When a dental office opens remote desktop so a doctor can finish charts from home, that portal becomes the front door — whether anyone treats it that way or not.
Azle Cube Smiles PLLC, a general dentistry practice at 224 Park Place in Azle, Texas, disclosed a data breach to the Texas Attorney General on September 11, 2026. The practice notified affected patients by U.S. Mail and posted a notice on its website. According to the public summary, 2,940 Texas residents were affected.
The incident timeline that matters for every practice with after-hours remote access is straightforward. On May 26, 2026, the practice’s IT support company identified irregularities related to remote access session hosts. The team’s immediate focus shifted to locking down external access to the practice’s remote desktop web services and terminating external connections. That is a familiar playbook: something looked wrong on the session hosts, and the first containment move was to close the web-facing remote desktop path.
Information reported as potentially exposed included names, addresses, dates of birth, Social Security numbers, driver’s license and other government-issued ID numbers, financial information, medical information, and health insurance information — the mix of PII and PHI that makes a dental chart cabinet valuable to criminals. The practice is offering complimentary identity protection monitoring to affected patients; questions can go to the dedicated line at 844-473-3900.
Azle is Texas, not Floyd County. The pattern is not. Practices across Rome and Northwest Georgia still rely on Remote Desktop, RD Gateway, and browser-based remote desktop web services so dentists, hygienists, and billing staff can work after the waiting room closes. Those same pathways are a common entry point when credentials are weak, MFA is missing, or a session host is reachable from the open internet longer than anyone intended.
Clear takeaway
Treat remote access like the front door. Multi-factor authentication, locked-down web RDP, monitored session hosts, and least-privilege accounts are not “extra IT.” They are how you decide who gets a key — and how fast you change the locks when something looks wrong.
Actions this week
- Inventory every remote path. List RD Gateway, remote desktop web services, VPN, and any vendor remote tools. If you cannot name it, assume an attacker can find it.
- Require MFA on every remote and admin login. Password-only RDP is an unlocked door after hours.
- Lock down web RDP and session hosts. Restrict who can reach session hosts from outside; prefer VPN or tightly controlled gateways over open web portals; terminate stale external sessions.
- Apply least privilege. Dentists need chart access; they rarely need domain-admin rights on the same account they use from a home laptop.
- Watch the hosts. Alert on unusual remote session times, new external IPs, and failed logons against session hosts — the same class of irregularity IT support flagged at Azle Cube Smiles.
- Rehearse the first hour. Know who locks external remote access, who preserves logs, and who calls counsel or cyber insurance before patient mailings become the next headline.
Brotherly Technology works with dental and medical practices across Northwest Georgia on the unglamorous controls that keep remote care from becoming remote compromise: MFA, remote-access hardening, session-host monitoring, least privilege, and calm incident playbooks. If your office still has a web RDP portal you have not reviewed this quarter, treat Azle Cube Smiles as the reminder to walk that front door this week — not after the notice letter goes out.
Sources: