<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Compudent Systems</title>
	<atom:link href="https://compudent.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://compudent.com/</link>
	<description>Dental I/T Support Solutions</description>
	<lastBuildDate>Mon, 28 Sep 2026 10:38:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.5</generator>

<image>
	<url>https://compudent.com/wp-content/uploads/2016/09/cropped-compudentinc_sticky-32x32.png</url>
	<title>Compudent Systems</title>
	<link>https://compudent.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>One Compromised Account, 45,853 Patients: The Hawaii Family Dental Breach and the Weak Link You Actually Control</title>
		<link>https://compudent.com/hawaii-family-dental-breach-compromised-account-mfa-dental-practice/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 10:38:56 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[account security]]></category>
		<category><![CDATA[compromised account]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[dental practice security]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[PHIPA]]></category>
		<category><![CDATA[Qilin ransomware]]></category>
		<guid isPermaLink="false">https://compudent.com/hawaii-family-dental-breach-compromised-account-mfa-dental-practice/</guid>

					<description><![CDATA[<p>A 12-office dental group has begun notifying nearly 46,000 patients after an attacker used a single compromised account to reach their records. Unlike the big supplier breaches, this one started somewhere your practice actually controls - a login. Here is what happened and exactly what to check this week.</p>
<p>The post <a href="https://compudent.com/hawaii-family-dental-breach-compromised-account-mfa-dental-practice/">One Compromised Account, 45,853 Patients: The Hawaii Family Dental Breach and the Weak Link You Actually Control</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The dental data breaches we have covered lately have mostly happened somewhere else &mdash; at a giant distributor, a billing vendor, a referral service &mdash; and landed on practices by association. The latest one is different, and that difference is the whole point. A 12-office dental group has begun notifying roughly <strong>45,853 patients</strong> that their information was exposed, and the attacker did not need a zero-day or a supply chain to get in. They used a <strong>single compromised account</strong>.</p>
<p>Hawaii Family Dental disclosed that on July 20, 2026 it detected suspicious activity and determined that an unauthorized individual had used a compromised account to access patient information over roughly a 24-hour window. The long-running ransomware group Qilin &mdash; known for stealing data and then threatening to leak it unless paid &mdash; has since claimed the attack and posted a sample of the stolen files. For a practice reading this in the GTA or anywhere in Ontario, that is the version of a breach that should keep you up at night, because it started at the one place you can actually do something about.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hawaii-family-dental-breach-compromised-account-mfa-dental-practice-1-scaled.jpg" alt="A single glowing credential unlocking a wall of patient records in a dental practice server room" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The breach did not start with a sophisticated exploit. It started with one account an attacker should never have been able to use.</figcaption></figure>
<h2>What was exposed</h2>
<p>According to the practice&#8217;s notice and its report to regulators, the accessed information included patient <strong>names, dates of birth, phone numbers, email addresses, mailing addresses, dental insurance details, and some medical and dental treatment information</strong>. Notably, the group has said no Social Security numbers or financial account details were involved, which may limit the fallout.</p>
<p>But do not let the absence of a credit-card number lull you. A date of birth paired with an address, a phone number, an insurer, and a note about the care someone is receiving is exactly the raw material for convincing, targeted fraud &mdash; and under HIPAA and Ontario&#8217;s PHIPA, treatment information is protected health information whether or not a bank account rode along with it. Its exposure is what triggers notification duties, investigations, and the very real cost of making it right.</p>
<h2>The detail that matters: it started with one login</h2>
<p>Strip away the ransomware-gang branding and the story is mundane, which is precisely why it is instructive. An account &mdash; a legitimate username and password that belonged in the environment &mdash; ended up in the wrong hands, and that was enough to walk into the systems holding patient records. There was no dramatic breaking-down of a firewall. Someone knocked using a key that was supposed to be yours.</p>
<p>Accounts fall into attacker hands in a handful of ordinary ways: a password reused from a site that was itself breached, a convincing phishing page that harvests the login, or malware that quietly lifts credentials and even active session tokens off a machine. We have written before about how <a href="https://compudent.com/infostealer-session-cookie-theft-mfa-bypass-dental-practice/">infostealers can grab a live session cookie and stroll past multi-factor authentication entirely</a> &mdash; a reminder that &#8220;we have MFA&#8221; is a strong start, not a finished sentence.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hawaii-family-dental-breach-compromised-account-mfa-dental-practice-2.jpg" alt="A diagram contrasting one over-privileged account key opening many doors with a limited key opening one" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The damage from a stolen login is decided before the theft: by how many doors that one account was allowed to open.</figcaption></figure>
<h2>Why a single account can equal the whole practice</h2>
<p>The damage a compromised login can do is decided long before the theft, by one question: how many doors was that account allowed to open? In a lot of small practices, the honest answer is &#8220;most of them.&#8221; Everyone shares a handful of logins, the front desk account can reach the same data as the office manager, and old staff accounts are never switched off. In that setup, one stolen credential is a master key.</p>
<p>The principle that limits this is called <strong>least privilege</strong>: each account can reach only what that role genuinely needs, and nothing more. When privileges are tight, a compromised front-desk login is a contained problem instead of a practice-wide catastrophe. When they are loose, the attacker inherits everything the account can touch &mdash; which, for patient data, is the ballgame.</p>
<h2>The uncomfortable part: you cannot outsource this one</h2>
<p>When a breach happens at a supplier &mdash; like the <a href="https://compudent.com/mckesson-data-breach-shinyhunters-saas-dental-practice/">McKesson incident that swept up practices through a vendor&#8217;s systems</a> &mdash; there is a grim kind of comfort in it: the failure was someone else&#8217;s, and your options were mostly to react. An account compromise inside your own four walls offers no such alibi. The login was yours to protect, the privileges were yours to scope, and the monitoring that might have caught it sooner was yours to set up. That is uncomfortable &mdash; and it is also good news, because it means this is a risk you can materially reduce with decisions entirely within your control.</p>
<h2>Exactly what to check this week</h2>
<ol>
<li><strong>Turn on multi-factor authentication everywhere it will go.</strong> Practice-management software, email, remote access, the patient database, cloud backups &mdash; every account that can reach patient data. MFA is the single change that most reliably turns a stolen password into a failed login. It is not perfect, but it defeats the overwhelming majority of credential attacks.</li>
<li><strong>Kill shared logins and enforce least privilege.</strong> Give each staff member their own account, scoped to what their role actually needs. Shared credentials make it impossible to know who did what &mdash; and hand an attacker one key that opens every door.</li>
<li><strong>Deprovision the moment someone leaves.</strong> Dormant accounts of former employees and departed contractors are a favourite way in. Build &#8220;disable every login, same day&#8221; into your offboarding, and audit the current user list for names that no longer belong.</li>
<li><strong>Make sure someone would actually notice.</strong> Hawaii Family Dental detected the intrusion the next day; many practices would not notice for months. Turn on login and access alerting where your systems support it &mdash; logins from unusual locations or at odd hours, and unexpected bursts of record access &mdash; so an anomaly reaches a human quickly.</li>
<li><strong>Use unique passwords and a password manager.</strong> Reuse is what lets a breach at some unrelated website become a breach at your practice. A password manager makes long, unique passwords for every account the path of least resistance rather than a chore.</li>
<li><strong>Have a plan for the bad day.</strong> Even a well-run practice can be hit. Knowing in advance how you would investigate, contain, notify, and keep seeing patients is the difference between a controlled response and a scramble &mdash; the same reasoning behind having a <a href="https://compudent.com/business-continuity-downtime-plan-dental-practice/">downtime and business-continuity plan</a> ready before you need it.</li>
</ol>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hawaii-family-dental-breach-compromised-account-mfa-dental-practice-3.jpg" alt="A dental office login protected by a multi-factor authentication prompt on a phone" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Multi-factor authentication is the single change that most often turns a stolen password into a failed login attempt.</figcaption></figure>
<h2>The habit underneath all of it</h2>
<p>Qilin, the group claiming this attack, does not hand-pick prestigious targets. Like most of today&#8217;s ransomware operators, it hunts for whatever is easy &mdash; smaller organizations, outdated systems, loose access &mdash; which quietly demolishes the old comfort that a modest practice is too small to bother with. You are not too small; you are, to an opportunist, potentially just easy. The practices that ride this out are not the ones with the biggest security budget. They are the ones where every login has an owner, MFA is on, privileges are tight, and someone is watching.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hawaii-family-dental-breach-compromised-account-mfa-dental-practice-4.jpg" alt="A monitoring dashboard flagging one anomalous login among normal activity in a dental office" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Hawaii Family Dental caught the intrusion the next day. Whether you would notice at all is a question worth answering before it matters.</figcaption></figure>
<h2>Where Compudent fits</h2>
<p>Most dental offices do not have someone whose job is to audit who can log into what, confirm MFA is switched on across every system that touches patient data, and make sure a strange login at 2 a.m. actually reaches a person. That is the gap we close. Compudent Systems helps dental and medical practices across the GTA and Ontario lock down accounts and access &mdash; enforcing multi-factor authentication, scoping permissions to the principle of least privilege, cleaning up dormant and shared logins, and putting monitoring in place so an intrusion is caught in hours, not months. If you are not certain who has access to your patient data today, or whether MFA is truly on everywhere it should be, <a href="https://compudent.com/">reach out to Compudent for a quick account-security assessment</a>. It is a short conversation now, or a notification letter to 45,000 patients later.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hawaii-family-dental-breach-compromised-account-mfa-dental-practice-5.jpg" alt="A dental practice patient database protected by a shield and padlock at a single controlled entry point" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Treat every login that touches patient data as a door: locked, monitored, and given only to people who need it.</figcaption></figure>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.paubox.com/blog/qilin-claims-40k-data-breach-at-hawaii-dental-group" target="_blank" rel="noopener">Qilin claims 40k data breach at Hawaii Dental Group</a></li>
<li><a href="https://hawaiifamilydental.com/notice-of-data-security-incident/" target="_blank" rel="noopener">Hawaii Family Dental &#8211; Notice of Data Security Incident</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/critical-adt-data-breach-exposes-5-5-million-customers-essential-security-lessons-for-dental-practices/">Critical ADT Data Breach Exposes 5.5 Million Customers: Essential Security Lessons for Dental Practices</a></li>
<li><a href="https://compudent.com/dental-data-breaches-2026-lessons/">9 Dental Data Breaches Already in 2026: What the DentaQuest and Absolute Dental Attacks Teach Every Practice</a></li>
<li><a href="https://compudent.com/california-dental-practice-suffers-major-data-breach-hipaa-compliance-under-scrutiny/">California Dental Practice Suffers Major Data Breach: HIPAA Compliance Under Scrutiny</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/hawaii-family-dental-breach-compromised-account-mfa-dental-practice/">One Compromised Account, 45,853 Patients: The Hawaii Family Dental Breach and the Weak Link You Actually Control</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>One Click and You Have a New Admin: The Elementor Flaw (CVE-2026-62062) Threatening Dental Practice Websites</title>
		<link>https://compudent.com/elementor-csrf-cve-2026-62062-dental-practice-website/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Sun, 27 Sep 2026 10:39:48 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[CVE-2026-62062]]></category>
		<category><![CDATA[dental IT]]></category>
		<category><![CDATA[Elementor]]></category>
		<category><![CDATA[PHIPA]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[practice website security]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://compudent.com/elementor-csrf-cve-2026-62062-dental-practice-website/</guid>

					<description><![CDATA[<p>A high-severity flaw in Elementor, the page builder running on over 10 million WordPress sites, lets an attacker create a rogue administrator the moment a logged-in admin opens a booby-trapped link. If your dental practice website was built with Elementor, here is why it matters and exactly what to do.</p>
<p>The post <a href="https://compudent.com/elementor-csrf-cve-2026-62062-dental-practice-website/">One Click and You Have a New Admin: The Elementor Flaw (CVE-2026-62062) Threatening Dental Practice Websites</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Just last week we warned that a WordPress core flaw went from disclosure to active exploitation in under five hours. This week the pressure point moves from the core to the plugins bolted onto it &mdash; and to the people who run them. Security researchers have disclosed a high-severity vulnerability in <strong>Elementor</strong>, the drag-and-drop page builder installed on more than 10 million WordPress sites, that lets an attacker create a rogue administrator account on your website. Tracked as <strong>CVE-2026-62062</strong> and scored 8.8 out of 10, it affects Elementor versions 4.3.0 and 4.3.1, and it is fixed in 4.3.2, released September 24, 2026.</p>
<p>If your dental practice website was designed in WordPress &mdash; and a large share of small-practice sites are &mdash; there is a good chance Elementor is what your designer used to build it. That makes this your problem to confirm, not just an industry headline.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/elementor-csrf-cve-2026-62062-dental-practice-website-1-scaled.jpg" alt="A browser showing a dental practice website with a shadow administrator account appearing after a malicious link is clicked" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The attack needs one thing: a logged-in administrator to open a crafted link. From there, a rogue admin account is created silently.</figcaption></figure>
<h2>What the flaw actually does</h2>
<p>The vulnerability is a <strong>cross-site request forgery</strong>, or CSRF. Unlike last week&#8217;s core flaw, which needed no interaction at all, this one has a single prerequisite: a logged-in administrator has to open a link the attacker controls. The attacker sends that link &mdash; in an email, a comment, a message, a page &mdash; and if an admin clicks it while still signed in to the site, their own authenticated browser session is quietly used to submit a request the admin never intended. In this case, that forged request tells the site to <strong>create a new administrator account</strong> under the attacker&#8217;s control.</p>
<p>The reason it works is that the vulnerable code accepted the action without properly verifying that the request genuinely came from the admin&#8217;s own click inside the dashboard. CSRF attacks abuse exactly this: the trust a site already extends to whoever is logged in. Once a second admin account exists, the attacker no longer needs the trick &mdash; they simply log in and own the site outright.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/elementor-csrf-cve-2026-62062-dental-practice-website-2.jpg" alt="A diagram of a cross-site request forgery attack routing a forged command through a trusted browser session" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">CSRF abuses the trust a site already places in a logged-in admin&#8217;s browser, riding along on their existing session.</figcaption></figure>
<h2>Why this is a dental-practice problem, not just a tech one</h2>
<p>It is easy to dismiss the marketing website as &#8220;just the brochure.&#8221; But a website an attacker fully controls is a liability that reaches your patients and your compliance obligations:</p>
<ul>
<li><strong>Harm aimed at your patients.</strong> A hijacked site can be rewired to serve malware, fake booking pages, or scam redirects to the very people who trust your name &mdash; patients checking your hours or requesting an appointment.</li>
<li><strong>Theft of the data your forms collect.</strong> Contact forms, appointment requests, and new-patient intake widgets routinely capture names, phone numbers, emails, and the reason someone is seeking care. Depending on what you gather, that can be protected health information &mdash; and its exposure can trigger notification duties under HIPAA and PHIPA.</li>
<li><strong>Reputation and search damage.</strong> Compromised sites are commonly stuffed with spam or malicious links, which search engines flag &mdash; turning your best marketing asset into a warning label.</li>
<li><strong>A foothold for more.</strong> Full control of your site&#8217;s server environment is a launch point for probing anything else that shares it.</li>
</ul>
<h2>The detail that makes this one different: it targets your people</h2>
<p>Because the trigger is a click by a logged-in administrator, this flaw sits at the intersection of a software problem and a human one. The attacker&#8217;s real target is whoever administers your site: your web designer, your marketing agency, or the front-desk person who was handed the login. That is the same lesson we raised when <a href="https://compudent.com/rathat-android-malware-dental-practice-mobile-device-security/">malware started targeting the tablets and phones your team uses every day</a> &mdash; the endpoint and the person operating it are part of your attack surface. A patched plugin protects you against this specific bug; a team that pauses before clicking protects you against the next one.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/elementor-csrf-cve-2026-62062-dental-practice-website-3.jpg" alt="A WordPress plugins screen highlighting an available update for a page builder plugin" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The fix is an update: Elementor 4.3.2, released September 24, 2026, closes the hole.</figcaption></figure>
<h2>Exactly what to do this week</h2>
<ol>
<li><strong>Update Elementor to 4.3.2 or later.</strong> This is the fix. If your site runs Elementor 4.3.0 or 4.3.1, treat it as urgent. If you are on an older 4.x release, update to the current version anyway. Sites with automatic plugin updates enabled may already be patched &mdash; verify it rather than assume it.</li>
<li><strong>Review your administrator accounts.</strong> Log in and look at the list of users with the Administrator role. Delete any account you do not recognize, and confirm every legitimate admin still needs that level of access. Fewer admins means a smaller target.</li>
<li><strong>Confirm who actually owns patching your site.</strong> Is it your web designer, an agency, your IT provider, or nobody? A site with an unclear owner is a site that does not get patched. Assign a named owner for updates and account reviews.</li>
<li><strong>Reinforce click discipline for your site&#8217;s admins.</strong> Because this attack rides on a click, the handful of people with dashboard access should treat unexpected links with the same caution you would want for any account that touches patient data. When in doubt, do not click &mdash; and never stay logged in to the site admin in a browser you also use for casual email and links.</li>
</ol>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/elementor-csrf-cve-2026-62062-dental-practice-website-4.jpg" alt="A practice manager pausing before clicking a suspicious link on a laptop in a dental office" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Because the trigger is a click, ordinary phishing discipline for the people who administer your site is part of the defense.</figcaption></figure>
<h2>The bigger habit this should reinforce</h2>
<p>Two critical website flaws in as many weeks is not a coincidence &mdash; it is the normal weather now. WordPress and its plugin ecosystem power an enormous share of small-business sites, which makes them a constant, automated target. The practices that ride this out are not the ones with the fanciest website; they are the ones that keep software current, know which plugins they run, limit who has admin access, and have a named owner for each of it. Those same habits are what keep a five-alarm advisory from becoming a <a href="https://compudent.com/business-continuity-downtime-plan-dental-practice/">downtime-and-recovery scramble</a> later.</p>
<h2>Where Compudent fits</h2>
<p>Most dental offices do not have someone whose job is to notice an Elementor advisory on a Thursday and confirm the practice site was patched before attackers went looking. That is the gap we close. Compudent Systems helps dental and medical practices across the GTA and Ontario inventory the systems that touch patient data &mdash; websites and their plugins included &mdash; keep them patched, review who has access, and make sure someone actually owns each piece. If you are not certain whether your practice website runs Elementor, which version it is on, or who has an admin login, <a href="https://compudent.com/">reach out to Compudent for a quick assessment</a>. It is a short conversation now, or a breach-notification letter later.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/elementor-csrf-cve-2026-62062-dental-practice-website-5.jpg" alt="A dental practice website protected by a shield and padlock with a verified-user checkmark" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Treat the practice website like any other system that touches patient information: patched, monitored, and owned by someone.</figcaption></figure>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html" target="_blank" rel="noopener">Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link</a></li>
<li><a href="https://thecybersecguru.com/news/elementor-cve-2026-62062-csrf-vulnerability/" target="_blank" rel="noopener">CVE-2026-62062: Critical Elementor CSRF Flaw Enables WordPress Admin Takeover</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/wordpress-cve-2026-87902-rce-dental-practice-website/">Hacked in Five Hours: The Critical WordPress Flaw (CVE-2026-87902) Your Practice Website Needs Patched Today</a></li>
<li><a href="https://compudent.com/wp2shell-wordpress-rce-cve-2026-63030-dental-practices/">Security Alert: &amp;ldquo;wp2shell&amp;rdquo; (CVE-2026-63030) Is a Critical WordPress Core Flaw &amp;mdash; Patch Your Practice Website Now</a></li>
<li><a href="https://compudent.com/wordpress-plugin-auth-bypass-practice-website-attack-surface/">Your Practice Website Is Part of Your Attack Surface: Hackers Are Forging Logins Into WordPress Right Now</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/elementor-csrf-cve-2026-62062-dental-practice-website/">One Click and You Have a New Admin: The Elementor Flaw (CVE-2026-62062) Threatening Dental Practice Websites</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hacked in Five Hours: The Critical WordPress Flaw (CVE-2026-87902) Your Practice Website Needs Patched Today</title>
		<link>https://compudent.com/wordpress-cve-2026-87902-rce-dental-practice-website/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Sat, 26 Sep 2026 10:38:43 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[cPanel]]></category>
		<category><![CDATA[CVE-2026-87902]]></category>
		<category><![CDATA[dental IT]]></category>
		<category><![CDATA[PHIPA]]></category>
		<category><![CDATA[practice website security]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://compudent.com/wordpress-cve-2026-87902-rce-dental-practice-website/</guid>

