eAssist Dental Solutions notified customers on September 8 that it is investigating a potential information security incident.
According to eAssist, outside experts have been engaged to assist with the investigation and response. The company is working to determine the nature and scope of the incident, including whether customer or patient information was affected.
At this time:
-
eAssist has confirmed that it is investigating a potential information security incident.
-
The investigation remains ongoing.
-
eAssist has not confirmed that customer or patient information was accessed or compromised.
-
No specific records, credentials, or patient data types have been verified as exposed.
-
eAssist stated that it will notify and provide guidance to affected parties as required based on the investigation’s findings.
-
The DireWolf ransomware group has separately listed eAssist on its extortion site and claimed access to the company’s internal systems. The details of that claim have not been independently verified.
Out of an abundance of caution, eAssist has advised customers to change system passwords and remove old or inactive user accounts associated with practice-management software, clearinghouses, claims software, and online portals.
|
|
|
-
Change practice management software passwords. Replace passwords for every account provided to or accessed by eAssist.
-
Change clearinghouse and claims software passwords. Update credentials for claims-processing platforms and related services.
-
Change insurance carrier portal passwords. Use completely new, unique passwords rather than variations of previous passwords.
-
Remove old or inactive accounts. Review accounts in your practice-management software, clearinghouses, claims applications, insurance portals, and remote-access platforms. Disable accounts that are no longer needed.
-
Secure remote access. Change remote-access credentials and remove any eAssist access that is no longer required.
-
Revoke active sessions and integrations. Changing a password may not terminate every active session or connection. Sign out active sessions and review saved credentials, third-party integrations, access tokens, and API keys where applicable.
-
Enable multifactor authentication. Require MFA wherever it is available, especially for email, remote access, insurance portals, clearinghouses, financial accounts, and administrative accounts.
-
Review account activity. Check recent login and access records for unfamiliar users, devices, locations, or activity. Preserve any suspicious logs or evidence before making additional changes.
-
Document your response. Record when your practice received the notification, which accounts eAssist could access, the credentials changed, the accounts disabled, and any suspicious activity identified.
-
Prepare for possible service interruptions. Identify time-sensitive claims, insurance verifications, payment postings, appeals, and follow-up work that may require internal attention during the investigation.
-
Alert your employees. Warn staff about potentially convincing phishing emails, calls, or text messages involving patients, claims, insurance carriers, billing activity, password resets, or requests to change payment information.
-
Contact your HIPAA compliance and cybersecurity partners. Ask them to help document the incident, review your practice’s exposure, and determine whether additional action is appropriate.
At this time, practices should not assume that a reportable HIPAA breach has occurred. That determination will depend on the findings of eAssist’s investigation and whether protected health information was accessed, acquired, used, or disclosed.
Practices should retain all communications from eAssist and consult their HIPAA compliance or legal advisors as additional facts become available.
eAssist directed customer questions to its Chief Operating Officer, Patrycja DeGradi, at patrycja.degradi@eassist.me.
Our endorsed managed IT services partner, TaaSPAK, is closely monitoring reports involving eAssist Dental Solutions and the DireWolf ransomware group to keep GDA members informed as the situation develops.
|
|
|