The Risk You Don’t Control: Why Third Parties and Shadow AI Are Creating a New Cybersecurity Challenge for DSOs

shadow AI cybersecurity DSO

 

Dental Service Organizations (DSOs) have spent years strengthening their cybersecurity. They have deployed firewalls, endpoint protection, employee training, multifactor authentication and other security technologies designed to protect their environments.

But one of the greatest risks facing a DSO today may not originate inside its network at all. It may come through a vendor.

Every DSO depends on an expanding ecosystem of third parties: practice management and imaging platforms, cloud providers, billing companies, payment processors, IT providers, marketing firms, payroll companies, laboratories, consultants and dozens of other technology partners.

Each connection creates efficiency. It can also create another potential pathway into the organization.

And now artificial intelligence is dramatically expanding that ecosystem.

“Your Security Is Increasingly Dependent on Someone Else’s Security”

shadow AI cybersecurity DSO

The healthcare industry received a dramatic demonstration of third-party concentration risk with the Change Healthcare cyberattack. HHS described the incident as having an “unprecedented magnitude” and widespread impact on healthcare providers and patients nationwide.

The lesson for DSOs is straightforward: you don’t have to be directly attacked to become a victim of a cyberattack.

Consider a 100-location DSO. Even if its internal cybersecurity program is strong, dozens or potentially hundreds of outside organizations may interact with its systems, employees or information. An attacker doesn’t necessarily need to attack the DSO’s front door. The easier path may be compromising a vendor with privileged access, stealing a vendor employee’s credentials, compromising a cloud application, or exploiting a poorly secured third-party integration. This is why third-party risk management needs to become part of the DSO’s overall cybersecurity strategy.

HIPAA recognizes this interconnected reality. HHS specifically identifies vendors such as EHR providers and managed service providers as business associates when their services involve creating, receiving, maintaining or transmitting PHI. HHS also makes clear that subcontractors handling PHI can themselves become business associates.

Signing a Business Associate Agreement, however, should not be confused with verifying cybersecurity. A contract transfers obligations. It does not stop ransomware.

DSOs Need to Know Who Has Access

The first step toward reducing third-party risk is visibility.

Leadership should be able to answer several basic questions:

  • What vendors have access to our network, systems or sensitive information?
  • Which vendors handle PHI?
  • Which vendors have remote or privileged access?
  • What security controls do those vendors maintain?
  • Are their users protected with MFA?
  • What happens to our information after a contract ends?
  • Who are the vendor’s subcontractors?
  • How quickly must the vendor notify us of a security incident?
  • Can we disable third-party access immediately if a vendor is compromised?

This shouldn’t be a questionnaire completed once and forgotten.

shadow AI cybersecurity DSO

Third party cybersecurity needs to become a continuous process involving vendor inventory, risk classification, access controls, contract requirements, periodic security reviews and ongoing monitoring. HHS itself recommends reviewing vendor and contractor relationships to ensure appropriate BAAs are in place and that security-incident and breach obligations are addressed.

But another category of third party is rapidly entering dental organizations, sometimes without leadership knowing it exists.

The Rise of Shadow AI

Imagine an employee at one of your practices discovers a free AI application that makes their job easier. They begin using it to draft correspondence, summarize documents, analyze spreadsheets or answer questions. Eventually, information from the practice gets copied into the application. Nobody intentionally violated policy.

The employee was simply trying to become more productive, but the organization may now have sensitive information being processed by a platform that security, compliance and leadership have never evaluated.

This is Shadow AI. Employees using AI applications without formal organizational approval or oversight. It is rapidly becoming a healthcare governance problem. A Wolters Kluwer healthcare survey found that 40% of respondents had encountered an unauthorized AI tool in their organization and another 17% acknowledged using one.

For a multi-location DSO, the challenge can become exponentially more complicated. Hundreds or thousands of employees can independently discover AI tools, browser extensions, transcription platforms, assistants and applications. Blocking AI entirely isn’t a realistic long-term strategy. The better strategy is to make safe AI easier to use than unsafe AI.

Then There Are AI Hallucinations

Protecting information isn’t the only concern. AI can also be wrong.

Generative AI systems sometimes produce information that sounds authoritative but is inaccurate or completely fabricated. These errors are commonly called AI “hallucinations.” NIST specifically identifies healthcare as an area where these errors can create significant consequences. That distinction is critical.

AI does not necessarily “know” whether its answer is true simply because the response sounds confident.

