
← The Raving Patients Podcast28 aug · 38 min
Your Vendors Have the Keys: The Cyber Risk Dental Practices Ignore
The biggest cybersecurity threat to your dental practice may not be a hacker trying to break through your firewall. It could be a vendor you already trust.
In this episode of the Raving Patients Podcast, Dr. Len Tau sits down with Anthony Jurjevic, CISSP, founder and CEO of Techspedient, to uncover the cybersecurity risks many dental practices do not realize are already inside their networks. With more than 25 years in healthcare IT and cybersecurity, including over 15 years focused on dental technology, Anthony explains why vendor access, outdated credentials, shared passwords, and poorly managed remote access tools can leave practices vulnerable.
Anthony explains how practice management companies, imaging vendors, billing services, patient communication platforms, phone systems, and other vendors may have ongoing access to a practice's network. The problem is not necessarily that these vendors are unsafe. It is that many practices do not know who still has access, how that access is being monitored, or what happens if a vendor's credentials are compromised.
The conversation also tackles one of the biggest misconceptions in dental cybersecurity: being in the cloud does not automatically mean your practice is backed up or secure. Anthony shares how attackers can compromise a workstation, use saved credentials to access cloud-based patient information, and quietly steal data without encrypting an entire network. He explains why modern ransomware attacks increasingly focus on data theft and extortion, making traditional backups only one piece of a much larger security strategy.
Dr. Len and Anthony also discuss HIPAA compliance, what happens after a ransomware attack, the importance of cyber insurance and forensic investigations, and the practical steps dentists can take right now to identify vulnerabilities. From auditing vendor access and removing former employees to testing backups, enabling multi-factor authentication, and conducting third-party cybersecurity assessments, this episode gives practice owners a practical look at protecting both their patients and their businesses.
What You'll Learn Why trusted vendors can become one of your biggest cybersecurity vulnerabilities
How unattended remote access can expose your dental practice
Why being "in the cloud" does not automatically make your data safe
How modern ransomware has shifted from encrypting data to stealing it
Why backups cannot protect you once patient data has already been stolen
What "HIPAA compliant" software really means for a dental practice
What to do immediately after discovering a possible ransomware attack