Managed detection and response on every endpoint
Workstations, the PMS server, the imaging workstation, doctor laptops. 24/7 SOC watching for ransomware canaries, credential theft, and lateral-movement patterns documented in dental-vertical attacks.
Dental cybersecurity
Managed cybersecurity for dental practices running Dentrix, Eaglesoft, Curve, Denticon, Microsoft 365, or Google Workspace. We operate MDR, ITDR, and Security Awareness Training, then package the HIPAA evidence your insurer and OCR actually want to see.
TL;DR
We operate managed detection and response, identity threat detection, and security awareness training for your practice end-to-end. The 24/7 SOC watches every endpoint and your Microsoft 365 or Google Workspace tenant for the attack patterns documented across the dental vertical:
Obsidian Ridge adds the security-operations side: HIPAA-aligned configuration, audit-control evidence, cyber-insurance readiness, incident-response coordination, and the quarterly executive briefing for the doctor and the practice manager.
Pricing, per month:
Not ready for the full program yet? Ridge Watch ($15 per device per month, monitoring only) is an honest first step — real protection now, though a practice handling ePHI will want the controls above before an audit or an insurance renewal.
What's included
Workstations, the PMS server, the imaging workstation, doctor laptops. 24/7 SOC watching for ransomware canaries, credential theft, and lateral-movement patterns documented in dental-vertical attacks.
On either platform it catches stolen session tokens replayed from somewhere new and the inbox rules that route insurance and wire emails away from the office manager. On Microsoft 365 it also catches the adversary-in-the-middle kits that bypass MFA (EvilProxy, Tycoon) and the OAuth-consent attacks dentists rarely see coming.
Phishing simulations and 5-minute micro-lessons tuned for dental staff: payment-redirect themes for the office manager, ePHI-handling lessons for the front desk, vendor-impersonation drills for the bookkeeper.
Audit-control logs, MFA coverage report, encryption-in-transit confirmation, training completion, and a written incident-response plan packaged for OCR review or insurance underwriting.
The practice-management server gets the same 24/7 monitoring as every workstation, and the imaging-vendor EDR-exclusion conversation is handled correctly. The software itself stays with your IT vendor and the software vendor.
If something happens, you are not alone with a vendor portal. We coordinate forensics, breach notification timing, cyber-insurance claim, OCR reporting, and the patient-facing communication.
How we work
Keep your IT company. They handle the help desk, the hardware and the everyday fixes. We run the security layer beside them: threat detection and response, and the evidence insurers and auditors ask for.
For a dental practice, that means your IT vendor and the software vendor keep Dentrix, Eaglesoft and Open Dental. We watch the computers and the server they run on.
The threat model
Three attack patterns matter most.
The attacker phishes the office manager and lands a loader. Then:
Monday morning the practice cannot bill, treat, or look up a patient.
Full walkthrough of the attack chain. What would the downtime cost your practice? Run the 2-minute calculator.
The attacker phishes the office manager's Microsoft 365 credentials through an adversary-in-the-middle kit. Then:
sa password from a 2018 installOCR enforcement keeps finding the same gaps:
What the Security Rule actually requires.
For the wider set of regulated-industry writeups — HIPAA, IRS Publication 5708, ABA model rules, cyber-insurance controls — browse the compliance blog.
The insurance wedge
Maybe a cyber-insurance renewal or new application just arrived with a 2026 questionnaire nobody at the front desk can answer.
In 7 business days the Cyber Insurance Readiness Sprint maps every question on your carrier's questionnaire to the control that answers it, closes the gaps we can, and hands you a signed evidence pack.
Flat fee, $1,500–$3,500 depending on location count and scope. Delivered, or we keep working at no additional cost until it is. We don't control underwriter decisions. We control whether you walk in with the evidence they ask for.
See the save
Composite incident built from public ransomware advisories. Real attack mechanics — phishing → loader → lateral movement to the Dentrix server → a canary fires as encryption begins. The kind of save that turns a Monday morning crisis into a calm phone call.
Dental field notes
Hands-on long reads. No marketing copy, no acronym soup. Each one written for a dental practice owner, not a CISO.
The pillar piece. 45 CFR § 164.308–164.318 in plain terms, the 2025 NPRM, and where most practices miss the mark.
Read the articleThe attack chain that ends with an encrypted Dentrix database on a Friday night, and the controls that break it.
Read the articleAccount hygiene, SQL Server defaults, audit-log paths, backup architecture, and the imaging-vendor EDR-exclusion problem.
Read the articleThe 2026 underwriting questionnaire, the co-insurance trap, and the operational sequence that passes the application.
Read the articleThe composite incident, the AiTM session-token theft, the callback-verification policy that costs nothing and stops it.
Read the articlePre-acquisition cyber diligence, the 4-quarter program, and the identity-consolidation question every growing group hits.
Read the articleThe role-distinction reframe. What your IT provider owns, what a security operation owns, the specific questions to ask to tell whether the layer is covered, and why co-managed is the healthy model.
Read the articleHonest fit check
How we start
Tell us how the practice runs. PMS, locations, headcount, current IT firm, cyber-insurance renewal date, recent incidents, and what is driving the conversation. We tell you which tier fits and where the real risks are.
