigating. This post now reflects that notification, alongside a categorized summary of what the attacker says it holds, a timeline of the claim so far, and a closer look at the categories that reach into a practice.

That leaves dental practices and DSOs in an awkward spot. The claim comes from a criminal group with an obvious incentive to exaggerate, the vendor has confirmed an investigation but not its scope, and the pages ranking for this story are mostly law firms recruiting plaintiffs and threat feeds republishing the listing. None of them tell an operator what to do.

The short answer: eAssist has confirmed that it is investigating a potential information security incident, and it has not confirmed that any customer or patient information was accessed. A ransomware group named eAssist on its leak site on September 6, 2026, and on September 8 eAssist notified customers that an investigation is underway with outside experts engaged. No eAssist entry appears in a search of the federal breach portal as of September 11, 2026, and no independent source has verified what the attacker says it took. If your practice sends data to eAssist, the useful response is not to wait for the investigation to finish but to inventory and tighten that vendor’s access to your systems this week, which is also what eAssist has told its own customers to do.

What is actually known about the eAssist breach claim

Strip out the speculation and the confirmed facts fit in a short list.

DireWolf published a listing naming eAssist Dental Solutions and its domain, dentalbilling.com, on September 6, 2026. Threat intelligence trackers including Ransomware.live, RedPacket Security and BrinzTech indexed the posting. What those trackers establish is that the listing exists, not that an attack occurred. Every detail in circulation, including every figure below, traces back to that single attacker-authored page.

Ransomware.live victim record for eAssist Dental Solutions showing the Direwolf group, a discovery date of September 6 2026, and an empty Data exfiltrated field
The tracker record for the listing. Note the Data exfiltrated field is blank, which is where a data volume would appear if the group had published one.

On September 8, eAssist notified its customers that it is investigating a potential information security incident and has engaged outside experts to assist with the investigation and response. The Georgia Dental Association published the substance of that notification on September 9. In it, eAssist says it has not confirmed that customer or patient information was accessed or compromised, that no specific records, credentials or patient data types have been verified as exposed, and that it will notify and provide guidance to affected parties as required based on what the investigation finds.

That is a meaningful change from the first days of this story, and it is worth reading precisely. Confirming an investigation is not the same as confirming a breach. What eAssist has acknowledged is the incident, not the attacker’s inventory.

What still has not happened matters just as much. Henry Schein has issued no public statement. No lawsuit has been filed, though several plaintiff firms have already opened investigations. And no independent party has verified the data the group says it holds.

None of that means the claim is false. It means the claim is unverified, and those are different things.

eAssist breach timeline: what has happened so far

Timeline of the eAssist breach claim: listed on the DireWolf leak site on September 6 2026, picked up by threat trackers and law firms on September 6 to 8, eAssist telling customers on September 8 that it is investigating, and what comes next being what the investigation finds
Dates are from the Ransomware.live record of the listing and from eAssist’s September 8 notification to customers as published by the Georgia Dental Association.

September 6, 2026. DireWolf published its eAssist listing, which Ransomware.live recorded at 16:55 UTC, together with the group’s own inventory of what it says it holds. Every figure in circulation comes from that one posting.

September 8, 2026. eAssist notified its customers that it is investigating a potential information security incident, engaged outside experts, and advised customers to change system passwords and remove old or inactive user accounts. It has not confirmed that customer or patient information was accessed.

Since then. Threat trackers indexed the listing within hours and plaintiff firms opened investigations, while the claim spread through dental groups on LinkedIn and Facebook, in one case with a count of affected offices that appears nowhere in the posting. Henry Schein has not commented publicly, and no independent party has verified the attacker’s data.

What comes next is the outcome of that investigation. If a breach is confirmed and eAssist was acting as your business associate, HIPAA requires it to notify you without unreasonable delay and no later than 60 days after discovery, and your agreement may set a shorter deadline. The formal clock can still run well past the news cycle, so plan for that gap rather than a quick resolution.

The numbers going around are the attacker’s numbers

You may have seen specific figures attached to this story: around 26 GB of data, 213 database tables, roughly 12.8 million database rows. Every one of those came from the attacker’s own posting, which lays out a database inventory in considerable detail.

Treat them accordingly. A leak site listing is an extortion tool, written to pressure a victim and advertise to buyers. Both goals reward inflation, and there is no independent confirmation of any of it.

One detail is worth knowing about where those numbers come from. The structured field where a data volume would normally appear on a tracker record is empty for this listing, which is why the trackers indexing it show no data size. The figures being repeated were read out of the body of the posting instead, where the group published its own overview and inventory of what it says it holds. The only source for the scale of this alleged theft is the party with the most to gain from making it sound large.