					<description><![CDATA[<p>A critical WordPress Core flaw, CVE-2026-87902, went from public disclosure to active exploitation in under five hours. If your practice website runs WordPress on typical cPanel hosting, here is why it may be in the vulnerable configuration and exactly what to do this week.</p>
<p>The post <a href="https://compudent.com/wordpress-cve-2026-87902-rce-dental-practice-website/">Hacked in Five Hours: The Critical WordPress Flaw (CVE-2026-87902) Your Practice Website Needs Patched Today</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On September 22, 2026, the WordPress security team disclosed and patched a critical flaw in WordPress Core, tracked as <strong>CVE-2026-87902</strong> and scored 9.2 out of 10. It is an unauthenticated path-traversal bug that, under the right conditions, lets an attacker run their own code on the server hosting your website &mdash; no password, no login, no user interaction required.</p>
<p>The alarming part isn&#8217;t just the severity. It&#8217;s the speed. Security firm Patchstack recorded the first malicious requests at 17:44 UTC the same day &mdash; less than five hours after the fix was published. Within a day, attack traffic had jumped roughly tenfold and moved from simply hunting for vulnerable sites to actively dropping code onto them. If your dental practice runs a WordPress website &mdash; and most do &mdash; this is a this-week problem, not a someday problem.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/wordpress-cve-2026-87902-rce-dental-practice-website-1-scaled.jpg" alt="A dental practice website fracturing behind a broken padlock, representing a compromised WordPress site" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">A public-facing website is part of a practice&#8217;s attack surface, and a critical WordPress flaw put many of them at risk within hours.</figcaption></figure>
<h2>What the flaw actually does</h2>
<p>The bug lives in how WordPress resolves page templates. In plain terms, a function that is supposed to load a template file from inside your theme can be tricked into loading a different, attacker-chosen <code>.php</code> file that already exists on the server. If the attacker can point that mechanism at the right file, they can turn &#8220;display a web page&#8221; into &#8220;execute a command.&#8221;</p>
<p>Discovered by security researcher Robert Ressl, the vulnerability doesn&#8217;t hit every single site automatically &mdash; remote code execution requires a specific combination: an active theme with a top-level folder whose name starts with <code>page-</code> (for example, <code>page-templates</code>), and a readable local PHP file the attacker can abuse. The official advisory points to <code>pearcmd.php</code> as the classic example when PHP&#8217;s <code>register_argc_argv</code> setting is switched on. That sounds obscure until you learn where those conditions are common.</p>
<h2>Why ordinary practice websites are squarely in the blast radius</h2>
<p>Here is the line that should get a practice owner&#8217;s attention: WordPress notes that the <strong>official PHP image for Docker is affected, and so is the default cPanel configuration when a PHP version older than 8.5 is used.</strong> cPanel is the control panel behind a huge share of small-business shared hosting &mdash; exactly the kind of budget hosting a dental office&#8217;s marketing site often sits on, frequently running a PHP version that is a release or two behind. In other words, the risky configuration isn&#8217;t exotic. For many practices, it&#8217;s the default they were handed and never touched.</p>
<p>This is the recurring lesson we keep coming back to: your website is not separate from your security posture. It is part of your attack surface. We made that case earlier this year when attackers were <a href="https://compudent.com/wordpress-plugin-auth-bypass-practice-website-attack-surface/">forging logins straight into WordPress</a>, and again when a <a href="https://compudent.com/wp2shell-wordpress-rce-cve-2026-63030-dental-practices/">separate critical Core flaw, &#8220;wp2shell,&#8221;</a> gave attackers code execution. CVE-2026-87902 is a new, distinct vulnerability &mdash; but the pattern is identical, and so is the fix discipline.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/wordpress-cve-2026-87902-rce-dental-practice-website-2.jpg" alt="A stopwatch beside a sharply rising attack-traffic curve representing exploitation within five hours of disclosure" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Reconnaissance began under five hours after the fix shipped, and malicious traffic soon jumped tenfold.</figcaption></figure>
<h2>What a compromise would cost a dental practice</h2>
<p>It is tempting to shrug off the marketing site as &#8220;just the brochure.&#8221; But once an attacker can run code on the server behind it, the damage is real and often reportable:</p>
<ul>
<li><strong>Harm to your patients directly.</strong> A compromised site can be quietly rigged to serve malware or scam pages to the very people who trust your name &mdash; existing patients looking up your hours or booking an appointment.</li>
<li><strong>Theft of the data your forms collect.</strong> Contact forms, appointment-request forms, and new-patient intake widgets routinely capture names, phone numbers, email addresses, and the reason someone is seeking care. Depending on what you collect, that can be protected health information &mdash; and its exposure can trigger notification obligations under HIPAA and PHIPA.</li>
<li><strong>Reputation and search damage.</strong> Sites hijacked this way are commonly stuffed with spam or malicious redirects, which search engines flag &mdash; turning your top marketing asset into a warning label.</li>
<li><strong>A foothold.</strong> Code execution on your hosting is a launch point for attackers to probe further into anything else that shares that environment.</li>
</ul>
<p>The observed attacks are already writing files with tell-tale names like <code>wp-pear-rce-flag.php</code>, <code>poc87902.php</code>, and randomized <code>luci_</code> or <code>zeta_</code> PHP files into locations such as <code>/tmp</code> and <code>/var/tmp</code>. Some payloads merely flag a host as exploitable; others plant a short snippet that runs a shell command whenever it is accessed.</p>
<h2>Exactly what to do this week</h2>
<p>The good news is that the remedy is straightforward and mostly a matter of confirming it happened.</p>
<ol>
<li><strong>Update WordPress to 7.1.2.</strong> That release fixes the flaw. Because the severity is critical, WordPress backported the fix down every branch to 4.7, so older-but-maintained sites have a patch too. (Anything before 4.6 will <em>not</em> get a fix &mdash; if that&#8217;s you, an upgrade is overdue for many reasons.) If your site has automatic core updates enabled, this may already be done; verify it rather than assume it.</li>
<li><strong>Check your PHP version.</strong> If your host runs PHP older than 8.5 on a default cPanel setup, you are in the configuration WordPress specifically called out. Ask your host to move you to a current, supported PHP release &mdash; a good idea independent of this bug.</li>
<li><strong>Confirm who actually owns patching your site.</strong> Is it your web designer, a marketing agency, your IT provider, or nobody? A site with an unclear owner is a site that doesn&#8217;t get patched. This is the same discipline behind knowing every piece of software you run &mdash; the theme we raised with the <a href="https://compudent.com/fastjson-cve-2026-16723-dental-practice-software-inventory/">FastJson zero-day and building a real software inventory</a>.</li>
<li><strong>Look for signs of compromise.</strong> Ask whoever manages the site to check for unexpected PHP files in <code>/tmp</code> and <code>/var/tmp</code> and in the web root, and to review access logs for the exploitation pattern. If anything looks off, treat it as a potential breach of any data the site collected.</li>
</ol>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/wordpress-cve-2026-87902-rce-dental-practice-website-3.jpg" alt="A web hosting control panel highlighting an outdated PHP version with a warning icon" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The risk concentrates on common setups: default cPanel hosting running a PHP version older than 8.5.</figcaption></figure>
<h2>The bigger habit this should reinforce</h2>
<p>CVE-2026-87902 is a textbook case of why speed matters now. The window between &#8220;a fix exists&#8221; and &#8220;criminals are weaponizing it&#8221; was under five hours &mdash; and the exploitation was fully automated, spraying the internet rather than hand-picking targets. A small dental practice doesn&#8217;t get overlooked in that model; it gets swept up in it.</p>
<p>That reality rewards two boring habits: keeping software current without waiting for a nudge, and knowing what you run and who is responsible for each piece of it. Auto-updates, a maintained hosting plan on a supported PHP version, and a named owner for the website are not luxuries &mdash; they are what turns a five-alarm headline into a non-event you patched before lunch.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/wordpress-cve-2026-87902-rce-dental-practice-website-4.jpg" alt="A practice manager applying a website software update on a laptop in a dental office" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The fix is simple: update to WordPress 7.1.2, or confirm your host already backported it.</figcaption></figure>
<h2>Where Compudent fits</h2>
<p>Most dental offices don&#8217;t have someone whose job is to watch for a WordPress advisory on a Tuesday afternoon and confirm the practice site got patched before attackers arrived. That&#8217;s the gap we close. Compudent Systems helps dental and medical practices across the GTA and Ontario inventory the systems that touch patient data &mdash; websites included &mdash; keep them patched, watch for exploitation of flaws like this one, and make sure someone actually owns each piece. If you&#8217;re not certain whether your practice website is running the fixed version of WordPress, or which PHP version your host serves, <a href="https://compudent.com/">reach out to Compudent for a quick assessment</a>. It&#8217;s a short conversation now, or a breach-notification letter later.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/wordpress-cve-2026-87902-rce-dental-practice-website-5.jpg" alt="A dental practice website protected by a shield and padlock icon representing a secured site" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Treat the practice website like any other system that touches patient information: patched, monitored, and owned by someone.</figcaption></figure>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/" target="_blank" rel="noopener">Hackers start exploiting critical WordPress flaw for code execution</a></li>
<li><a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp" target="_blank" rel="noopener">WordPress security advisory GHSA-7hp8-65ch-5whp (CVE-2026-87902)</a></li>
<li><a href="https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/" target="_blank" rel="noopener">Patchstack: attackers started probing WordPress sites hours after the patch</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/wp2shell-wordpress-rce-cve-2026-63030-dental-practices/">Security Alert: &amp;ldquo;wp2shell&amp;rdquo; (CVE-2026-63030) Is a Critical WordPress Core Flaw &amp;mdash; Patch Your Practice Website Now</a></li>
<li><a href="https://compudent.com/elementor-csrf-cve-2026-62062-dental-practice-website/">One Click and You Have a New Admin: The Elementor Flaw (CVE-2026-62062) Threatening Dental Practice Websites</a></li>
<li><a href="https://compudent.com/wordpress-plugin-auth-bypass-practice-website-attack-surface/">Your Practice Website Is Part of Your Attack Surface: Hackers Are Forging Logins Into WordPress Right Now</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/wordpress-cve-2026-87902-rce-dental-practice-website/">Hacked in Five Hours: The Critical WordPress Flaw (CVE-2026-87902) Your Practice Website Needs Patched Today</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI That Reads Your CBCT Scans Just Arrived for General Dentists: What Pearl&#8217;s Second Opinion 3D Means for Your Practice</title>
		<link>https://compudent.com/pearl-second-opinion-3d-cbct-ai-dental-practice/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 11:31:32 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[3D radiographic analysis]]></category>
		<category><![CDATA[AI diagnostic assist]]></category>
		<category><![CDATA[CBCT AI]]></category>
		<category><![CDATA[cloud imaging]]></category>
		<category><![CDATA[dental imaging software]]></category>
		<category><![CDATA[dental practice IT]]></category>
		<category><![CDATA[digital dentistry workflow]]></category>
		<category><![CDATA[FDA 510(k)]]></category>
		<category><![CDATA[Pearl Second Opinion 3D]]></category>
		<category><![CDATA[PHIPA Compliance]]></category>
		<guid isPermaLink="false">https://compudent.com/pearl-second-opinion-3d-cbct-ai-dental-practice/</guid>

					<description><![CDATA[<p>Pearl has brought its FDA-cleared 3D imaging AI to general dentists in the U.S. and Canada. The tool that reads cone-beam scans is now a mainstream purchase - which makes it an IT and data question, not just a clinical one. Here is what your practice should sort out before the scans start leaving the building.</p>
<p>The post <a href="https://compudent.com/pearl-second-opinion-3d-cbct-ai-dental-practice/">AI That Reads Your CBCT Scans Just Arrived for General Dentists: What Pearl&#8217;s Second Opinion 3D Means for Your Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>For years, the AI that reads dental radiographs was a two-dimensional affair &#8211; clever software that scanned a bitewing or a periapical and flagged a suspected caries or bit of bone loss for the dentist to confirm. The three-dimensional world of the cone-beam CT stayed the province of specialists and their reading software. That line just moved. Pearl has taken its FDA-cleared 3D imaging AI, <strong>Second Opinion 3D</strong>, and launched it as a commercial product aimed squarely at general dentists in the United States and Canada &#8211; software that reviews a CBCT volume and surfaces findings for the clinician to verify.</p>
<p>This is not a breach alert, and there is nothing to patch this morning. It is a shift in what an ordinary general practice can buy &#8211; and every time a new class of tool becomes mainstream, it quietly becomes an IT and data question long before anyone in the operatory notices. Here is what the launch actually means, and the handful of things worth settling before your scans start leaving the building.</p>
<h2>What actually changed</h2>
<p>Pearl is not new to this. Its two-dimensional analysis tool has been reading intraoral X-rays chairside for some time. What is new is that the company has extended that FDA 510(k)-cleared imaging AI into cone-beam scans and packaged it for general dentistry rather than only for radiologists and large groups. In the same window, industry watchers counted <strong>five separate FDA clearances for 3D dental AI</strong> &#8211; a sign that regulators and vendors alike now treat AI review of a CBCT as a normal clinical tool, not an experiment.</p>
<p><figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/pearl-second-opinion-3d-cbct-ai-dental-practice-1-scaled.jpg" alt="A translucent blue 3D cone-beam CT volume of a jaw floating above an imaging workstation with light-blue AI analysis lines tracing structures inside it, illustrating AI reviewing a dental CBCT scan" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The new capability in plain terms: software that reviews a three-dimensional cone-beam scan and flags what merits a closer look &#8211; a second set of eyes on the volume.</figcaption></figure>
</p>
<p>The practical effect is that the wait-list of practices thinking about AI is being converted into buyers. The ADA Health Policy Institute&#8217;s Q2 2026 read on the profession found that <strong>43.3% of dentists reported using AI for at least one task</strong>, with another 26.4% saying they do not yet but plan to &#8211; and imaging and diagnostics sat near the top of both lists. Cone-beam review moving within reach of the general dentist is exactly the kind of step that turns a &#8220;planning to&#8221; into a purchase order.</p>
<h2>Why a clinical tool lands on the IT desk</h2>
<p>Because AI does not read a scan by magic. Modern diagnostic-assist tools are overwhelmingly cloud services: the imaging system hands the volume off across your network to the vendor&#8217;s servers, the model does its work there, and a result comes back. That is a sensible architecture &#8211; the compute is heavy and centralising the model keeps it current &#8211; but it means a full patient CBCT, one of the richest pieces of personal health information you hold, now travels off your premises as a matter of routine. The clinical question is what the AI finds. The IT question is where the scan goes to be read, and whether that path keeps the data under your control.</p>
<p><figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/pearl-second-opinion-3d-cbct-ai-dental-practice-2.jpg" alt="A diagram of a CBCT scan leaving a dental office through a shield-gated network boundary up to a cloud with an AI motif and a result returning, illustrating patient imaging data being sent off-site for AI analysis" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The clinical question is what the AI finds. The IT question is where the scan goes to be read &#8211; and whether that path keeps patient data under your control.</figcaption></figure>
</p>
<p>This is the same due diligence we applied when <a href="https://compudent.com/medit-auravue-overjet-ai-dental-practice-imaging/">Medit&#8217;s AuraVue put Overjet&#8217;s AI onto one screen with your scans and X-rays</a>, and it rests on the same foundation as keeping <a href="https://compudent.com/orthanc-dicom-server-cve-2026-87020-dental-pacs/">your imaging server and PACS off the open internet</a>. A tool that reaches into your imaging pipeline is only as safe as the pipeline it joins.</p>
<h2>The PHIPA question you have to answer first</h2>
<p>For an Ontario practice, sending patient imaging to a third party for processing is not a grey area &#8211; it is a health-information custodian handing personal health information to a service provider, and PHIPA holds you responsible for what happens to it. That is workable and common, but it is conditional. Before the first scan is uploaded, you want three things pinned down in writing: <strong>where the data is stored and processed</strong> (a Canadian or U.S. data-residency answer matters to some patients and some contracts), <strong>whether your scans are used to train the vendor&#8217;s models</strong> and your ability to opt out, and <strong>a signed agreement</strong> &#8211; a written data-processing or business-associate arrangement that names the vendor&#8217;s obligations. These are the same instincts that apply whenever a free or consumer-grade cloud service creeps into clinical use, a trap we walked through with <a href="https://compudent.com/google-meet-hipaa-phipa-teledentistry-dental-practice/">teledentistry over general-purpose video tools</a>. &#8220;It just works in the browser&#8221; is not a compliance posture.</p>
<p><figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/pearl-second-opinion-3d-cbct-ai-dental-practice-3.jpg" alt="A calm blue practice decision-maker reviewing a checklist across from an AI software vendor, with a data-processing agreement document between them, illustrating vetting an AI imaging tool before adopting it" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Adopting the tool is a purchasing decision like any other: the leverage is greatest before you sign, when a clear answer on data handling is still a condition of the sale.</figcaption></figure>
</p>
<h2>Four questions to ask before you switch it on</h2>
<p>You do not need to become an AI expert to adopt one responsibly. Make these part of the evaluation and treat a vague answer as the answer:</p>
<ol>
<li><strong>&#8220;Where is our data processed and stored, and for how long?&#8221;</strong> Get data residency and a retention period in writing, not a shrug about &#8220;the cloud.&#8221;</li>
<li><strong>&#8220;Are our patient scans used to train your models, and can we opt out?&#8221;</strong> Both answers are defensible &#8211; but you must know which one you are agreeing to.</li>
<li><strong>&#8220;What is the FDA clearance, and what is the tool cleared to do?&#8221;</strong> A 510(k)-cleared diagnostic-<em>assist</em> is a second reader, not an autonomous diagnostician. Know the boundary so your team uses it inside its lane.</li>
<li><strong>&#8220;How does this connect to our imaging system and network?&#8221;</strong> Cloud round-trip, on-prem appliance or a plug-in to your existing software &#8211; each has a different security and reliability profile, and your IT partner should size it up before go-live.</li>
</ol>
<h2>A second opinion, not a replacement</h2>
<p><figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/pearl-second-opinion-3d-cbct-ai-dental-practice-4.jpg" alt="Two overlapping panels of the same blue dental radiograph, one reviewed by a human eye icon and one with an AI highlight overlay, meeting in the middle to show AI and clinician confirming each other" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The point of a second opinion is that a human still owns the first one. The AI proposes; the dentist disposes &#8211; and the chart should show who decided.</figcaption></figure>
</p>
<p>The name is honest about the role. A tool like this earns its keep by catching the thing a tired clinician glances past at the end of a long day, and by giving a general dentist more confidence in reading a volume that used to be shipped out for interpretation. But the clinician still owns the diagnosis. The most important workflow decision is a documentation one: when the AI flags something and the dentist agrees or overrides, the chart should reflect that a human made the call. That habit protects the patient, protects the practice, and keeps the tool firmly in the assist role the FDA cleared it for.</p>
<p>It also pairs with the buying discipline we have argued for all along &#8211; the same posture behind treating <a href="https://compudent.com/fda-524b-cybersecurity-dental-imaging-device-purchasing/">imaging-device cybersecurity as a purchasing checklist</a>. New capability is worth having; it is worth having on your terms.</p>
<h2>What to do this week</h2>
<p>Nothing here is urgent, and that is the point &#8211; it is far cheaper to decide how AI enters your practice than to discover after the fact that patient scans have been leaving it under terms nobody read. If a diagnostic-assist tool is on your radar, add the four questions above to the evaluation. If one is already in use somewhere in the practice, take ten minutes to confirm the data path and the agreement behind it.</p>
<p>At Compudent Systems we help dental practices across the GTA and Ontario vet imaging and AI software before it is adopted, map how patient data moves on and off the network, and put the segmentation, agreements and safeguards in place to keep it compliant and secure. If you are weighing an AI imaging tool &#8211; or want to know exactly where your scans already go &#8211; <a href="https://compudent.com/contact/">contact Compudent Systems</a> for an assessment. The best time to set the terms is before the first scan leaves the building.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.nextdentallab.com/2026-dental-software-news-ai-integration-trends" target="_blank" rel="noopener">Next Dental Lab &#8211; 2026 Dental Software News: AI Integration Trends</a></li>
<li><a href="https://www.oralhealthgroup.com/dental-industry/timeline-five-fda-clearances-for-3d-dental-ai-as-pearl-launches-cbct-software-for-general-dentists-1003998767" target="_blank" rel="noopener">Oral Health Group &#8211; Five FDA clearances for 3D dental AI as Pearl launches CBCT software for general dentists</a></li>
<li><a href="https://www.ada.org/resources/research/health-policy-institute" target="_blank" rel="noopener">ADA Health Policy Institute &#8211; The State of the U.S. Dental Economy, Q2 2026</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/medit-auravue-overjet-ai-dental-practice-imaging/">One Screen for Scans and X-Rays: What Medit&#8217;s AuraVue With Overjet AI Means for Your Dental Practice</a></li>
<li><a href="https://compudent.com/how-dental-ai-connects-imaging-twain-dicom-api-pms-bridges/">How Dental AI Tools Connect to Your Imaging Software: TWAIN, DICOM, API, and PMS Bridges</a></li>
<li><a href="https://compudent.com/chatgpt-hipaa-dental-practice/">Can Your Dental Practice Use ChatGPT Without Breaking HIPAA and PHIPA? A 2026 Compliance Guide</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/pearl-second-opinion-3d-cbct-ai-dental-practice/">AI That Reads Your CBCT Scans Just Arrived for General Dentists: What Pearl&#8217;s Second Opinion 3D Means for Your Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Congress Wants Mandatory Cybersecurity Standards for Healthcare: What HISAA Would Mean for Your Dental Practice</title>
		<link>https://compudent.com/hisaa-mandatory-healthcare-cybersecurity-standards-dental-practice/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Thu, 24 Sep 2026 11:31:19 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[dental IT]]></category>
		<category><![CDATA[healthcare cybersecurity]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HISAA]]></category>
		<category><![CDATA[PHIPA]]></category>
		<guid isPermaLink="false">https://compudent.com/hisaa-mandatory-healthcare-cybersecurity-standards-dental-practice/</guid>

					<description><![CDATA[<p>A bill reintroduced in the Senate would replace healthcare's voluntary cybersecurity guidance with enforceable minimum standards, mandatory audits, annual executive sign-off, and far larger penalties. Here is what the Health Infrastructure Security and Accountability Act would require, and why a small dental practice should start preparing now rather than later.</p>
<p>The post <a href="https://compudent.com/hisaa-mandatory-healthcare-cybersecurity-standards-dental-practice/">Congress Wants Mandatory Cybersecurity Standards for Healthcare: What HISAA Would Mean for Your Dental Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>For years, the cybersecurity expectations placed on healthcare have been a patchwork of &#8220;you really should&#8221; rather than &#8220;you must.&#8221; That may be about to change. On September 17, 2026, U.S. Senators Mark Warner and Ron Wyden reintroduced the <strong>Health Infrastructure Security and Accountability Act</strong> (HISAA) &mdash; a bill that would replace healthcare&#8217;s voluntary cybersecurity guidance with enforceable minimum standards, mandatory audits, annual executive sign-off, and dramatically higher penalties.</p>
<p>It is federal legislation, not yet law, and its path through Congress is uncertain. But for a dental practice, the direction of travel matters more than the odds of any single bill. Regulators and lawmakers have concluded that asking nicely hasn&#8217;t worked, and the requirements being drafted are a preview of the standard every practice will eventually be held to. Here is what HISAA would demand, and what a small office should take from it right now.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hisaa-mandatory-healthcare-cybersecurity-standards-dental-practice-1-scaled.jpg" alt="The U.S. Capitol dome behind a glowing digital shield representing federal healthcare cybersecurity legislation" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">A reintroduced Senate bill would turn healthcare&#8217;s voluntary cybersecurity guidance into enforceable law.</figcaption></figure>
<h2>Why lawmakers say voluntary standards failed</h2>
<p>The argument behind the bill is a numbers story. When HISAA was first introduced in 2024, 394 large hacking-related breaches had been reported to the HHS Office for Civil Rights, exposing the protected health information of roughly 43 million Americans. Two years later, the year-to-date figures the senators cite are worse: 426 hacking-related breaches and about 73 million individuals affected &mdash; a jump of roughly 70% in people exposed.</p>
<p>In 2024, OCR published two tiers of voluntary <em>cybersecurity performance goals</em> (Essential and Enhanced) for the health sector, and predicted at the time that voluntary measures alone wouldn&#8217;t move the needle. The senators frame these attacks bluntly as &#8220;entirely preventable&#8221; results of &#8220;lax cybersecurity practices by health care providers and their business partners.&#8221; HISAA is their answer: make the floor mandatory. This is the same regulatory shift already visible elsewhere &mdash; the FDA, for example, has moved from suggesting to <a href="https://compudent.com/fda-524b-cybersecurity-dental-imaging-device-purchasing/">requiring imaging devices to be cyber-secure by design</a>.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hisaa-mandatory-healthcare-cybersecurity-standards-dental-practice-2.jpg" alt="Stylized infographic of a rising trend line representing increasing healthcare data breaches" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Hacking-related healthcare breaches keep climbing; lawmakers argue voluntary standards are not slowing them.</figcaption></figure>
<h2>What HISAA would actually require</h2>
<p>The 2026 bill is largely unchanged from the 2024 version, with the timeline shifted forward. Its core requirements would apply to covered entities <em>and</em> their business associates &mdash; language that reaches well beyond hospitals and into ordinary practices and the vendors they rely on:</p>
<ul>
<li><strong>Mandatory minimum cybersecurity standards</strong> established, enforced, and updated by HHS at least every two years, with heightened requirements for &#8220;systemically important&#8221; entities.</li>
<li><strong>Continuity and recovery plans</strong> for technical failures, disruptive cyberattacks, and natural disasters &mdash; plus <strong>stress tests</strong> to prove you can actually recover essential functions, not just claim you can.</li>
<li><strong>Annual risk analyses</strong>, including a specific assessment of the risk you inherit through your business associates.</li>
<li><strong>Written annual attestations signed by the CEO and the chief information security officer</strong>, formally certifying the organization meets the applicable standards.</li>
<li><strong>Independent audits</strong> of security measures, plus annual HHS audits of at least 20 regulated entities, focused on those of systemic importance.</li>
<li><strong>Much larger penalties.</strong> The bill would lift the current caps, setting escalating minimums &mdash; from $500 for a no-knowledge violation up to $250,000 for uncorrected willful neglect.</li>
</ul>
<p>To soften the blow for smaller and rural providers, HISAA pairs the mandates with money: a proposed $1.3 billion investment, including $800 million in up-front funding for hospitals in rural and underserved communities to adopt the essential goals, and $500 million in incentives for adopting the enhanced ones.</p>
<h2>What this means for a dental practice</h2>
<p>It is tempting to read &#8220;systemically important entities&#8221; and &#8220;annual HHS audits of at least 20 organizations&#8221; and conclude this is a big-hospital problem. That would be a mistake for two reasons.</p>
<p>First, the <strong>minimum standards and the business-associate language apply broadly</strong> &mdash; not only to the twenty organizations HHS audits each year. A dental practice is a covered entity, and your practice-management host, billing service, and imaging-software vendor are business associates. When a bill makes you responsible for assessing the risk your vendors carry, the collapse of an outsourced partner becomes your compliance problem, not just theirs. Practices learned that lesson the hard way when a billing vendor like <a href="https://compudent.com/eassist-direwolf-dental-billing-rcm-vendor-ransomware/">eAssist landed on a ransomware leak site</a>, dragging the patient data of the practices it served along with it.</p>
<p>Second, even if HISAA never passes in its current form, its requirements are a <strong>checklist of where the bar is heading</strong>. Annual risk analyses, tested recovery plans, vendor risk assessment, and leadership accountability are exactly what the delayed HIPAA Security Rule update also points toward. The specifics of the breach headlines change, but the <a href="https://compudent.com/dental-data-breaches-2026-lessons/">lessons from this year&#8217;s dental data breaches</a> keep repeating: the practices that get hurt are the ones treating security as a someday project.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hisaa-mandatory-healthcare-cybersecurity-standards-dental-practice-3.jpg" alt="A dentist and practice manager reviewing a cybersecurity compliance checklist on a tablet" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The proposed rules reach small practices too: annual risk analyses and business-associate scrutiny would become table stakes.</figcaption></figure>
<h2>The four things worth doing before any law forces you</h2>
<p>You don&#8217;t need to wait for a final vote to be in a strong position. Everything HISAA would mandate is defensible, sensible practice today &mdash; and doing it now is far cheaper than doing it under an audit deadline:</p>
<ol>
<li><strong>Run a real annual risk analysis.</strong> Not a checkbox &mdash; an honest inventory of where protected health information lives, who can reach it, and where it is exposed. This is already a HIPAA expectation; HISAA would simply put teeth behind it.</li>
<li><strong>Write down your vendors and their risk.</strong> List every business associate that touches patient data, confirm you have current agreements, and ask each one what happens to your data if <em>they</em> are breached. Their weakness is your liability.</li>
<li><strong>Have a recovery plan you have actually tested.</strong> A <a href="https://compudent.com/business-continuity-downtime-plan-dental-practice/">downtime and business-continuity plan</a> only counts if you&#8217;ve rehearsed it. HISAA&#8217;s &#8220;stress test&#8221; language is a reminder that an untested backup is a hope, not a plan.</li>
<li><strong>Make one person accountable.</strong> The bill&#8217;s CEO/CISO attestation reflects a simple truth: security that is &#8220;everyone&#8217;s job&#8221; is usually no one&#8217;s. In a small practice, name an owner and give them a partner who does this for a living.</li>
</ol>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hisaa-mandatory-healthcare-cybersecurity-standards-dental-practice-4.jpg" alt="A signed attestation document beside a pen and a security shield icon" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">HISAA would require an annual statement signed by leadership attesting that security standards are met.</figcaption></figure>
<h2>The trend line is the real story</h2>
<p>Whether HISAA advances this session, stalls, or returns again in two years, the message from Washington is consistent and getting louder: voluntary is over. Between rising breach numbers, the FDA&#8217;s device mandates, the pending HIPAA Security Rule changes, and now a bill that would attach personal executive sign-off and six-figure penalties to healthcare security, the era of good intentions is closing. Practices that build the habits now &mdash; documented risk analyses, tested recovery, vendor oversight, clear accountability &mdash; won&#8217;t be scrambling when the floor becomes mandatory.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/hisaa-mandatory-healthcare-cybersecurity-standards-dental-practice-5.jpg" alt="A secured dental practice server cabinet with a padlock icon representing protected patient data" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Whether or not the bill passes, its direction of travel is clear: security expectations for practices are only rising.</figcaption></figure>
<h2>Where Compudent fits</h2>
<p>Turning a dense piece of proposed legislation into a short list of things your practice should actually do is exactly the kind of translation we handle every day. Compudent Systems works with dental and medical practices across the GTA and Ontario to run genuine risk analyses, keep business-associate agreements current, build and test recovery plans, and put a steady hand on security so compliance isn&#8217;t a fire drill. If you&#8217;d like to know how your practice measures against where the standards are heading &mdash; before anyone requires you to &mdash; <a href="https://compudent.com/">reach out to Compudent for an assessment</a>. Getting ahead of the rules is always cheaper than catching up to them.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.hipaajournal.com/health-infrastructure-security-and-accountability-act-2026/" target="_blank" rel="noopener">Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act</a></li>
<li><a href="https://www.warner.senate.gov/newsroom/press-releases/warner-wyden-introduce-bill-to-strengthen-cybersecurity-standards-for-american-health-care-system/" target="_blank" rel="noopener">Warner, Wyden Introduce Bill to Strengthen Cybersecurity Standards for American Health Care System</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/2026-hipaa-security-rule-changes-what-dental-practices-need-to-know/">2026 HIPAA Security Rule Changes: What Dental Practices Need to Know</a></li>
<li><a href="https://compudent.com/new-hipaa-security-rule-requirements-mandatory-vulnerability-scanning-and-penetration-testing-for-dental-practices/">New HIPAA Security Rule Requirements: Mandatory Vulnerability Scanning and Penetration Testing for Dental Practices</a></li>
<li><a href="https://compudent.com/new-hipaa-privacy-rule-update-what-dental-practices-must-do-before-the-february-16-deadline/">New HIPAA Privacy Rule Update: What Dental Practices Must Do Before the February 16 Deadline</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/hisaa-mandatory-healthcare-cybersecurity-standards-dental-practice/">Congress Wants Mandatory Cybersecurity Standards for Healthcare: What HISAA Would Mean for Your Dental Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>September&#8217;s Windows Updates Are Breaking Always On VPN: What Practices With Remote Access Need to Check Now</title>
		<link>https://compudent.com/september-2026-windows-update-breaks-always-on-vpn-dental-practice/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 12:27:04 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Always On VPN]]></category>
		<category><![CDATA[dental IT]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[remote access]]></category>
		<category><![CDATA[Windows Update]]></category>
		<guid isPermaLink="false">https://compudent.com/september-2026-windows-update-breaks-always-on-vpn-dental-practice/</guid>

