
Key takeaways
- No IT company can make a dental office HIPAA compliant on its own; what good IT does is put the technical and physical safeguards in place and give you the documentation, so that the practice can meet its obligations.
- The HIPAA Security Rule asks for three kinds of safeguards, administrative, physical and technical, and a single-location dental office can cover the IT side of all three without buying enterprise products.
- A risk assessment is a documented look at where patient data lives, what could go wrong, and what you are doing about it; I perform the technical side and it has to be repeated on a schedule, not done once and filed.
- Backups for a dental practice must cover the practice management database and the imaging store, keep a copy that ransomware cannot alter, and be restored as a test regularly.
- For a single-location practice in Dallas, HIPAA-minded IT is a matter of configuration and habits more than spending, and I bill it month to month with no contract.
Who provides HIPAA-compliant IT for dental offices in Dallas?
I do, with one honest correction to the question first. I am Anthony Omini, the owner of Cross River Tech in Dallas, and IT for dental practices is one of the industries I work in most. The correction is this: no IT company can hand you HIPAA compliance, and anyone who describes their service as making your practice fully compliant is overstating what IT can do. Compliance belongs to the practice. It includes your policies, your training, your business associate agreements and how your front desk talks about patients within earshot of the waiting room, and no firewall touches any of that.
What IT can do is substantial. The HIPAA Security Rule is largely a list of safeguards for electronic patient information, and most of the technical and physical items on that list are exactly the things I configure, monitor and document: encryption, access control, audit logs, backups, endpoint protection, network segmentation, secure disposal of old hardware. Done properly and written down, that work helps you meet the Security Rule and gives you real answers when an auditor, a cyber insurer or a patient asks how their records are protected.
So the accurate answer to "who provides HIPAA-compliant IT for a dental office in Dallas" is: someone who knows what the Security Rule actually asks for, puts the IT-side safeguards in place, performs the technical risk assessment, and hands you the documentation, without pretending to be your compliance officer or your lawyer. That is the service I offer, remotely for most of it and onsite by appointment across Dallas–Fort Worth. If you would rather start with a conversation, contact me and tell me what software your practice runs.
What does the HIPAA Security Rule actually ask of a dental office?
Stripped of the legal language, the Security Rule says: protect electronic patient health information (the rule calls it ePHI) so that it stays confidential, accurate and available, and be able to show how you do it. It groups the "how" into three families of safeguards, and it is worth knowing them by name because every vendor pitch and every insurance questionnaire uses the same three words.
- Administrative safeguards are the decisions and paperwork: who is responsible, what the policies say, how staff are trained, how risk is assessed, what happens when something goes wrong.
- Physical safeguards are about the building and the hardware: who can get to the server, where monitors face, what happens to an old computer.
- Technical safeguards are the settings inside the systems: passwords and access control, encryption, audit logs, protection against malware and against data being altered in transit.
The rule is deliberately flexible. It tells a practice what outcome to reach, not which product to buy, and it lets a four-operatory office in North Dallas meet the standard differently from a hospital. That flexibility is good news for a small practice and it is also why "just buy this and you are covered" is never true. The sections below go through each family in plain language and say which parts I handle.
One boundary I keep: I am not a lawyer or a compliance consultant, and nothing here is legal advice. When a question is about what the rule requires of your practice as a covered entity, your healthcare attorney or a compliance consultant answers it. When it is about how to configure, protect and document the technology, I do.
Administrative safeguards: the paperwork and the people
This is the family most dental offices are weakest on, because it is not about technology and nobody sells it in a box. Here is what it covers and where I fit.
- A named security officer. Someone in the practice, usually the dentist or the office manager, owns this. I can be the person they lean on, but the name on the policy is yours.
- A risk analysis and a risk management plan. Covered in its own section below. I perform the technical assessment and write it up; you decide how to act on the findings.
- Written policies. Password rules, acceptable use, what staff may and may not do with patient data on their phones. Your compliance consultant or a reputable template supplies these; I make sure the technology matches what the policy says, because a policy that requires multi-factor authentication while the practice management login has none is worse than no policy.
