SeriousIT
Dental practices

Your practice isn't
a side account.

Managed IT, HIPAA compliance, phones, and fiber for Utah dental practices, from a team that knows Open Dental from Dentrix and picks up when every op is full.

A dental operatory with a chair and a wall-mounted monitor
Op 2, imaging up, patched before the first patient
HIPAA, delivered

Compliance you can hand to an auditor.

We run the HIPAA program, not just the servers. Every element below is part of the service, kept current on a schedule, and written down where you can find it.

Every item is documented and evidence-backed, so an auditor, an insurer, or a patient gets a file, not a scramble.

What a covered practice looks like
The HIPAA items we keep current for every dental client
  • Annual risk analysis due in 6 weeks scheduled
  • Business associate agreements 12 on file current
  • Workforce HIPAA training 18 of 18 current
  • MFA on every login, front desk included enforced current
  • Backup restore test passed Wed current
  • Encrypted email whole domain current
  • Breach response playbook reviewed Q3 current
  • Cyber-insurance attestation ready current
Every line is documented and evidence-backed, so when an auditor, an insurer, or a patient asks, the answer is a file, not a scramble.
The HIPAA year, item by item
A year of the program, item by item. Dots are the months we act; bars run all year.
Annual risk analysis

The written assessment HIPAA actually requires, refreshed every year and after any big change.

Policies and procedures

A policy set tailored to the practice, approved by the owner, acknowledged by the staff.

Business associate agreements

Every vendor that touches PHI, on file and tracked to renewal.

Workforce training

At hire and every year, with completion records, including phishing that looks like your own insurance carrier.

Encrypted email and MFA

Protected health information encrypted in transit; multi-factor on every login, front desk included.

Backups with tested restores

Immutable offsite copies of the practice server and imaging, restore-tested on a schedule, not assumed.

Breach response playbook

Who calls whom, what gets preserved, and the notification clock, rehearsed before you need it.

Cyber-insurance attestation

The MFA, backup, EDR, and training questions on your renewal, answered with evidence.

A receptionist working at a dental front desk
Day one

Day one: what we usually find.

Not a sales pitch, an inventory. These are the conditions we walk into at most dental practices, in the order we find them.

  1. A ransomware hit with no tested restore

    The practice management server is the whole business. A backup nobody has ever restored is a hope, not a plan.

  2. Imaging workstations nobody patches

    The sensor vendor said not to touch it, so the op computer runs an OS from two owners ago and sits on the same network as everything else.

  3. Shared front-desk logins with no MFA

    One password on a sticky note, used by everyone who has worked the desk since the office opened.

  4. IT that goes quiet during patient hours

    The ticket gets answered at 6 p.m. The chair was empty at 10 a.m.

  5. Vendor finger-pointing

    The practice software blames imaging, imaging blames the network, and you are on hold with all three while a patient waits.

  6. A HIPAA binder from 2019

    Policies exist. Nobody can find the risk analysis, the training records, or the BAA for the new billing service.

AI, done right

AI is already in the practice. Put it on a leash you can show.

AI answering the phones, reading radiographs, drafting the recall text, and someone at the front desk pasting a patient note into a chatbot to reword it. Some of that is good. All of it touches PHI, and HIPAA does not care that it was convenient.

Already happening on your network
  • Front desk pasting insurance narratives into a free chatbot
  • AI phone answering and scheduling assistants trialed by the office manager
  • Radiograph AI turned on by the imaging vendor
  • Practice-management copilots and AI-written recall texts
Nobody meant to create a risk. They wanted the work done faster. The fix is a short list and a few settings, not a ban.
A BAA before a login

Every AI tool that sees patient data signs a business associate agreement first, or it does not get patient data. We keep the list.

An approved list the team can actually use

A short list of AI tools the practice pays for, with the rule for each, so nobody has to guess and nobody has to sneak.

The dentist signs, the AI drafts

Radiograph findings and treatment notes stay the clinician’s call. AI suggests, a person approves, and the record says who.

Ten minutes, inside the HIPAA training

What can go into which tool, taught in the same yearly session the practice already sits through.

Never leaves the building
  • Patient names or charts in free chatbots
  • Radiographs uploaded to unknown AI sites
  • Insurance narratives with PHI in personal accounts
  • Any AI tool without a BAA

We write the AI use policy into the HIPAA program, so it is one more line the risk analysis covers instead of a separate project.

The software we live in

We already know your stack.

Practice management, imaging, and the everyday office systems around them.

Practice management
  • Open Dental
  • Dentrix
  • Dolphin for orthodontics
  • Cloud migrations when the practice is ready
Imaging
  • Dexis sensors and software
  • Schick, Carestream, and Planmeca behave the same way
  • Scanner and 3D workstations
  • Isolated, patched, and backed up
The rest of the office
  • Windows workstations in every op
  • On-prem servers while you need them
  • Microsoft 365, printers, label makers
  • Patient Wi-Fi kept off the clinical network

We prefer to move practices to cloud practice management when it fits, and we support the on-prem server properly until you get there.

After go-live

What changes for the people in the building.

The front desk, the doctor, and the office manager each feel it differently. This is what each of them gets.

Front desk

One login, and it just works.

  • One account with MFA that takes seconds, not a password on a sticky note.
  • Phones that route to the right person, with voicemail in email.
  • Scanners and printers that work the first time, every op.
Doctor

Every op, every image, every time.

  • Imaging up in every op before the first patient of the day.
  • The chart from home, securely, when you need to look at it.
  • No more calling three vendors from the hallway.
Office manager

The binder becomes a dashboard.

  • HIPAA training, BAAs, and the risk analysis tracked and current.
  • The cyber-insurance questionnaire answered with evidence, not memory.
  • One bill and one number to call.
Which plan

Most practices land on Hardened.

Same plans as every SeriousIT client, no dental surcharge. The compliance pack is what dental needs, so Hardened is where most offices belong.

Hardenedmost common
The HIPAA program above, 24/7 detection and response, log retention, and the compliance evidence your insurer and auditor ask for.
Secured
Solo or two-op offices that want the security baseline with EDR, email security, and tested backups, and handle their own HIPAA paperwork.
Managed
Rarely the right fit for a practice with patient data. We will tell you if it is.
Questions we get

Straight answers.

Do you support cloud practice management, or just on-prem?

Both. We prefer to move practices to cloud practice management when it fits the office, and we run and back up the on-prem server properly until then.

Can you do our HIPAA risk analysis?

Yes. The annual risk analysis, the policy set, workforce training, BAAs, and the breach playbook are part of the Hardened plan, kept current on a schedule.

Our imaging vendor says not to touch the workstation. What then?

We isolate it, patch it in a maintenance window the vendor agrees to, and back it up. An unpatched imaging PC on the same network as the practice server is the most common way we see dental offices get hit.

Will you be reachable during patient hours?

That is the point. Business-hours support with real response times, and no after-hours or per-ticket surcharges on any plan.

What if we already have a phone system or internet?

Keep what works. We manage IT alongside your existing vendors, and we quote phones or fiber only when they would save you money or trouble.

Do you work with multi-location practices and DSOs?

Yes. Standardized builds per location, one help desk, and compliance evidence rolled up across offices.

A bright modern dental office interior

Start with a HIPAA gap check.

Send us your current bills and your last risk analysis, if you have one. We come back with what is exposed, what it would take to fix, and what consolidating would cost.