Field notes
IT support for dental and medical practices: what good looks like
A practice is a small business where the technology carries patient data and the schedule has no slack. When the front-desk PC hangs, patients stack up in the lobby. When the imaging workstation dies, the operatory it serves stops earning until it's fixed. The bar for "good IT" is simply higher here, and most generalist providers don't clear it.
Your imaging gear is IT, whether anyone admits it or not
Digital sensors, panoramic units, scanners, and clinical imaging systems all end at a computer: an acquisition workstation running vendor software, storing studies, and feeding your practice management system. Equipment vendors support their device and their software, and very little around it. The workstation's operating system, its updates, its backups, its network connection, and its eventual replacement are your problem, which means they should be your IT provider's problem.
This is a corner of IT most providers avoid because they've never stood next to the equipment. Our team has hands-on experience supporting clinical imaging systems, including ophthalmic imaging used in laser eye surgery, and the unglamorous PCs that drive them. The rule we work by: coordinate with the equipment vendor, own everything around the device.
HIPAA is an IT checklist before it's a legal one
We're not lawyers and this isn't legal advice, but most of what HIPAA expects from a small practice's technology is concrete and unglamorous:
- Encryption on every machine that touches patient data, including the laptop that goes home.
- Individual logins, not a shared front-desk password. Access should end the day employment does.
- Business associate agreements with the vendors that handle your data, your IT provider included. A provider who hesitates to sign one is telling you something.
- A record of what exists: which devices, which software, who can reach what. You can't protect an inventory you don't have.
Backups that restore, not backups that exist
For a practice, the backup question is existential: patient records, imaging studies, billing history. Ransomware crews target small healthcare specifically because the data is irreplaceable and the pressure to pay is high. "We have a backup drive" is not a plan. A plan is three copies, two kinds of storage, one of them off-site and out of reach of an attacker who gets into your network, and a scheduled test restore proving the whole thing actually works. Ask your current provider when they last restored a file for real. The pause tells you everything.
Email is the front door
Nearly every practice breach story starts with an email. Multi-factor authentication everywhere, modern filtering, and fifteen minutes of staff training on what a payroll-change scam looks like will do more for your security than any single product. Two configuration items do outsized work here: MFA on every mailbox without exceptions for the doctors, and sender authentication on your domain so nobody can impersonate the practice to patients or suppliers. It's also most of what your cyber insurance renewal now demands; we wrote a plain-English walkthrough of that questionnaire.
What response time means when the chairs are full
A practice books in fifteen-minute increments. "We'll get to it tomorrow" means a day of rescheduled patients and a front desk absorbing the anger. When you evaluate an IT provider, translate their SLA into your schedule: how many patients sit in the lobby between "we called" and "someone is working on it"? Same-day on-site for business-down problems is the standard a practice should hold out for. That's precisely what our support plans commit to in writing.
One more advantage of keeping data in the building: practices sit on years of documents and correspondence they can't ship to a consumer AI chatbot, because the data can't leave. Running AI models on hardware inside your own walls changes that calculus: private search and drafting over your own records, with nothing sent to anyone's cloud. We wrote about what on-prem AI is actually good for if that's interesting.
Common questions
Our imaging vendor says not to touch the workstation. What does that mean for updates?
It usually means updates must be validated against their software first, not skipped forever. An unpatched, internet-connected clinical workstation is a liability. The workable pattern: isolate those machines on the network, apply vendor-approved updates on a schedule, and document the exceptions.
We have a tech-savvy office manager who handles IT. Is that enough?
Up to a point, and every practice we've met passed that point years ago. The honest test: if the server died at 8am, could they have you seeing patients by lunch, and would anything be lost? If the answer is a shrug, the practice is carrying risk it hasn't priced.
Do we need a server in the office, or is cloud fine?
It depends on your practice management and imaging software; plenty of dental platforms still run best on a small local server, with the cloud handling backup and email. That's a right-tool decision, not a religion. What matters is that whichever it is, it's backed up, monitored, and owned by someone accountable.
What should switching IT providers look like?
Quiet. Credentials collected and rotated, documentation built, backups verified, staff told whom to call. If a provider can't describe their onboarding in that kind of detail, they haven't done it often.
Your imaging vendor supports the device. We support everything around it.
Bay Area practices, on-site, same-day when it's business-down. Call (415) 555-0134 or tell us about your practice. →