Firm bound by compliance have different but similar rules from HIPAA, CJIS, PCI, and FTC Safeguards. SMBs may only care about Cyber Insurance, CIS and Texas Safe Harbor

The Henry Schein ransomware attack showed that a practice can be disrupted without ever being hacked itself. When BlackCat hit the dental and medical distributor in October 2023, ordering stalled for weeks, customer data was put at risk and the same group struck again a month later. The lesson is to plan for vendor outages, not just your own.

Most healthcare security advice focuses on what happens inside the practice. Phishing training, strong passwords, backups. All of that matters. But the Henry Schein incident, and the much larger Change Healthcare attack a few months later, made a different point clear for dental offices, specialty clinics and medical groups around Dallas-Fort Worth. Some of your biggest risks live in the systems of the companies you depend on, and you don’t control those systems.

Here’s what happened, what it meant for practices and the practical steps worth taking now.

What happened in the Henry Schein ransomware attack?

Henry Schein is one of the largest distributors of dental and medical supplies in the world. On October 14, 2023, the company detected a cyberattack and took some systems offline to contain it. The BlackCat ransomware group, also known as ALPHV, claimed responsibility and said it had stolen 35 terabytes of data.

According to reporting by DrBicuspid, the disruption to ordering and distribution lasted about a month, with e-commerce and distribution restored by November 13. Then on November 22, the same group struck again and took Henry Schein’s e-commerce sites in the US, Canada and Europe offline. The US site came back about six days later. Customers and suppliers were advised to change passwords and watch their accounts, because bank account and credit card details may have been exposed.

The company projected full-year 2023 sales 1% to 3% lower than 2022 and received a Nasdaq noncompliance notice after delaying a quarterly filing. A year later, in October 2024, Henry Schein began notifying 166,432 individuals that their personal information was involved, as TechRadar reported.

How did the attack affect dental and medical practices?

Practices weren’t breached, but plenty of them felt it. When your main supplier’s ordering portal is down, reorders for gloves, anesthetic, impression materials and everyday consumables have to go through phone calls, backup distributors or whatever stock is on the shelf. Office managers end up spending the week chasing supplies instead of running the front desk.

There was also a second wave of risk. Any time a vendor announces a breach involving customer account data, criminals follow with phishing emails that look like they came from that vendor. “Please update your account” and “new payment instructions” are the classic openings. Our guide to business email compromise and wire fraud explains how those scams work and how to stop them.

Why does the Change Healthcare attack matter here too?

Four months after the Henry Schein incident, the February 2024 ransomware attack on Change Healthcare disrupted claims processing for a huge share of the US healthcare system. An American Medical Association survey of about 1,400 respondents, mostly from practices with 10 or fewer physicians, found that 55% had used personal funds to cover practice expenses. About two-thirds had core functions like submitting claims or receiving payments restricted, and 85% needed extra staff time to manage the revenue cycle.

Taken together, the two attacks tell the same story. For a small practice, a vendor’s bad week can turn into your cash flow problem, your staffing problem and your patient scheduling problem.

What should healthcare practices learn from the Henry Schein attack?

1. List the vendors your practice can’t run without

Write down the handful of outside services that would stop or slow patient care if they went dark. For most dental and medical practices that includes the main supply distributor, the practice management or EHR system, the clearinghouse, the payment processor, imaging software and email. Next to each, note who your contact is and what the fallback would be.

2. Have a backup plan for ordering and billing

Set up an account with a secondary supplier before you need it. Keep a modest buffer of critical consumables. For billing, know whether your clearinghouse has an alternate submission path and how long your practice could cover payroll if claims stopped paying for a few weeks. Those are business continuity questions as much as IT questions, and they deserve a conversation with your practice administrator and accountant.

3. Treat vendor breach notices as a phishing warning

When a vendor announces an incident, tell your team to expect convincing fake emails. Verify any change to payment details by calling a number you already have on file, not one from the email. Change the password for that vendor’s portal, and make sure it’s not reused anywhere else. Our business password policy guide covers why reuse is such a problem.

4. Know what data your vendors hold

Under HIPAA, vendors that handle protected health information on your behalf are business associates and need a business associate agreement. That agreement should spell out how quickly they’ll tell you about a breach. Our post on HIPAA facts for small practices walks through the basics.

5. Make sure your own recovery plan is tested

You can’t control a vendor’s recovery, but you can control yours. That means a written incident response plan and backups you’ve actually restored. See our guides to the first 72 hours after a cyberattack and how to test your business backups.

Is the HIPAA Security Rule changing?

Probably, but not yet. In December 2024, HHS proposed the first major update to the HIPAA Security Rule since 2013. It would make most safeguards required rather than “addressable,” including encryption and multifactor authentication, and would add a written technology inventory and procedures to restore critical systems within 72 hours. As of August 2026, HIPAA Journal reports the final rule hasn’t been published and the federal regulatory agenda now targets July 2027.

Truthfully, practices shouldn’t wait for the final rule. Most of what it proposes, like MFA, encryption, asset inventories and tested recovery, is already good practice and already what cyber insurers ask about.

How can a small practice manage vendor risk without a big IT team?

Keep it proportional. A 12-person dental office doesn’t need an enterprise vendor risk program. It needs a one-page list of critical vendors, signed business associate agreements, a secondary supplier, MFA on every vendor portal and a short annual review of whether any of that has changed. Thirty minutes a quarter goes a long way, and it’s a lot cheaper than learning these lessons during an outage.

Frequently asked questions

When was Henry Schein hit by ransomware?

Henry Schein detected the first attack on October 14, 2023. The BlackCat (ALPHV) ransomware group claimed it and struck again on November 22, 2023, taking e-commerce sites offline in the US, Canada and Europe.

Who was behind the Henry Schein cyberattack?

The BlackCat ransomware group, also called ALPHV, claimed responsibility for both attacks and said it stole 35 terabytes of data. The group has since shut down its operation.

How many people were affected by the Henry Schein data breach?

In October 2024, Henry Schein began notifying 166,432 individuals that their personal information was involved in the 2023 incident.

How can dental practices protect themselves from vendor cyberattacks?

List the vendors you can’t operate without, set up a secondary supplier, verify payment changes by phone, use unique passwords and MFA on vendor portals, keep business associate agreements current and test your own backups and incident response plan.

Is the new HIPAA Security Rule final?

Not as of August 2026. HHS proposed the update in December 2024, and the federal regulatory agenda now targets a final rule in July 2027. Practices can adopt most of its proposed safeguards now.

How The Fulcrum Group helps

Healthcare practices around North Texas have enough on their plates without becoming security experts. Through SPOT Managed Security Services and SPOT Managed IT Services, we help practices map critical vendors, secure accounts and portals with MFA, prepare for the proposed HIPAA changes and keep backups and recovery plans tested, so a supplier’s bad month doesn’t become yours.

If you’d like a practical look at your practice’s vendor and recovery risk, Schedule a Discovery Call.