Your practice isn't
a side account.
Managed IT, HIPAA compliance, phones, and fiber for Utah dental practices, from a team that knows Open Dental from Dentrix and picks up when every op is full.
Compliance you can hand to an auditor.
We run the HIPAA program, not just the servers. Every element below is part of the service, kept current on a schedule, and written down where you can find it.
Every item is documented and evidence-backed, so an auditor, an insurer, or a patient gets a file, not a scramble.
- Annual risk analysis due in 6 weeks scheduled
- Business associate agreements 12 on file current
- Workforce HIPAA training 18 of 18 current
- MFA on every login, front desk included enforced current
- Backup restore test passed Wed current
- Encrypted email whole domain current
- Breach response playbook reviewed Q3 current
- Cyber-insurance attestation ready current
The written assessment HIPAA actually requires, refreshed every year and after any big change.
A policy set tailored to the practice, approved by the owner, acknowledged by the staff.
Every vendor that touches PHI, on file and tracked to renewal.
At hire and every year, with completion records, including phishing that looks like your own insurance carrier.
Protected health information encrypted in transit; multi-factor on every login, front desk included.
Immutable offsite copies of the practice server and imaging, restore-tested on a schedule, not assumed.
Who calls whom, what gets preserved, and the notification clock, rehearsed before you need it.
The MFA, backup, EDR, and training questions on your renewal, answered with evidence.
Day one: what we usually find.
Not a sales pitch, an inventory. These are the conditions we walk into at most dental practices, in the order we find them.
- A ransomware hit with no tested restore
The practice management server is the whole business. A backup nobody has ever restored is a hope, not a plan.
- Imaging workstations nobody patches
The sensor vendor said not to touch it, so the op computer runs an OS from two owners ago and sits on the same network as everything else.
- Shared front-desk logins with no MFA
One password on a sticky note, used by everyone who has worked the desk since the office opened.
- IT that goes quiet during patient hours
The ticket gets answered at 6 p.m. The chair was empty at 10 a.m.
- Vendor finger-pointing
The practice software blames imaging, imaging blames the network, and you are on hold with all three while a patient waits.
- A HIPAA binder from 2019
Policies exist. Nobody can find the risk analysis, the training records, or the BAA for the new billing service.
AI is already in the practice. Put it on a leash you can show.
AI answering the phones, reading radiographs, drafting the recall text, and someone at the front desk pasting a patient note into a chatbot to reword it. Some of that is good. All of it touches PHI, and HIPAA does not care that it was convenient.
- Front desk pasting insurance narratives into a free chatbot
- AI phone answering and scheduling assistants trialed by the office manager
- Radiograph AI turned on by the imaging vendor
- Practice-management copilots and AI-written recall texts
Every AI tool that sees patient data signs a business associate agreement first, or it does not get patient data. We keep the list.
A short list of AI tools the practice pays for, with the rule for each, so nobody has to guess and nobody has to sneak.
Radiograph findings and treatment notes stay the clinician’s call. AI suggests, a person approves, and the record says who.
What can go into which tool, taught in the same yearly session the practice already sits through.
- Patient names or charts in free chatbots
- Radiographs uploaded to unknown AI sites
- Insurance narratives with PHI in personal accounts
- Any AI tool without a BAA
We write the AI use policy into the HIPAA program, so it is one more line the risk analysis covers instead of a separate project.
We already know your stack.
Practice management, imaging, and the everyday office systems around them.
- Open Dental
- Dentrix
- Dolphin for orthodontics
- Cloud migrations when the practice is ready
- Dexis sensors and software
- Schick, Carestream, and Planmeca behave the same way
- Scanner and 3D workstations
- Isolated, patched, and backed up
- Windows workstations in every op
- On-prem servers while you need them
- Microsoft 365, printers, label makers
- Patient Wi-Fi kept off the clinical network
We prefer to move practices to cloud practice management when it fits, and we support the on-prem server properly until you get there.
What changes for the people in the building.
The front desk, the doctor, and the office manager each feel it differently. This is what each of them gets.
One login, and it just works.
- One account with MFA that takes seconds, not a password on a sticky note.
- Phones that route to the right person, with voicemail in email.
- Scanners and printers that work the first time, every op.
Every op, every image, every time.
- Imaging up in every op before the first patient of the day.
- The chart from home, securely, when you need to look at it.
- No more calling three vendors from the hallway.
The binder becomes a dashboard.
- HIPAA training, BAAs, and the risk analysis tracked and current.
- The cyber-insurance questionnaire answered with evidence, not memory.
- One bill and one number to call.
Most practices land on Hardened.
Same plans as every SeriousIT client, no dental surcharge. The compliance pack is what dental needs, so Hardened is where most offices belong.
One team for the whole office.
Front-desk phones, internet, and the cabling and cameras for a new op or a second location, from the same people who run your IT.
Front-desk phones
Hosted phones with call routing built for a busy front desk, mobile apps for the doctor, and after-hours handling that actually works.
Business phonesBusiness fiber
UTOPIA Fiber for the practice, supported by the team that runs your network, so imaging uploads and cloud software stop waiting.
Business fiberBuildouts and second locations
Structured cabling, cameras, and door access for new ops, tenant improvements, and expansion, managed after install.
InfrastructureStraight answers.
Do you support cloud practice management, or just on-prem?
Both. We prefer to move practices to cloud practice management when it fits the office, and we run and back up the on-prem server properly until then.
Can you do our HIPAA risk analysis?
Yes. The annual risk analysis, the policy set, workforce training, BAAs, and the breach playbook are part of the Hardened plan, kept current on a schedule.
Our imaging vendor says not to touch the workstation. What then?
We isolate it, patch it in a maintenance window the vendor agrees to, and back it up. An unpatched imaging PC on the same network as the practice server is the most common way we see dental offices get hit.
Will you be reachable during patient hours?
That is the point. Business-hours support with real response times, and no after-hours or per-ticket surcharges on any plan.
What if we already have a phone system or internet?
Keep what works. We manage IT alongside your existing vendors, and we quote phones or fiber only when they would save you money or trouble.
Do you work with multi-location practices and DSOs?
Yes. Standardized builds per location, one help desk, and compliance evidence rolled up across offices.
Start with a HIPAA gap check.
Send us your current bills and your last risk analysis, if you have one. We come back with what is exposed, what it would take to fix, and what consolidating would cost.