Multi-location DSO M365 consolidation: a four-quarter security program walkthrough
A scenario walkthrough of a DSO with multiple M365 tenants and no central detection, brought to consolidated identity coverage in four quarters.
Read articleCompliance
For a dental practice, downtime is revenue. Why the PMS server needs a security operation of its own, and what to ask before the schedule empties.
The practice runs on the schedule. When the practice-management server stops responding at 7:15 a.m. and the first hygiene appointment is at 8:00, the day does not compress — it collapses. That single operational fact reshapes the entire question of what a dental IT firm covers versus what a security operation covers, because the failure mode for the practice is not a slow ticket queue. It is an empty schedule, a lobby of confused patients, and a doctor billing zero for the day.
Everything below sits inside that frame. The point is not that a dental IT firm is bad at its job. Most are excellent at the layer that keeps Dentrix, Eaglesoft, or Open Dental running, the imaging chain producing images, and the front desk on the phone. The point is that the layer they run and the layer that keeps the schedule intact under attack are two different disciplines with two different sets of hours.
A dental practice is a chair-hour business. A ten-operatory office with an average producing rate of $600 per operatory hour loses roughly $6,000 per hour of unavailable schedule. Two days of a hard PMS outage is meaningful five-figure revenue plus the reputational cost of rescheduled patients and the operational cost of pulling paper charts (if they exist) or reconstructing the day by memory (if they do not).
That number changes how a practice should think about the difference between IT support and security operations. IT support is optimized for the eight-hour recovery of a slow workstation. A security operation is optimized so that the PMS server does not become the reason two days of the schedule disappears. Both are legitimate and both matter. Confusing one for the other is what leaves the practice exposed on the day it costs the most.
The good dental IT firms handle the layer that keeps the practice moving:
None of that reads as security operations, and none of it should be asked to be. It is the layer the practice cannot function without on ordinary days. A security operation is what the practice cannot function without on the day someone is actively attacking it.
The concrete incidents that pull the schedule apart share a pattern: the tool worked, the alert fired, nobody was watching it.
PMS server ransomware, staged from Tuesday, detonated Friday. The initial phish lands on an operatory workstation. The endpoint agent logs suspicious script activity into the IT firm's ticket queue. Nobody is on-call. The intruder moves laterally through weak service-account credentials, encrypts the PMS database and the imaging archive over the weekend. Monday morning, the front desk cannot look up an appointment, verify insurance, or produce a treatment plan. The recovery-without-preparation window is five to twenty-one days.
Imaging system compromise via an unpatched vendor console. Intraoral, panoramic, and CBCT capture stations often run on vendor-supplied Windows builds that have not been updated since the equipment was installed. The vendor did the installation, wrote "do not update — will break integration" in an email, and left. An unpatched console with SMB exposed to the operatory LAN becomes the lateral-movement launch point. The imaging chain is where a Security Rule risk analysis is supposed to look and rarely does.
BEC targeting the office manager's mailbox on payment day. An adversary-in-the-middle phishing kit captures the session token and defeats MFA. An inbox rule quietly routes anything containing the word "payment" or the vendor's name into a hidden folder. The attacker replies from inside the thread with updated ACH instructions on the day the practice pays its lab bill or supply invoice. The five-figure loss is not the worst part; the mailbox now contains attachments with ePHI, and the disclosure obligation is the second act.
Each of these is stopped or bounded by the same thing: when the alert fires at 3 a.m. on a Saturday, somebody is actually watching it and able to contain the endpoint, instead of it sitting in a queue until the practice reopens.
HIPAA is often shorthand for "we handle this" when in fact the Security Rule (45 CFR § 164.308 and § 164.312) is a set of principles-based obligations rather than a running service. It requires reasonable and appropriate administrative, physical, and technical safeguards. It names audit controls, security incident procedures, and risk analysis by function. It does not name a product, does not name a monitoring cadence, and does not say who has to be awake at 2 a.m. That is the practice's decision to make.
The Breach Notification Rule (§ 164.404, § 164.406, and § 164.408) does prescribe something specific: for a breach of unsecured PHI, the practice must notify affected individuals without unreasonable delay and no later than sixty calendar days after discovery, notify HHS on that same clock for events affecting 500 or more individuals, and notify prominent media in the state or jurisdiction on the same clock at that threshold. That obligation is triggered on the day of the incident and starts running before the practice knows the extent. Whether the extent is small or large depends heavily on whether someone was watching the endpoint and identity layers when the compromise began.
For a dental practice, satisfying the Security Rule as a documented reality — rather than as an unexamined assumption — is the reason to distinguish IT support from operated security in the first place.
A Business Associate under HIPAA is a person or entity that performs services on behalf of a covered entity involving the use or disclosure of protected health information. A managed-services IT firm with remote access to the PMS server, the imaging workstations, or Microsoft 365 mailboxes that touch chart data almost always meets that definition. The signed BAA is not optional. It is the contractual instrument HIPAA § 164.502(e) requires and the artifact an OCR complaint investigator will ask for on the first request.