					<description><![CDATA[<p>Microsoft's September security updates are knocking out Always On VPN connections on Windows. If your team logs in from home or a satellite office, here is exactly what breaks, how to confirm it, and how to restore secure remote access without leaving your practice exposed.</p>
<p>The post <a href="https://compudent.com/september-2026-windows-update-breaks-always-on-vpn-dental-practice/">September&#8217;s Windows Updates Are Breaking Always On VPN: What Practices With Remote Access Need to Check Now</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>If a team member who normally works from home or a satellite operatory suddenly can&#8217;t reach your practice server this week, don&#8217;t assume it&#8217;s their internet. Microsoft has confirmed that its September security updates are breaking <strong>Always On VPN</strong> connections on Windows &mdash; the same technology many practices rely on to give staff automatic, encrypted access back to the office network.</p>
<p>This is the kind of problem that looks like a dozen small issues at once: charts won&#8217;t load, the practice management system times out, imaging can&#8217;t reach the server. Underneath, it&#8217;s one cause. Here&#8217;s what is happening and how to handle it without opening a hole in your defenses.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/september-2026-windows-update-breaks-always-on-vpn-dental-practice-1-scaled.jpg" alt="Dental practice staff member facing a failed VPN connection on a desktop computer" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">A broken VPN tunnel usually shows up first thing in the morning, when a remote or branch login silently fails.</figcaption></figure>
<h2>What Always On VPN actually does for your practice</h2>
<p>Always On VPN is a Windows feature that automatically establishes a secure, encrypted tunnel between a remote computer and your practice network. Unlike an old-fashioned VPN client someone has to remember to launch, it connects on its own the moment the device has internet &mdash; which is exactly why it&#8217;s popular for remote administrators, a bookkeeper who works from home, or a second location sharing your central server.</p>
<p>That convenience is also why an outage is easy to miss at first. Nobody &#8220;forgot to connect.&#8221; The tunnel simply fails to form, and every service that depends on the office network fails with it. For a practice handling patient records, that tunnel is not a nicety &mdash; it is the encrypted boundary keeping protected health information off the open internet.</p>
<h2>What the September updates break</h2>
<p>Microsoft has acknowledged that the September cumulative updates for Windows can cause Always On VPN connections to fail after installation. Affected devices install the update normally, then can no longer bring up the VPN tunnel &mdash; often with a generic connection error rather than a clear &#8220;this update did it&#8221; message. Everything else on the machine works, which is what sends people chasing the wrong culprit.</p>
<p>This follows a familiar pattern. Earlier the same month, a separate Windows Server update was <a href="https://compudent.com/september-2026-windows-server-update-breaks-remote-desktop-rds-dental-practice/">breaking Remote Desktop sessions</a> for practices that rely on RDS. When a monthly patch collides with the very tools you use to reach the office remotely, the fix is rarely to stop patching &mdash; it&#8217;s to patch deliberately.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/september-2026-windows-update-breaks-always-on-vpn-dental-practice-2.jpg" alt="Illustration of an encrypted VPN tunnel with a break in the middle representing a failed connection" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Always On VPN builds an automatic encrypted tunnel back to the practice; a bad update can sever it while everything else keeps working.</figcaption></figure>
<h2>How to confirm this is your problem</h2>
<p>Before you change anything, verify the pattern. A few quick checks separate an update-induced VPN failure from an unrelated network hiccup:</p>
<ul>
<li><strong>Timing:</strong> Did the failures start right after the September updates installed? Check Windows Update history on an affected device and note the date it applied.</li>
<li><strong>Scope:</strong> Is it only remote or branch users on Always On VPN who are affected, while in-office computers work fine? That points squarely at the tunnel, not the server.</li>
<li><strong>Consistency:</strong> Does the tunnel fail to establish on every attempt, on multiple devices that all received the same update? One machine is a coincidence; several is a pattern.</li>
<li><strong>Everything-else-works test:</strong> Can the affected device browse the web and reach non-VPN resources normally? If yes, the problem is the tunnel, not connectivity.</li>
</ul>
<p>Document what you find. Knowing which specific update is installed is what lets your IT provider match it to Microsoft&#8217;s guidance and choose the right remedy.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/september-2026-windows-update-breaks-always-on-vpn-dental-practice-3.jpg" alt="IT technician reviewing Windows Update history on a laptop in a server room" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Confirming which cumulative update landed is the first diagnostic step before any rollback decision.</figcaption></figure>
<h2>Restoring access &mdash; the safe way</h2>
<p>The dangerous shortcut here is obvious and tempting: turn the VPN off and let people connect &#8220;just for today&#8221; some other way. Don&#8217;t. Exposing a practice-management server or opening remote access without the encrypted tunnel is exactly the kind of gap ransomware crews and credential thieves look for. A one-day workaround becomes a permanent liability.</p>
<p>Instead, work through the options in order of preference:</p>
<ol>
<li><strong>Apply Microsoft&#8217;s targeted fix.</strong> When Microsoft acknowledges an update-caused regression like this, it typically ships an out-of-band fix or a Known Issue Rollback that resolves it without removing your security patches. This is the cleanest path &mdash; you keep the protection and regain the tunnel.</li>
<li><strong>Roll back only if you must, and briefly.</strong> Uninstalling the offending cumulative update can restore VPN connectivity, but it also strips out that month&#8217;s security fixes. Treat rollback as a short bridge, not a destination, and reapply patches as soon as the corrected update is available.</li>
<li><strong>Use a secured alternate path in the meantime.</strong> If a user genuinely cannot work, route them through another already-hardened, encrypted method rather than a bare connection &mdash; and log it, so nothing is left open by accident.</li>
</ol>
<p>Whatever route you take, this is a good moment to confirm your <a href="https://compudent.com/business-continuity-downtime-plan-dental-practice/">downtime and business-continuity plan</a> actually covers &#8220;remote access is down.&#8221; A practice that can keep seeing patients on paper for a few hours is a practice that never has to make a risky security compromise under pressure.</p>
<h2>The bigger lesson: patch on purpose, not on autopilot</h2>
<p>Two remote-access-breaking updates in a single month is a reminder that fully automatic, immediate patching has a cost. The answer isn&#8217;t to delay security updates &mdash; unpatched systems are how most breaches start, and this same month&#8217;s <a href="https://compudent.com/september-2026-patch-tuesday-974-vulnerabilities-dental-practice/">Patch Tuesday closed hundreds of vulnerabilities</a>, some already being exploited. The answer is a small buffer: let critical updates land on a test or pilot machine first, watch for exactly this kind of regression for a day or two, then roll out to the rest of the practice.</p>
<p>For a busy office, that discipline is hard to maintain in-house. It usually falls to whoever has a spare moment &mdash; which means it doesn&#8217;t happen consistently, and you find out about a broken tunnel from a frustrated staff member instead of a test bench.</p>
<figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/september-2026-windows-update-breaks-always-on-vpn-dental-practice-4.jpg" alt="A remote-access security checklist on a desk beside a laptop and phone" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">Restoring access safely means having a checklist: confirm the patch, test the tunnel, and never disable encryption as a shortcut.</figcaption></figure>
<h2>Where Compudent fits</h2>
<p>Managing Windows updates so they protect your practice without knocking out remote access is exactly the kind of routine that benefits from a steady hand. Compudent Systems works with dental and medical practices across the GTA and Ontario to keep patching deliberate, remote access secure, and downtime rare. If your Always On VPN has gone quiet this week &mdash; or you&#8217;d simply like update rollouts handled so surprises like this never reach your front desk &mdash; <a href="https://compudent.com/">reach out to Compudent for an assessment</a>. Secure remote access should be something you never have to think about.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/microsoft/" target="_blank" rel="noopener">Microsoft: September Windows updates break Always On VPN connections</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/september-2026-windows-server-update-breaks-remote-desktop-rds-dental-practice/">The Patch That Locks Out the Front Desk: September&#8217;s Windows Server Update Is Breaking Remote Desktop</a></li>
<li><a href="https://compudent.com/windows-ike-cve-2026-33824-rce-dental-practice/">A Single Packet, No Password Required: The Actively Exploited Windows IKE Flaw (CVE-2026-33824) and Your Practice</a></li>
<li><a href="https://compudent.com/checkpoint-vpn-cve-2026-85102-85103-dental-practice-remote-access/">The Gateway That Lets Your Team In Can Let Attackers In Too: Critical Check Point VPN Flaws (CVE-2026-85102 / 85103) and Your Practice</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/september-2026-windows-update-breaks-always-on-vpn-dental-practice/">September&#8217;s Windows Updates Are Breaking Always On VPN: What Practices With Remote Access Need to Check Now</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The FDA Now Requires Imaging Devices to Be Cyber-Secure by Design. Here Is How to Make It Your Purchasing Checklist.</title>
		<link>https://compudent.com/fda-524b-cybersecurity-dental-imaging-device-purchasing/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 09:38:13 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[CBCT]]></category>
		<category><![CDATA[dental imaging]]></category>
		<category><![CDATA[dental practice IT]]></category>
		<category><![CDATA[FDA]]></category>
		<category><![CDATA[medical device cybersecurity]]></category>
		<category><![CDATA[PHIPA]]></category>
		<category><![CDATA[procurement]]></category>
		<category><![CDATA[QMSR]]></category>
		<category><![CDATA[SBOM]]></category>
		<category><![CDATA[Section 524B]]></category>
		<guid isPermaLink="false">https://compudent.com/fda-524b-cybersecurity-dental-imaging-device-purchasing/</guid>

					<description><![CDATA[<p>Since 2023, U.S. law has required the makers of connected medical and dental imaging devices to build cybersecurity in and prove it to the FDA. Most practices have never thought to ask about it. Here is how to turn that rule into three questions you ask before you sign a purchase order.</p>
<p>The post <a href="https://compudent.com/fda-524b-cybersecurity-dental-imaging-device-purchasing/">The FDA Now Requires Imaging Devices to Be Cyber-Secure by Design. Here Is How to Make It Your Purchasing Checklist.</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>When your practice buys a new cone-beam CT unit, an intraoral sensor or a chairside scanner, the questions in the room are predictable: image quality, workflow, price, service contract. There is one question almost no one asks &#8211; and since 2023, U.S. federal law has quietly made it a fair one. The manufacturer of that connected device now has a legal duty to build cybersecurity into it and prove that to the FDA before it can be sold. You paid for that work. You are entitled to see it. Most practices never think to look.</p>
<p>This is not a breach alert and there is nothing to patch this morning. It is something more useful: a durable rule you can turn into leverage at the exact moment you have the most of it &#8211; before you sign the purchase order.</p>
<h2>What the law actually requires</h2>
<p>In December 2022, Congress added <strong>Section 524B</strong> to the Food, Drug, and Cosmetic Act, and it took effect in March 2023. It applies to &#8220;cyber devices&#8221; &#8211; broadly, any device that includes software and can connect to the internet or a network, which covers essentially every modern digital imaging system in a dental office. To win FDA clearance, the maker must now do several things and document them in the premarket submission:</p>
<ul>
<li>Design, develop and maintain the device to be reasonably cyber-secure &#8211; so-called <strong>secure by design</strong>, rather than security added after the fact.</li>
<li>Provide a plan to <strong>monitor, identify and address</strong> post-market vulnerabilities, including issuing patches on a reasonable cadence and out-of-cycle for critical flaws.</li>
<li>Publish a <strong>coordinated vulnerability disclosure</strong> process, so researchers have a legitimate way to report problems.</li>
<li>Provide a <strong>Software Bill of Materials (SBOM)</strong> &#8211; a machine-readable inventory of the software components inside the device, including the open-source libraries it depends on.</li>
</ul>
<p><figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/fda-524b-cybersecurity-dental-imaging-device-purchasing-1-scaled.jpg" alt="A modern dental cone-beam CT scanner shown as a blue device with a protective cybersecurity shield built directly into the hardware and a small approval checkmark badge, illustrating imaging devices that are secure by design under FDA rules" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The idea behind the rule is simple: security should be engineered into an imaging device before it ships, not bolted on by the practice years later.</figcaption></figure>
</p>
<p>The FDA has been willing to refuse submissions that fail to include this material since late 2023. In 2026 the guidance was refreshed to line up with the agency&#8217;s new <strong>Quality Management System Regulation (QMSR)</strong>, which folds these expectations into the manufacturer&#8217;s overall quality system. The headline for a buyer is unchanged and worth repeating: the SBOM and cybersecurity requirements did not loosen. They are the baseline now.</p>
<h2>Why a dental practice should care about a manufacturing rule</h2>
<p>Because the burden of a device&#8217;s flaws does not stay with the manufacturer. It lands on the practice that owns the device, holds the patient records it touches, and answers to patients and to PHIPA when something goes wrong. We have written before about how imaging hardware becomes a security question the moment it joins your network &#8211; from <a href="https://compudent.com/medical-device-provenance-supply-chain-dental-practice/">where a sensor was made and what it quietly talks to</a>, to the awkward reality of <a href="https://compudent.com/legacy-imaging-device-network-segmentation-dental-practice/">keeping an older scanner or CBCT running safely after the vendor stops patching it</a>.</p>
<p>Section 524B attacks that problem at the source. A device built to the standard is one whose maker has committed, on the record, to shipping patches and telling you about vulnerabilities for the life of the product. A device that predates or ignores the standard is one where you are on your own. The difference between those two purchases is invisible on the spec sheet and enormous over the eight-to-ten years the equipment will sit in your operatory.</p>
<h2>The one document that changes your leverage: the SBOM</h2>
<p><figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/fda-524b-cybersecurity-dental-imaging-device-purchasing-2.jpg" alt="A blue imaging device connected to an orderly exploded diagram of dozens of small software component blocks it is built from, with a magnifying glass over the list, illustrating a Software Bill of Materials that reveals what is inside a device" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">A Software Bill of Materials is an ingredients list for the device&#8217;s software &#8211; so when a component makes headlines, you can tell in minutes whether your scanner contains it.</figcaption></figure>
</p>
<p>Of everything in the rule, the SBOM is the piece a practice can use directly. Think of it as an ingredients list for the device&#8217;s software. Modern imaging systems are assembled from dozens of third-party and open-source components you never chose and cannot see &#8211; and those components are where a growing share of critical vulnerabilities live. When one of them makes the news, the first question is always the same: <em>do we run it?</em></p>
<p>Without an SBOM, answering that means waiting on the vendor&#8217;s goodwill and hoping they respond before an attacker does. With one, you &#8211; or the IT partner who manages your network &#8211; can check in minutes whether the flawed component is inside your scanner. That is the same discipline that turned a recent scramble over a buried software flaw into a five-minute lookup for practices that knew what they were running. The SBOM is what makes &#8220;know what you run&#8221; possible for a sealed medical device.</p>
<h2>Turn the rule into three purchasing questions</h2>
<p><figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/fda-524b-cybersecurity-dental-imaging-device-purchasing-3.jpg" alt="A calm blue practice decision-maker with a three-point checklist speech bubble asking questions of a vendor holding an imaging device, with an unsigned purchase order between them, illustrating asking cybersecurity questions before buying" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">You do not need to read the FDA submission. You need three questions and the confidence to withhold the purchase order until you get straight answers.</figcaption></figure>
</p>
<p>You do not need to read an FDA submission or become a compliance expert. You need to make three requests part of every imaging-equipment evaluation, and treat a vague answer as the answer:</p>
<ol>
<li><strong>&#8220;Please provide the SBOM for this device.&#8221;</strong> A vendor building to the standard has one ready. Hesitation, confusion or a promise to &#8220;look into it&#8221; tells you where cybersecurity sits on their priority list.</li>
<li><strong>&#8220;What is your patching commitment and your end-of-support date?&#8221;</strong> Get the cadence for routine and emergency updates, and the year support ends, <em>in writing</em>. This is the single most valuable fact for planning, because the device will outlive its support window and you need to know when.</li>
<li><strong>&#8220;How do I report a security problem, and how will you notify me of one?&#8221;</strong> A real coordinated-disclosure process and a defined customer-notification path separate a serious manufacturer from one that will go quiet the day a flaw surfaces.</li>
</ol>
<p><figure style="margin:24px 0;text-align:center;"><img decoding="async" src="https://compudent.com/wp-content/uploads/2026/09/fda-524b-cybersecurity-dental-imaging-device-purchasing-4.jpg" alt="A blue imaging device on a timeline stretching into the future with recurring update-and-shield badges representing ongoing vendor patching, and one faded badge at the far end marking an end-of-support point to plan for" style="max-width:100%;height:auto;border-radius:6px;" /><figcaption style="text-align:center;font-size:0.9em;color:#666;">The rule is a floor, not a guarantee. The device you buy today will outlive its support window &#8211; so ask, in writing, how long the patches will keep coming.</figcaption></figure>
</p>
<p>None of this slows a purchase you were going to make anyway. It simply ensures that when two units are close on price and image quality &#8211; the situation you are usually in &#8211; the tiebreaker is the one that will cost you the least grief three years from now. It also pairs naturally with the questions you should already be asking about how a new device connects to your network, the same due diligence we applied when the <a href="https://compudent.com/fda-velmeni-ai-cbct-dental-imaging/">FDA cleared AI that reads 3D dental scans</a> and when a widely used <a href="https://compudent.com/orthanc-dicom-server-cve-2026-87020-dental-pacs/">imaging server flaw showed why a PACS should never face the internet</a>.</p>
<h2>What to do this week</h2>
<p>Nothing here is urgent, and that is the point &#8211; it is far cheaper to build this into how you buy than to retrofit it after an incident. If you have a device purchase on the horizon, add the three questions above to your evaluation. If your existing fleet is a mystery, start a simple inventory: what each connected imaging device is, what it runs, when its support ends, and whether the vendor can supply an SBOM. That list is the foundation of every good decision that follows.</p>
<p>At Compudent Systems we help dental practices across the GTA and Ontario vet imaging and IT equipment before it is purchased, inventory what is already on the network, and build the segmentation and monitoring that keep it all safe for its full service life. If you have a device on order &#8211; or a fleet you have never fully mapped &#8211; <a href="https://compudent.com/contact/">contact Compudent Systems</a> for an assessment. The best time to ask these questions is before the invoice is paid.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket" target="_blank" rel="noopener">FDA &#8211; Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions</a></li>
<li><a href="https://www.interlynk.io/resources/fda-sbom-requirements-medical-devices" target="_blank" rel="noopener">Interlynk &#8211; FDA SBOM Requirements for Medical Devices: The Complete 2026 Guide</a></li>
<li><a href="https://censinet.com/perspectives/fda-cybersecurity-guidance-medical-device-reporting-rules" target="_blank" rel="noopener">Censinet &#8211; FDA Cybersecurity Guidance: Medical Device Reporting Rules</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/medical-device-provenance-supply-chain-dental-practice/">Where Was Your Imaging Sensor Made, and What Is It Talking To? Device Provenance Is Now a Dental Practice Security Question</a></li>
<li><a href="https://compudent.com/legacy-imaging-device-network-segmentation-dental-practice/">You Can&#8217;t Patch That Old Sensor or CBCT: How to Safely Keep Legacy Imaging Devices on Your Dental Network</a></li>
<li><a href="https://compudent.com/medit-auravue-overjet-ai-dental-practice-imaging/">One Screen for Scans and X-Rays: What Medit&#8217;s AuraVue With Overjet AI Means for Your Dental Practice</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/fda-524b-cybersecurity-dental-imaging-device-purchasing/">The FDA Now Requires Imaging Devices to Be Cyber-Secure by Design. Here Is How to Make It Your Purchasing Checklist.</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Zero-Day Is Hitting Healthcare in Software Nobody Names: The FastJson Flaw (CVE-2026-16723) and Why You Can&#8217;t Protect Code You Don&#8217;t Know You Run</title>
		<link>https://compudent.com/fastjson-cve-2026-16723-dental-practice-software-inventory/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Mon, 21 Sep 2026 09:39:41 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[CVE-2026-16723]]></category>
		<category><![CDATA[dental practice IT]]></category>
		<category><![CDATA[FastJson]]></category>
		<category><![CDATA[healthcare cybersecurity]]></category>
		<category><![CDATA[open-source components]]></category>
		<category><![CDATA[PHIPA]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[software inventory]]></category>
		<category><![CDATA[supply chain]]></category>
		<category><![CDATA[zero-day]]></category>
		<guid isPermaLink="false">https://compudent.com/fastjson-cve-2026-16723-dental-practice-software-inventory/</guid>

