Tuesday, September 22, 2026

eAssist Suffers Ransomeware attack from group Direwolf

 


I haven't heard of a bad ransomware attack for a bit, but maybe that's because I haven't been looking hard enough.  Sometimes the news of a small practice suffering a hack doesn't make it to the major news sources.  However, when a company the size of eAssist does, it definitely makes news.

From what I can discern, on September 6, 2025 eAssist was hacked by a ransomware group calling itself DireWolf.  In case you haven't heard of eAssist, they are a company that allows doctors to outsource their billing, freeing the admin team up for other duties.  They are also majority owned by Henry Schein.

This is, or course, the second big cyber incident that Henry Schein has had to deal with.  You may well remember that in the fall of 2023 Henry Schein was hit by a *major* cyber attack that took their systems offline for several weeks.  It ended up affecting 166.000 individuals.  The company kept a pretty tide public lid on that event and even now, not much is known about it.  I suppose it would be helpful for the company to have already been through something like this before, to help them deal with the current situation.

I want to be clear in this post... I am NOT denigrating Henry Schein or eAssist here.  In the cyber realm all you can do is to try and lock things down as best you can.  There are sometimes ways these attacks unfold that even the best IT security people couldn't have foreseen.  If you are an eAssist customer, odds are that you have already been contacted by them regarding this, but on the odd chance you didn't know yet, you do now.

As far as what customers need to do...

I big salute to the Georgia Dental Association!  They have a put a great page together about this incident.  You can read their page here, but I've also put the contents of that page below so that you can read it here.

eAssist Dental Solutions notified customers on September 8 that it is investigating a potential information security incident.

According to eAssist, outside experts have been engaged to assist with the investigation and response. The company is working to determine the nature and scope of the incident, including whether customer or patient information was affected.

At this time:

  • eAssist has confirmed that it is investigating a potential information security incident.
  • The investigation remains ongoing.
  • eAssist has not confirmed that customer or patient information was accessed or compromised.
  • No specific records, credentials, or patient data types have been verified as exposed.
  • eAssist stated that it will notify and provide guidance to affected parties as required based on the investigation’s findings.
  • The DireWolf ransomware group has separately listed eAssist on its extortion site and claimed access to the company’s internal systems. The details of that claim have not been independently verified.

Out of an abundance of caution, eAssist has advised customers to change system passwords and remove old or inactive user accounts associated with practice-management software, clearinghouses, claims software, and online portals.

TaaSPAK recommends that practices currently using eAssist take the following actions:

  1. Change practice management software passwords. Replace passwords for every account provided to or accessed by eAssist.
  2. Change clearinghouse and claims software passwords. Update credentials for claims-processing platforms and related services.
  3. Change insurance carrier portal passwords. Use completely new, unique passwords rather than variations of previous passwords.
  4. Remove old or inactive accounts. Review accounts in your practice-management software, clearinghouses, claims applications, insurance portals, and remote-access platforms. Disable accounts that are no longer needed.
  5. Secure remote access. Change remote-access credentials and remove any eAssist access that is no longer required.
  6. Revoke active sessions and integrations. Changing a password may not terminate every active session or connection. Sign out active sessions and review saved credentials, third-party integrations, access tokens, and API keys where applicable.
  7. Enable multifactor authentication. Require MFA wherever it is available, especially for email, remote access, insurance portals, clearinghouses, financial accounts, and administrative accounts.
  8. Review account activity. Check recent login and access records for unfamiliar users, devices, locations, or activity. Preserve any suspicious logs or evidence before making additional changes.
  9. Document your response. Record when your practice received the notification, which accounts eAssist could access, the credentials changed, the accounts disabled, and any suspicious activity identified.
  10. Prepare for possible service interruptions. Identify time-sensitive claims, insurance verifications, payment postings, appeals, and follow-up work that may require internal attention during the investigation.
  11. Alert your employees. Warn staff about potentially convincing phishing emails, calls, or text messages involving patients, claims, insurance carriers, billing activity, password resets, or requests to change payment information.
  12. Contact your HIPAA compliance and cybersecurity partners. Ask them to help document the incident, review your practice’s exposure, and determine whether additional action is appropriate.

At this time, practices should not assume that a reportable HIPAA breach has occurred. That determination will depend on the findings of eAssist’s investigation and whether protected health information was accessed, acquired, used, or disclosed.

Practices should retain all communications from eAssist and consult their HIPAA compliance or legal advisors as additional facts become available.

eAssist directed customer questions to its Chief Operating Officer, Patrycja DeGradi, at patrycja.degradi@eassist.me.

Our endorsed managed IT services partner, TaaSPAK, is closely monitoring reports involving eAssist Dental Solutions and the DireWolf ransomware group to keep GDA members informed as the situation develops.

This is obviously a developing story.  If I get any more information on this, I will post more.  At this point *I highly recommend reach out to eAssit for further instructions on how your office should handle this situation.

 

No comments:

Post a Comment