FBI Warning to Dental Practices: What the Ransomware Threat Means and How to Respond

On May 6, 2024, the FBI informed the American Dental Association (ADA) and the American Association of Oral and Maxillofacial Surgeons (AAOMS) of a credible cybersecurity threat aimed specifically at oral and maxillofacial surgery practices. At the time of the alert there were no known victims — the FBI was moving proactively, trying to get ahead of the group before it started collecting practices.

That’s an unusual thing for a federal agency to do. It means the intelligence was specific enough to be worth acting on before anyone had been hit.

And the part most practice owners skimmed past matters more than the headline: the FBI said it was concerned that general dentists and other specialists could eventually be targeted too. If you own a general practice and read that alert as “a surgery problem,” you read it wrong. The warning was a preview.

This guide walks through what the alert actually said, why dental offices sit in the crosshairs, how the attack starts (it is not what most owners picture), and what a practice owner can realistically do about it — before someone calls your front desk pretending to be a new patient.

What the FBI actually told the ADA and AAOMS

Strip away the commentary and the alert contains four concrete pieces of information.

One: the threat was credible and current. The FBI didn’t describe a general trend. It described an active threat actor with dental practices in its sights.

Two: the group appears to have moved down-market from another specialty. The FBI suspects the group behind these attacks may be shifting tactics to oral and maxillofacial surgery practices after targeting plastic surgeons the prior year. That’s the detail that should get your attention. This is a crew that picks a specialty, works it, and then moves to the next one with a similar profile: high-value patient data, meaningful revenue, and a small back office.

Three: the entry point is social engineering, not hacking. The FBI named the methods explicitly — phishing (email), SMSishing or smishing (text and instant-messaging apps), and vishing (phone calls and voicemail). It also called out spear phishing: a phishing email crafted to appear to come from a trusted contact, such as a threat actor impersonating a credentialing agency.

Four: the FBI gave a specific playbook the group uses. This is the part worth reading twice, because it is designed precisely to defeat a well-trained, helpful front desk:

The threat actor poses as a new patient, or says they want to become a patient at the practice, in order to obtain new patient forms online. Once they have the forms, they contact the practice to report that they’re having trouble submitting them online, and ask if they can scan the forms and email them instead. The threat actor then emails the “forms” as an attachment. When the attachment is opened, malware is deployed. That malware can lead to ransomware — blocking access to your systems and files until money is paid.

Read that scenario from your front desk coordinator’s chair. A prospective patient calls. They’re polite. They already have your new-patient forms — the ones on your own website — so they’re clearly legitimate. They’re having a technology problem, which happens constantly. They ask to email a scan instead. Your team member says yes, because saying yes to that request is their job.

There is no suspicious link, no misspelled domain, no Nigerian prince. There is a helpful person doing the thing you hired them to do.

The FBI asked dental practices experiencing fraudulent or suspicious activity to report it to the Internet Crime Complaint Center at ic3.gov.

Why dental practices are attractive ransomware targets

Owners often assume they’re too small to be worth a criminal’s time. The economics say the opposite, for four reasons.

The data is valuable and concentrated. A dental practice stores electronic protected health information (ePHI), demographic and identity data, insurance details, financial records, and employee data — all in one place, usually in one practice-management database.

Security maturity is perceived as lower than at a hospital. Criminals target dental offices in part because of perceived gaps in security compared with larger healthcare organizations. Fewer defenses, fewer people watching, no in-house security staff. That perception is often accurate, and it’s not a knock on owners — it’s a resourcing reality.

Downtime pressure is enormous. Your practice-management system is your business. When Dentrix, Eaglesoft, or Open Dental won’t open, you can’t check schedules, can’t verify eligibility, can’t chart, can’t bill. Attackers know that dental offices facing a stopped schedule feel real pressure to pay quickly to get moving again.

One employee is enough. Attackers don’t need to defeat your firewall. They need one person to open one attachment. In an office of eight to fifteen people who answer the phone all day and are rewarded for being accommodating, that’s a favorable bet.