- Workforce training at hire and on a schedule, with a record. I provide the technical part, how to spot a phishing email, how to lock a workstation, and the practice keeps the attendance record.
- Business associate agreements. Every vendor that touches ePHI, including your IT provider, your cloud backup, your practice management vendor and your email platform, signs one. I sign a business associate agreement with every dental client, and I check that your other vendors have too.
- A contingency plan. What happens if the server dies, the office floods or ransomware hits on a Monday morning. The backup and recovery work below is the technical heart of this plan, and I write down the actual restore steps rather than leaving them in my head.
- Access management. A process for granting access when someone is hired and removing it the day they leave. I run the technical side of that on request, and it is one of the most common gaps I find: a hygienist who left last year still has a working login.
Physical safeguards: the building and the devices
Physical safeguards are the ones a visitor could check by walking through your office, and a dental office has a few particular problems here because computers sit in operatories, at the front desk and in a closet that also holds supplies.
- The server and network closet. If you keep a server for Dentrix, Eaglesoft or imaging, it belongs in a lockable space with a lock that is actually used, on a battery backup, with the door not propped open for the cleaning crew. I set up the rack and tell you plainly if the current spot is a problem.
- Workstation placement. A front-desk monitor angled toward the waiting room, or an operatory screen visible from the hallway, exposes patient information to anyone walking past. Privacy screens and screen placement are cheap fixes, and an automatic screen lock after a few minutes idle is a setting I enforce on every workstation.
- Portable devices. Laptops, tablets used for intake, phones that receive practice email. Each one is encrypted, protected by a passcode, and able to be wiped remotely if it walks out the door.
- Media and hardware disposal. An old server, a retired workstation, the copier's internal drive, a failed external backup disk: every one of them contains patient information until it is wiped or destroyed. I keep a written record of each device and what was done to it, which is exactly the document you want if a question is ever asked.
- Visitor and vendor access. The imaging technician, the equipment rep, the cabling crew during a build-out. They should not be alone with unlocked workstations. That is a policy point, but I make the technology cooperate by locking screens fast and keeping guest Wi-Fi separate from the clinical network.
Most of these cost nothing but attention. When I first visit a practice I walk through with this list, and the report you get says, in plain words, what is fine and what to change.
Technical safeguards: what I actually configure
This is where IT work maps most directly onto the rule. The Security Rule lists the outcomes; the table shows what I put in place at a typical single-location dental practice to reach them.
| What the rule asks for | What I set up in a dental office |
|---|---|
| Unique user identification | A separate login for every staff member in Windows, the practice management software and email. No shared "frontdesk" account, no sticky notes. |
| Access control | Each role sees what it needs. Hygienists do not see billing; the front desk does not have administrator rights on the server. Multi-factor authentication on email, remote access and anything reachable from outside the office. |
| Automatic logoff | Workstations lock after a short idle period, set centrally so nobody can turn it off. |
| Encryption at rest | Every laptop, workstation and server drive encrypted. Backups encrypted before they leave the building. |
| Encryption in transit | Remote access only through an encrypted connection, never an open remote desktop port. Email that carries patient information sent through an encrypted email service. |
| Audit controls | Logging enabled in the practice management software and on the server, retained, and reviewed on a schedule rather than only after an incident. |
| Integrity and malware protection | Managed endpoint protection on every device that reports to me, email filtering, and patching of Windows and applications on a schedule. |
| Network protection | A business firewall, the clinical network separated from guest Wi-Fi and from the smart TV in the waiting room, and imaging devices on their own segment where the manufacturer allows. |
| Contingency and availability | The backup and recovery setup described below, with restore steps written down. |
None of this requires enterprise products. It requires the ordinary business versions of Windows, Microsoft 365 or Google Workspace, a business firewall, a managed endpoint product and a backup service, all configured with the rule in mind and documented. That configuration and monitoring is what my cybersecurity, backup and disaster recovery service consists of, and for a dental office it is bundled into the managed IT agreement rather than sold as an extra.
What is a HIPAA risk assessment, and who does it?