					<description><![CDATA[<p>Security firms are tracking active, unpatched attacks against a flaw in FastJson - an open-source Java component buried inside other people's software - and healthcare is on the list of industries being hit. Most dental practices will never run FastJson directly. The reason this still matters: you cannot patch, or even worry about, software you do not know is running in your building and in your vendors' products. Here is the flaw, the honest scope for a dental office, and the discipline it should prompt.</p>
<p>The post <a href="https://compudent.com/fastjson-cve-2026-16723-dental-practice-software-inventory/">A Zero-Day Is Hitting Healthcare in Software Nobody Names: The FastJson Flaw (CVE-2026-16723) and Why You Can&#8217;t Protect Code You Don&#8217;t Know You Run</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Some security alerts name a product you recognize &#8211; Windows, a firewall, a backup tool &#8211; and you can quickly decide whether it is yours to worry about. This week&#8217;s is the uncomfortable other kind. Security firms are tracking active, ongoing attacks against a flaw in a piece of software called <strong>FastJson</strong>, and the researchers watching it confirm the targets include <strong>healthcare</strong> organizations. Most dental practices have never heard of FastJson and will never install it on purpose. That is exactly why it is worth three minutes of your attention: the hardest software to protect is the software you do not know you are running.</p>
<h2>What is actually happening</h2>
<p>FastJson is an <strong>open-source Java library</strong> &#8211; a small, free building block that programs use to convert data to and from the JSON format. It is maintained by Alibaba and is embedded inside a great many applications, particularly enterprise and Chinese-origin software. On September 2026, an offensive-security firm published a technical write-up of a serious flaw, now tracked as <strong>CVE-2026-16723</strong>, affecting FastJson versions <strong>1.2.68 through 1.2.83</strong>. Within days, security companies ThreatBook and Imperva reported it was being <strong>actively exploited in the wild</strong> against organizations across financial services, healthcare, computing and retail &#8211; almost entirely in the United States so far, with a handful of attacks already seen in <strong>Canada</strong> and Singapore, and expected to spread.</p>
<p>The flaw allows <strong>remote code execution with no user interaction and no need for elevated privileges</strong>. In plain terms: an attacker can send a specially crafted piece of data to a vulnerable, internet-facing application and make it run their code &#8211; no stolen password, no employee clicking a bad link, no warning. That combination is about as bad as a vulnerability gets. Worse, at the time of writing there was <strong>no patched release</strong> for the affected 1.x branch; the guidance is to move to the maintained successor library (fastjson2) and put network and web-application-firewall protections in front of anything exposed. A flaw that is unauthenticated, already exploited, and unpatched is the trifecta that gets defenders out of their chairs.</p>
<h2>&#8220;So is this us?&#8221; &#8211; the honest answer</h2>
<p>We would rather give you a straight answer than manufacture alarm. For a typical dental practice, the <strong>direct</strong> exposure to this specific flaw is <strong>low and, more importantly, uncertain</strong>. FastJson is a <em>Java</em> component, and the mainstream systems most Canadian practices run &#8211; Dentrix, Eaglesoft, Open Dental and their kin &#8211; are generally built on Microsoft&#8217;s .NET stack, not Java. So the odds that this exact library is sitting on your operatory PC are slim.</p>
<p>But notice the word &#8220;uncertain,&#8221; because that is the whole point. The reason nobody can hand you a confident &#8220;no&#8221; is that components like FastJson are <strong>buried invisibly inside other software</strong> &#8211; inside a vendor&#8217;s server product, an imaging or integration server, a web application your website runs on, or a system your IT or hosting provider operates on your behalf. The reflex &#8220;we don&#8217;t use Java, so this isn&#8217;t about us&#8221; is comforting and frequently wrong, because you did not choose these components and cannot see them from the login screen. We ran into the same theme when <a href="https://compudent.com/orthanc-dicom-server-cve-2026-87020-dental-pacs/">an open-source DICOM server flaw put imaging systems at risk</a>: the vulnerable code was open-source plumbing tucked inside the imaging stack, not a product anyone consciously &#8220;installed.&#8221;</p>
<h2>Why healthcare being on the list matters</h2>
<p>Attackers do not spray these exploits at random; the industries researchers named are the industries being probed right now, and healthcare is on it. That is not a coincidence. Medical and dental organizations hold exactly the data extortion crews want &#8211; names, dates of birth, health and insurance details &#8211; and they have a low tolerance for downtime, which makes them more likely to pay to get running again. A no-click, no-password flaw in an internet-facing service is the kind of front door that lets an attacker skip the phishing email entirely. When a target list includes your sector, the right response is not panic but a quick, honest look at your own attack surface.</p>
<h2>You cannot protect what you cannot see</h2>
<p>Here is the lesson worth keeping long after CVE-2026-16723 is patched and forgotten. Modern software is <strong>assembled, not written</strong> &#8211; a single application can pull in dozens or hundreds of third-party open-source components, each with its own flaws surfacing on its own schedule. Your ability to respond to any given alert comes down to one unglamorous capability: <strong>knowing what you actually run</strong>. A practice that keeps even a basic inventory of its software and its internet-facing services can answer &#8220;is this us?&#8221; in an afternoon. A practice that does not is left guessing every single time the news breaks &#8211; and guessing, in security, usually means hoping. The same visibility gap shows up whenever practices bolt on new tools: every one of those <a href="https://compudent.com/how-dental-ai-connects-imaging-twain-dicom-api-pms-bridges/">integration bridges between imaging software and AI or practice-management systems</a> quietly brings its own bundle of third-party code along with it.</p>
<h2>What to do this week</h2>
<p>None of this requires you to become a Java expert. It requires a few sensible questions and a little bookkeeping:</p>
<ul>
<li><strong>Write down what you run.</strong> Keep a simple, current list of your key software and &#8211; especially &#8211; anything that is reachable from the internet: your website, any remote-access or portal, imaging or integration servers. This one list is what turns future alerts from a scramble into a lookup.</li>
<li><strong>Ask your vendors the direct question.</strong> Email your practice-management, imaging and integration vendors and ask plainly: do any of your products include FastJson 1.x, and if so, what is your fix or mitigation plan? A vendor who answers crisply has done the work; one who cannot has told you something too.</li>
<li><strong>Ask your website and IT/hosting provider the same thing.</strong> Your public website and the environments your provider runs are the most likely places a Java component like this would live. Whoever manages them should be able to confirm they have assessed it.</li>
<li><strong>Keep internet-facing services patched and, where possible, off the open internet.</strong> The services most exposed to a flaw like this are the ones facing the public web. Anything that does not need to be internet-reachable should not be, and the rest should be patched promptly and sit behind sensible protections. This is the same discipline we urged when <a href="https://compudent.com/acronis-backup-plugin-cve-2026-87886-dental-practice-backup-security/">a flaw turned up in backup software</a>: treat every exposed service as software that will eventually have a bug.</li>
<li><strong>File this as a rehearsal.</strong> FastJson may or may not touch you. The next component-level zero-day is a certainty. The practices that stay calm are the ones that already know what they run and have a habit of asking their vendors sharp questions.</li>
</ul>
<h2>What this means for your practice</h2>
<p>CVE-2026-16723 is a flaw in software most dental offices will never knowingly touch, being used in attacks that specifically include healthcare. Both halves of that sentence are true, and the tension between them is the takeaway: the threat you cannot name is the one you cannot rule out. The answer is not fear &#8211; it is <strong>visibility</strong>. Know your software estate, know which of your services face the internet, and know that your vendors are watching the components buried in their own products. That awareness is also the backbone of a real <a href="https://compudent.com/business-continuity-downtime-plan-dental-practice/">business-continuity and downtime plan</a>, because you cannot recover cleanly from a compromise in a system you did not know you had. Compudent Systems helps dental practices across the GTA and Ontario build and maintain exactly this picture &#8211; a clear inventory of software and internet-facing services, a hardened and patched attack surface, and a straight line to the vendor answers that alerts like this one demand. If you cannot say with confidence which of your systems this week&#8217;s alert does or does not touch, <a href="https://compudent.com/contact/">contact Compudent for a software-inventory and vendor-risk assessment</a>. Knowing what you run is the cheapest security control there is &#8211; and the one too many practices skip.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/" target="_blank" rel="noopener">BleepingComputer &#8211; Hackers target US firms in FastJson RCE zero-day attacks</a></li>
<li><a href="https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/" target="_blank" rel="noopener">Imperva &#8211; Customers protected against CVE-2026-16723 critical FastJson 1.x zero-day RCE</a></li>
<li><a href="https://fearsoff.org/research/fastjson-1-2-83-rce" target="_blank" rel="noopener">FearsOff &#8211; FastJson 1.2.83 RCE technical write-up</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/lazarus-job-offer-windows-zero-day-cve-2026-68820-dental/">A Fake Job Offer, a Windows Kernel Rootkit: The Lazarus Zero-Day (CVE-2026-68820) and What It Means for Your Dental Practice</a></li>
<li><a href="https://compudent.com/n-central-cve-2026-86218-preauth-rce-dental-msp-rmm/">A Perfect 10, No Password Required: The N-central Zero-Day (CVE-2026-86218) Your IT Provider Must Have Patched</a></li>
<li><a href="https://compudent.com/n-able-n-central-rmm-breach-dental-msp-risk/">When the Tool That Manages Your Network Gets Hacked: The N-able N-central Breach and What It Means for Dental Practices</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/fastjson-cve-2026-16723-dental-practice-software-inventory/">A Zero-Day Is Hitting Healthcare in Software Nobody Names: The FastJson Flaw (CVE-2026-16723) and Why You Can&#8217;t Protect Code You Don&#8217;t Know You Run</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Tool That Protects Your Data Is Now a Target: The Actively-Exploited Acronis Backup Flaw (CVE-2026-87886) and Why Backup Software Needs Guarding Too</title>
		<link>https://compudent.com/acronis-backup-plugin-cve-2026-87886-dental-practice-backup-security/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Sun, 20 Sep 2026 09:37:39 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Acronis]]></category>
		<category><![CDATA[attack surface]]></category>
		<category><![CDATA[backup security]]></category>
		<category><![CDATA[CISA KEV]]></category>
		<category><![CDATA[cPanel WHM]]></category>
		<category><![CDATA[CVE-2026-87886]]></category>
		<category><![CDATA[dental practice IT]]></category>
		<category><![CDATA[PHIPA]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<category><![CDATA[Ransomware]]></category>
		<guid isPermaLink="false">https://compudent.com/acronis-backup-plugin-cve-2026-87886-dental-practice-backup-security/</guid>

					<description><![CDATA[<p>Backup software is supposed to be the thing that saves you after an attack - so it is unsettling when the backup tool itself becomes the way in. On September 16, 2026, CISA added CVE-2026-87886, a flaw in the Acronis Backup plugin for cPanel and WHM, to its Known Exploited Vulnerabilities catalog. Here is what it is, whether it touches a dental practice, and the bigger lesson: the software that guards your data is a high-value target and needs guarding of its own.</p>
<p>The post <a href="https://compudent.com/acronis-backup-plugin-cve-2026-87886-dental-practice-backup-security/">The Tool That Protects Your Data Is Now a Target: The Actively-Exploited Acronis Backup Flaw (CVE-2026-87886) and Why Backup Software Needs Guarding Too</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>There is a particular kind of unease that comes with this week&#8217;s advisory. Backup software is the thing a practice leans on when everything else has gone wrong &#8211; the safety net under the ransomware, the fire, the failed drive. So it lands differently when the backup tool itself turns out to be the way in. On September 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added <strong>CVE-2026-87886</strong>, a flaw in the <strong>Acronis Backup plugin for cPanel and WHM</strong>, to its Known Exploited Vulnerabilities catalog after confirming it is being used in real attacks. Before anyone panics: this specific flaw probably does not touch the workstation at your front desk. But the reason it matters to every dental practice is the lesson underneath it &#8211; the software that guards your data is a high-value target, and it needs guarding of its own.</p>
<h2>What happened</h2>
<p>CVE-2026-87886 is a <strong>local privilege-escalation</strong> vulnerability caused by <strong>incorrect default file permissions</strong> in Acronis&#8217;s backup add-on for the cPanel and WHM web-hosting control panels. Acronis rated it <strong>7.8 on the CVSS scale</strong> &#8211; high severity. What pushed it onto CISA&#8217;s radar was not the score but the activity: security researchers observed <strong>limited, targeted exploitation</strong> in cPanel and WHM environments, and CISA&#8217;s listing set a federal remediation deadline of <strong>September 19, 2026</strong>. When a flaw moves from &#8220;theoretically bad&#8221; to &#8220;actively being used,&#8221; the calculus changes from patch-when-convenient to patch-now.</p>
<h2>&#8220;Do we even run this?&#8221;</h2>
<p>For most dental practices, honestly, the answer to this exact CVE is no &#8211; and we would rather tell you that than manufacture alarm. cPanel and WHM are <strong>web-hosting control panels</strong>: the software that runs on the server hosting a website, not the practice-management PC or the imaging workstation in the operatory. Where it can reach a dental practice is at the edges you may not think of as &#8220;yours&#8221;: the <strong>server that hosts your public practice website</strong>, and the <strong>hosting or IT provider environments</strong> that run cPanel to manage many customers at once. If your website lives on shared or managed hosting &#8211; and most do &#8211; it is worth a one-line email to whoever runs it asking whether they use the Acronis cPanel plugin and whether it has been patched. This is the same fourth-party-tool exposure we saw when <a href="https://compudent.com/eassist-direwolf-dental-billing-rcm-vendor-ransomware/">a dental billing vendor&#8217;s breach dragged its client practices onto a ransomware leak site</a>: the flaw was in someone else&#8217;s software, but the consequences flowed downhill.</p>
<h2>Why backup software is a target in the first place</h2>
<p>Here is the part that matters no matter which backup product you run. Backup software is, by design, one of the most <strong>privileged</strong> pieces of software in any environment. To do its job it needs deep, sweeping access &#8211; to read every file it protects and to write those files back during a restore. That is exactly the kind of access an attacker covets. And there is a second, colder reason it draws fire: <strong>modern ransomware crews hunt for backups and destroy them first</strong>. They know a practice with clean, current backups can restore and walk away without paying, so before they detonate they go looking for backup servers, repositories, and cloud credentials to delete or encrypt them. We saw this pattern spelled out in the <a href="https://compudent.com/medusa-ransomware-healthcare-advisory-dental-practice/">Medusa ransomware advisory for healthcare</a>: knock out the recovery option, and the victim&#8217;s leverage disappears. A vulnerability in the backup tool itself is a shortcut to both goals at once &#8211; privileged access and control over the one thing standing between the practice and a ransom demand.</p>
<h2>Why &#8220;only local&#8221; is not the reassurance it sounds like</h2>
<p>You may notice CVE-2026-87886 is a <em>local</em> privilege-escalation flaw, meaning an attacker needs to already be on the server to use it. That sounds comforting &#8211; and it is a genuine mitigating factor &#8211; but it is not a reason to relax. Real intrusions are built in stages. An attacker rarely walks straight into full control; they get a modest foothold first &#8211; a phished credential, a hijacked session, a separate flaw in some other service &#8211; and then <strong>chain</strong> that foothold into a privilege-escalation bug like this one to climb from &#8220;limited user&#8221; to &#8220;owns the whole machine.&#8221; A local flaw in privileged backup software is a perfect final rung on that ladder. Treating &#8220;local only&#8221; as &#8220;safe&#8221; is how a manageable foothold becomes a full compromise.</p>
<h2>What to do this week</h2>
<p>Whether or not the Acronis cPanel plugin is anywhere in your world, this advisory is a useful prompt to shore up backup security generally:</p>
<ul>
<li><strong>Find out where backup software actually runs.</strong> Inventory it honestly &#8211; the practice server, any cloud backup agent, and the hosting environment behind your website. If you use the Acronis cPanel/WHM plugin directly, apply the vendor&#8217;s patched release now; given the active exploitation and CISA deadline, this is not one to defer.</li>
<li><strong>Ask your website host and IT provider the direct question.</strong> Do you run the affected Acronis plugin, and is it patched? A provider who can answer crisply has already done the work; one who cannot has told you something too.</li>
<li><strong>Keep at least one copy offline or immutable.</strong> Follow the <strong>3-2-1 rule</strong> &#8211; three copies, on two kinds of media, with one kept offline or air-gapped. A backup an attacker can reach and delete over the network is a backup you cannot count on when it matters.</li>
<li><strong>Run backup agents and consoles under least privilege.</strong> Backup software does not need to be logged in as a domain administrator to do its job, and the backup console has no business facing the public internet. Reducing what the tool can touch reduces what an attacker inherits if they seize it.</li>
<li><strong>Patch backup software like the exposed service it is.</strong> It is easy to treat backup and security tools as set-and-forget infrastructure. They are software, they have flaws, and &#8211; as this week shows &#8211; they get exploited. Fold them into the same patch discipline as everything else.</li>
<li><strong>Test your restores.</strong> None of the above matters if the backups do not actually come back. A backup you have never restored from is a hope, not a plan &#8211; which is the whole point of <a href="https://compudent.com/backups-only-as-good-as-last-test-restore/">treating your last successful test restore as the real measure of protection</a>.</li>
</ul>
<h2>What this means for your practice</h2>
<p>CVE-2026-87886 is a narrow flaw with a wide moral: the tools you trust most &#8211; the ones with the deepest access and the most important job &#8211; are precisely the ones attackers most want to turn against you. A backup system is only protection if it is itself protected, patched, least-privileged, partly offline, and proven by a real restore. That belongs in your broader <a href="https://compudent.com/business-continuity-downtime-plan-dental-practice/">downtime and business-continuity plan</a>, not in a folder marked &#8220;someone set that up once.&#8221; Compudent Systems designs and manages backup for dental practices across the GTA and Ontario with exactly this threat model in mind &#8211; immutable and offline copies, hardened and least-privileged agents, patched backup software, and restores we actually test so the safety net is there on the day it is needed. If you are not certain your backups would survive an attack that came looking for them &#8211; or you would like a second set of eyes on how your data is protected &#8211; <a href="https://compudent.com/contact/">contact Compudent for a backup and security assessment</a>. The best time to find out your safety net has a hole in it is not the morning after.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html" target="_blank" rel="noopener">The Hacker News &#8211; Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks</a></li>
<li><a href="https://securityaffairs.com/199239/security/u-s-cisa-adds-acronis-backup-cisco-ise-and-google-pixel-flaws-to-its-known-exploited-vulnerabilities-catalog.html" target="_blank" rel="noopener">SecurityAffairs &#8211; U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog</a></li>
<li><a href="https://www.scworld.com/brief/acronis-backup-plugin-vulnerability-allows-privilege-escalation" target="_blank" rel="noopener">SC Media &#8211; Acronis backup plugin vulnerability allows privilege escalation</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/sonicwall-sma1000-vpn-ransomware-dental-practices/">Ransomware Gangs Are Now Through the Front Door: What the SonicWall SMA1000 VPN Attacks Mean for Dental Practices</a></li>
<li><a href="https://compudent.com/dental-ransomware-leak-site-fairview-soniva-practice/">Two Dental Groups on Leak Sites in One Week: What It Means When Your Practice&#8217;s Name Appears on a Ransomware Blog</a></li>
<li><a href="https://compudent.com/backups-only-as-good-as-last-test-restore/">Your Backups Are Only as Good as Your Last Test Restore: A Dental Practice Reality Check</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/acronis-backup-plugin-cve-2026-87886-dental-practice-backup-security/">The Tool That Protects Your Data Is Now a Target: The Actively-Exploited Acronis Backup Flaw (CVE-2026-87886) and Why Backup Software Needs Guarding Too</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Perfect 10, No Password Required: The N-central Zero-Day (CVE-2026-86218) Your IT Provider Must Have Patched</title>
		<link>https://compudent.com/n-central-cve-2026-86218-preauth-rce-dental-msp-rmm/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Sat, 19 Sep 2026 10:37:25 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[CVE-2026-86218]]></category>
		<category><![CDATA[dental practice IT]]></category>
		<category><![CDATA[managed service provider]]></category>
		<category><![CDATA[MSP supply chain]]></category>
		<category><![CDATA[N-able N-central]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[PHIPA]]></category>
		<category><![CDATA[pre-auth RCE]]></category>
		<category><![CDATA[RMM security]]></category>
		<category><![CDATA[zero-day]]></category>
		<guid isPermaLink="false">https://compudent.com/n-central-cve-2026-86218-preauth-rce-dental-msp-rmm/</guid>

