
Group Dentistry Now Show: The Voice of the DSO Industry
Dissecting a Cyberattack: Insights from a Real-Time Simulation — Dental Cyber Watch Live Episode 4
Defending a DSO against cybercriminals requires far more than robust cybersecurity—it demands proper insurance coverage and timely legal guidance. In Episode 4 of the Dental Cyber Watch Live podcast, Bill Neumann (CEO of Group Dentistry Now) hosts a cyberattack simulation with Gary Salman (CEO of Black Talon Security ), Carrie Millar (VP of Business Development at Dentist Insurance Services ), and Brittany Cambre (Partner at Grubman Warner Berry ). Together, the panel unpacks the complex operational, legal, and financial decisions dental organizations face when responding to a ransomware incident. The First 24 Hours : Why initial response decisions dictate long-term financial and legal risk. Legal Shielding : Establishing attorney-client privilege before internal missteps are documented. Cyber Insurance Pitfalls : Policy exclusions, coverage gaps, and where not to store your policy file. The Extortion Dilemma : Dark web negotiations, OFAC compliance checks, and the reality of 3-to-6-month recovery timelines. Industry News & Strategic Partnerships The episode opens with major industry developments, including a strategic partnership between Black Talon Security and Henry Schein One Tech Central . Through this alliance, Henry Schein One will deploy Black Talon's EAGLEi™ cyber risk management platform, providing automated vulnerability detection and remediation across dental networks. The panel also discusses recent security breaches targeting prominent organizations like 1-800-DENTIST and DentaQuest . These incidents reinforce a stark reality: cybercriminals indiscriminately target dental entities of all sizes. Salman references recent comments from Palo Alto Networks' CEO highlighting the vulnerability of dental and medical infrastructure, emphasizing that healthcare represents one of the nation's highest-risk sectors. The First 24 Hours, Evidence Preservation, and Legal Privilege In the simulation, a practice manager discovers a ransom note on a Monday morning. Initial reactions often involve IT attempting quick fixes—a mistake that can destroy digital evidence or overwrite firewall logs critical to proving whether Protected Health Information (PHI) was exfiltrated. Cambre emphasizes bringing in data privacy counsel immediately within the first 24 hours to cloak forensic investigations and internal discussions under attorney-client privilege: "A lot of things are said in the heat of the moment that you wish were never reduced to writing... 'We didn't do X, Y, or Z,' or 'This was done incorrectly and now we are facing the consequences of that.' All of that stuff becomes fodder for plaintiff's attorneys to be like, 'See, you knew you did something wrong.'" — Brittany Cambre Insurance Strategy & Coverage Gaps Millar notes that only 30% to 40% of dental practices carry standalone comprehensive cyber insurance, with many relying on basic malpractice endorsements that lack third-party liability or extortion coverage. She also cautions practices against storing policy documents on their local network: "When we set the policies up, we say to people, 'Please do not save your cyber insurance policy on your computer,' because that's one of the first things that the hackers will look for. If they know your policy limits, that's exactly what they're going to ask for first." — Carrie Millar Furthermore, Millar cautions that a policy limit acts as "one bag of money" shared across forensic investigations, extortion payments, and subsequent legal defense. Without realizing how costly even a small cyberattack can be, organizations routinely operate under a false sense of security, discovering too late that their coverage falls far short. Check out this Group Dentistry Now article by Carrie Millar for more insights: Commercial Insurance Loss Trends in the Dental Industry Extortion, Compliance, and Class-Action Lawsuits When backups are encrypted, organizations are forced to negotiate ransom demands on the dark web. Cambre highlights that counsel uses negotiations as a stall tactic to gather "proof of life" (verifying stolen data) while completing Office of Foreign Assets Control (OFAC) checks to ensure funds do not go to sanctioned entities. Even after paying or receiving decryption keys, recovery is rarely instantaneous. Wiping infected workstations, rebuilding servers, and re-integrating practice management, imaging, and revenue cycle software takes significant time: "It's not a two or three week problem... In many of these cases, there's tremendous pain for three to six months. It's just the reality of it." — Gary Salman Cambre adds that class-action lawsuits are filed with "near mechanical regularity" following public breach