None of it changes what you should do. We tell the groups we work with to treat attacker figures as an unverified claim rather than a measurement, and to act on their own exposure instead, because your exposure is a fact you can establish today without anyone’s cooperation.

What the DireWolf listing says was taken from eAssist

The posting is organized as a database inventory, table by table, with row counts, and a snapshot of the leak site page is publicly mirrored for anyone who wants to read the original without visiting the dark web. Grouped into the categories a practice would care about, it reads like this. Every number is the attacker’s claim, a row is a database record rather than a person or a practice, and where a category spans several tables the row shows the one table a practice would care about.

What the listing says it holds Rows claimed Why it matters to a practice
Insurance portal logins 13,119 Login records for the carrier portals your claims flow through
Dental office records 10,343 Includes per-office practice software and remote access passwords, software serial numbers and network names
Software, device, cloud and access credentials 8,955 File transfer, cloud storage and local sync accounts that connect eAssist to client systems
EOB, claims and billing records 530,213 Insured and patient names, dates of birth, payer, procedure narratives and payment dates from 2001 to 2026
Provider onboarding records 22,871 Dentist names and email addresses collected when an office signed up
Accounting, AR, deposit and financial records 5,543,186 Per-office invoices, deposits, AR balances and scorecards

Those six rows come to roughly 6.1 million of the 12.8 million. Most of the rest is internal to eAssist: about 3.3 million rows of payroll and commission detail, 1.1 million rows of employee accounts and time records, 618,000 survey records, 535,000 archived emails and reports, 493,000 applicant and hiring records, 153,000 sales lead records covering prospect offices and their staff, and smaller sets of contracts, onboarding files and support tickets. The 12.8 million total is the attacker’s own figure.

Diagram of what the DireWolf ransomware group claims it took from eAssist Dental Solutions: 10,343 dental office records with software serials and remote access names, 13,119 insurance carrier portal logins, 22,871 dentists with names and email addresses, and claims and patient data including member names, dates of birth and procedures
These categories come from the attacker’s own inventory of what it says it holds. eAssist has not confirmed any of it.

The credential claims are the part that reaches your practice

The posting itself labels the credential vaults its top risk, and that is the right place to start regardless of who is saying it. The posting says the office master holds each office’s practice software password and remote access password, describes the portal logins as per-office logins for insurance carrier portals, and adds that the stored passwords sit behind an encryption scheme the group says it can reverse, with a handful it says are readable outright. A claim that it can decrypt them is not evidence that it has.

In plain terms: if the claim is accurate, a working login to your practice management software, your remote access tool and your payer portals may be in a criminal group’s hands. That is why credential rotation and multi-factor authentication lead the action list below, and why both are worth doing before anyone confirms anything.

The patient and claims data it describes

About 530,000 rows of EOB and claim records, which the posting says carry insured and patient names, dates of birth, the payer, procedure narratives and payment dates, plus roughly 258,000 rows of patient concern tickets, daily patient financial reports and work lists. This is the category a HIPAA breach analysis would turn on if the exposure is confirmed, and it is also the category most likely to reach a patient as a convincing phone call. One detail worth noting: the payment dates in those records run back to 2001, so the exposure the posting describes is not limited to recent claims.

What the listing says about eAssist’s own workforce

Payroll, commissions, employee accounts, applicant files with background check flags and banking details, and the email archives are serious for eAssist’s own workforce and do not reach into your systems directly, though a compromised vendor mailbox or employee identity can still be used to impersonate the vendor to its clients. One direct exception: the 153,000 rows of sales leads cover prospect offices and their staff, so an office that only ever took a sales call could still see targeted phishing that knows its name.

Who eAssist is, and why this vendor matters

eAssist sells outsourced dental billing and revenue cycle management: insurance claims, patient billing, insurance verification, credentialing. Henry Schein acquired a 70% ownership position in June 2021, and eAssist’s own website says it serves more than 3,000 dental practices.

A remote billing service cannot do its job without reaching into your systems. That typically means access to your practice management software, a route into your claims and patient ledgers, and credentials for the payer portals your claims flow through. The whole value of the service is that someone outside your building can work inside your systems.

That is why this claim is worth your attention even unconfirmed. The concern is not one company’s servers. It is that a billing vendor is, by design, holding keys to a lot of practices at once.

