Back to Blog
Industry Specific
5 min read

Dental Practice Cybersecurity: Small Team, Same Obligations

Imaging systems that cannot be patched, a practice management vendor holding everything, and the same privacy obligations as a hospital.

GuardsArm Team

Security Experts

September 25, 2026

Dental practice cybersecurity and compliance

A dental practice holds health information and is subject to health privacy obligations in essentially the same way a larger provider is. It also has one or two people handling everything administrative, an IT arrangement that may be a local contractor, and clinical software chosen for clinical reasons rather than security ones.

The obligations do not scale down. The resources do.

Obligations do not scale down
Same duties, far fewer resources
Two vendors hold everything
Practice management and imaging
No partial mode
Without the schedule, the practice stops

Two systems hold everything

Practice management holds patient records, appointments, treatment history, billing and insurance details. Imaging holds radiographs, often in a separate system with its own database and its own vendor.

Both are typically supplied, installed and maintained by vendors, which concentrates the security position in decisions the practice did not make.

Questions worth asking your vendors directly:

QuestionWhy it matters
Is our data hosted by you or stored here?Determines who is responsible for backup
How do you access our system for support?Persistent access is common and usually unlogged
Is that access logged, and can we see it?You are accountable for what happens in your system
What happens to our data if we leave?Export format, and deletion
Have you had a security assessment?Ask for a summary

The support access question is the important one. Practice management and imaging vendors frequently hold standing remote access, shared among their support staff. See third-party remote access.


Imaging systems age badly

Radiography equipment has a long service life and its controlling computer often runs an operating system no longer supported. The vendor may not certify updates, and replacing the computer can mean replacing the imaging hardware.

The imaging computer is usually the oldest thing on the network
It runs an unsupported operating system because the vendor certified that version with the hardware, and replacing it can mean replacing the imaging equipment. Segment it and restrict it rather than waiting for a replacement cycle that may be years away.

Containment is the answer: put the imaging workstation on its own network segment, restrict what it can reach and what can reach it, remove internet access, and monitor around it. See legacy endpoint containment.


Ransomware stops a practice completely

A practice that cannot access its schedule cannot see patients. There is no partial mode. Recovery capability is therefore the single most important investment.

What that means concretely:

  • Backups that are offline or immutable, so ransomware cannot encrypt them
  • A tested restore — not a backup job reporting success, an actual restoration of the practice management database
  • A printed day sheet produced daily, so tomorrow's appointments exist on paper
  • A known contact route to patients that does not depend on the practice system
  • A written decision about who to call, before you need to

The printed day sheet is trivially cheap and has saved practices from a complete standstill on day one of an incident.


The free and near-free list

For a practice with no budget line for security, these close most of the realistic exposure:

  1. Unique logins for every person. Shared front-desk accounts are the norm and defeat every audit trail.
  2. MFA on email, which is where practice compromise usually begins.
  3. Remove access promptly when staff leave.
  4. Screen locks on operatory and reception machines.
  5. Encryption on laptops and any portable media.
  6. Ask the vendor to disable any support access that is not needed.

Privacy obligations

Depending on your province, you are a custodian or trustee under health privacy legislation with duties around safeguards, access and breach notification. See Alberta HIA, Ontario PHIPA and Manitoba PHIA.

The common requirement across all of them is written safeguards and the ability to say who accessed a record. Both are achievable at practice scale.


The local IT contractor question

Most practices rely on a local IT provider, and the relationship is usually informal and long-standing. That is not a problem in itself, but it is worth establishing a few things explicitly:

  • Do they hold administrative access to your systems, and is it individual to each of their technicians or a shared account?
  • Is their access logged, and can you see it?
  • Do they have a written agreement covering confidentiality and health information?
  • What is their own security posture — are their remote support tools protected with MFA?
  • What happens if they are unavailable? A single contractor is a single point of failure for the practice.

Compromise of an IT provider affects every client they serve, and small healthcare practices have been reached this way. The questions are not a criticism of the provider; they are the same questions any vendor should expect.


What a practice should be able to demonstrate

If a regulator or a patient complaint arrives, these are the artefacts that matter, and each is achievable for a small practice:

ArtefactEffort
A written risk assessmentOne-off, then reviewed
Written privacy and security policiesOne-off
Training records with datesAn hour a year per person
A list of who has access, reviewedQuarterly, fifteen minutes
Audit log capability, tested onceOne afternoon
Vendor agreementsOne-off
A written breach procedureOne page

None of that requires a security budget. It requires somebody to own it and a few afternoons across a year.


Where to start

Print tomorrow's schedule tonight, and test whether you can restore your practice management database from backup. The first takes a minute and protects your worst day; the second tells you whether your backup is real.

GuardsArm works with small healthcare practices on proportionate security. See healthcare solutions or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Dental Practice Cybersecurity: Small Team, Same Obligations”

Talk to the GuardsArm team about how these services apply to your environment.