For years, cybersecurity felt like a hospital-system problem. In 2026, that stopped being true for dental practices. A steady run of breach disclosures, most at practices with just a handful of locations, made clear that a small front desk and one shared login are exactly the kind of target ransomware groups have started working through.
HIPAA Journal has tracked a run of 2026 incidents that reads less like bad luck and more like a pattern. A multi-location practice group had its network breached in January when a ransomware group claimed to have stolen 580 gigabytes of data affecting more than 10,000 patients, and a pediatric practice lost email credentials to a phishing message the same month, exposing records for almost 6,000 patients. Several more practices disclosed breaches in early 2026, together exposing information for more than 32,700 patients across a handful of states.
The data exposed rarely stopped at appointment histories, it included Social Security numbers, insurance details, and treatment records, the combination that turns a breach letter into a lasting trust problem. Two attack methods keep showing up: a phishing email that harvests a login, and unauthorized system access that went uncaught because nothing was monitored closely enough. Neither requires a sophisticated attacker, and both are addressable with ordinary safeguards.
In December 2024, the US Department of Health and Human Services (HHS) proposed the first major overhaul of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule since 2013, making most "addressable" safeguards mandatory. That means multifactor authentication everywhere, encryption at rest, twice-yearly vulnerability scans, annual penetration testing, and a disaster recovery plan that restores critical systems within 72 hours.
The deadline has already moved once, pushed to July 2027 after HHS estimated industry-wide first-year compliance costs near $9 billion. That extra runway doesn't change the exposure in the meantime, which is why the ADA maintains ongoing HIPAA and cybersecurity guidance: the risk to a five-chair practice doesn't wait for a federal rule to take effect.
Most of what the rule will eventually require is good practice today, regardless of the deadline:
None of this needs a big budget to start. It just needs the same operational seriousness a practice already gives sterilization protocols or controlled substance logs.
The rule won't be final until 2027, but the incidents driving it aren't waiting. MFA, encrypted backups, a written recovery plan, and staff who can spot a phishing attempt address most of what actually went wrong in this year's disclosed breaches, regardless of what HHS finalizes next.