Dental MSP Checklist

MSP Requirements Checklist for Dental Practices (HIPAA Edition)

By SynergyIQ 12 min read Dental · HIPAA · Dentrix · Eaglesoft

A dental practice is not a law firm with teeth. The IT requirements — HIPAA, practice management software, imaging workflows, operatory equipment — are specialized enough that a general MSP frequently fails. Here's what a dental practice should actually require from its managed IT provider.

Why Dental IT Is Different From Generic Small-Business IT

Most MSPs can set up Microsoft 365, run a help desk, and patch Windows. Not all of them have dealt with a Dentrix database corruption at 7:30 a.m. the Monday after a holiday weekend, with 40 patients scheduled and no diagnostic radiographs visible in the operatory. Dental IT has specific landmines that only show up after you've supported a few practices:

  • Practice management software (Dentrix, Eaglesoft, Open Dental, Curve) has idiosyncratic database structures, update cycles, and vendor support relationships that differ from typical business software.
  • Imaging systems (Dexis, Sirona Schick, Carestream, Planmeca) integrate with the PMS through bridges that break routinely and require specialized knowledge to fix.
  • Operatory equipment — CBCT scanners, intraoral cameras, CAD/CAM mills — often runs on specialized workstations with vendor-mandated software configurations that conflict with standard MSP hardening.
  • HIPAA adds encryption, BAA, audit logging, and risk assessment requirements that dental practices frequently underspend on until they're audited or breached.
  • Uptime sensitivity is extreme. A 2-hour PMS outage during business hours can cost $4,000–$15,000 in rescheduled appointments and lost walk-ins, plus the compounding scheduling chaos that follows.
$10,930
Average HHS OCR settlement for a dental-practice HIPAA violation involving unencrypted data, based on published resolution agreements 2020–2025

The Non-Negotiables: What Every Dental MSP Must Deliver

Before we get into the nice-to-haves, here's the baseline. If an MSP cannot produce all of these on request, they should not be servicing a dental practice.

1. A signed Business Associate Agreement (BAA)

Under HIPAA, any third party that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate. Your MSP qualifies the moment they touch your network — they can see PHI in Dentrix, they have admin access to imaging servers, they may be handling backups that contain patient records. Without a signed BAA, you are out of compliance.

Ask to see the MSP's standard BAA template. A good BAA includes:

  • Specific safeguards the MSP commits to (encryption, access controls, audit logs)
  • Breach notification timeline (must be within 60 days per HHS, but best-practice is 24–72 hours internally)
  • Subcontractor provisions (any fourth-party vendor the MSP uses must also sign a BAA)
  • Indemnification for breaches caused by the MSP's failures
  • Data return or destruction obligations when the relationship ends

2. HIPAA Security Rule controls — documented and auditable

Not just "we use encryption." A real dental MSP has a documented mapping of every HIPAA Security Rule control (§164.308 administrative, §164.310 physical, §164.312 technical) to a specific technology or process in your practice. When a state board or HHS comes asking, the MSP should produce that documentation on request.

3. Encrypted backups with tested restores

Backups are worthless until they've been tested. We see dental practices every year who discover during an emergency that their backups are corrupted, too old, missing the imaging server, or can't be decrypted because the encryption key was stored only on the device that failed. A good dental MSP performs a quarterly test restore of the Dentrix/Eaglesoft database and at least monthly restore-spot-checks of imaging data — and provides you a report.

4. Endpoint encryption (BitLocker or equivalent)

Every workstation that touches PHI should have full-disk encryption enabled and centrally managed. A laptop left at a dental conference that isn't encrypted is a reportable HIPAA breach. The MSP should be able to show you an encryption compliance report for every workstation in the practice.

5. MFA on everything that can be MFA'd

Microsoft 365, VPN, practice management admin accounts, imaging servers, remote access tools, the domain registrar, cyber-insurance portal. If the MSP isn't pushing MFA to every possible surface, they're not taking your security posture seriously.

6. Practice management software expertise

The MSP should be able to name their Dentrix or Eaglesoft specialist — and confirm that person has done a version upgrade in the last 12 months, run a database maintenance routine, and troubleshot a failed imaging bridge. Generalists can keep the server running; specialists prevent the bigger issues before they happen.

The Complete Dental MSP Capability Checklist

Print this and take it to every MSP meeting. Score each provider on every row.

