What this is: a working checklist from an IT company that installs and secures dental networks in NYC. It is not legal advice and it is not a substitute for a compliance consultant or your own risk analysis. Where an item is a legal obligation rather than a technical recommendation, we say so — and for the obligations, verify the current requirement with HHS or your attorney rather than taking our word for it.
Technical safeguards
The infrastructure layer. This is the part we build.
A unique login for every person
IT builds thisNo shared front-desk account, no sticky note on the monitor. Every staff member gets a named account, because audit logs are worthless if six people share one identity.
Automatic logoff on every workstation
IT builds thisScreens lock on a timer, including the operatory machines. An unattended charted patient record in a room a stranger can walk into is the most common physical exposure in a dental office.
Encryption at rest on anything holding records
IT builds thisServer drives, workstation drives, and every backup copy. This is the single control that turns a stolen laptop from a reportable breach into a non-event.
Encryption in transit
IT builds thisAnything leaving the building — backups going offsite, remote access, email carrying patient information — travels encrypted.
Audit logging that someone can actually read
IT builds thisYour practice management software logs record access. That logging needs to be switched on, retained, and reviewable, not left at defaults nobody has looked at since install day.
Network segmentation
IT builds thisImaging, office workstations, and guest Wi-Fi on separate VLANs. A patient's phone on your guest network should have no path to the machine holding your records.
A backup you have restored from
IT builds thisNightly, encrypted, with an offsite copy and at least one test restore you personally watched succeed. Ransomware turns an untested backup into a very expensive discovery.
Patching that actually happens
IT builds thisOperating systems, firmware, and the firewall. An unpatched edge device is how most small-practice intrusions start.
Physical safeguards
Mostly about where the hardware lives and who can touch it.
The server is behind a locked door
SharedNot in the break room, not under the front desk where anyone waiting can reach it. A small locked closet or rack with proper ventilation.
Screens the waiting room cannot read
Practice owns thisCheck the sight lines from every chair in your reception area. Privacy filters are cheap; reangling a monitor is free.
A documented disposal process
SharedDrives from retired computers get wiped or destroyed, with a record that it happened. Handing an old front-desk machine to a staff member's kid is a breach.
Control of who gets a key
Practice owns thisKnow who can access the space after hours, including the cleaning service and the landlord, and revoke access when people leave.
Administrative safeguards
Paperwork and process. Nobody can do this part for you, and it's the part auditors ask about first.
A written risk analysis
Practice owns thisThis one is explicitly required, not optional, and it's the most commonly missing document in a small practice. HHS publishes a free Security Risk Assessment tool that walks you through it.
One named person responsible for security
Practice owns thisA specific human, written down. In a small practice this is usually the owner or the office manager.
Staff training, on the record
Practice owns thisAnnual awareness training with attendance recorded. Most breaches at practices this size start with a staff member clicking something, not with a sophisticated attack.
Business Associate Agreements with every vendor touching records
SharedYour IT company, your backup provider, your billing service, your cloud PMS host. If they can see patient information, you need a BAA on file. Ask us for ours — a vendor who hesitates at this question is telling you something.
A written incident and breach response plan
Practice owns thisWho you call, in what order, and on what clock. Notification deadlines are tight, and reading the rule for the first time during an incident is how practices miss them.
A contingency plan for losing the building
SharedFire, flood, extended power loss. How do you see patients, and how long until records are back? Your offsite backup is the technical half of this answer.
Periodic re-evaluation
Practice owns thisThe rule expects you to revisit this as your practice changes. Adding operatories, changing software, or hiring staff all change your risk picture.
We Build the Technical Half Into Every Install
Encryption, per-user access control, audit logging, VLAN segmentation, and a backup we restore from with you watching — all included in the flat-rate packages, not sold as an upgrade. You get the documentation for your risk analysis at handover.
HIPAA Questions Dentists Ask Us
Related reading: FBI warning: hackers targeting dental practices · Dental office network installation NYC · Dentrix vs Eaglesoft vs Open Dental