Put those together and a two-to-six-operatory practice isn’t a small target. It’s an efficient one.

How the attack starts: phishing, smishing, vishing, and your front desk

The most useful mental shift a practice owner can make is this: the attack doesn’t begin at your network perimeter. It begins with a conversation.

The FBI named four flavors of that conversation.

Phishing — email. An attachment that isn’t what it claims to be, or a link to a page that harvests a login. The “new patient forms” scenario the FBI described is a phishing attack wrapped in a totally plausible business interaction.

Smishing — text messages and instant-messaging apps. Increasingly effective because staff read texts on personal phones, outside any filtering your practice has in place, and often in a hurry between patients.

Vishing — phone calls and voicemail. Someone calls claiming to be from your software vendor, your imaging support line, or your bank, and walks a team member into giving up a credential or approving a login prompt.

Spear phishing — any of the above, but personalized and made to look like it’s from a trusted contact. The FBI’s example was impersonating a credentialing agency. Others write themselves: your practice-management vendor, your insurance clearinghouse, your dental board, a referring specialist.

Notice that a firewall stops none of this. Antivirus catches some of it, sometimes, after the fact. The controls that actually reduce this risk are people-and-process controls layered with technical ones:

  • Staff who have been trained on this specific scenario — not “don’t click suspicious links,” but “here is how the new-patient-forms scam works and here’s what we do instead.”
  • A defined, documented alternative path for receiving patient forms that doesn’t involve opening unverified email attachments.
  • Multifactor authentication so a stolen password isn’t a stolen practice.
  • Email filtering, endpoint protection that catches malicious attachments, and prompt patching.
  • A no-blame reporting culture, so the person who did open the attachment tells you in the first five minutes instead of the next morning.

CISA’s guidance for practices in this position is short and unglamorous: teach your team to recognize and avoid phishing, require strong passwords, require multifactor authentication, and keep all business software updated. HHS also publishes free cybersecurity trainings aligned to the top threats facing the health sector, and the Office of the National Coordinator offers a Security Risk Assessment Tool built for small and medium providers.

Those resources are real and worth using. What they can’t do is tell you whether your environment is actually configured the way you assume it is.

Ransomware is a two-front crisis: your operations and your HIPAA obligations

Here’s where most practice planning stops short. Owners picture ransomware as an IT outage: bad week, restore from backup, move on. It’s actually two simultaneous emergencies, and the second one lasts far longer than the first.

Front one: business continuity. Schedule down. Charting down. Imaging possibly down. Eligibility checks down. Claims not going out, so revenue stops arriving weeks later even after you’re back up. Staff standing around being paid. Patients rescheduling, some of whom don’t come back. If your backups weren’t tested, or if the backup was reachable from the same network the ransomware encrypted, “restore from backup” becomes a theory rather than a plan.

Front two: regulatory and legal. If you submit claims electronically, check eligibility online, or send statements through a clearinghouse, HIPAA considers your practice a covered entity — and the Security Rule applies in full, not a lighter version because you’re small. A ransomware event that touches ePHI is presumptively a reportable breach, which pulls you into notification obligations to affected individuals and to HHS. Separately, every U.S. state has a data-breach-notification law; state law requires timely notification to affected individuals and often to regulators, regardless of your industry. The exact windows and thresholds vary — your attorney can confirm your state’s specific notification deadline.

And once a breach is reported, an investigation may follow. When the HHS Office for Civil Rights (OCR) opens one, the first document requested isn’t your firewall model. It’s your risk analysis — the written, accurate, thorough assessment of risks to the ePHI your practice creates, receives, stores, and transmits. It’s required under 45 CFR 164.308(a)(1)(ii)(A), and it is the single most-cited deficiency in OCR enforcement, year after year. “We never got around to it” reads, to a regulator, as evidence you never understood your own risk. We break the full requirement down in our guide to what the HIPAA Security Rule actually requires of dental practices in 2026.

Then there’s the cost side, which extends well past any ransom: regulatory exposure, notification and credit-monitoring costs, legal fees, lost productivity and revenue, and reputational damage in a community where word travels fast. In a small town or a tight referral network, the last one can outlast all the others.