					<description><![CDATA[<p>Weeks after the last N-central scare, a worse one has landed: CVE-2026-86218, a pre-authentication remote code execution zero-day rated a perfect 10.0 and already exploited in the wild. It needs no password. Most dental practices are exposed through their IT provider, not directly - here is what it is, why an RMM flaw is a skeleton key into a clinic, and the questions to ask whoever manages your computers this week.</p>
<p>The post <a href="https://compudent.com/n-central-cve-2026-86218-preauth-rce-dental-msp-rmm/">A Perfect 10, No Password Required: The N-central Zero-Day (CVE-2026-86218) Your IT Provider Must Have Patched</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Six weeks ago we wrote about a flaw in the tool your IT provider uses to run your computers. It is happening again &#8211; and this time it is worse. On September 6, 2026, N-able shipped an emergency hotfix for <strong>CVE-2026-86218</strong>, a vulnerability in its N-central platform that carries a <strong>perfect 10.0 severity score</strong>, requires <strong>no password at all</strong>, and has already been <strong>observed being exploited in the wild</strong>. For a dental practice, the important part is not the version number. It is a single question you should put to whoever manages your network this week: have you patched it, and were we ever exposed?</p>
<h2>What happened</h2>
<p>N-central is a <strong>remote monitoring and management (RMM)</strong> platform &#8211; the software many managed service providers (MSPs) use to keep an eye on, update, and remotely fix all of their clients&#8217; computers from one console. CVE-2026-86218 is a <strong>pre-authentication remote code execution</strong> flaw in that platform. In plain terms: an attacker who can reach a vulnerable N-central server over the network can make it run their code <strong>without logging in and without any user doing anything</strong>. N-able rated it 10.0 on the CVSS scale &#8211; the maximum &#8211; and confirmed active exploitation. It affects on-premises N-central installations before version <strong>2026.3.1.14</strong>, which is the fixed release. The Shadowserver Foundation counted roughly <strong>1,500 internet-facing N-central servers</strong>, mostly across the US and Europe, when the flaw was disclosed &#8211; each one a high-value target.</p>
<h2>Why an RMM flaw is a skeleton key into a clinic</h2>
<p>An RMM console is not just another server. It is, by design, the one machine that can reach every device it manages &#8211; to push software, run scripts, and open remote sessions across many networks at once. That is enormously useful when a trusted technician is at the keyboard. It is catastrophic when an attacker is. Seize the console and you inherit its reach: potentially the workstations at the front desk, the imaging server in the back, and the practice-management database in between. This is the same lesson we drew from <a href="https://compudent.com/n-able-n-central-rmm-breach-dental-msp-risk/">the N-central authentication-bypass flaw back in August</a> &#8211; the difference is that the earlier bug still had to get past a login, while this one skips the login entirely. It is a worse version of the same skeleton key.</p>
<h2>&#8220;But we don&#8217;t run N-central&#8221;</h2>
<p>Almost no dental practice does &#8211; and that is precisely the trap. You very likely do not operate an N-central server yourself, so it is tempting to file this under &#8220;not our problem.&#8221; But the practices at risk are mostly exposed <strong>through their IT provider, not directly</strong>. If the company that manages your computers runs N-central to do it, then their console is a door into your network, and a flaw in their software becomes your exposure even though you did nothing wrong. Security people call this <strong>fourth-party risk</strong>: not your vendor, but your vendor&#8217;s tools. We have watched this pattern play out through a supplier before &#8211; it is exactly what happened when <a href="https://compudent.com/eassist-direwolf-dental-billing-rcm-vendor-ransomware/">a dental billing company ended up on a ransomware leak site</a> and the practices that used it were dragged along. The RMM version is more dangerous, because an RMM has hands-on control of your machines, not just a copy of your data.</p>
<h2>Why this one earns the perfect 10</h2>
<p>Not every &#8220;critical&#8221; advisory deserves the same alarm. This one does, for three compounding reasons. It is <strong>pre-authentication</strong>, so the usual last line of defence &#8211; a login the attacker has to defeat &#8211; is not even in the way. It is <strong>remote code execution</strong>, the most complete form of compromise, letting the attacker run whatever they want on the server. And it is <strong>already being exploited</strong>, which turns &#8220;patch when convenient&#8221; into &#8220;patch now.&#8221; N-able also has recent history here: earlier N-central flaws (CVE-2025-8875 and CVE-2025-8876) were exploited and later added to the US CISA <strong>Known Exploited Vulnerabilities</strong> catalog, the government&#8217;s list of bugs attackers are actively using. A platform that has been hit repeatedly, that sits at the centre of many networks, and that is reachable from the internet is exactly the kind of target that attracts sustained attention.</p>
<h2>What to do this week</h2>
<p>You cannot apply this patch yourself &#8211; it lives on your provider&#8217;s infrastructure. What you can do is verify, and verification is your right as the customer whose patient data is at stake. Ask your IT provider, plainly:</p>
<ul>
<li><strong>Do you use N-able N-central to manage our systems?</strong> A straight yes/no. If yes, continue down the list.</li>
<li><strong>Is it on-premises, and has it been updated to 2026.3.1.14?</strong> The fix is that version or later. &#8220;We&#8217;re on it&#8221; is not an answer; a version number is.</li>
<li><strong>Was the console ever reachable from the public internet during the exposure window?</strong> A management console has no business facing the open internet. It belongs behind a firewall or VPN &#8211; the same principle we applied to <a href="https://compudent.com/checkpoint-vpn-cve-2026-85102-85103-dental-practice-remote-access/">hardening remote access appliances</a>: if it does not need to be public, it should not be.</li>
<li><strong>If there was any exposure, what is your compromise-assumption plan?</strong> A mature provider will not just patch and move on; they will check for signs of intrusion, rotate credentials, and tell you what they found.</li>
<li><strong>Are our backups current, tested, and offline?</strong> If the worst happened through any vendor, clean backups you have actually restored from are what get the practice running again &#8211; which is the heart of <a href="https://compudent.com/business-continuity-downtime-plan-dental-practice/">having a real downtime and business-continuity plan</a> rather than hoping.</li>
</ul>
<p>Good providers will welcome these questions and answer them crisply, because they have already done the work. A provider who is evasive, or who cannot tell you what software they run in your environment, has told you something important too.</p>
<h2>What this means for your practice</h2>
<p>CVE-2026-86218 is a reminder that your security perimeter no longer ends at your own walls &#8211; it now includes the tools your suppliers use to reach inside them. That is not a reason for paranoia; it is a reason for a short, specific conversation with whoever holds the keys to your network. Compudent Systems manages dental practices across the GTA and Ontario with that fourth-party exposure in mind: we keep our management tooling patched and off the public internet, we design for the assumption that any vendor can have a bad day, and we make sure a practice&#8217;s backups and downtime plan would actually carry it through one. If you are not certain whether the software running your office has been patched against this flaw &#8211; or you would simply like a second set of eyes on who can reach your systems and how &#8211; <a href="https://compudent.com/contact/">contact Compudent for a security assessment</a>. A perfect-10, no-password flaw in the wrong tool is the kind of thing you want to have already handled, not to be reading about after the fact.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html" target="_blank" rel="noopener">The Hacker News &#8211; N-able N-central Pre-Auth RCE Flaw Exploited in the Wild</a></li>
<li><a href="https://www.huntress.com/blog/n-able-vulnerability-exploitation" target="_blank" rel="noopener">Huntress &#8211; Critical N-able N-central Vulnerability and Active Exploitation</a></li>
<li><a href="https://horizon3.ai/attack-research/vulnerabilities/cve-2026-86218/" target="_blank" rel="noopener">Horizon3 &#8211; CVE-2026-86218: N-able N-central RCE</a></li>
</ul>
<p><!-- winner-link:START --></p>
<p class="winner-related"><strong>Related:</strong> <a href="https://compudent.com/fastjson-cve-2026-16723-dental-practice-software-inventory/">A Zero-Day Is Hitting Healthcare in Software Nobody Names: The FastJson Flaw (CVE-2026-16723) and Why You Can&#8217;t Protect Code You Don&#8217;t Know You Run</a></p>
<p><!-- winner-link:END --></p>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/n-able-n-central-rmm-breach-dental-msp-risk/">When the Tool That Manages Your Network Gets Hacked: The N-able N-central Breach and What It Means for Dental Practices</a></li>
<li><a href="https://compudent.com/sharepoint-cve-2026-55040-auth-bypass-dental-practices/">A Forged Login Walks Straight Into SharePoint: What the Actively Exploited CVE-2026-55040 Auth Bypass Means for Dental Practices</a></li>
<li><a href="https://compudent.com/sonicwall-sma1000-vpn-ransomware-dental-practices/">Ransomware Gangs Are Now Through the Front Door: What the SonicWall SMA1000 VPN Attacks Mean for Dental Practices</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/n-central-cve-2026-86218-preauth-rce-dental-msp-rmm/">A Perfect 10, No Password Required: The N-central Zero-Day (CVE-2026-86218) Your IT Provider Must Have Patched</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Tablet in Operatory 3 Is Now a Target: What AI-Powered &#8216;RatHat&#8217; Android Malware Means for Your Practice</title>
		<link>https://compudent.com/rathat-android-malware-dental-practice-mobile-device-security/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 09:40:06 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[accessibility abuse]]></category>
		<category><![CDATA[ADB]]></category>
		<category><![CDATA[Android malware]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[dental practice IT]]></category>
		<category><![CDATA[MDM]]></category>
		<category><![CDATA[mobile device security]]></category>
		<category><![CDATA[OTP theft]]></category>
		<category><![CDATA[RatHat]]></category>
		<category><![CDATA[tablet security]]></category>
		<guid isPermaLink="false">https://compudent.com/rathat-android-malware-dental-practice-mobile-device-security/</guid>

					<description><![CDATA[<p>A new strain of Android malware called RatHat uses an AI engine to drive a phone or tablet on its own, self-pairs with Android's debug bridge to keep shell-level control even after the app is deleted, and is built to steal banking logins and one-time passcodes. Dental practices now run tablets in operatories and at the front desk - which makes those devices a target, not a footnote. Here is what RatHat does, why it matters for a clinic, and the mobile-device controls that shut it out.</p>
<p>The post <a href="https://compudent.com/rathat-android-malware-dental-practice-mobile-device-security/">The Tablet in Operatory 3 Is Now a Target: What AI-Powered &#8216;RatHat&#8217; Android Malware Means for Your Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>For years, the security conversation in a dental practice has revolved around the server, the workstations, and the firewall. Meanwhile, quietly, a second fleet of computers moved into the office: the Android tablets on the operatory arms running the intraoral-camera and imaging apps, the phone at the front desk that texts appointment reminders, the tablet patients tap to sign a medical history. A newly disclosed piece of malware called <strong>RatHat</strong> is a blunt reminder that those devices are not accessories &#8211; they are full computers holding real access to patient information and practice money, and attackers now treat them accordingly.</p>
<h2>What RatHat actually does</h2>
<p>Security researchers (among them Zimperium) have flagged RatHat as a new Android malware family assessed to be operated by China-based threat actors. It does not arrive from the official app store. Instead it spreads the way most modern mobile threats do &#8211; through <strong>smishing</strong> (scam text messages) and malicious ads that push a user to a fake site and a sideloaded app. The moment of compromise is almost always the same: the app asks for Android&#8217;s <strong>Accessibility</strong> permission &#8211; the powerful setting meant to help people with disabilities operate their phone &#8211; and the user, expecting the app to work, taps &#8220;allow.&#8221;</p>
<p>From there RatHat abuses that permission to do something genuinely clever and genuinely nasty. It silently switches on Developer Options and Wireless Debugging, then uses a built-in copy of Android&#8217;s <strong>Debug Bridge (ADB)</strong> to pair with the device&#8217;s own debugging service &#8211; granting the attacker <strong>shell-level control without any computer plugged in by USB</strong>. That is the level of access engineers use to rebuild a phone from the command line. Worse, this ADB backdoor is designed to <strong>persist even after the visible malicious app is uninstalled</strong>. Deleting the dodgy app you were tricked into installing does not evict the intruder &#8211; the shell is still there.</p>
<h2>The part that is new: an AI at the wheel</h2>
<p>What sets RatHat apart from the last decade of Android trojans is how it navigates a device. Older malware was scripted and brittle &#8211; it only knew how to tap the exact buttons its authors had hard-coded. RatHat instead uses an <strong>AI-powered automation engine</strong>: it serializes the live Accessibility tree &#8211; essentially a machine-readable map of everything on the screen right now &#8211; and sends it to an AI model, which identifies the on-screen elements and generates the taps and swipes needed to accomplish a goal. In effect, the malware can <em>operate the phone by itself</em>, adapting to whatever app or layout it finds instead of breaking the moment a screen changes.</p>
<p>This is the same trend we described when <a href="https://compudent.com/ai-accelerated-malware-attacks-dental-practice/">AI began accelerating and rewriting attacks</a> on the desktop side &#8211; automation that used to require a human is now handled by a model, at machine speed and scale. RatHat is that idea landing on the phone in your pocket.</p>
<h2>Why a dental practice should care about a banking trojan</h2>
<p>RatHat&#8217;s ultimate purpose is financial: it is built to steal <strong>banking credentials</strong> and intercept <strong>one-time passcodes (OTPs)</strong>. At first glance that sounds like a consumer problem. It is not, for three reasons that land squarely on a clinic.</p>
<p>First, <strong>your practice devices are attractive targets, not neutral ones.</strong> A tablet used for patient check-in and imaging, or a front-desk phone tied to your payment and messaging systems, is a device an attacker would very much like shell-level control of. Anything that device can see or reach &#8211; patient details, appointment data, saved logins &#8211; is exposed the moment it is compromised, and patient information carries <strong>PHIPA and HIPAA</strong> obligations that a personal phone infection never does.</p>
<p>Second, <strong>RatHat specifically defeats SMS-based security.</strong> Because it can read the screen and intercept messages, an SMS one-time code is no longer a secret between you and your bank or your software vendor. Any multi-factor authentication that relies on a texted code is weakened against a device like this &#8211; a point worth remembering the next time you set up MFA on a practice account.</p>
<p>Third, <strong>the line between work and personal has blurred.</strong> If a hygienist checks a personal banking app on the same phone they use to text patients, or a manager installs practice software on a personal tablet, one careless &#8220;allow&#8221; can put a foot in both worlds at once.</p>
<h2>The controls that actually shut it out</h2>
<p>The good news is that RatHat, for all its cleverness, is stopped by ordinary, well-understood mobile-device hygiene. None of this is exotic; most practices simply have never applied it to their tablets and phones the way they do to their PCs.</p>
<ul>
<li><strong>Manage the devices centrally.</strong> Enrol every practice tablet and phone in a <strong>mobile device management (MDM)</strong> platform. MDM lets you enforce policy, block risky settings, push updates, and &#8211; crucially &#8211; <strong>remotely wipe</strong> a device that is lost or suspected compromised. An unmanaged fleet is a blind spot.</li>
<li><strong>Block sideloading.</strong> Practice devices should install apps only from vetted, approved sources. RatHat depends on getting a user to install an app from outside the store; a device that cannot sideload cannot be infected this way.</li>
<li><strong>Guard the Accessibility permission.</strong> This is the single hinge of the whole attack. No app should be granted Accessibility access unless it genuinely needs it, and someone should periodically audit which apps hold it. Train the team that an unexpected request to &#8220;allow&#8221; accessibility or device control is a stop-and-ask moment, not a tap-through.</li>
<li><strong>Turn off developer and debugging modes.</strong> On a clinical device, Developer Options, USB debugging, and wireless debugging should be off and, under MDM, locked off. That removes the exact door RatHat pries open.</li>
<li><strong>Separate work from personal.</strong> Keep patient-facing and payment functions on managed, work-only devices, or at minimum a managed work profile &#8211; not on a staff member&#8217;s personal phone alongside their banking apps and family messages.</li>
<li><strong>Move off SMS codes.</strong> Prefer phishing-resistant MFA &#8211; an authenticator app or passkeys &#8211; over texted one-time codes for practice logins, since malware like this is built to intercept SMS. This is the same reasoning behind keeping <a href="https://compudent.com/checkpoint-vpn-cve-2026-85102-85103-dental-practice-remote-access/">remote access to the practice properly hardened</a>: the way people log in is exactly where attackers concentrate.</li>
<li><strong>Keep protection on and patch.</strong> Leave Google Play Protect and any endpoint protection enabled, and keep devices updated. Train staff to recognise smishing &#8211; the scam text is the first domino.</li>
</ul>
<p>The same discipline applies to how patient data travels off these devices, too &#8211; which is why we keep returning to the theme of <a href="https://compudent.com/google-meet-hipaa-phipa-teledentistry-dental-practice/">using the right, compliant tools rather than convenient consumer apps</a> for anything that touches patient information.</p>
<h2>What this means for your practice</h2>
<p>RatHat is not a reason to rip the tablets out of your operatories &#8211; they are too useful for that, and the threat is manageable. It is a reason to treat those tablets and phones with the same seriousness as the server they connect to. A modern practice&#8217;s mobile devices are a real part of its attack surface, and until now most clinics have secured the desktops and left the mobile fleet to chance. Compudent Systems helps dental practices across the GTA and Ontario inventory every device that touches patient data, deploy mobile device management, lock down debugging and sideloading, separate work from personal use, and move accounts onto phishing-resistant MFA. If you are not sure how many tablets and phones can currently reach your patient information &#8211; or what any one of them is allowed to do &#8211; <a href="https://compudent.com/contact/">contact Compudent for a mobile-device security assessment</a>. The tablet in operatory 3 is a computer on your network. It deserves to be defended like one.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/" target="_blank" rel="noopener">BleepingComputer &#8211; New RatHat Android malware uses AI to automate device control</a></li>
<li><a href="https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/" target="_blank" rel="noopener">Infosecurity Magazine &#8211; New &#8216;RatHat&#8217; Android Malware Leverages AI to Steal Financial Data</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/ai-accelerated-malware-attacks-dental-practice/">When the Malware Rewrites Itself: AI-Accelerated Attacks and What They Mean for Your Practice</a></li>
<li><a href="https://compudent.com/connected-dental-devices-attack-surface/">The Other Computers in Your Operatory: Why Connected Dental Devices Are the Attack Surface Nobody Audits</a></li>
<li><a href="https://compudent.com/lazarus-job-offer-windows-zero-day-cve-2026-68820-dental/">A Fake Job Offer, a Windows Kernel Rootkit: The Lazarus Zero-Day (CVE-2026-68820) and What It Means for Your Dental Practice</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/rathat-android-malware-dental-practice-mobile-device-security/">The Tablet in Operatory 3 Is Now a Target: What AI-Powered &#8216;RatHat&#8217; Android Malware Means for Your Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When the System Goes Down: Building a Downtime and Business-Continuity Plan for Your Dental Practice</title>
		<link>https://compudent.com/business-continuity-downtime-plan-dental-practice/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Thu, 17 Sep 2026 09:38:27 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[3-2-1 backup]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[data backup]]></category>
		<category><![CDATA[dental practice IT]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[downtime plan]]></category>
		<category><![CDATA[practice management software]]></category>
		<category><![CDATA[ransomware recovery]]></category>
		<category><![CDATA[RTO RPO]]></category>
		<category><![CDATA[vendor outage]]></category>
		<guid isPermaLink="false">https://compudent.com/business-continuity-downtime-plan-dental-practice/</guid>