As for who DireWolf is, the short version is the part that matters to you. The group surfaced in May 2025 and runs a double extortion model, encrypting systems to disrupt operations and stealing data to threaten publication. Security firm Proven Data counted 127 claimed victims as of September 7, 2026, with healthcare the largest slice at 17%. That concentration is the signal worth keeping: healthcare data stays valuable for decades, downtime is expensive, and the industry increasingly routes its data through vendors who hold many organizations’ records in one place.

What should a dental practice that uses eAssist do now?

Here is the reframe that makes this manageable. You are not deciding whether the breach happened. You are deciding whether your exposure to that vendor is acceptable, and that is a question you can answer today with no help from anyone.

Every step below is worth doing regardless of how this particular claim resolves. That is the test we apply to any unconfirmed incident. Work that only pays off if the claim is true is a bet. Work that pays off either way was already overdue.

1. Write down what you actually send them

Most practices cannot answer this quickly, which is itself the finding. List what data leaves your practice for the vendor, what comes back, and how. Claims files, patient demographics, insurance details, ledgers, imaging attachments. Not what the contract says. What actually moves.

2. Find every way they can get in

Inventory the live connections: remote access into your practice management software, any interface between their platform and your systems, file transfer accounts, shared drives. Vendor access tends to accumulate quietly. Someone set it up during onboarding years ago and nobody has looked since.

3. Rotate the credentials attached to those pathways

Change the passwords tied to vendor access, especially any shared account. Coordinate it with the vendor and your own team first, because rotating a credential that an active integration depends on can interrupt claims work. Done in order it is one of the cheapest ways to close a path between a vendor compromise and your practice.

While you are in there, turn on multi-factor authentication for every vendor-facing account that can support it, rotate file transfer keys and integration tokens along with the passwords, sign out any active sessions and remembered devices, and confirm the vendor contact you hand new access to through a phone number you already had. Look hardest at remote support and remote desktop tools. The attacker’s inventory specifically names remote access passwords for individual offices, and that is the category that turns a vendor breach into a practice breach.

This is also where a lot of dental groups discover an uncomfortable arrangement they have been living with for years. Outsourced billing frequently runs on shared payer portal logins, one account and one password used by whoever is working the claim that day. Rotating that password is the small fix. The payer portal problem underneath it is the larger one, and several carriers will issue individual logins to your team if you ask.

4. Read your access logs

Look at vendor account activity for the last several months. Logins at odd hours, from unfamiliar locations, or pulling far more records than a billing task requires. You are looking for the shape of bulk data access, not a single suspicious login.

5. Cut access down to what the work requires

A biller working claims does not need administrative rights, every patient record in your database, or access that outlives the engagement. Most vendor accounts are over-permissioned because it was faster to grant broad access than to scope it properly.

6. Pull the agreement out of the drawer

Find the signed business associate agreement and read what it obligates the vendor to do when they have an incident, including how fast they must tell you. A signed agreement is not a security control, but it is the document that governs what happens next, and the worst time to read it for the first time is after a confirmation lands. Our guide to what HIPAA breach notification actually requires covers the deadlines that would apply to you.

7. Ask the vendor directly, in writing

Contact your eAssist representative and ask for a security update in writing. eAssist has directed customer questions about the incident to its chief operating officer, and its September 8 notification said it will notify and provide guidance to affected parties based on what the investigation finds. Ask to be told what that finding is for your practice specifically, and ask when. An active investigation and legal review genuinely do limit what a representative can say, so a partial answer is not evidence of bad faith. How promptly and clearly a vendor answers is still worth knowing before your next renewal conversation.

8. Tell your front desk what to expect

This one is standing hygiene rather than a response to this claim, and it is worth a two-minute huddle whenever any vendor breach is in the news. If patient details ever do circulate, the symptom that reaches your office is a convincing phone call: someone claiming to be from your practice or an insurer, armed with real information. Your team should know that a caller knowing a patient’s details does not make them legitimate. If this does become a confirmed incident, our guide on what to do after a breach walks through the sequence.

The vendor question this should actually raise

Do not let this end with eAssist. The reason an unconfirmed claim is worth this much attention is that a billing vendor sits in a position most dental groups have never risk-assessed: outside your walls, inside your systems, holding data for many practices at once.

You almost certainly have several vendors in that position. Your clearinghouse, your imaging platform, your patient communication tool, your analytics dashboard. Any of them could be next month’s leak site post, and the eight steps above would not change. It is why the biggest dental data breaches on record are mostly incidents at vendors and payers rather than at practice networks.

