Techspedient

Techspedient Techspedient provides managed IT, cybersecurity, backups, and compliance-focused technology support for dental and healthcare practices.

We help protect your systems, your data, and your ability to keep seeing patients.

BREACH OF THE WEEKA dental practice in Connecticut went up on a ransomware leak site last weekend. The countdown on thei...
08/31/2026

BREACH OF THE WEEK

A dental practice in Connecticut went up on a ransomware leak site last weekend. The countdown on their page has run out.

I am not naming them. They are small, they are having the worst week of their career, and they do not need the traffic.

But here is what the criminals posted, because every owner should see it:

The whole patient database. Just over 8,000 files. Some records with Social Security numbers in them. Sample documents published publicly as proof. And a clock that has now expired, which means whatever that practice decided is decided.

The leak page lists their revenue at under $5 million a year.

Read that again. Eight thousand files. That is a one or two doctor office. Not a DSO.

Every time I say small practices get hit, someone tells me "we're too small to be a target." Small is not protection. Small is the reason.

No in-house IT, everybody sharing one login, a vendor who can dial into the server whenever he feels like it, and a backup nobody has ever tested. Two gigabytes walks out the door in minutes and nobody is watching.

The worst part is not the downtime. It is the Social Security numbers. That turns "we lost a day of production" into patient notification letters, state reporting, credit monitoring, and a permanent public listing your patients can look up.

Paying does not fix that. The data was copied before anything got locked. You cannot buy it back.

One thing from the comments on my last post, because it surprised a lot of people.

Two people who migrate practice management data for a living said the same thing independently: unencrypted databases sitting on practice servers are common. Not rare. Common. And the practice usually has no idea how easily that data can be pulled off their own machine.

Worth knowing the difference, though, because it is the part that trips owners up:

Full disk encryption protects a drive that leaves the building. Stolen laptop, old server going out the door. Once the server is on and running, it is doing nothing for you.

Database encryption is better. A copied file comes out unreadable.

Neither one does anything about someone already logged in with a valid password, pulling data the same way your software pulls it every day.

Encryption is the floor. Not the plan.

Five things you can do this week that cost nothing:

1. Multi-factor authentication on email, your PMS, and any remote access. Everyone, not just the doctor.

2. Get rid of shared logins. Every person gets their own.

3. Write down every vendor who can remote into your network, then find out which ones can get in without asking you first.

4. Actually restore a file from your backup and open it. A green checkmark is not a test.

5. Make sure your HIPAA Security Risk Analysis is current. OCR settled another ransomware case in June for $450,000 and the first thing they cited was not having one.

Last thing: please do not go hunting for the leaked files to see if anyone you know is in there. Leak sites can be dangerous. Don't.

Happy to answer questions in the comments. If anyone wants a second set of eyes on where their own practice stands, my inbox is open. 25 years in enterprise IT and Cybersecurity, CISSP, and I have helped walk more practices through this week than I would like to count

BREACH OF THE WEEKA ransomware crew posted four victims this week.An industrial engineering firm in Kansas. Two manufact...
08/09/2026

BREACH OF THE WEEK

A ransomware crew posted four victims this week.

An industrial engineering firm in Kansas. Two manufacturers overseas,

AND A PERIODONTAL PRACTICE.

Here's how their site works, and this is the part that should change how you think about ransom.

Every victim gets a price. The engineering firm's data is listed at $30,000. Someone can buy it. While it's for sale, the victim can still negotiate. Still pay. Still get it pulled.

Then there's a countdown.

When the countdown hits zero, the price disappears and the data goes free. Public. Download button. Anyone with a browser.

The practice's listing didn't have a price anymore.

It said FREE. 800 GB.

The description says patient medical documents, including imaging files. The doctor's own personal data.

No countdown left. No negotiation left. No decision left to make.

Whatever window that practice had, it closed before most of us heard the name.

Read the sequence again.

The demand was never "pay us or we publish."

It was "pay us before the clock runs out." And after that, by the attackers' own description, there's nothing left to buy back.

So, the practice that waits three weeks hoping it resolves itself doesn't get a worse deal. It gets no deal.

Now put your own operatory in that listing. Your imaging server. Your patient photos. Your treatment records.

The question isn't whether you'd pay. It's whether you'd know the timer was running at all. Most practices find out when a patient calls them.

🔒 BREACH OF THE WEEK: Dental is in the crosshairsHere’s what’s happening in dental right now, and it’s worth your two mi...
08/02/2026

đź”’ BREACH OF THE WEEK: Dental is in the crosshairs

Here’s what’s happening in dental right now, and it’s worth your two minutes.

This isn’t slowing down. Since last week, more dental practices have surfaced on ransomware leak sites across several different groups. (Pictures (redacted) of practices hit in the past week will be in the comments) The trend is unmistakable: attackers are working through dental as a category, not picking off one unlucky office.