The risk assessment (the rule calls it a risk analysis) is the single administrative requirement that regulators ask about first, and it is the one most small practices have never done or did once, years ago, from a checklist someone emailed them. In plain terms it is a documented answer to three questions: where does patient information live in this practice, what could realistically go wrong with each of those places, and what are you doing about it.
When a Dallas practice asks who does both the risk assessment and the IT support, the answer is that I do the technical assessment and the IT, and I am clear about where the technical part ends. Here is what the technical assessment involves:
- Inventory. Every system that stores or touches ePHI: the practice management server or cloud service, imaging software and sensors, workstations, laptops, phones, email, backups, the clearinghouse, patient communication tools, and any vendor with remote access.
- Threats and weaknesses, per system. Ransomware on the server, a lost laptop, a phishing email at the front desk, a former employee's login, an unpatched imaging workstation the vendor told you never to update.
- Existing safeguards against each, honestly assessed. Not "antivirus installed" but "endpoint protection, current, reporting, reviewed weekly".
- Likelihood and impact for each risk, rated simply so the dentist can read it.
- A written report with a prioritized list of what to fix, roughly what each fix costs, and what I recommend doing first.
That report is the input to your risk management plan, and it is repeated on a schedule, usually yearly and whenever something major changes, such as a new server, a move or a new imaging system. The policy and workforce parts of the assessment, and the question of whether the practice has met its obligations, belong with your compliance consultant or healthcare attorney, and I am glad to work alongside either. The same technical assessment applies to medical practices, which carry the same duties.
Backups and HIPAA security for a dental practice
Backups are where the Security Rule's contingency requirement and the practical survival of your practice meet. A dental office that loses its practice management database and imaging store without a working backup does not have a compliance problem; it has an existential one. Here is what I build.
- Cover the database and the images. Dentrix, Eaglesoft and Open Dental keep the schedule, charts and ledger in a database that must be backed up in a way the software supports, not by copying files while it is running. Imaging stores (radiographs, intraoral photos, 3D scans) are large and grow fast, and they are patient records too.
- Local plus offsite. A local copy for fast restores when a drive fails, and an encrypted offsite copy for when the office is the problem.
- One copy that cannot be changed. Ransomware looks for backups before it encrypts anything. At least one copy is written so that nobody, including an administrator whose password was stolen, can alter or delete it for a set period.
- Encrypted before it leaves the building, with the keys held by the practice, not only the vendor.
- Tested. On a schedule I restore a copy of the database and a set of images to a separate location and confirm they open. You receive the result in writing. A backup that has never been restored is a guess.
- Written restore steps. How long a full restore takes and exactly what to do, so the practice is not dependent on my memory on the worst day.
For a practice on a cloud practice management platform, the vendor handles the database, but the workstations, email, scanned documents and any local imaging still need this treatment, and the vendor's own backup terms deserve a read. I cover the software side in IT support for Dentrix, Eaglesoft and dental imaging software.
Affordable HIPAA-minded IT for a single-location practice
A single-location dental office in Dallas with one dentist, a couple of hygienists and a front desk does not need, and should not pay for, the compliance products aimed at hospital groups. Here is what affordable actually looks like.
What you do not need to buy. A compliance portal with a monthly fee that mostly stores templates. A second antivirus. An enterprise firewall sized for a hundred users. A separate "HIPAA package" from your IT provider that repackages things a competent managed service should include anyway.
What you do need. Business editions of Windows and Microsoft 365 or Google Workspace, a business firewall, managed endpoint protection, a backup service that supports your practice management database and immutable copies, encrypted email for the occasional message that must carry patient information, and someone to configure, monitor and document it all. Most of these are ordinary licenses you pay the vendors directly, and I do not mark them up.
My time. Managed IT is billed per user or per device, month to month, cancel anytime, and for a dental office it includes the safeguards above, the backup monitoring, the yearly technical risk assessment and the documentation. I quote it after a short conversation rather than publishing a number, because an office with six workstations and cloud software is a different amount of work from one with a server, a 3D scanner and twelve devices. For context, small business managed IT in the Dallas market is commonly quoted somewhere around $100 to $175 per user per month; that is a typical market range, not my price. If you only want the technical risk assessment as a one-time project, I bill it at my published hourly rates with an estimate up front. Details on both are on the pricing page.
