Nearly every conversation with a dental practice starts the same way: "we have IT, we should be fine on security." Sometimes that is true. More often it is a category mistake. IT support and cybersecurity operations are related jobs, but they are different jobs. When an assumption gets made that the first one covers the second, the practice ends up with a gap that only shows up on the day the office manager's mailbox does something strange or the practice-management server stops responding on a Friday evening.
This piece is not "your IT firm is bad." Most IT firms are excellent at what they do. This piece is about which job is which, when a dental practice needs a specific security operation on top of its IT provider, and — importantly — how to tell whether the IT firm you already have is quietly covering it.
The direct answer
Your IT provider is probably not your security team. That is usually not their fault; the two roles have different training, different tools, and different hours. Some IT firms have added a real 24/7 security operations team and can produce insurance-grade evidence — most cannot. The way to tell is to ask a small number of specific questions and listen for a specific kind of answer. The questions are below.
What a general IT provider is built to do
A good IT firm handles the layer that keeps the practice operational day-to-day:
- Helpdesk for staff — the front desk cannot print, the operatory workstation is slow, the printer is jammed.
- Hardware procurement and refresh — workstations, monitors, imaging PCs, and the practice-management server itself.
- Patching and routine maintenance — Windows updates, application updates, driver cleanup.
- Backups — the nightly job runs, the backup drive is swapped, the offsite copy syncs.
- Microsoft 365 or Google Workspace administration — user provisioning, mailbox forwarding, license changes.
- Wi-Fi, firewall, and network device management — the guest SSID, the office manager's VPN.
- Practice-management-system upgrades — service packs, version bumps, application updates on the PMS server.
- Vendor coordination — the imaging vendor, the phone-system provider, the internet carrier.
Every one of those is real work. A dental practice without a competent IT provider runs slower, breaks more often, and takes longer to recover from small problems. This is not the layer we are trying to displace.
What a security operation is built to do
A security operation is built for a different question: not "is it working?" but "is someone attacking it right now, and if so, what are we doing about it?"
The concrete pieces:
- 24/7 detection. A real security operations center reading endpoint and identity alerts around the clock — not software that fires notifications into an email inbox nobody watches after hours.
- Response. When something fires that looks real, the compromised workstation is isolated within minutes, the identity is disabled, and the incident is contained before it spreads to the practice-management server.
- Identity threat detection. Watching Microsoft 365 or Google Workspace sign-ins for adversary-in-the-middle phishing kits, mailbox rules that hide invoice emails, OAuth-consent attacks, and token-replay activity — the identity-layer attacks that bypass MFA and steal wire transfers.
- Security awareness training. Continuous phishing simulations calibrated for dental staff — payment-redirect themes for the office manager, ePHI-handling for the front desk — and the click-rate trend a cyber-insurance carrier will ask about.
- Incident response coordination. When something happens: forensics coordination, HIPAA breach-notification timing, cyber-insurance claim support, and the patient-facing communication.
- HIPAA evidence. Audit-control logs, MFA-coverage reports, encryption-in-transit confirmation, training completion records, and the written incident-response plan — the evidence package a HIPAA audit or an insurance underwriter actually asks for.
These are operational security tasks. They are what a security team does, not what an IT team does. A general IT firm may configure some of these; very few operate them continuously.
Why the assumption fails: everyone assumes someone else is watching
The failure mode in a dental practice is not usually a missing tool. It is a missing owner.
The office manager gets phished at 8pm on a Wednesday through a payment-redirect email that looks like it came from a supply vendor. An endpoint alert fires. The IT firm's ticket queue receives the notification. Nobody at the IT firm is on-call for it; their support hours are 8am to 6pm. Meanwhile the attacker has the office manager's session token, sets an inbox rule that hides supplier emails, and starts staging lateral movement toward the practice-management server. By the time the IT firm opens tickets Thursday morning, the attacker has been inside for 14 hours.
By Friday night the PMS server is encrypted. Monday morning the practice cannot bill, treat, or look up a patient. When the doctor asks who was supposed to be watching for this, everyone points to someone else.
The alert was there. The tool worked. Nobody was watching it.
When your IT provider IS enough (honest read)
Some IT firms have genuinely built a security operation. Others have added a security bundle from a distributor and describe it that way. The words look identical on a website. The operational reality is different.