The gap most practices have — and why “our IT person has it” fails here

The most expensive assumption we hear from dental owners is “our IT person has HIPAA handled.”

They don’t, and it isn’t their job to. The Security Rule places the obligation on you, the covered entity — not your software vendor, not your IT company. A generalist IT provider can fix your printer, patch your workstations, and keep a firewall running. What a generalist usually can’t tell you is whether your backups would actually restore your practice-management database after a ransomware attack, whether your imaging system logs who accessed what, or whether you have the one written document a regulator asks for first.

Against the FBI’s specific threat, the gap shows up in three places:

1. Nobody has trained the front desk on this attack. Generic annual “don’t click links” training doesn’t inoculate anyone against a polite prospective patient with a scanner problem. Workforce security awareness training is an explicit administrative safeguard under the Security Rule (164.308(a)(5)) — and “we talked about it at a staff meeting once” isn’t documentation.

2. Backups exist but have never been restore-tested. Regular, verified backups are the single control that most reliably takes the ransom decision off the table — you can wipe a machine, reinstall, restore, and get running again without paying. But a backup nobody has tested is a hope, not a control. Across the dental practices we support, workstation and remote-support issues are the highest-volume ticket categories month over month; silent backup failures hide comfortably inside that noise.

3. There’s no written risk analysis, incident response plan, or vendor paper trail. Every outside company that touches your ePHI — practice-management vendor, cloud backup provider, imaging platform, your IT company — is a business associate requiring a signed business associate agreement. When a vendor causes a breach and you can’t produce the BAA, OCR treats it as your compliance failure, not just theirs. We wrote about exactly that scenario in our piece on a dental practice-management software breach and why the HIPAA duty still lands on your practice.

The pattern is consistent: the technical work may be getting done, but the documented compliance work — the part that determines your position after an incident — was never part of the job you hired anyone to do.

A practical response plan: what to do before you’re targeted

None of this requires panic. It requires a short list of specific actions, in order.

Brief your team on the actual scam, this week. Read the FBI’s new-patient-forms scenario aloud at a staff meeting. Then decide, out loud, what your practice does instead — a secure patient-forms portal, a required callback to a number your team looks up independently, or a rule that unexpected email attachments from unknown senders never get opened on a workstation with practice-management access. Write the decision down. That’s both risk reduction and Security Rule documentation.

Turn on multifactor authentication everywhere it’s available. Email first, then remote access, then your practice-management and imaging platforms if they support it. MFA is the single control that turns a stolen credential from a catastrophe into an annoyance.

Verify your backups by restoring one. Not “check that the job says success.” Actually restore a database to a test environment and confirm it opens. Keep multiple copies, including at least one offsite or cloud copy that ransomware on your network can’t reach or encrypt. Then schedule that test to repeat.

Patch on a schedule, not on a whim. Operating systems, practice-management software, imaging drivers, antivirus, firewall firmware. Attackers routinely exploit known vulnerabilities in outdated software; automatic updates close most of that window for free.

Lock down remote access. If you have multiple locations or anyone works remotely, use a VPN rather than exposing remote-desktop or database ports directly to the internet. Open ports get port-scanned by people looking for exactly that.

Give every user their own login. No shared “frontdesk” account. Unique logins and audit controls are technical safeguards under the Security Rule (164.312) — and after an incident, they’re the only way to reconstruct what actually happened.

Write the incident response plan before you need it. One page is fine to start: who gets called first, who disconnects what from the network, who contacts your cyber carrier, who contacts counsel, who talks to patients, and how you keep seeing patients on paper for 48 hours. The middle of an attack is the worst possible time to invent this.

Get a current, written risk analysis. This is the anchor. It’s the document that tells you where your real exposure is — and it’s the first thing requested when an investigation opens. It is not a checklist a vendor emails you; it’s a documented look at every place ePHI actually lives, with an honest evaluation of what could go wrong.