					<description><![CDATA[<p>A Windows update locks out your server, a billing vendor lands on a leak site, or ransomware freezes the schedule at 8 a.m. - and suddenly a fully digital dental practice cannot see patients. The fix is not more panic on the day; it is a written downtime and business-continuity plan built before the outage. Here is what that plan contains, how to size your backups with RTO and RPO, and how to keep the chairs running when the system is dark.</p>
<p>The post <a href="https://compudent.com/business-continuity-downtime-plan-dental-practice/">When the System Goes Down: Building a Downtime and Business-Continuity Plan for Your Dental Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Picture 8:05 on a Monday morning. The first patient is in the chair, the waiting room is filling, and the front desk clicks into the practice-management software &#8211; and nothing loads. The schedule is gone. The charts are gone. The X-rays are gone. The card terminal that talks to the software is dead. In a fully digital dental practice, an IT outage is not an inconvenience; it is a clinical and financial emergency that stops the whole business in its tracks. The uncomfortable truth is that <em>when</em> this happens is far less in your control than <strong>how prepared you are for it</strong>. That preparation has a name &#8211; a business-continuity and downtime plan &#8211; and every practice should have one written down before it is needed.</p>
<h2>Why every practice is now one outage away from a standstill</h2>
<p>A generation ago, a power cut meant you reached for the paper daybook. Today, the schedule, the patient charts, the digital radiographs, the e-claims, the recall reminders, and often the phones all live on computers and networks. That efficiency is exactly why an outage hurts so much: there is no analogue fallback humming quietly in the background. When the system is dark, you cannot see who is booked, you cannot pull a history, you cannot capture or read an image, and you cannot submit a claim. The practice does not slow down &#8211; it stops.</p>
<h2>Four ways the lights go out</h2>
<p>Downtime almost always arrives by one of four doors, and recent months have shown every one of them in the wild:</p>
<ul>
<li><strong>A bad patch or update.</strong> Security updates are essential, but they occasionally break things. September 2026&#8217;s Windows Server update did exactly that, <a href="https://compudent.com/september-2026-windows-server-update-breaks-remote-desktop-rds-dental-practice/">knocking out Remote Desktop and locking staff out of the very server their software runs on</a>.</li>
<li><strong>Ransomware or a security incident.</strong> An attacker who encrypts your files can freeze the schedule and charts in seconds, as the steady stream of <a href="https://compudent.com/watchguard-firebox-cve-2025-14733-ransomware-dental-practice-firewall/">firewall-borne ransomware campaigns</a> aimed at small clinics keeps proving.</li>
<li><strong>A third-party vendor or cloud outage.</strong> When your billing company, cloud practice-management host, or imaging provider goes down, so do you &#8211; even though your own office is fine. The <a href="https://compudent.com/eassist-direwolf-dental-billing-rcm-vendor-ransomware/">eAssist/Direwolf attack on an outsourced dental-billing provider</a> was a reminder that your uptime depends on your vendors&#8217; uptime.</li>
<li><strong>Ordinary hardware, power, or internet failure.</strong> The least dramatic and most common cause of all &#8211; a dead server drive, a failed switch, a cut internet line, or a power surge.</li>
</ul>
<p>Notice that all four produce the <em>same</em> outcome: no access to the tools that run the practice. A good plan prepares for that outcome, not for one specific villain.</p>
<h2>The two numbers that size your plan: RPO and RTO</h2>
<p>Before you buy anything, answer two questions &#8211; they turn &#8220;we should be more prepared&#8221; into a concrete, buildable plan.</p>
<p><strong>Recovery Point Objective (RPO):</strong> how much data can you afford to lose? If your backup runs once a night and the server dies at 4 p.m., you have lost a full day of charting, images, and payments. If losing an hour is the most you can stomach, you need backups every hour. RPO sets your <strong>backup frequency</strong>.</p>
<p><strong>Recovery Time Objective (RTO):</strong> how long can you be down before it becomes a serious problem? A four-hour RTO and a three-day RTO call for completely different setups &#8211; the first may need standby hardware and near-instant restore; the second can tolerate rebuilding from an off-site copy. RTO sets your <strong>recovery method and spare capacity</strong>. Put a real number on each, and the rest of the plan almost designs itself.</p>
<h2>Backups: the foundation, done properly</h2>
<p>Every continuity plan rests on backups &#8211; but not all backups are equal. The durable standard is the <strong>3-2-1 rule</strong>: keep <strong>three</strong> copies of your data, on <strong>two</strong> different types of media, with <strong>one</strong> copy off-site. In the ransomware era, add one more word to that off-site copy: <strong>immutable</strong> (or at least offline). Modern attackers deliberately hunt for and delete backups before they trigger the encryption, so a backup sitting on an always-connected drive can be destroyed alongside everything else. A copy they cannot reach or alter is what lets you say no to a ransom.</p>
<p>And the single most overlooked rule of all: <strong>an untested backup is not a backup &#8211; it is a hope.</strong> Backups fail silently more often than anyone expects. Schedule periodic test restores so that the first time you recover real data is not the day you are relying on it.</p>
<h2>The cloud does not remove your responsibility</h2>
<p>Many practices have moved to cloud practice-management software or outsourced billing, and assume continuity is now the vendor&#8217;s problem. It is not &#8211; it is shared. The servers may be off-site, but the duty to keep the practice running, and to safeguard patient information, stays with you. Practically, that means three things: know your vendor&#8217;s promised recovery time and read the <strong>service-level agreement</strong>; keep your own <strong>exportable copy</strong> of your data wherever the platform allows it, so you are never wholly locked inside someone else&#8217;s system; and have a <strong>paper fallback</strong> for the day the vendor is simply unreachable. This is the same vendor-and-data discipline we set out in our guide to <a href="https://compudent.com/phipa-hipaa-dental-ai-data-governance-vendor-risk/">PHIPA, HIPAA, data governance, and vendor risk</a> &#8211; continuity is one more reason to know exactly who holds your data and how you get it back.</p>
<h2>The downtime kit: keeping the chairs running when the screens are dark</h2>
<p>Restoring the systems is the IT half of the job. The other half is keeping the practice moving during the outage, and that comes down to a simple, printed <strong>downtime kit and runbook</strong> the front desk can reach for without thinking:</p>
<ul>
<li><strong>A printed daily schedule</strong> &#8211; generated automatically each morning and kept on paper, so you always know who is coming even when the software is down.</li>
<li><strong>Paper charting, medical-history, and consent forms</strong> to capture the day&#8217;s clinical notes and signatures for later entry.</li>
<li><strong>A manual card-payment fallback</strong> (a standalone terminal or phone-based option) so you can still take payment when the integrated terminal is offline.</li>
<li><strong>A one-page runbook</strong>: who to call first, in what order, and who does what &#8211; the step-by-step for the first thirty minutes, written before the stress of the moment.</li>
<li><strong>Key contacts and a communication plan</strong>: your IT provider, your PMS and billing vendors, plus ready messages for patients and staff so the practice communicates calmly instead of going silent.</li>
</ul>
<h2>Assign an owner and practise it</h2>
<p>A plan filed away and forgotten fails at the worst moment. Name an <strong>incident owner</strong> &#8211; the person who takes charge, works the runbook, and coordinates the team &#8211; and make sure a backup person can step in if they are away. Then walk the staff through it at least once, so that when a monitor really does stay dark on a Monday morning, the front desk is executing a familiar routine rather than improvising in a panic.</p>
<h2>What this means for your practice</h2>
<p>Downtime is not a question of <em>if</em> but <em>when</em> &#8211; a patch, a vendor, an attacker, or a failed drive will eventually take a fully digital practice offline. What separates a bad hour from a lost week is entirely down to preparation: sized backups you have actually test-restored, an off-site copy ransomware cannot touch, a realistic RTO, and a printed runbook the team knows how to use. Compudent Systems builds and tests business-continuity plans for dental practices across the GTA and Ontario &#8211; assessing your backups, hardening them against ransomware, defining your RTO and RPO, assembling your downtime kit, and providing the rapid recovery that turns a potential catastrophe into a manageable interruption. If you cannot say with confidence how long you would be down after an outage &#8211; or whether your last backup would even restore &#8211; <a href="https://compudent.com/contact/">contact Compudent for a business-continuity and backup review</a>. The best time to build the plan is on an ordinary Tuesday, long before you need it.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.cisa.gov/" target="_blank" rel="noopener">CISA &#8211; Cyber Resilience and Business Continuity guidance</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/ransomware-patient-safety-38-percent-mortality-dental-practice/">Ransomware Is Now a Patient-Safety Issue: What a 38% Hospital Mortality Study Means for Your Dental Practice</a></li>
<li><a href="https://compudent.com/eassist-direwolf-dental-billing-rcm-vendor-ransomware/">Your Billing Company Is on a Leak Site: The eAssist/Direwolf Attack and Outsourced-RCM Risk</a></li>
<li><a href="https://compudent.com/medusa-ransomware-healthcare-advisory-dental-practice/">The FBI Just Refreshed Its Medusa Ransomware Warning for Healthcare: The Real Lesson for Your Dental Practice</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/business-continuity-downtime-plan-dental-practice/">When the System Goes Down: Building a Downtime and Business-Continuity Plan for Your Dental Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Is Google Meet Safe for a Patient Video Visit? Teledentistry, HIPAA/PHIPA, and the Free-Account Trap</title>
		<link>https://compudent.com/google-meet-hipaa-phipa-teledentistry-dental-practice/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 09:39:02 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[business associate agreement]]></category>
		<category><![CDATA[dental IT security]]></category>
		<category><![CDATA[Google Meet]]></category>
		<category><![CDATA[Google Workspace]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[PHI protection]]></category>
		<category><![CDATA[PHIPA]]></category>
		<category><![CDATA[teledentistry]]></category>
		<category><![CDATA[video conferencing security]]></category>
		<category><![CDATA[virtual care]]></category>
		<guid isPermaLink="false">https://compudent.com/google-meet-hipaa-phipa-teledentistry-dental-practice/</guid>

					<description><![CDATA[<p>Google Meet can be used for a compliant patient video visit - but only on a paid Google Workspace plan with a signed Business Associate Agreement and the right configuration. The free version most people click into is not covered, and using it for a teledentistry consult puts patient information outside any agreement. Here's what actually makes a video visit compliant under HIPAA and Ontario's PHIPA, and how a dental practice should set it up.</p>
<p>The post <a href="https://compudent.com/google-meet-hipaa-phipa-teledentistry-dental-practice/">Is Google Meet Safe for a Patient Video Visit? Teledentistry, HIPAA/PHIPA, and the Free-Account Trap</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It has never been easier to see a patient by video. Someone types <em>meet.google.com</em>, clicks &#8220;new meeting,&#8221; sends the link, and a consult that used to require a room now happens in seconds. That convenience is exactly the problem. A dental practice that runs a virtual visit on a free, personal Google account has just handled protected patient information on a service it has no agreement with &#8211; and no amount of &#8220;but the call is encrypted&#8221; fixes that. With teledentistry now a normal part of triage, follow-ups, and second opinions, it&#8217;s worth answering the question straight: <strong>is Google Meet safe &#8211; and lawful &#8211; for a patient video visit?</strong></p>
<h2>The short answer: yes, but only under specific conditions</h2>
<p>Google Meet <em>can</em> support a compliant patient video visit. The industry consensus, reflected in the HIPAA Journal&#8217;s 2026 update on the question, is that it is compliant only when three things are all true at once: it&#8217;s used as part of a <strong>paid Google Workspace plan</strong> (Business or Enterprise) whose covered services include Meet; the practice has a <strong>signed Business Associate Agreement</strong> (BAA) with Google; and it&#8217;s <strong>configured and used correctly</strong>, with sound administrative practices around it. Miss any one of those and you don&#8217;t have a compliant setup &#8211; you have a video call that happens to look the same on screen.</p>
<p>The version most people actually reach for &#8211; a free consumer Google Meet run off a personal Gmail address &#8211; meets none of those conditions. There is <strong>no BAA available for free consumer accounts</strong>, which means Google isn&#8217;t contractually bound to protect the information that passes through, and the practice has no agreement to point to if something goes wrong. That&#8217;s the free-account trap: the tool works identically, so nothing warns you that you&#8217;ve stepped outside the rules.</p>
<h2>Why the agreement matters more than the encryption</h2>
<p>It&#8217;s tempting to assume that because a video call is encrypted, it must be safe to use. Encryption is necessary, but it isn&#8217;t sufficient. Under HIPAA, any outside company that creates, receives, stores, or transmits protected health information (PHI) on your behalf is a <strong>business associate</strong>, and you&#8217;re required to have a BAA with them. The BAA is the legal hinge: it&#8217;s the document in which the vendor commits to specific safeguards, to breach notification, and to using the data only for permitted purposes. Without it signed, the vendor handling your patients&#8217; information simply isn&#8217;t bound to protect it &#8211; and your practice, not the vendor, carries the exposure. This is the same principle we&#8217;ve walked through for other everyday tools, from <a href="https://compudent.com/texting-emailing-patients-hipaa-phipa-dental-practice/">texting and emailing patients</a> to <a href="https://compudent.com/chatgpt-hipaa-dental-practice/">whether a practice can use ChatGPT without breaking HIPAA and PHIPA</a>. The tool is rarely the deciding factor; the agreement and the configuration behind it are.</p>
<h2>PHIPA: the same duty, worded for Ontario</h2>
<p>For a practice here in Ontario, HIPAA is only half the picture &#8211; the <strong>Personal Health Information Protection Act (PHIPA)</strong> is the law that actually governs you. PHIPA doesn&#8217;t publish a list of &#8220;approved&#8221; apps, but it places a parallel, unambiguous duty on health information custodians: take <strong>reasonable steps to safeguard</strong> personal health information, and put a <strong>written agreement</strong> in place with any service provider who handles that information on your behalf. In practice that means the same test as HIPAA &#8211; a paid plan, a signed agreement, real configuration &#8211; plus a few PHIPA-specific habits: obtain and document a patient&#8217;s <strong>informed consent</strong> for a virtual visit, be able to say <strong>where the data is stored</strong>, and make sure your workflow doesn&#8217;t quietly route patient information through a personal account. A free video link fails on all counts.</p>
<h2>This isn&#8217;t just a Google question</h2>
<p>Google Meet gets singled out because it&#8217;s so easy to launch, but the exact same logic applies to every mainstream platform. <strong>Zoom</strong> can be compliant &#8211; but through its healthcare offering with a signed BAA, not a free personal Zoom account. <strong>Microsoft Teams</strong> can be compliant &#8211; under a business/enterprise plan with the Microsoft BAA in place. The pattern never changes: a paid business tier, a signed agreement, correct settings, trained staff. We covered the practical security side of this when we looked at <a href="https://compudent.com/safety-and-security-while-video-conferencing-with-zoom/">safety and security while video conferencing</a>; the compliance layer sits on top of those same good habits. Choosing a platform is the easy part &#8211; operating it correctly is the work.</p>
<h2>What a compliant teledentistry setup actually looks like</h2>
<p>Turning &#8220;we do video visits&#8221; into &#8220;we do <em>compliant</em> video visits&#8221; is a short, concrete checklist:</p>
<ul>
<li><strong>Stop using personal accounts.</strong> No teledentistry consult should ever run on a free, personal Gmail or a free meet.google.com link. This is the single most common gap.</li>
<li><strong>Move to a paid Workspace plan</strong> (Business or Enterprise) that includes Meet as a covered service, then <strong>sign the BAA</strong> with Google and keep a copy on file.</li>
<li><strong>Turn on the compliance-supporting settings</strong> in the admin console &#8211; the controls that restrict access, manage recordings, and limit external sharing &#8211; rather than assuming the defaults are enough.</li>
<li><strong>Treat the extras as PHI too.</strong> Meeting recordings, in-call chat, and even calendar invites that name a patient and their reason for visiting all count. Decide where they&#8217;re stored and who can see them.</li>
<li><strong>Document consent</strong> for virtual care, and train every staff member who books or hosts a visit so nobody defaults to the convenient-but-non-compliant link under time pressure.</li>
</ul>
<p>None of this is exotic &#8211; it&#8217;s the same disciplined vendor-and-data governance we outlined in our <a href="https://compudent.com/phipa-hipaa-dental-ai-data-governance-vendor-risk/">guide to PHIPA, HIPAA, and vendor risk</a>, applied to the camera instead of the software.</p>
<h2>What this means for your practice</h2>
<p>Google Meet is not &#8220;unsafe&#8221; and it&#8217;s not automatically &#8220;compliant&#8221; &#8211; it&#8217;s a tool that becomes one or the other depending on how you buy it, agree to it, and configure it. The danger for a dental practice isn&#8217;t the technology; it&#8217;s the frictionless free version that anyone can start in seconds, with no signed agreement and no record of where a patient&#8217;s information just went. Compudent Systems sets up virtual-care stacks for Ontario dental practices the right way: the correct paid plan, the signed business associate agreements, the admin settings actually switched on, and the staff workflows that keep patient information from leaking into personal accounts. If your team is doing video visits and you can&#8217;t say for certain that there&#8217;s a signed BAA and a properly configured platform behind them, <a href="https://compudent.com/contact/">contact Compudent for a teledentistry and PHIPA-compliance review</a>. We&#8217;ll make sure the convenient way and the compliant way are the same way.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.hipaajournal.com/is-google-meet-hipaa-compliant/" target="_blank" rel="noopener">The HIPAA Journal &#8211; Is Google Meet HIPAA Compliant? (2026 Update)</a></li>
<li><a href="https://www.ipc.on.ca/" target="_blank" rel="noopener">Information and Privacy Commissioner of Ontario &#8211; Privacy and virtual health care (PHIPA)</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/chatgpt-hipaa-dental-practice/">Can Your Dental Practice Use ChatGPT Without Breaking HIPAA and PHIPA? A 2026 Compliance Guide</a></li>
<li><a href="https://compudent.com/texting-emailing-patients-hipaa-phipa-dental-practice/">Is Texting or Emailing Your Patients a PHIPA and HIPAA Violation? Secure Patient Communication for Dental Practices</a></li>
<li><a href="https://compudent.com/phipa-hipaa-dental-ai-data-governance-vendor-risk/">PHIPA, HIPAA, and Dental AI: PHI, Data Governance, and Vendor Risk</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/google-meet-hipaa-phipa-teledentistry-dental-practice/">Is Google Meet Safe for a Patient Video Visit? Teledentistry, HIPAA/PHIPA, and the Free-Account Trap</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>One Screen for Scans and X-Rays: What Medit&#8217;s AuraVue With Overjet AI Means for Your Dental Practice</title>
		<link>https://compudent.com/medit-auravue-overjet-ai-dental-practice-imaging/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 13:49:31 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[AI radiographic analysis]]></category>
		<category><![CDATA[dental imaging software]]></category>
		<category><![CDATA[dental practice IT]]></category>
		<category><![CDATA[digital dentistry workflow]]></category>
		<category><![CDATA[imaging integration]]></category>
		<category><![CDATA[Intraoral Scanner]]></category>
		<category><![CDATA[Medit AuraVue]]></category>
		<category><![CDATA[Overjet AI]]></category>
		<category><![CDATA[patient communication]]></category>
		<category><![CDATA[PHIPA Compliance]]></category>
		<guid isPermaLink="false">https://compudent.com/medit-auravue-overjet-ai-dental-practice-imaging/</guid>

