Dental & Healthcare

eAssist Investigating a Potential Security Incident — What Georgia Dental Practices Should Do Now

eAssist is investigating a potential security incident after a DireWolf leak-site claim; PHI access not confirmed. What Georgia dental practices should do now on credentials, MFA, and BA hygiene.

If your practice uses eAssist Dental Solutions for billing or revenue-cycle work, this week’s news is for you — even if nothing is confirmed yet.

On or about September 6, 2026, the DireWolf ransomware group listed eAssist on its extortion site and claimed access to the company’s internal systems. Trackers logged the posting; the listing itself did not come with independently verified file samples, a confirmed data volume, or a patient count. Treat that claim as pressure until facts catch up.

What is confirmed: on September 8, eAssist notified customers that it is investigating a potential information security incident. Outside experts are involved. The company is still working to determine nature and scope — including whether customer or patient information was affected. As of the Georgia Dental Association’s September 9 advisory, eAssist has not confirmed that customer or patient information was accessed or compromised, and no specific records or data types have been verified as exposed. A reportable HIPAA breach is not automatic; that depends on what the investigation finds.

GDA flagged this because Georgia practices that outsource claims, insurance verification, and collections often sit downstream of the same billing BA. Rome and Northwest Georgia offices are in that mix. Your patients know your practice name — not the vendor’s dark-web listing.

What to do this week (without overreacting)

eAssist, out of an abundance of caution, advised customers to change system passwords and remove old or inactive user accounts tied to practice-management software, clearinghouses, claims tools, and online portals. GDA’s advisory (with partner guidance) is more specific. Prioritize:

  1. Rotate credentials eAssist could use — practice-management accounts, clearinghouse/claims logins, insurance portals, and remote access. Use new unique passwords, not slight variations.
  2. Disable stale accounts — anything unused in PMS, portals, or remote tools. Least privilege beats “we might need it later.”
  3. Kill lingering sessions and integrations — a password change does not always end every token, API key, or saved connection. Sign out active sessions and review integrations.
  4. Turn on MFA wherever it exists — email, remote access, portals, clearinghouses, admin accounts.
  5. Review recent access logs for unfamiliar users, devices, or locations. Preserve suspicious evidence before you overwrite it.
  6. Document everything — when you got notice, which accounts eAssist could reach, what you changed, and any odd activity. That file is your friend if scope expands.
  7. Watch for phishing — expect convincing emails or calls about claims, password resets, or payment changes. Verify out-of-band.
  8. Read your BAA — notification timelines, forensic cooperation, and who owns patient notices if PHI was involved. Ask eAssist for a written status if you have not received one.

Takeaway for IT decision-makers

Act on access hygiene now; wait for confirmed findings before assuming a reportable breach.

Billing and revenue-cycle vendors sit inside your HIPAA risk perimeter. You do not need a confirmed leak to rotate shared credentials, lock down remote access, and make sure your Business Associate Agreement is not a forgotten PDF. You do need discipline not to treat an unverified leak-site post as a finished investigation.

If you need help walking through credential rotation, MFA, logging, or BA documentation for a Georgia dental practice, Brotherly Technology can run that checklist with you — practical steps, not panic.

Sources: Georgia Dental Association, “Important Cybersecurity Advisory: Reported eAssist Ransomware Incident” (Sep 9, 2026); eAssist customer notice as summarized by GDA; MedRisk / ransomware.live reporting on the DireWolf listing (Sep 6, 2026). Status may change as eAssist’s investigation continues.

One accountable technology partner.

Tell us what's slowing your team down. We'll show you exactly how we'd fix it — no pressure, no jargon.

Book a Free Consultation
Book a Free Consultation