reports on regulatory portals. Salman concludes that executive leadership—not just IT vendors—must maintain active visibility into cyber risks, maintain an incident response plan, and test security controls regularly. The Path to Cyber Resilience To safeguard their future, DSO leadership must pivot from reactive IT maintenance to proactive, board-level risk management. True resilience requires a unified strategy, leveraging real-time security metrics and robust prevention controls while maintaining comprehensive cyber insurance and pre-established legal counsel to ensure the organization is prepared to navigate the complexities of the modern threat landscape. If you're unsure of where your organization stands today, schedule a cyber risk review . Introducing ONIX Alliance, Healthcare Technology Leaders Exchange ONIX Alliance allows healthcare technology executives from single practices to massive multi-site health systems to knowledge share on what works within their organizations regarding AI deployment, cybersecurity defenses, cloud infrastructure, and the challenges of managing complex EHR platforms. Read the press release to learn more. DSO leaders can express interest in joining the community by visiting onixalliance.org . Thank you to our guest panelists: Carrie Millar , VP of Business Development, Dentist Insurance Services Carrie Millar is a self-proclaimed insurance nerd who somehow convinced people that reading insurance policies for fun is a perfectly normal career. With more than 20 years of experience helping dental practices manage risk, she loves turning confusing insurance language into plain English and helping clients sleep a little better at night. She is part of the leadership team at Dentist Insurance Services/FDA Services, a boutique insurance agency specializing exclusively in the dental industry. The agency focuses on serving dental practices, multi-location groups, and DSOs across the country and is proud to be the self-proclaimed nation's largest insurance brokers dedicated exclusively to dental practices. Brittany Cambre , Partner, Grubman Warner Berry Brittany Cambre advises healthcare providers and organizations on HIPAA compliance and data privacy matters, with a particular focus on breach and incident response. She regularly assists clients in responding to cybersecurity incidents and data breaches, guiding them through regulatory notification requirements, government and internal investigations, and potential litigation. Her approach emphasizes rapid response, risk mitigation, and practical solutions that allow healthcare organizations to continue operations while addressing regulatory and enforcement concerns. Grubman Warner Berry is a full-service litigation firm that is uniquely positioned to assist clients from small "mom & pop" businesses to Fortune 500 companies and everyone in between. Recent notable healthcare cyber incidents: Cure Dental Data Breach Impacts Current and Former Patients: PII Exposed . Cure Dental , a dental practice located in Belton, Texas, disclosed a data breach that affected 878 individuals in the United States. The practice, which describes itself as dedicated to providing excellent dental care in a comfortable setting, discovered the breach on June 25, 2025. On Aug. 10, 2025, a ransomware group known as ThreeAM claimed responsibility for the attack. The group posted on the Tor network, claiming to have obtained data from the dental practice. Soniva Dental Care Data Breach Affects at least 30,000 Texans . Soniva Dental Care , a multi-location dental practice with 14 locations in the United States, disclosed a data breach after a ransomware attack was discovered in late May 2026. On June 1, 2026, six days after the breach was discovered, a ransomware group known as The Gentlemen claimed responsibility for the attack. The claim was posted on a dark web forum hosted on the Tor network. The group stated that it had obtained the organization's data and intended to publish the information within nine to 10 days. As of July 28, 2026, the ransomware group indicated the full dataset has been made publicly available and includes additional information types like patients' Social Security numbers. Dental Cyber Watch is sponsored by Black Talon Security, the recognized cybersecurity leader in the dental/DSO industry and a proud partner of Group Dentistry Now . With deep roots within the dental and dental specialty segments, Black Talon understands the unique needs that DSOs and dental groups have when it comes to securing patient and other sensitive data from hackers. Black Talon's mission is to protect all businesses from the devastating effects caused by cyberattacks—and that begins with a robust cyber risk mitigation strategy. To evaluate your group's current security posture visit www.blacktalonsecurity.com .