					<description><![CDATA[<p>Medit has launched AuraVue, a workspace built with Overjet that puts a 3D intraoral scan and the patient's X-rays side by side on one screen, with Overjet's AI reading the radiographs for decay and bone levels. It's a genuinely useful step for digital practices - but the real questions for a dental office are about workflow fit, data flow, and compliance. Here's a practical, vendor-neutral look at what AuraVue is and what to check before you adopt any AI imaging tool.</p>
<p>The post <a href="https://compudent.com/medit-auravue-overjet-ai-dental-practice-imaging/">One Screen for Scans and X-Rays: What Medit&#8217;s AuraVue With Overjet AI Means for Your Dental Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Medit, one of the larger names in 3D intraoral scanning, has launched a new platform called <strong>AuraVue</strong>, built in partnership with dental-AI company Overjet. The pitch is simple and genuinely appealing: instead of clicking between your scanner software and a separate X-ray viewer, AuraVue puts a patient&#8217;s <strong>3D intraoral scan and their radiographs side by side in one interactive workspace</strong>, with Overjet&#8217;s AI reading the X-rays for findings like decay and bone level. For a profession that has spent years accumulating a drawer full of disconnected imaging programs, a single unified view is a welcome idea. But a new product headline and a good decision for <em>your</em> practice are two different things &#8211; so here&#8217;s a plain, vendor-neutral look at what AuraVue actually is, and the questions that matter before you adopt it or any AI imaging tool.</p>
<h2>What AuraVue actually is</h2>
<p>At its core, AuraVue is a visualization workspace. It combines Medit&#8217;s 3D intraoral scan data with a patient&#8217;s 2D radiographs so a clinician can see both in the same screen rather than in two separate applications. Layered on top of the X-rays is Overjet&#8217;s analysis: Overjet is a dental-AI company whose technology automatically reads radiographs to help detect decay and measure bone levels, highlighting areas of interest for the clinician&#8217;s review. Overjet is widely used across larger dental organizations and insurers, and its imaging analysis carries US FDA clearance for specific uses. The combination is meant to turn a pile of raw imaging data into a clearer, more visual story &#8211; one the dentist can interpret faster and, crucially, one the patient can actually understand.</p>
<h2>The problem it&#8217;s trying to solve</h2>
<p>Two real frustrations sit behind a product like this. The first is <strong>workflow friction</strong>: in many practices the intraoral scanner has its own software, the sensors and pan/CBCT feed a different imaging suite, and the practice-management system is a third world entirely. Clinicians switch windows, re-open studies, and mentally stitch the pieces together. The second is <strong>patient communication</strong>. A patient staring at a grayscale periapical radiograph rarely sees what the dentist sees. Put a recognizable 3D model of their own teeth next to that X-ray, with the area of concern visually flagged, and the conversation changes &#8211; which is why tools like this tend to be pitched as much for case acceptance as for diagnosis. Those are legitimate wins. The caution is simply that AI-flagged findings are <strong>decision support, not a diagnosis</strong>: the clinician remains responsible for the read, and a highlight is a prompt to look closely, not a verdict.</p>
<h2>The questions that matter more than the demo</h2>
<p>A slick unified screen is easy to show in a launch video. Whether it fits a working practice comes down to less glamorous details &#8211; and this is where the IT and compliance side earns its keep.</p>
<h2>1. Will it actually connect to what you already run?</h2>
<p>The single biggest reason imaging tools disappoint is integration. Does the platform work with your existing scanner, sensors and practice-management system, or does it assume you&#8217;re all-in on one vendor&#8217;s ecosystem? Dental software talks through a patchwork of standards and bridges &#8211; TWAIN, DICOM, direct APIs and PMS integrations &#8211; and how a new tool plugs in determines whether it saves clicks or adds another silo. We walked through this in detail in our look at <a href="https://compudent.com/how-dental-ai-connects-imaging-twain-dicom-api-pms-bridges/">how dental AI tools connect to your imaging software</a>; the short version is that &#8220;it integrates&#8221; is a claim to test with your own setup, not to take on faith.</p>
<h2>2. Where does the patient&#8217;s image go?</h2>
<p>If the AI analysis runs in the cloud &#8211; as most modern dental-AI services do &#8211; then a patient&#8217;s diagnostic images are leaving your building and being processed by a third party. That is not automatically a problem, but it is automatically something you must govern. In Ontario, patient images are personal health information under PHIPA, and sending them to an external processor makes that vendor part of your compliance perimeter. You need to know where the data is stored, who can access it, how long it&#8217;s retained, and what happens if the vendor is breached. This is the same vendor-risk discipline we covered in <a href="https://compudent.com/phipa-hipaa-dental-ai-data-governance-vendor-risk/">PHIPA, HIPAA and dental AI</a>: a written agreement and clear data-handling answers come <em>before</em> the first image is uploaded, not after.</p>
<h2>3. Is it cleared for clinical use where you are?</h2>
<p>Overjet&#8217;s clearances are <strong>US FDA</strong> clearances. That does not automatically translate to Canada. A practice north of the border should confirm the tool&#8217;s regulatory status with Health Canada and understand exactly which uses are authorized here versus which are informational. It&#8217;s a five-minute question to ask a vendor, and the answer tells you a great deal about how carefully they&#8217;ve entered the Canadian market.</p>
<h2>4. Does it strengthen or complicate your device security?</h2>
<p>Adding a cloud AI layer means new connections into and out of your imaging environment &#8211; and your imaging environment is often the least-hardened corner of the network, full of appliances that are hard to patch. Any new tool should fit a network you already keep segmented and monitored, not become an excuse to open it up. If your scanners, sensors and older imaging PCs aren&#8217;t already isolated appropriately, that&#8217;s worth fixing first; we covered the how in <a href="https://compudent.com/legacy-imaging-device-network-segmentation-dental-practice/">keeping legacy imaging devices safely on your dental network</a>.</p>
<h2>A practical adoption checklist</h2>
<ul>
<li><strong>Confirm compatibility</strong> with your specific scanner, sensors, CBCT/pan and practice-management system before signing anything.</li>
<li><strong>Get the data story in writing:</strong> a vendor/data-processing agreement, data-residency details, retention and breach-notification terms.</li>
<li><strong>Verify regulatory clearance</strong> for clinical use in Canada, and know which features are diagnostic support versus informational.</li>
<li><strong>Pilot before you commit:</strong> run it on real cases with a couple of clinicians, and measure whether it actually saves time and improves the patient conversation.</li>
<li><strong>Train the team</strong> and set the expectation that AI flags are prompts for review, not final calls.</li>
<li><strong>Fit it to a secure network:</strong> make sure imaging devices and any cloud connections are segmented and monitored.</li>
</ul>
<p>None of this is a reason to avoid modern imaging tools &#8211; the unified-view trend is a real improvement over the disconnected software of the last decade, and it pairs naturally with the broader imaging decisions practices are already making, like <a href="https://compudent.com/fmx-vs-cbct-dental-practice-imaging-decision/">choosing between an FMX and a CBCT</a> for a given case. It&#8217;s a reason to adopt deliberately.</p>
<h2>What this means for your practice</h2>
<p>AuraVue is a good signal of where digital dentistry is heading: fewer disconnected programs, more unified views, and AI quietly doing first-pass reads to sharpen the clinician&#8217;s eye and the patient&#8217;s understanding. For a dental practice, the opportunity is real &#8211; and so is the homework. The difference between a tool that pays for itself and one that becomes shelfware usually isn&#8217;t the software; it&#8217;s whether it fits your existing systems, keeps patient data compliant, and lands on a secure, well-run network. Compudent Systems helps dental practices across Ontario evaluate exactly these decisions &#8211; imaging and PMS integration, PHIPA-ready data governance and vendor agreements, and the network security that any cloud AI tool depends on. If you&#8217;re considering AuraVue or any AI imaging platform and want a straight answer on whether it will fit and stay compliant, <a href="https://compudent.com/contact/">contact Compudent for an imaging and data-governance assessment</a>. We&#8217;ll help you adopt the good ideas without inheriting the hidden risks.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.prnewswire.com/news-releases/medit-launches-auravue-a-unified-3d-intraoral-scan-and-x-ray-visualization-powered-by-overjet-ai-302636354.html" target="_blank" rel="noopener">PR Newswire &#8211; Medit Launches AuraVue: A Unified 3D Intraoral Scan and X-Ray Visualization Powered by Overjet AI</a></li>
<li><a href="https://www.overjet.com/blog/overjet-partners-with-medit-to-launch-auravue-a-unified-3d-intraoral-scan-and-x-ray-visualization-tool" target="_blank" rel="noopener">Overjet &#8211; Overjet Partners with Medit to Launch AuraVue</a></li>
<li><a href="https://www.medit.com/meditauravue/" target="_blank" rel="noopener">Medit &#8211; AuraVue product page</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/how-dental-ai-connects-imaging-twain-dicom-api-pms-bridges/">How Dental AI Tools Connect to Your Imaging Software: TWAIN, DICOM, API, and PMS Bridges</a></li>
<li><a href="https://compudent.com/overjet-integration-rcm-workflow-data-governance/">Overjet in Your Practice: Integration, RCM Workflow, and Data Governance</a></li>
<li><a href="https://compudent.com/roentgen-to-practice-server-xray-imaging-it-discipline/">From Roentgen&#8217;s Lab to Your Practice Server: How Dental X-ray Imaging Became an IT Discipline</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/medit-auravue-overjet-ai-dental-practice-imaging/">One Screen for Scans and X-Rays: What Medit&#8217;s AuraVue With Overjet AI Means for Your Dental Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Gateway That Lets Your Team In Can Let Attackers In Too: Critical Check Point VPN Flaws (CVE-2026-85102 / 85103) and Your Practice</title>
		<link>https://compudent.com/checkpoint-vpn-cve-2026-85102-85103-dental-practice-remote-access/</link>
		
		<dc:creator><![CDATA[Raymond]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 09:36:49 +0000</pubDate>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Check Point VPN]]></category>
		<category><![CDATA[CVE-2026-85102]]></category>
		<category><![CDATA[CVE-2026-85103]]></category>
		<category><![CDATA[dental IT security]]></category>
		<category><![CDATA[Dutch NCSC]]></category>
		<category><![CDATA[firewall security]]></category>
		<category><![CDATA[network perimeter]]></category>
		<category><![CDATA[remote access]]></category>
		<category><![CDATA[unauthenticated RCE]]></category>
		<category><![CDATA[VPN security]]></category>
		<guid isPermaLink="false">https://compudent.com/checkpoint-vpn-cve-2026-85102-85103-dental-practice-remote-access/</guid>

					<description><![CDATA[<p>Two critical flaws in Check Point VPN gateways (CVE-2026-85102 and CVE-2026-85103, both rated 9.8) let an unauthenticated attacker run code on the device that guards your network - no password, no VPN account needed. The Dutch national cyber agency says mass exploitation is imminent. Here's what it means for a dental practice, and why the box that lets your team in remotely is exactly the box you can't afford to leave unpatched.</p>
<p>The post <a href="https://compudent.com/checkpoint-vpn-cve-2026-85102-85103-dental-practice-remote-access/">The Gateway That Lets Your Team In Can Let Attackers In Too: Critical Check Point VPN Flaws (CVE-2026-85102 / 85103) and Your Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On September 9, Check Point disclosed two critical vulnerabilities in its VPN products, and within days the Dutch National Cyber Security Centre (NCSC) issued an unusually blunt warning: assume large-scale exploitation is coming, and patch now. The flaws, tracked as <a href="https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/">CVE-2026-85102 and CVE-2026-85103</a>, both carry a CVSS score of <strong>9.8 out of 10</strong> &#8211; about as high as these ratings go &#8211; and both allow an attacker to run code on the device with <strong>no password and no VPN account</strong>. For any dental practice that offers remote access, this is the kind of alert that belongs at the top of the day&#8217;s list, not the bottom.</p>
<h2>What Check Point VPN is &#8211; and why your practice may depend on it</h2>
<p>Check Point is a widely deployed enterprise firewall and VPN platform. In a dental office, a device like this typically plays two roles at once: it&#8217;s the <strong>firewall</strong> that separates your internal network from the internet, and it&#8217;s the <strong>VPN gateway</strong> that lets a doctor review images from home, a bookkeeper connect from another location, or your IT provider reach the network to support it. That dual role is exactly what makes it valuable &#8211; and exactly what makes a flaw in it so serious. You may not even know the brand of the box in your server closet; many practices simply have &#8220;the firewall the IT company installed.&#8221; This advisory is a good reason to find out what it is.</p>
<h2>What the flaws actually do</h2>
<p>Both bugs live in the way the gateway handles digital certificates while it&#8217;s setting up a VPN connection &#8211; the handshake that happens <em>before</em> anyone logs in. <strong>CVE-2026-85102</strong> is an improper validation of certificate data during VPN negotiation that lets a remote attacker execute arbitrary code on a Security Gateway. <strong>CVE-2026-85103</strong> is a heap overflow in the certificate decoder that can allow remote code execution on Security Gateways <em>and</em> Security Management Servers. The critical detail for both: they are <strong>pre-authentication</strong>. An attacker doesn&#8217;t need a stolen password, a valid VPN account, or any authorized access &#8211; only the ability to reach the gateway&#8217;s VPN service over the internet, which is precisely what a VPN gateway is designed to allow. That&#8217;s what earns the 9.8 rating, and it&#8217;s why the NCSC assessed both the likelihood and the impact as high. As of this writing there&#8217;s no public proof-of-concept exploit, but the agency&#8217;s message is that this is a matter of when, not if.</p>
<h2>Why &#8216;the firewall&#8217; is the worst possible thing to lose</h2>
<p>When the compromised device is a workstation, you have a problem. When it&#8217;s the gateway itself, you have a catastrophe. Successful exploitation here means an attacker can, in the NCSC&#8217;s words, take full control of the system, view or modify confidential data, and disrupt operations. Translate that into a dental practice: the box that was supposed to keep intruders out is now the intruder&#8217;s foothold &#8211; sitting at the boundary of your network, with a clear line to your practice-management server, your imaging archive, and every patient record behind it. It&#8217;s the ideal launch point for ransomware, for quietly exfiltrating PHI, or for simply shutting the practice down. This is the same reason we keep sounding the alarm on internet-facing perimeter gear, from <a href="https://compudent.com/watchguard-firebox-cve-2025-14733-ransomware-dental-practice-firewall/">firewall flaws that ransomware groups actively exploit</a> to <a href="https://compudent.com/mikrotrick-mikrotik-routeros-cve-2026-dental-practice-router/">the practice router as a hidden backdoor</a>. The device guarding the door is always the highest-value target in the building.</p>
<h2>Which versions are affected, and the fix</h2>
<p>The affected releases include R81.20, R82, R82.10, R81.10.x and R82.00.x, along with the end-of-support versions R80 through R80.40, R81 and R81.10. Notably, R82.20 is <em>not</em> affected. Check Point has published fixes and rated the response as straightforward for supported versions:</p>
<ul>
<li><strong>Live Patch:</strong> Take 24 for R81.20, R82 and R82.10 &#8211; and for practices using Check Point Live Patch, these protections have applied automatically since September 9, without even a reboot. Confirm you&#8217;re actually covered, because the automatic mitigation only supports those three versions and not every configuration.</li>
<li><strong>Jumbo Hotfix Accumulators:</strong> R82.10 Take 44 or later, R82 Take 126 or later, R81.20 Take 166 or later.</li>
<li><strong>Spark firewalls:</strong> R82.00.10 Build 2325 or later, or R81.10.17 Build 4968 or later.</li>
</ul>
<p>If you&#8217;re running one of the <strong>end-of-support</strong> versions (R80 through R81.10), there is no clean fix path &#8211; that gear needs to be upgraded or replaced, not merely patched. Running EoS security appliances on the edge of a network holding patient data is a risk that predates this specific CVE and outlives it. As an interim hardening step for anyone using the Site-to-Site VPN component, Check Point advises modifying VPN rules to limit access to specific, trusted IP addresses.</p>
<h2>What to do now</h2>
<p>The response is short and time-sensitive. <strong>Identify your gear:</strong> confirm whether your practice &#8211; or the MSP that manages your network &#8211; runs Check Point, and which version. If you use an outside IT provider, this is a completely fair thing to email them today and ask for a straight answer. <strong>Patch immediately:</strong> apply the Live Patch, Jumbo Hotfix or Spark build for your version, and verify the automatic Live Patch protection is actually in place rather than assuming it. <strong>Retire end-of-support devices:</strong> if you&#8217;re on R80-R81.10, plan the replacement now, not next quarter. <strong>Reduce exposure:</strong> restrict VPN and management access to trusted sources where you can, and never leave a management interface open to the whole internet. <strong>Layer your defenses:</strong> multi-factor authentication on all remote access, and monitoring that would flag anomalous activity at the gateway. And treat this as a standing habit, not a one-off &#8211; the same patch discipline applies to your servers and endpoints, which is why we walked through <a href="https://compudent.com/september-2026-patch-tuesday-974-vulnerabilities-dental-practice/">how a practice should read this month&#8217;s Patch Tuesday</a> just last week.</p>
<h2>What this means for your practice</h2>
<p>CVE-2026-85102 and CVE-2026-85103 are a textbook example of the risk that comes with convenience: the very gateway that lets your team work remotely is a single, internet-facing box that, if it falls, takes the whole network with it. The fix for supported versions is fast and low-drama; the danger is a practice that simply doesn&#8217;t know what&#8217;s in its server closet, or assumes &#8220;the IT company handles it&#8221; without ever confirming. Compudent Systems manages exactly this for dental practices across Ontario: we inventory and patch your firewall and VPN gateways, retire the end-of-support gear that quietly accumulates risk, lock down and monitor remote access, and make sure a critical advisory like this one is acted on the day it lands &#8211; not discovered after an incident. If you&#8217;re not certain your VPN gateway is patched, supported, and properly restricted right now, <a href="https://compudent.com/contact/">contact Compudent for a perimeter and remote-access security assessment</a>. We&#8217;ll find out what&#8217;s guarding your network and make sure it&#8217;s actually doing the job.</p>
<hr />
<p><strong>Sources &amp; further reading:</strong></p>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/" target="_blank" rel="noopener">BleepingComputer &#8211; Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent</a></li>
<li><a href="https://support.checkpoint.com/results/sk/sk1000118/" target="_blank" rel="noopener">Check Point Advisory sk1000118</a></li>
</ul>
<p><!-- ray:related:start --></p>
<h2>Related Reading</h2>
<ul>
<li><a href="https://compudent.com/sonicwall-sma1000-vpn-ransomware-dental-practices/">Ransomware Gangs Are Now Through the Front Door: What the SonicWall SMA1000 VPN Attacks Mean for Dental Practices</a></li>
<li><a href="https://compudent.com/n-central-cve-2026-86218-preauth-rce-dental-msp-rmm/">A Perfect 10, No Password Required: The N-central Zero-Day (CVE-2026-86218) Your IT Provider Must Have Patched</a></li>
<li><a href="https://compudent.com/windows-ike-cve-2026-33824-rce-dental-practice/">A Single Packet, No Password Required: The Actively Exploited Windows IKE Flaw (CVE-2026-33824) and Your Practice</a></li>
</ul>
<p><!-- ray:related:end --></p>
<p>The post <a href="https://compudent.com/checkpoint-vpn-cve-2026-85102-85103-dental-practice-remote-access/">The Gateway That Lets Your Team In Can Let Attackers In Too: Critical Check Point VPN Flaws (CVE-2026-85102 / 85103) and Your Practice</a> appeared first on <a href="https://compudent.com">Compudent Systems</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