Category Required Capability Why It Matters
Compliance Signed BAA on file HIPAA legally required before MSP touches PHI
Compliance Annual HIPAA Security Risk Assessment Required by HIPAA; supports state board exams
Compliance Documented incident response plan Reduces breach impact; required for OCR audit
Compliance HIPAA training materials for staff Workforce training is a Security Rule requirement
Security EDR on every endpoint (not traditional AV) Modern ransomware defense; cyber-insurance requirement
Security Full-disk encryption (BitLocker) on every device Lost-laptop breach prevention
Security MFA on M365, PMS, VPN, admin accounts Eliminates credential-theft breaches
Security Segregated patient Wi-Fi (separate VLAN) Patient Wi-Fi should never touch operatory network
Security DNS filtering (Cisco Umbrella, DNSFilter) Blocks phishing/malware sites before load
Backup Encrypted offsite backups of PMS database Ransomware recovery; HIPAA contingency plan
Backup Quarterly tested restore of PMS database Untested backups frequently fail
Backup Imaging data included in backup scope Images are PHI; most commonly excluded by accident
Backup Immutable backups (ransomware can't delete) Modern ransomware targets backup repositories
Software Named Dentrix/Eaglesoft/Open Dental specialist Generalists miss database and imaging-bridge issues
Software Upgrade planning & testing process PMS upgrades are high-risk and need staging
Software Imaging bridge troubleshooting history Dexis/Sirona/Carestream integrations break often
Operations 15-min critical SLA, 24/7 during business days 2-hour outage = $4K–$15K in lost production
Operations Same-day on-site response (local presence) Some issues require hands-on (printer, imaging, cabling)
Operations Monthly patching + compliance report Unpatched systems = #1 ransomware vector
Operations Quarterly vCIO / business review Roadmap, compliance status, budget visibility

Dental-Specific Landmines Most MSPs Miss

The imaging bridge problem

When Dentrix or Eaglesoft talks to imaging software (Dexis, Sirona Schick, Carestream, etc.), it does so through a bridge — an integration layer that's notoriously fragile. An operating system update, a PMS upgrade, or a new user profile can break the bridge without warning. When it breaks, radiographs taken at the chair don't attach to the patient chart automatically, and staff spend the rest of the day manually linking images or, worse, pulling duplicate radiographs that shouldn't be clinically necessary.

"Our general MSP knew Dentrix well enough to keep the server up. They didn't know the Dexis bridge. When the integration broke after a Windows Update, it took them three days of tickets to figure out they needed to reinstall the bridge DLLs in a specific order. A dental-specialized MSP would have fixed it in 30 minutes."

— Multi-op Sugar Land dental practice

The operatory workstation isolation problem

Operatory workstations often need to stay on older Windows versions or specific configurations because of vendor compatibility. That creates a security problem — old Windows is a known target. The solution is not to upgrade blindly (which breaks imaging integration); it's to isolate those workstations on a separate VLAN, apply tight firewall rules, and keep them off the internet entirely. Most MSPs skip this.

The Dentrix backup that isn't actually a backup

Dentrix has a built-in backup feature. It's not sufficient alone — it doesn't include imaging data by default, it often runs to the same local drive as the live database, and the encryption is optional. A real backup is offsite, encrypted, immutable, includes both the PMS database AND imaging storage, and is tested. If your MSP tells you "Dentrix handles the backup," that's a red flag.

The end-of-day backup race condition

Dental practices often have backup jobs scheduled for 6 or 7 p.m. — but the last staff member is often still in the system at that time, and an open database file can cause the backup to silently fail. Good dental MSPs check for this specifically in monthly reports.

The patient Wi-Fi catastrophe

Patient Wi-Fi and operatory Wi-Fi on the same flat network means a compromised patient device (phone, laptop) can potentially reach your imaging server. This is a HIPAA violation waiting to happen. Separate VLANs, separate SSIDs, with firewall isolation between them, are standard — and alarmingly often missing.