What makes HIPAA-related IT expensive is not any of these lines. It is the incident: a ransomware event that closes the practice for a week, a lost laptop that triggers patient notifications, or a network that keeps failing between patients, which I wrote about in why your dental office network keeps going down.
What I do not do, so you know exactly what you are getting
Because HIPAA attracts a lot of vague promises, I would rather be explicit about the edges of my service.
- I do not give legal advice or tell you whether your practice has met its obligations. That is your healthcare attorney's job.
- I do not write your policies from scratch. I work from what your compliance consultant or template provides and make the technology match it, and I will point out when a policy says something the systems cannot support.
- I do not promise that nothing will ever go wrong. Safeguards reduce risk; they do not remove it. What I promise is that the safeguards will be in place, monitored and written down, so that if something does happen you can show what was done and recover.
- I do not claim any HIPAA approval or accreditation, because no government body grants one to IT companies. I sign a business associate agreement, I know the Security Rule, and I do the work.
What you get instead is an owner who knows your practice and answers the phone himself, a small team behind him for the day-to-day monitoring, and a Security Rule treated as a practical list of things to configure and document rather than a marketing word.
How to get started
The first step is a short conversation, remote, no charge: what practice management and imaging software you run, whether you have a server, how many devices, and whether you have ever had a risk assessment done. From there I usually propose a technical risk assessment as the first piece of work, because it produces a written picture of where you stand before you spend anything else.
The assessment takes a visit to the office and some remote work, and the report comes back in plain language with a prioritized fix list. You can act on it with me under a month-to-month agreement, hire me hourly for specific items, or take it to anyone else. Either way you will have the document most Dallas dental practices are missing when someone finally asks for it. Start at contact, or read more about how I work with dental practices.
Questions people ask
Can an IT company make my dental office HIPAA compliant?
No, and be cautious of anyone who says otherwise. Compliance belongs to the practice and includes policies, training, business associate agreements and daily habits that no technology controls. What IT does is put the technical and physical safeguards of the Security Rule in place, monitor them and document them, which helps you meet the rule and gives you real answers when an auditor or insurer asks. That is the part I handle.
What is a HIPAA risk assessment and how often is it needed?
It is a documented review of where patient information lives in your practice, what could go wrong with each system, what safeguards exist and what you plan to do about the gaps. Regulators ask for it first. I perform the technical side and write the report in plain language; it should be repeated about yearly and whenever something major changes, such as a new server, a move or a new imaging system.
Do you sign a business associate agreement?
Yes. Any vendor that can access electronic patient information, including an IT provider, is a business associate under HIPAA and needs a written agreement with the practice. I sign one with every dental and medical client before any work that touches patient data begins, and during the risk assessment I check that your other vendors, such as cloud backup and practice management, have signed one too.
What backups does a dental office need for HIPAA?
A backup that covers the practice management database and the imaging store in a way the software supports, kept both locally and offsite, encrypted before it leaves the building, with at least one copy that ransomware or a stolen administrator password cannot alter. It must be restored as a test on a schedule, with written restore steps. Cloud practice management reduces the burden but does not remove it for workstations, email and local images.
How much does HIPAA-minded IT cost for a single-location dental office in Dallas?
Software licenses are paid to the vendors at their published prices, and I do not mark them up. My managed IT is billed per user or per device, month to month, cancel anytime, quoted after a short conversation and including the safeguards, backup monitoring and yearly technical assessment. For context, small business managed IT in the Dallas market is commonly quoted somewhere around $100 to $175 per user per month; that is a market range, not my price.
Do you also handle the day-to-day IT, or only the compliance side?
Both, and that is the point. The company configuring your safeguards should be the same one that supports your workstations, your Dentrix or Eaglesoft server, your imaging and your network, because those are the systems the safeguards live in, and with me that is one phone number. Remote support is available around the clock, including holidays, with after-hours rates outside business hours; onsite visits across Dallas–Fort Worth are by appointment.
Sources and further reading
Market price ranges in this article are my own observation of quotes in the Dallas market, not a published survey. Where I state a rule or a standard, the source is linked above.