The groups that handle these weeks calmly are not the ones with better threat intelligence. They already know which vendors touch patient data, already scoped that access to the minimum, and already monitor for data leaving. For a DSO that work compounds, because vendor sprawl multiplies with every acquisition, and each practice you buy arrives with its own billing arrangement and its own uninventoried integrations. It is the difference between answering this question in an afternoon and spending three weeks discovering what you are connected to.

eAssist Data Breach FAQs

Has eAssist confirmed a data breach?

No. eAssist has confirmed something narrower: on September 8, 2026 it notified customers that it is investigating a potential information security incident and has engaged outside experts. It has not confirmed that customer or patient information was accessed or compromised, and it says no specific records, credentials or patient data types have been verified as exposed. Those are different claims, and the difference matters. A confirmed investigation is not a confirmed breach, and the Georgia Dental Association’s advisory on the notification tells practices not to assume a reportable HIPAA breach has occurred while the investigation runs. If your office received that notification directly, keep it.

What data was taken in the eAssist breach?

According to the attacker’s listing, and only according to it: insurance portal logins, per-office software and remote access credentials, EOB and claims records with patient details, provider onboarding files, and a large volume of eAssist’s own accounting, payroll and hiring data, about 12.8 million database rows in all. eAssist has not confirmed any of it. The categories that matter to a practice are the credentials and the claims data, covered above.

When did the eAssist breach happen?

The listing went up on September 6, 2026. Neither the attacker nor eAssist has said when the intrusion itself occurred, and leak site listings typically follow the intrusion by days or weeks, after a ransom demand goes unanswered. Treat September 6 as the date the claim became public, not the date of the breach.

Is eAssist owned by Henry Schein?

Yes, majority owned. Henry Schein announced on June 10, 2021 that it had acquired a 70% ownership position in eAssist Dental Solutions. eAssist continues to operate under its own brand.

Was patient data exposed in the eAssist breach?

There is no public, independently verified answer, and anyone stating one with confidence is guessing. eAssist’s own position as of September 8, 2026 is that it has not confirmed customer or patient information was accessed and that no specific records, credentials or patient data types have been verified as exposed. DireWolf’s listing describes roughly 530,000 EOB and claims records carrying patient names, dates of birth and payer details, but no independent source has confirmed that any of it exists, and the tracker record for the listing shows no data volume in the field where one would normally appear. eAssist handles claims and billing data for dental practices, so patient information is plainly within reach of its systems, but reach is not evidence. Treat the exposure as unconfirmed and act on your own access controls rather than on an assumption in either direction.

Should we terminate eAssist over this?

Not on the basis of an unconfirmed claim, and switching billing vendors mid-cycle carries its own operational risk. The proportionate response is to tighten and verify vendor access now, ask the vendor for a written update, and watch how they communicate. How a vendor responds to a public allegation is legitimate information for a renewal conversation later. A leak site listing on its own is not grounds for an emergency exit.

Do we have to notify patients about this?

Not on today’s facts. Notification obligations run from the discovery of a breach of unsecured protected health information, and right now there is no confirmed incident, no confirmed data set, and no notification from the vendor. If eAssist was acting as your business associate and later confirms a breach involving patient information it holds for you, it must notify you, and your own obligation to notify patients does not disappear because the incident happened on someone else’s systems. That is the moment to involve counsel, and the reason to locate your business associate agreement this week rather than that week.

How do I know if my practice was affected by the eAssist breach?

You cannot know yet. eAssist notified customers on September 8 that it is investigating, but no verified list of affected practices is public and the investigation has not established what, if anything, was exposed. What you can establish today is your own exposure: whether you send data to eAssist, what data that is, and what access their people and systems have inside yours. If a confirmation does come, that inventory is what turns a vague worry into a specific, answerable question.

How credible is DireWolf?

Credible enough to take seriously, not credible enough to quote. A group in this business has a reason not to invent victims outright, because a listing that gets publicly disproven costs it leverage on the next target. It has an equally clear reason to inflate the value of what it took, because that is the number doing the negotiating. Treat the fact of the listing as the signal and the inventory attached to it as marketing.

Work that list and whatever the investigation turns up, a confirmation or a denial or a long quiet stretch, is a news item rather than an emergency.

That is the work we do for the dental groups and DSOs we protect at Medix Dental IT. We map every vendor and integration that can reach patient data, scope that access down to what each role actually needs, and monitor for the credential abuse and bulk data access that can follow a vendor compromise. If you want a second set of eyes on how exposed your vendor chain makes you, a cybersecurity assessment is the place to start.

Posted in Dental Cybersecurity, News

Filter By: