Dental Cybersecurity

Dental Ransomware Cases: 3 Incidents and Cost Lessons

Review three dental-sector ransomware incidents, cost evidence, and lessons for downtime, backups, access control, response, and cyber insurance.

Dental IT Team August 5, 2026 13 min read
dental ransomware cases dental practice ransomware dental cyberattack costs ransomware recovery dental office
Dental practice leadership reviewing a ransomware incident response plan in a conference room
Ransomware cost includes investigation, downtime, restoration, legal duties, communications, lost revenue, and long-term remediation—not only a ransom demand.

Public ransomware reporting often combines ransom demands, litigation amounts, direct response expenses, business interruption, insurance limits, and estimated losses as though they were the same number. They are not. This review examines three dental-sector incidents—the MCNA Dental event, the American Dental Association attack, and Henry Schein’s 2023 cyber incident—to separate confirmed public facts from claims and extract practical recovery lessons for independent practices.

Key Takeaways

Publicly reported numbers must be labeled accurately: a demand, direct expense, insurance recovery, settlement, and total economic impact measure different things.

Identity controls, restricted privileged access, monitored endpoints, segmentation, protected backups, and practiced response procedures work together to reduce impact.

A small practice needs a proportionate response plan with decision authority, legal and insurance contacts, downtime workflows, restoration priorities, and preserved evidence.

What counts as a ransomware recovery cost?

A ransom demand is the amount an attacker asks for; it is not proof of payment and does not represent total loss. Direct incident expenses may include forensics, restoration, legal counsel, notification, call centers, credit monitoring, public relations, temporary systems, overtime, and security improvements. Business interruption can include canceled appointments, delayed claims, lost sales, and reduced productivity.

Insurance figures require the same care. A policy limit is not a payment, a retention operates differently from a simple deductible, and proceeds may reimburse only covered losses after review. Litigation settlements and regulatory resolutions measure separate legal processes and should not be presented as the technical cost of restoring systems.

Most organizations do not publish a complete ledger. Independent practices should therefore use case studies to understand categories of impact and control failures, not to predict one exact dollar amount. A responsible budget includes prevention, response, recovery, and operational continuity.

Case 1: What happened in the MCNA Dental incident?

Managed Care of North America, a dental benefits administrator, reported an external system breach to the Maine Attorney General. The public filing listed 8,923,662 affected individuals and described unauthorized activity occurring between February 26 and March 7, 2023, with the incident discovered on May 3, 2023.

The notification said affected information could include names and combinations of identifiers, insurance information, dental or orthodontic care information, and other personal data depending on the individual. Public reporting associated the event with the LockBit ransomware group and a claimed demand, but the official breach notice is the stronger source for affected population, dates, and notification facts.

The cost lesson is scale and data concentration. A benefits administrator or shared service provider may hold information for many plans and providers, so one compromise can create notification, investigation, communication, and identity-protection duties across a very large population. Dental practices should understand which partners aggregate their patient data and how those partners report incidents.

What should practices learn from the MCNA case?

Third-party risk belongs in the practice’s own risk analysis. Inventory clearinghouses, benefits administrators, cloud platforms, software vendors, billing services, communications providers, IT companies, and any subcontractors that create, receive, maintain, or transmit protected information on the practice’s behalf.

A business associate agreement is important when required, but it does not configure security. Ask how the vendor protects privileged access, encrypts data, segments tenants, monitors activity, tests recovery, manages subcontractors, and notifies customers. Determine what information the practice will receive during an incident and who coordinates patient and regulatory duties.

Minimize unnecessary data exchange and retention. The practice may not control every partner’s architecture, but it can select vendors carefully, limit integrations, remove dormant accounts, review access, retain contracts and contacts, and prepare for the operational consequences of a vendor outage or breach.

Case 2: What happened to the American Dental Association?

In April 2022, the American Dental Association disclosed a cybersecurity incident that disrupted systems. Subsequent notification materials described a sophisticated cyberattack involving ransomware. Public reporting attributed the event to the Black Basta group, but attribution claims should be distinguished from the organization’s confirmed statements.

The incident affected access to services and demonstrated that a dental-sector organization can experience both security and availability consequences. Public sources do not provide a complete total recovery-cost figure, so it would be misleading to assign one based on a threat-actor demand, a news estimate, or unrelated downstream costs.

The operational lesson is that ransomware can interrupt shared resources beyond the victim’s internal office. Associations, vendors, portals, credentialing services, education systems, and connected organizations may become unavailable. A practice’s continuity plan should account for third-party downtime even when its own network remains healthy.

What should practices learn from the ADA case?

Separate essential workflows from convenience. Document which external services are required for patient care, claims, prescriptions, credentialing, communications, training, or administration. Identify manual workarounds and alternate contacts before a provider’s portal becomes unavailable.

Treat email and identity security as critical controls. Ransomware intrusions often begin with stolen credentials, phishing, exploited remote access, or software vulnerabilities. Use multifactor authentication where supported, protect password-reset methods, restrict administrator accounts, patch supported systems, filter email, and train staff to report suspicious activity quickly.

Preserve incident evidence. Staff should know not to delete suspicious messages, wipe devices, or improvise restoration without direction. The response plan should identify who can isolate systems, disable accounts, contact insurance and counsel, preserve logs, coordinate vendors, and authorize recovery actions.

Case 3: What do Henry Schein’s filings reveal about cost?

Henry Schein reported an October 2023 cyber incident that disrupted parts of its operations. In its filings, the company reported $11 million of direct incident-related expense in 2023 and $9 million in 2024, mostly professional fees. Its 2025 annual filing reported no additional expense for 2025 in that disclosure.

The company also disclosed a $60 million cyber-insurance policy following a $5 million retention, $40 million in proceeds received during 2024, and the remaining $20 million received during 2025. Those figures should not be subtracted casually to produce a supposed total loss; insurance recovery may relate to multiple covered loss categories and accounting periods.

This is useful because it shows how a public company distinguishes direct expense from insurance proceeds. It does not establish what an independent dental practice would spend, and it does not make the policy limit a proxy for the attack’s total economic impact.

What should practices learn from the Henry Schein case?

Review cyber insurance before an incident. Know the policy period, retention, sublimits, exclusions, approved vendors, notification deadline, consent requirements, business-interruption conditions, funds-transfer coverage, social-engineering terms, restoration coverage, and who has authority to contact the carrier.

Coordinate the policy with the response plan. An otherwise sensible action may affect coverage if the carrier requires prior approval for forensics, counsel, negotiators, restoration firms, or public communications. Keep the current policy, broker, claims contact, and required reporting information accessible outside the production network.

Insurance transfers part of financial risk; it does not restore operations by itself. The practice still needs protected backups, documented systems, vendor contacts, secure administrator access, incident leadership, patient-care contingencies, and enough liquidity to handle costs before reimbursement.

Which controls reduce ransomware impact?

Protect identity first. Require multifactor authentication for email, remote access, cloud administration, backup portals, security consoles, and other privileged systems where supported. Use named accounts, least privilege, separate administrator identities, rapid offboarding, password managers, and alerts for unusual login or enrollment changes.

Monitor endpoints and restrict movement. Managed endpoint detection and response can identify suspicious execution, credential access, privilege escalation, persistence, lateral movement, encryption behavior, and security-tool interference. Network segmentation can limit access between user devices, servers, imaging, management systems, guest networks, and backups.

Maintain supported software and controlled remote access. Remove unused tools, close exposed services, patch operating systems and applications, verify vendor access, and document exceptions for legacy clinical devices. No single safeguard guarantees prevention, but layers create more opportunities to detect and contain an intrusion.

How should backups be designed for ransomware recovery?

Back up the complete clinical and operational environment. Practice-management databases, images, scanned documents, file shares, configuration, cloud data, and specialty applications may require separate jobs. Document recovery order and dependencies so the team does not discover missing components during restoration.

Use separate credentials and at least one copy that is isolated, immutable, or otherwise resistant to modification from production systems. Monitor deletion, retention changes, disabled jobs, unusual administrative activity, and repeated failures. Keep recovery documentation available when normal systems are unavailable.

Test restoration. Recover representative data into a safe environment, verify database integrity, open patients and images, check permissions, and measure the process. A test should reveal the realistic recovery point and recovery time, not simply confirm that a backup dashboard is green.

What belongs in a dental ransomware response plan?

Define incident authority and contact paths. Identify practice leadership, IT, security responders, legal counsel, cyber-insurance contacts, software vendors, backup providers, communications support, and law enforcement or regulatory contacts as appropriate. Store current copies securely outside the affected environment.

Create first-hour actions: report the event, preserve evidence, isolate affected systems when authorized, protect backups, disable compromised accounts, record decisions, and establish a trusted communication channel. Staff should not negotiate, pay, announce, or restore systems without the designated response team.

Prepare downtime procedures for scheduling, clinical documentation, imaging, prescriptions, payments, claims, phones, and patient communications. Define minimum safe operations, how temporary records are protected, and how information is reconciled after systems return.

How should leaders discuss ransomware cost?

Use ranges and scenarios rather than one frightening headline. A short workstation event with no data exposure is different from domain-wide encryption, backup compromise, vendor disruption, or confirmed exfiltration. Model clinical downtime, restoration labor, notification, legal support, temporary operations, lost revenue, and security improvements.

Label every public number. State whether it is a demand, alleged payment, direct expense, insurance limit, insurance recovery, settlement fund, regulatory payment, or estimate. Avoid using an affected-person count to imply that every record contained the same data or that every individual experienced the same harm.

The objective is preparation, not fear. Leadership should use incident evidence to fund proportionate safeguards, close known access gaps, test recovery, improve vendor governance, and rehearse decisions. A smaller practice cannot copy a public company’s program, but it can protect the pathways most likely to determine impact.

Sources and References

Primary sources used for this article

Regulations, product support information, and incident details can change. Review the linked primary sources for the latest status.

Maine Attorney General — MCNA Dental Breach Notice

Official breach filing with dates, affected population, information categories, and consumer notice details.

Montana Department of Justice — ADA Data Event Notice

Public notification letter describing the April 2022 ADA cyberattack as involving ransomware.

Henry Schein 2025 Annual Report

SEC filing with incident-related expense, cyber-insurance retention, and insurance-recovery figures through 2025.

ADA — Protect Your Practice from Ransomware

Dental-sector ransomware prevention and preparedness resource.

Common Questions

Frequently asked questions

How much does a dental ransomware attack cost?

There is no reliable universal amount. Cost depends on scope, downtime, data exposure, restoration, professional services, notification duties, business interruption, insurance, litigation, and remediation. Public demands and settlements should not be treated as total recovery cost.

Did MCNA Dental pay the reported ransom demand?

The official breach notice confirms the event details and affected population but does not establish a ransom payment. Threat-actor claims and reported demands should be labeled separately from verified payment or total-loss information.

Was the American Dental Association attack ransomware?

Public notification materials described the April 2022 cyberattack as involving ransomware. Public attribution to a specific group came through reporting and should be distinguished from the confirmed incident statement.

Does paying a ransom guarantee recovery or deletion?

No. Payment does not guarantee that a decryptor will work, all systems will be restored, stolen data will be deleted, or attackers will not return. Decisions require legal, insurance, law-enforcement, technical, and leadership input.

Are cloud backups enough to stop ransomware?

Backups do not stop initial compromise or data theft. Properly protected and tested backups can reduce operational impact, but they must use separate access, resilient retention, complete scope, monitoring, and documented restoration procedures.

What should staff do first when ransomware is suspected?

Staff should follow the incident plan, report the event through a trusted channel, avoid deleting evidence or improvising restoration, and take isolation steps only as authorized. The response team should protect backups, accounts, logs, and communications quickly.

Keep Reading

Related dental technology articles.

View All Articles