Your IT firm may already have you covered if all of these are true:
- They operate — not merely resell — a managed endpoint detection and response service on every workstation AND the practice-management server, with a real 24/7 security operations team behind it.
- They can produce, on request, the audit-control logs, MFA-coverage report, and identity-monitoring evidence a cyber-insurance underwriter wants for a renewal application.
- They have a documented incident-response process specific to your practice, including who they call at your practice at 2am and how they coordinate with your cyber-insurance carrier and legal counsel.
- They are willing to sign a Business Associate Agreement — any vendor with remote access to systems that store or transmit ePHI needs one under HIPAA.
- They carry appropriate cybersecurity insurance and errors-and-omissions coverage themselves.
If all five are true and you can verify them, you may not need a separate security firm. If any are unclear, the security layer is not owned — the practice is uncovered even if the IT relationship is excellent.
Questions to ask your IT provider (bring these to your next review)
The point of these questions is not to trap anyone. It is to find out what is being operated on the practice's behalf and what is not, so any gaps can be assigned to someone before the gap becomes an incident.
-
"Is there a security operations center monitoring our endpoints 24 hours a day, or is it software that runs unattended after your business hours?" A yes-there-is-a-team answer should name the team and the escalation path.
-
"If a workstation starts behaving like an active ransomware intrusion at 2am on a Saturday, who acts, how fast, and what do you do first?" The answer should describe automatic isolation within minutes, not "we'd see it Monday and call you."
-
"Can you produce the audit-control logs, MFA-coverage report, and identity-monitoring evidence our cyber-insurance renewal will ask for?" The answer should be "yes, here are samples from last quarter," not "we'd have to check."
-
"Are you our Business Associate under HIPAA, and do we have a signed Business Associate Agreement on file?" Any vendor with remote access to workstations that touch ePHI needs a BAA. "We've been with you for years, we're fine" is not a defense in an OCR investigation.
-
"Do you monitor our Microsoft 365 or Google Workspace tenant for identity attacks — session-token theft, adversary-in-the-middle sign-ins, malicious inbox rules — not just email spam filtering?" The answer should distinguish identity threat detection from anti-spam. Most IT firms provide the second and not the first.
-
"When you deploy patches, do you have a documented SLA for critical CVEs, and do you specifically track the CISA Known Exploited Vulnerabilities list?" The answer should be a written policy, not "auto-update is on."
If the answers on any of these are hesitant or unclear, the security layer for that specific piece is unowned. That does not mean firing anyone. It means naming who owns it going forward.
Co-managed is the healthy model
The mental model most dental owners default to — one firm, all of it — is not the model that works best for security. It is a leftover from the 1990s, when small offices had a single IT contact and everything technical went through that person.
The model that works now is co-managed. Your IT firm keeps the practice operational — the layer they are excellent at. A security firm operates the detection, response, identity monitoring, awareness training, and evidence layer — the layer they are excellent at. The two coordinate: when a security incident touches an IT-owned system, the two firms work together. When an IT change might affect the security posture, the two firms coordinate the change.
No one gets fired. The practice pays for two functions instead of one because those functions are actually two things. Total cost is often closer than owners expect to what a single do-everything provider would charge for comparable depth, because each specialist runs its own layer more efficiently than a generalist can run both.
What we do
Obsidian Ridge is a managed security firm, not an MSP. We coordinate with the IT firm the dental practice already has — we do not replace them. Our program is managed detection and response, identity threat detection, and security awareness training, operated end-to-end for the practice with the HIPAA evidence package and cyber-insurance readiness support attached. Deeper on the dental context: the dental cybersecurity page.
If a cyber-insurance renewal is the pressure point that surfaced this whole question, the Cyber Insurance Readiness Sprint is the fixed-scope engagement — from $1,500, delivered in 7 business days — that turns the questionnaire into a paperwork step instead of a scramble.
If you want the broader tool-and-service-model taxonomy before the co-managed conversation with your IT firm, the MDR vs EDR vs MSSP vs SOC-as-a-service decision tree is the buyer-side companion piece.
Next step
If this article named a gap you already suspected, the practical next step is either the free carrier questionnaire — score the practice yourself first — or the Cyber Insurance Readiness Sprint if the renewal or audit pressure is already on the calendar.
Last updated
July 28, 2026. We refresh this content as the threat landscape and tools evolve.