Two adjacent things matter here. First, the BAA needs the required contractual safeguards, breach-notification obligations back to the practice, and permitted-use limits — not a marketing paragraph that mentions HIPAA. Second, a signed BAA is not a substitute for the IT firm actually operating the safeguards it obligates itself to. It is the paper. The operation is separate.
A security operation for a dental environment covers a distinct list, and the specifics matter:
None of the above is what a general IT firm was built to run. It is what a security operation runs alongside them.
A minority of dental IT firms have genuinely stood up a security practice. Whether the one on retainer is that firm is a question that produces specific artifacts:
Anything unclear is not an accusation. It is an unowned function that will be assigned to someone in the middle of an event.
Practical, evidence-oriented, no room for the answer that describes intent instead of operation.
Any hesitant answer is an owned-by-nobody function to hand to someone on a defined date.
The single-vendor mental default is the shape a practice accretes when it grows one hire at a time. It is not the shape that keeps the schedule intact when someone actively tries to take the practice offline.
The co-managed shape splits the two functions to the specialists that operate them. The IT firm keeps the practice-management system, the imaging chain, and the front-desk technology working. The security operation runs detection, response, identity monitoring, awareness training, the HIPAA evidence packet, and the Breach Notification Rule coordination. When an incident touches both layers, the two coordinate. Total spend is closer than owners expect to a single generalist charging for equivalent depth, because each specialist runs its own layer more efficiently.
We are a CISSP-led managed security practice. We do not replace the dental IT firm — we operate the security layer next to them. The program is managed detection and response, identity threat detection, and security awareness training with the HIPAA evidence package, DSO-scale identity coverage, and cyber-insurance readiness attached. The vertical deep dive lives on the dental cybersecurity page.
If the pressure point is a cyber-insurance renewal or a patient-data incident on the calendar, the Cyber Insurance Readiness Sprint is the fixed-scope engagement — from $1,500, delivered in seven business days — that turns the questionnaire into a paperwork step.
If this article named a gap the practice already suspected, the practical starting move is either the free carrier questionnaire to score the practice before an underwriter does, or the Readiness Sprint if a renewal or a post-incident cleanup is already on the calendar. For the broader tool-and-service-model taxonomy, the MDR vs EDR vs MSSP vs SOC-as-a-service decision tree is the buyer-side companion piece.
Last updated
August 22, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Sometimes, if the IT company has actually built a security operation. Most have not — they are staffed and licensed for IT operations, not for 24/7 security monitoring and response. The way to tell is to ask the specific questions in the article above and listen for whether the answers describe an operated security service or a software subscription. Both are legitimate but they are different products.
No. Co-managed is the normal and healthy model. Your IT firm keeps operations running; the security firm operates detection, response, identity monitoring, awareness training, and the evidence packet. The two coordinate on incidents and on changes that affect the security posture. The common pattern is that the practice keeps its IT firm and adds the security firm as a separately-scoped function.
IT provider: helpdesk, hardware, patching, backups, practice-management-system upgrades, Microsoft 365 or Google Workspace administration, Wi-Fi and firewall management. Security provider: 24/7 detection and response, identity threat detection, security awareness training, HIPAA evidence, incident response coordination, cyber-insurance readiness. The split is not rigid — some IT firms do some security tasks and some security firms coordinate some IT changes — but that is the working division.
Not literally. The HIPAA Security Rule (45 CFR § 164.308 and § 164.312) requires 'reasonable and appropriate' administrative, physical, and technical safeguards, including audit controls, security incident procedures, and risk analysis. It does not name a specific technology or a specific monitoring frequency. In practice, most cyber-insurance underwriters and most reasonable-safeguards interpretations for practices that handle ePHI now expect continuous monitoring with a response capability. But the regulatory phrasing is risk-based, not literal. This is educational information, not legal advice — a HIPAA privacy officer or healthcare attorney should confirm what constitutes reasonable safeguards for your specific practice.
Yes, if the IT firm has meaningful access to systems that create, receive, maintain, or transmit ePHI on behalf of the practice. A Business Associate under HIPAA is a person or entity that performs services on behalf of a covered entity involving the use or disclosure of protected health information. A managed-services IT firm with remote access to the practice-management server, imaging systems, or workstations that touch chart data almost always meets that definition. A signed BAA (with the required contractual safeguards, breach-notification obligations, and permitted-use limits) is required before that access begins. Confirm application to your practice with a HIPAA privacy officer or healthcare counsel.
Related reading
A scenario walkthrough of a DSO with multiple M365 tenants and no central detection, brought to consolidated identity coverage in four quarters.
Read articleWhy DSO and multi-location dental groups inherit the worst cybersecurity posture of their weakest practice.
Read articleWhat dental cyber insurance actually covers in 2026, the underwriting questionnaire controls carriers review.
Read article