Endpoint and user counts, tier recommendation, the implementation schedule, and the HIPAA evidence deliverables. Fixed monthly pricing. Month-to-month or annual. No vendor markup games.
MDR agent on every endpoint and the PMS server. Managed ITDR connected to your Microsoft 365 or Google Workspace tenant. Awareness program launched with a phishing simulation calibrated to the practice. Business Associate Agreement signed before any access.
The 24/7 SOC is watching from day one. Obsidian Ridge handles escalations, quarterly executive briefings, the HIPAA evidence package, the cyber-insurance renewal support, and the tabletop exercise the practice owner should be running annually.
HIPAA risk and insurance readiness
The HIPAA Security Rule lists a risk analysis as Required: “an accurate and thorough assessment of the potential risks and vulnerabilities” to the electronic protected health information the practice holds.
The same section requires:
A cyber insurance application asks about many of the same controls: endpoint detection, multi-factor authentication, staff training and backups. Evidence built for one answers much of the other, so we build it once.
We work alongside the practice's existing IT vendor. We do not support Dentrix, Eaglesoft or Open Dental: installing, upgrading, configuring and troubleshooting them stays with your IT vendor and the software vendor. Backups are not part of any tier; the Readiness Sprint checks yours.
Obsidian Ridge is not an insurance producer, broker, or agent. We do not sell, place, or advise on insurance products.
Source: 45 CFR 164.308(a)(1)(ii), eCFR, current text, fetched September 25, 2026. A general summary, not legal advice.
HIPAA breach notification
Under the HIPAA Breach Notification Rule, a HIPAA-covered entity that experiences a breach of unsecured protected health information generally must:
A business associate that experiences a breach must notify the covered entity, generally without unreasonable delay and no later than 60 calendar days after discovery.
This is a general summary for educational purposes, not legal advice. Requirements depend on your specific circumstances and may change. Consult qualified counsel and the official HHS guidance. Source: HHS Breach Notification Rule (hhs.gov).
Questions dental owners ask
We deliver the technical safeguards required by the HIPAA Security Rule — audit controls, encryption, identity threat detection, integrity monitoring — and we sign a Business Associate Agreement before any engagement.
Vendors are not 'HIPAA certified' in any formal sense; the meaningful question is whether they can produce the technical evidence and sign the BAA. We can do both. We are not, and we do not claim to be, your HIPAA Privacy Officer.
No, and we are explicit about that. We are a managed cybersecurity firm, not an MSP. Your IT firm continues to handle help-desk, Wi-Fi, hardware procurement, and PMS upgrades.
We handle 24/7 monitoring, identity threat detection, security awareness training, and incident response. The two functions belong with different specialists; most general MSPs are not staffed or licensed to operate a 24/7 SOC.
Foundation starts at $15 per agent per month — that covers the practice management server, every workstation, and doctor laptops with 24/7 monitoring.
Protected at $32 per user per month adds Managed ITDR on the cloud productivity suite and the awareness-training program — the tier built for identity-layer attacks.
Complete at $55 per user per month adds SIEM and the formal compliance evidence program for practices with an upcoming insurance renewal or audit.
Yes. Our managed detection and response runs on Windows Server. We deploy the agent on the Dentrix server, the imaging workstation, every operatory workstation, and the front desk.
The PMS server is usually the highest-value endpoint in the practice and the one most MSPs overlook on EDR coverage — we treat it as the priority. The Dentrix software itself stays with your IT vendor and the software vendor.
Cloud PMS shifts the server burden to the vendor and the threat model toward account compromise.
That is exactly where Managed ITDR matters most: monitoring sign-in anomalies, mailbox rules, and token-replay attacks on your Microsoft 365 or Google Workspace tenant, plus OAuth consent on Microsoft 365.
The endpoint side is still important — laptops accessing the cloud PMS still get phished — so the Protected tier is usually the right starting point for cloud-PMS practices.
Endpoint agent rollout typically completes within 5 business days of contract signing. Identity threat detection on Microsoft 365 or Google Workspace activates within 24–48 hours of tenant connection.
The awareness-training program launches within the first two weeks. The HIPAA evidence package builds continuously and is review-ready after 90 days of operating data.
Yes. Our Cyber Insurance Readiness sprint maps the carrier questionnaire to the actual controls you have or need, packages the evidence the underwriter wants to see, and tells you honestly which gaps are worth closing before renewal.
The goal is to turn a declined, surcharged, or uncertain application into a cleaner underwriting conversation backed by evidence.
Huntress's 24/7 SOC acts on the alert around the clock. For an active incident, call your cyber insurance carrier's breach hotline first; there is no emergency line here. Within one business day, Kfir takes over everything past containment.
We coordinate forensics, help file the cyber-insurance claim, produce the patient-notification language, and work with you through the HIPAA Breach Notification Rule requirements.
See the HIPAA breach notification summary on this page for what the rule requires.
The practice owner remains the decision-maker for legal and patient-facing communication; we operate every technical and process step required by the breach response.
Two ways to start
The 10-minute assessment scores your practice against the controls insurers and OCR ask about — no email required to see your result.
The 30-minute dental briefing goes deeper — PMS, locations, insurance renewal, the threat model, and what your first 90 days would look like.
Both are free, both are no-obligation, and we tell you when you don't need us.