Ask a dental practice about cybersecurity and most people picture a locked-down server room, or something the IT vendor handles once a year. But for a dental office, the actual exposure isn't the server room — it's the billing workflow. Every claim that goes out and every EOB that comes back carries protected health information, and that data moves through more hands, more logins, and more inboxes than almost anything else the practice touches.
Dental practices are also, structurally, a soft target. A hospital system has a security team. A single-location practice has a front desk and maybe an outsourced IT contact. Attackers know this, which is exactly why healthcare — and dental specifically — shows up disproportionately in breach reports relative to the size of the businesses involved.
Written by John Moses, founder of Dental Claim Professionals, whose team handles claims, EOBs, and PHI across dozens of practices every week.
Why billing is the real exposure point
Clinical records mostly stay inside the practice management system, behind whatever access controls the office set up. Billing data doesn't stay put. It gets checked against eligibility portals, submitted to a clearinghouse, returned as an EOB or ERA, emailed to a biller working from home, exported to a spreadsheet for an aging report, and sometimes forwarded to a specialist's office for a referral. Every one of those handoffs is a place where a password, an attachment, or a login can be the weak link.
That's the practical reason dental billing deserves its own conversation about security, separate from "cybersecurity" as a general IT topic. The risk isn't abstract — it's tied to specific, everyday steps in getting a claim paid.
Five places PHI actually leaks in a normal billing week
Shared logins with no second factor. It's common for an entire front office to use one login for the clearinghouse portal or practice management system, because setting up individual accounts feels like extra work. The problem is that a shared password is also a shared point of failure — one phishing email, one reused password from a breached shopping site, and whoever has it can see every patient's insurance ID, date of birth, and claim history.
PHI sent as a plain email attachment. A chart note, a claim form, or an EOB with a patient's SSN gets emailed to a specialist's office or an outsourced biller because it's the fastest option, not because anyone checked whether it's encrypted in transit. Standard email isn't secure by default, and once that attachment leaves the practice's inbox, there's no way to control where it ends up.
Clearinghouse and vendor breaches. Practices don't have to be breached directly to be affected. Claims data for thousands of dental and medical offices routes through a small number of clearinghouses, so a single vendor-side breach can expose data from practices that never had a security incident of their own. The 2024 Change Healthcare breach is the clearest recent example — a single clearinghouse compromise disrupted claims and payments for practices nationwide, dental included, none of whom had done anything wrong themselves.
Payment redirect and business email compromise scams. A fake email claiming to be from a carrier or clearinghouse asks the practice to "update" its EFT or ACH deposit information. If billing staff make the change without calling a known number to verify, insurance payments start landing in the attacker's account instead of the practice's — sometimes for weeks before anyone notices the deposits stopped.
Old data sitting around unencrypted. Aging reports exported to Excel for a meeting, PDF copies of EOBs saved to a desktop "just in case," patient rosters kept in an old spreadsheet from a software migration years ago — none of it gets cleaned up, and all of it is PHI sitting outside any access control the practice actually manages.
Why dental specifically, and why now
Dental billing data is attractive for the same reason any healthcare billing data is: it bundles identity information (name, SSN, date of birth) with insurance details in a single record, which is more valuable on the black market than a stolen credit card number alone. But dental practices add a second factor — most are small businesses without a dedicated security function, running on whatever practice management vendor they picked years ago and whatever habits the front desk built up over time.
Ransomware operators specifically target this combination: valuable data, low defenses. A practice that can't access its own patient and billing records for a week isn't just inconvenienced — it can't submit claims, can't verify eligibility, and can't post payments, which means real revenue stops moving until the system is restored or the ransom is paid.
What a secure billing process actually looks like
None of this requires an enterprise security budget. The practices that stay out of trouble tend to get a short list of things right, consistently:
- Multi-factor authentication everywhere it's offered — the practice management system, the clearinghouse portal, and email, at minimum. This single change stops the majority of account-takeover attempts cold.
- Individual logins for every staff member, not one shared account. It's the only way to know who did what, and to shut off access for a single person without resetting a password everyone relies on.
- A secure channel for PHI — an encrypted portal or secure file transfer, not a plain email attachment — for anything containing a patient's insurance ID, SSN, or clinical detail.
- A verification habit for any payment or banking change request, meaning a callback to a known number before updating EFT or ACH details, no matter how legitimate the email looks.
- A signed Business Associate Agreement with every vendor and outsourced partner that touches PHI, including a billing company, along with a clear answer to "where does our data actually live and who can see it."
- A routine for retiring old exports and files, so aging reports and EOB PDFs don't quietly accumulate in places nobody is monitoring.
Most of this is process, not technology — which is exactly why it's achievable for a practice without an IT department. See our insurance and billing services for how we build these safeguards into day-to-day billing work.
Does outsourcing billing help or hurt?
It genuinely depends on the vendor. Handing billing to an outside team without a BAA, without MFA on their side, and without a clear answer about data handling adds risk on top of whatever the practice already has. But a billing partner that treats security as part of the job — individual access controls, a signed BAA, encrypted handling of PHI, and a documented process for exceptions like payment redirects — can actually reduce a practice's exposure compared to an in-house process built on shared logins and habit.
The honest question to ask any billing vendor isn't "do you have security" — everyone will say yes. It's "walk me through exactly how a claim, an EOB, and a payment move through your systems, and who can see them at each step." If the answer is vague, that's the answer.
Frequently asked questions
Is dental billing data covered by HIPAA?
Yes. Claims, EOBs, eligibility responses, and payment records all contain protected health information — diagnosis and procedure codes, dates of service, and insurance identifiers tied to a named patient. Anyone who creates, receives, or transmits that data on a practice's behalf, including an outsourced billing team, is a business associate under HIPAA and needs a signed Business Associate Agreement (BAA).
Why would anyone target a small dental office instead of a hospital?
Small practices carry the same valuable data — SSNs, insurance IDs, dates of birth — with far less security staff and budget to defend it. Attackers also know a single clearinghouse or practice management vendor breach can expose claims data from thousands of small practices at once, which makes the whole dental billing ecosystem an efficient target.
What is a business email compromise scam in dental billing?
It's when an attacker impersonates an insurance carrier, clearinghouse, or vendor by email and asks the practice to update EFT or ACH deposit information. If billing staff make the change without verifying it through a known phone number, insurance payments get redirected to the attacker's account instead of the practice's.
Does outsourcing billing increase or reduce cybersecurity risk?
It depends entirely on the vendor. Outsourcing to a billing partner without a signed BAA, without MFA on their systems, or without a clear data-handling process adds risk. Outsourcing to a partner with documented security practices, restricted access, and a BAA in place can actually reduce risk compared to an in-house team relying on shared logins and ad hoc email.
What's the single highest-impact change a practice can make?
Turn on multi-factor authentication for the practice management system, the clearinghouse portal, and email, and give every staff member their own login instead of a shared one. Most breaches in small healthcare offices trace back to a compromised password with no second factor to stop it.
Billing handled by a team that treats PHI like PHI
Dental Claim Professionals works inside your existing practice management system — Open Dental, Dentrix, Eaglesoft, Denticon, or Softdent — with individual access controls, a signed BAA, and a documented process for every claim, EOB, and payment we touch.
Book a Free Consultation