Ransomware groups have shifted their aim. For years the big targets were hospitals and health systems. But the crews operating today figured out something: small and mid-size practices are softer, faster, and just as willing to pay when patient care is on the line.

The threat intelligence backs this up. INC Ransom, one of the most active groups of 2026, lists healthcare among its top target sectors, right alongside legal and professional services. And they’re not alone. Multiple newer groups are running the same playbook, get in, steal everything, threaten to publish, start a countdown clock.

Why dental specifically?

Think about what a practice holds. Patient records. Insurance data. Payment info. Imaging. And it all sits on top of the same software stack, Eaglesoft, Dentrix, Open Dental, Patterson, imaging bridges, running on networks often set up for convenience, not security. A practice is a data-rich target with, too often, a small-office defense.

The groups know this. They target the software you run every day because they know exactly what’s sitting behind it.

What the pattern looks like when a practice gets hit:

- Data stolen before anything is encrypted, so “we have backups” doesn’t save you from the leak
- A countdown timer and a threat to publish patient files publicly, notify regulators, and even patients.
- The stolen data sorted by what they found, patient forms, payroll folders, insurance materials, backups.
- HIPAA exposure that lands on the practice regardless of how the attackers got in.

What actually protects you, none of it is exotic

1. Detection, not just prevention. Antivirus stops known threats. It doesn’t catch an attacker already inside, moving toward your data. You need monitoring that sees the movement.
2. Backups the attacker can’t reach. If your backup is on the same network as the attack, it’s not a backup, it’s another casualty. Offline, tested, verified.
3. Least-privilege access. Not everyone needs everything. The fewer doors, the fewer an attacker can walk through.
4. Someone watching. The practices that get hit hardest are the ones where nobody was watching at 2 AM. Detection with no response is just a log nobody reads.

The uncomfortable truth, most practices won’t know they’re a target until they’re a victim. The ones who prepare now are the ones who stay out of the countdown.

Stay secure out there.

KNOW YOUR ENEMY: CRPxOHalf of everything this new group that came on the scene this month has listed is healthcare. Seve...
07/30/2026

KNOW YOUR ENEMY: CRPxO

Half of everything this new group that came on the scene this month has listed is healthcare. Seven of the twelve healthcare victims are Dental practices

They charge affiliates $333 to join.

One time. Not a subscription. Pay it, get a payload builder, keep 70% of whatever gets extorted. They handle the negotiation with the victim themselves.

No hacking experience required. Their own recruitment material says so.

So the person who hits your practice isn’t a genius in a basement. It’s someone who had $333 and access.

And when they get in, the threat isn’t just your files.

Researchers report this group threatens to report victims to HHS OCR and state Attorneys General directly. And notify your patients. And their insurers.

Pay us, or we call the regulator on you. That’s the business model now.

Here’s how they get in.

It’s called ClickFix.

Your front desk is on a website. A browser error pops up. Or a CAPTCHA. “Verify you are human.” The instructions say press Windows+R and paste this command.

The team member does it. Because it looks like every other fix they've been walked through.

No attachment. No link to hover over. No email at all.

Every phishing training you’ve ever paid for taught your team two things. Don’t open attachments. Check the link before you click.

This attack has neither.

The victim runs it themselves. Manually. Tuesday morning, between patients.

One more thing.

Researchers found this group left their own admin and database login pages exposed on the open internet. Wide open.

They’re not careful. They’re not sophisticated.

They don’t have to be. They just need one person who thinks they're fixing a browser.

Ask your team this week. If a website told you to paste a command to fix an error, would you?

You already know the answer.

04/27/2026

Most dental practices do not need more technology.

They need the technology they already have to be secure, reliable, documented, and properly supported.

That is where Techspedient comes in.

We help dental and healthcare practices with:

Managed IT support
Cybersecurity protection
Firewall and network security
Backup and disaster recovery
Microsoft 365 and Google Workspace security
Dental software and vendor coordination
HIPAA-focused technology guidance

The goal is simple.

Protect the practice. Secure the data. Keep the schedule moving.

04/26/2026

Techspedient Networks is now Techspedient.

Same leadership. Same commitment to service. Sharper focus.

We are continuing to help dental and healthcare practices protect their technology, secure patient data, reduce downtime, and defend against today’s cybersecurity threats.

The name is getting simpler, but the mission is getting stronger.

More focused. More secure. More aligned with where the industry is heading.

Welcome to Techspedient.

Address

710 Easton Avenue, Suite 1B
Somerset, NJ
08873

Alerts

Be the first to know and let us send you an email when Techspedient posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Techspedient:

Shortcuts

Share