Report suspicious contacts. If someone runs the new-patient-forms play on your office, report it at ic3.gov. Your report is what lets the next practice get warned.

How REAL Cyber closes the gap

REAL Cyber is a veteran-owned cybersecurity and compliance MSP built for practices your size. We do the technical work and produce the paper trail — because in HIPAA, the paper trail is the compliance.

For a dental practice reacting to the FBI’s warning, that looks like:

  • A written HIPAA risk analysis covering your practice-management database, imaging system, email, backups, mobile devices, and every workstation — plus the risk management plan that follows from it.
  • Security awareness training built around the attacks actually aimed at dental offices, including phishing, smishing, vishing, and spear-phishing simulations against your real staff, with documented completion records.
  • Backup design and verified restore testing so “we’ll restore from backup” is a demonstrated fact rather than an assumption.
  • Endpoint protection, MFA rollout, patching, and monitoring across the systems your day depends on.
  • Business associate agreement review so you know which vendors need one and you can produce them on demand.
  • Incident response planning — the written playbook, and someone to call at 6:45 a.m. when the schedule won’t load.

We deliver cybersecurity, remote IT management, security-awareness training, and VoIP to practices nationwide. For hands-on onsite work — server rooms, network builds, hardware, in-person staff training — we cover Kentucky, Indiana, Ohio, West Virginia, and Tennessee.

If you’re not sure where your practice stands against the exact entry points the FBI named, that’s the point of an assessment. We’ll tell you what’s actually in place, what isn’t, and what to fix first — in plain language, with no obligation to buy anything.

Book a consult or assessment, and let’s find the gaps before someone else does.

This guide is educational and is not legal advice. For questions about your specific notification obligations or regulatory exposure, consult your attorney.

Sources

FAQ

Frequently asked questions

What exactly did the FBI warn dental practices about in May 2024?

On May 6, 2024, the FBI informed the ADA and the American Association of Oral and Maxillofacial Surgeons (AAOMS) of a credible cybersecurity threat targeting oral and maxillofacial surgery practices. There were no known victims at the time — the FBI was raising awareness proactively. The agency also said it was concerned that general dentists and other specialists could eventually be targeted, and suspects the group may have shifted to oral surgery after targeting plastic surgeons the prior year.

How does the attack the FBI described actually work?

The FBI described a specific scenario: the threat actor poses as a new patient, or someone wanting to become a patient, to obtain new-patient forms from the practice's website. They then contact the practice claiming they're having trouble submitting the forms online and ask to email a scan instead. The emailed 'forms' attachment deploys malware when opened, which can lead to ransomware locking your systems and files until payment is made.

Does the FBI warning apply to my general dental practice, or only to oral surgeons?

The immediate threat the FBI described was focused on oral and maxillofacial surgeons, but the FBI explicitly stated it was concerned that the practices of general dentists and other specialists could also eventually be targeted. Given that the group reportedly moved from plastic surgery to oral surgery, treating the warning as a preview rather than someone else's problem is the reasonable posture for any dental owner.

Is a ransomware attack on my dental practice a reportable HIPAA breach?

If your practice is a HIPAA covered entity — which it is if you submit claims electronically, check eligibility online, or send statements through a clearinghouse — a ransomware event affecting ePHI triggers breach analysis and, in most cases, notification obligations to affected individuals and HHS. Separately, every U.S. state has a data-breach-notification law requiring timely notification to affected individuals and often to regulators. Your attorney can confirm your state's exact notification window.

What are the highest-value steps a small dental practice can take right now?

CISA's guidance is short: teach your team to recognize and avoid phishing, require strong passwords, require multifactor authentication, and keep all business software updated. Add to that regular, verified backups — including a copy ransomware on your network can't reach — restore-tested rather than assumed, plus a written incident response plan and a current HIPAA risk analysis. Those cover both the technical exposure and the documentation a regulator asks for first.

REAL People. REAL Experience. REAL Solutions.

Book a 20-minute Cyber Risk Consult.

No pressure, no obligation — just a clear picture of where your practice stands.