Questions to Ask Specifically About Dental Experience

Beyond the general MSP questions, dental practices should drill specifically on software and vertical expertise:

  1. How many dental practices do you currently support? (Three or more is a reasonable floor.)
  2. Can you name specific Dentrix, Eaglesoft, or Open Dental versions you've supported?
  3. Have you performed a PMS version upgrade in the last 12 months? Walk me through what that looked like.
  4. Which imaging systems have you integrated and troubleshot?
  5. Show me an example HIPAA risk assessment deliverable from another dental client (redacted).
  6. Have you supported a dental practice through a HIPAA breach notification? What was the timeline?
  7. What cyber-insurance carriers have your dental clients used? What did the carrier's security questionnaire ask?
  8. Do you have a dedicated Dentrix/Eaglesoft specialist, or does dental work go into your general tech queue?

The simple test: ask the MSP what a "Dexis bridge" is and how they'd troubleshoot one that's dropped. A generalist will either not know or will answer vaguely about "imaging software." A dental specialist will immediately talk about DLL registrations, named pipes, or service account permissions. You don't need to understand the answer — you just need to notice whether they're confident about it.

Real Cost Ranges for Dental Practice IT in Houston

A full HIPAA-compliant dental MSP service in Greater Houston typically runs:

  • Small single-location (5–10 staff): $1,500–$2,800/month. Includes EDR, backup, MFA, patching, help desk, HIPAA documentation, monthly reporting.
  • Mid-size practice (11–20 staff, one location): $2,800–$5,000/month. Adds quarterly business reviews, imaging-specific backup, more on-site hours.
  • Multi-location group (20–50 staff, 2–4 locations): $5,000–$10,000/month. Adds inter-site networking, centralized imaging archive management, dedicated account ownership.
  • DSO or large group: priced per-location and per-user at negotiated rates.

Practices paying less than $75 per user per month almost universally have gaps — either no real HIPAA documentation, backups that aren't tested, no EDR, or no after-hours coverage. The bargain tier looks like savings until the first incident.

Related Reading for Dental Practices

For a deeper look at dental-specific IT and workflow issues:

Frequently Asked Questions

What does HIPAA require from a dental practice's IT provider?

HIPAA requires a signed Business Associate Agreement (BAA), encryption of PHI at rest and in transit, access controls and audit logs, risk assessments, breach notification procedures, and a documented incident response plan. The MSP is a Business Associate under HIPAA and shares legal liability for breaches caused by their failures. Any MSP that cannot produce a BAA on request is non-compliant by definition.

Does a general IT provider know Dentrix or Eaglesoft?

Most general MSPs know them at a surface level — enough to keep the server running. Few know them well enough to handle database maintenance, imaging integration troubleshooting, upgrade planning, and workflow optimization. Before signing, ask specifically: have you done a Dentrix or Eaglesoft version upgrade in the last 12 months? Can you show a sample Dentrix database maintenance report? Have you integrated imaging (Dexis, Sirona, Carestream) with the practice management system in another practice?

How much does IT cost for a dental practice?

Most Greater Houston dental practices fall in the $125–$225 per user per month range for a full HIPAA-compliant managed IT service. A single-location 8-operatory practice with 12 staff runs roughly $1,800–$3,000 per month. Multi-location groups with imaging servers and HIPAA documentation typically reach $3,500–$7,500 per month. Tiers below $100 per user generally lack the HIPAA controls dental practices need.

What IT failures are most common in dental practices?

The five most common we see: (1) unencrypted imaging servers (a HIPAA violation), (2) practice management backups that have never been successfully test-restored, (3) MFA missing on Dentrix or Eaglesoft server admin accounts, (4) patient Wi-Fi sharing a network with operatory equipment, and (5) workstations running end-of-life Windows versions because of software compatibility fears. All five are findable in a 2-hour audit and all five are HIPAA-relevant.

What is a BAA and why does my MSP need one?

A Business Associate Agreement is a HIPAA-required contract between a covered entity (your dental practice) and any third party that creates, receives, maintains, or transmits PHI on your behalf (your MSP). It defines the MSP's obligations for safeguarding PHI, breach notification timelines, and their shared liability. Without a BAA, you cannot legally share PHI access with the MSP — and your practice is out of compliance the moment the MSP touches your network.

The Honest Answer for Houston-Area Dental Practices

SynergyIQ is a dental-specialized MSP for Greater Houston practices. We support Dentrix, Eaglesoft, and Open Dental; we carry a signed BAA for every practice; and we'll walk you through every row of the checklist above in a free 30-minute audit call.

Book a Free Dental IT Audit →

Related: Dental IT ServicesHealthcare ITDentrix Feature Gaps

Call Text Book Consult