For DSOs, imagine AI being used to interpret a policy, summarize patient information, generate HR guidance, answer a compliance question, recommend a clinical protocol or create patient-facing communications.

An employee may see a polished, confident response and assume it is accurate.

This creates a new category of organizational risk: “Automation Bias”. This is humans trusting technology too much because the technology appears authoritative.

AI therefore requires more than cybersecurity. It requires governance.

AURA: Enabling AI Instead of Simply Blocking It

This is the philosophy behind AURA Ai™ from Black Talon Security. The goal shouldn’t be to tell DSO employees, “Don’t use AI.” AI has enormous potential to improve productivity, streamline administrative processes, improve communication and help DSOs operate more efficiently. The objective should be: Use AI but use it safely. AURA is designed to help organizations establish the guardrails necessary to adopt AI responsibly while reducing the cybersecurity, privacy and operational risks surrounding its use.

AURA Ai™ from Black Talon Security

Rather than allowing employees to independently decide which AI platforms are appropriate, organizations need a structured framework for evaluating AI tools, establishing acceptable use policies, educating employees, protecting sensitive information and determining where human verification must remain part of the process.

This is particularly important because AI risk doesn’t stop with the AI provider itself. Organizations must understand what information is entering an AI platform, where that information may go, how it may be retained and whether additional third parties or integrations are involved. AURA helps turn AI adoption from an uncontrolled employee experiment into a managed organizational strategy. See what AURA can do for your DSO.

The New DSO Security Perimeter

For years, organizations thought about cybersecurity as protecting a network.

That concept is becoming obsolete. The modern DSO’s security perimeter now extends across cloud applications, vendors, business associates, remote users, mobile devices, third-party integrations and AI platforms.

The question leadership should be asking is no longer simply:

“Are we secure?” It should be: “Do we know everywhere our data is going, everyone who can access it, and every technology (including AI) that our employees are using?”

If the answer is no, the organization has a visibility problem.

Third party risk and Shadow AI ultimately share the same underlying challenge: “Organizations Cannot Protect What They Cannot See.”

The DSOs that successfully embrace AI will not be the organizations that simply move the fastest. They will be the organizations that establish the visibility, governance and security necessary to move quickly without introducing unacceptable risk.

AI is coming to dentistry whether organizations are prepared for it or not.

The opportunity for DSO leadership is to make sure innovation doesn’t outrun security.

The future isn’t about stopping AI. It’s about making AI safe. Schedule a cyber risk review today to understand where your DSO may have gaps.


🚨 Recent notable healthcare cyber incidents:

Park Dental Partners, a practice resource and management support organization serving brands in Minnesota, Wisconsin and Arizona, has reported a potential data breach in a Form 8-K filed with the Securities and Exchange Commission (SEC) on September 1, 2026. While operations remain unaffected, the investigation into the Park Dental Partners data breach is ongoing as the company assesses the potential compromise of personal or protected health information. Previously, Park Dental experienced a data breach in early 2024 that exposed sensitive patient information.


DentaQuest, the nation’s second-largest dental insurer, suffered a May cyberattack that exposed the personal and health information of 15 million patients, making it the largest reported healthcare data breach of 2026. A ransomware group later claimed it had stolen 234 gigabytes of data, although DentaQuest has not confirmed that ransomware was involved or addressed the group’s claims. The company investigated the incident with an outside cybersecurity firm, strengthened its security and monitoring controls, and provided additional employee training.


Issaqueena Pediatric Dentistry, a three-location pediatric dental and orthodontic practice in South Carolina, has reported a data breach involving sensitive information. According to a notice posted to its website, Issaqueena fell victim to a criminal cyberattack and, following an investigation into the incident, determined on July 1, 2026 that some personal and protected health information may have been subject to unauthorized access.


Dental Cyber Watch is sponsored by Black Talon Security, the recognized cybersecurity leader in the dental/DSO industry and a proud partner of Group Dentistry Now. With deep roots within the dental and dental specialty segments, Black Talon understands the unique needs that DSOs and dental groups have when it comes to securing patient and other sensitive data from hackers. Black Talon’s mission is to protect all businesses from the devastating effects caused by cyberattacks—and that begins with a robust cyber risk mitigation strategy. To evaluate your group’s current security posture visit www.blacktalonsecurity.com.

DSO cybersecurity


Have a cybersecurity question or concern that you would
like addressed in future Dental Cyber Watch articles,
please email it to info@groupdentistrynow.com


group dentistry now subscribe

 

Facebooktwitterlinkedinmail