Dental IT Support: A Checklist for Small Practices, With Costs

Rick Smaczniak
October 5, 2026
Blue 360 Business Solutions card reading dental IT support, the checklist for a small dental practice

Dental IT support is the outside team that keeps a practice's computers, imaging, practice management software, network and backups running, and keeps patient data protected under HIPAA. This dental IT support checklist covers what a small practice actually needs, what it should cost, where HIPAA fits, and the questions to ask before you sign with anyone, including us.

What dental IT support covers in a small practice

A dental office runs on more technology than most small businesses its size. The front desk, the operatories and the back office all depend on it, and when one piece stops, the schedule stops with it.

Here is what a dental IT support provider should be responsible for:

  • Practice management software: the system holding your schedule, charts and billing, whether that's Dentrix, Eaglesoft, Open Dental or a cloud platform, plus the workstations and server it runs on.
  • Imaging: the sensors, the computers in each operatory and wherever the images are stored. A sensor that stops talking to the chairside PC is a patient waiting in the chair.
  • The network: firewall, Wi-Fi for staff kept separate from the guest network, and secure remote access for the doctor checking charts from home.
  • Backups and recovery: patient records and images copied off site every day, with restores actually tested.
  • Security: malware protection, patching, encryption on laptops, multi-factor authentication and staff phishing training.
  • Your other vendors: one point of contact who calls the software company, the internet provider and the phone vendor so your office manager doesn't have to.

Rick Smaczniak, President of 360 Business Solutions, puts the goal simply: "anytime any of your technology breaks, you call us and we manage it for you."

The dental IT support checklist

Use the checklist below to check the IT you have now. If you can't answer a line with a name or a date, that's a gap.

Every day

  • Patient records and images back up automatically to a second location outside the office.
  • Every workstation and the server get security updates without anyone remembering to run them.
  • Someone is watching for alerts: failed backups, full disks, malware detections, unusual logins.

Every month

  • A backup restore is tested, not just checked off as "completed."
  • Accounts for staff who left are switched off, and nobody shares a login at the front desk.
  • Remote access for the doctor or the billing person uses multi-factor authentication.

Once a year

  • A written HIPAA security risk analysis is done or updated, and the gaps it finds have an owner and a date.
  • Staff complete security training, including how to spot a phishing email.
  • Aging computers and the server are reviewed before they fail, not after.

On paper

  • A signed business associate agreement with every vendor that touches patient data, including your IT provider.
  • A one-page plan for what happens if the server dies or ransomware hits: who calls whom, where the backups are, how you run the schedule in the meantime.
  • A current list of every device, every software license and who has access to what.

The once-a-year and on-paper items are the easiest to put off. The paperwork feels optional until someone asks for it, and the someone is usually an insurer after a claim or the Office for Civil Rights after a complaint.

Where HIPAA fits for a dental practice

HIPAA is the reason dental IT carries more weight than IT at a typical office of the same size. Two requirements land directly on the IT side.

The first is the risk analysis. The HHS guidance on risk analysis marks it as required under the Security Rule, at 45 CFR 164.308(a)(1)(ii)(A). HHS also says the rule doesn't prescribe one method, because the right approach depends on the size and complexity of the practice. A 12-person office doesn't need a 200-page report. It needs an honest one.

JD Sentz, COO and CTO of 360, describes where we start: "We start with a HIPAA Security Risk Analysis to identify risks, gaps, and the safeguards needed to better protect electronic patient information."

The second is the business associate agreement. Any outside company that creates, receives, maintains or transmits patient data for you is a business associate, and the HHS guidance on cloud services says that holds even for a provider storing encrypted data it can't read. Your IT company logs into the machines that hold your charts, so it belongs on that list.

Business associates get investigated too. In March 2026, HHS announced a settlement with MMG Fusion, a software company that sends messages to patients for healthcare providers, after a breach exposing the information of about 15 million people. Among the potential violations OCR listed was failing to conduct an accurate and thorough risk analysis.

About the "new HIPAA rule" you may have heard about: HHS proposed a major update to the Security Rule in January 2025. As of the federal regulatory agenda, the final rule is listed for July 2027, so the current rule is the one in force. The HHS fact sheet on the proposal lists multi-factor authentication, separate backup and recovery controls, and written plans to restore systems within 72 hours, most of which already sit on the checklist above.

One line we hold firmly: no IT company can make your practice HIPAA compliant or certify that it is. Compliance includes your policies, your training and your decisions. A good provider finds the gaps, closes the technical ones and keeps the documentation ready. Our compliance and security work for medical and dental practices is built around exactly that split. This post explains the requirements; it isn't legal advice.

What dental IT support costs

At 360, most practices pay between $100 and $200 per user per month, plus a few flat monthly costs set by what the office needs. For a practice with 8 to 15 people on computers, the per-user part works out to roughly $800 to $3,000 a month. Those figures are our own range applied to common practice sizes, not a quote. For what moves that number up or down, see how managed IT pricing works.

Where a practice lands depends mostly on how much HIPAA work comes with it and how much equipment there is to look after, like operatory computers and an on-site server. You get the exact number after we look at your setup.

Compare that against what an outage costs you. A morning with no schedule and no X-rays means rescheduled patients, a front desk on the phone apologizing, and production you don't get back.

A dental-only IT company or a local managed IT provider?

Plenty of IT companies sell to dentists only, and several of them rank for this search with lists of the "best dental IT companies," usually with themselves at number one. Specialization can help. It isn't the only thing that matters.

What matters more for a small practice is who shows up when the server won't boot at 7:30 on a Monday, whether they will sign a business associate agreement without a fight, and whether they'll take ownership of your software vendor's calls instead of telling you to call the vendor yourself. A national dental IT firm with no one within three hours of Buffalo can't walk into your sterilization room.

Ask any provider, specialist or not, how often they work with your practice management and imaging software, and ask to talk to a current client.

You also don't have to pick one or the other. If your imaging vendor or a dental software specialist already handles part of your setup and you're happy with them, co-managed IT keeps them in place. We take the rest: monitoring, backups, security, the network and the HIPAA paperwork, and we coordinate with them instead of competing with them.

Questions to ask before you sign

  • Will you sign a business associate agreement, and can I see it before I sign the contract?
  • Who calls our practice management and imaging vendors when something breaks?
  • How do you back up patient records and images, and when did you last test a restore?
  • Do you come on site, and how far are you from our office?
  • What's your average response time, and is it a promise or an average?
  • What exactly is included in the monthly fee, and what costs extra?

On that fifth question, we'll go first: our average response time is under 15 minutes, and it's an average, not a contract guarantee. If you want to compare answers, our managed IT services for medical and dental practices lay out what's included.

What should dental IT support include?

Dental IT support should include monitoring and help desk support for every workstation and server, care of the practice management and imaging systems, daily off-site backups with tested restores, security updates, multi-factor authentication, staff training, a signed business associate agreement, and help keeping the HIPAA risk analysis current. For dental practices in Buffalo and Western New York, 360 Business Solutions in Amherst provides managed IT and compliance support on site and remotely. Call (716) 650-7200 or book a 30-minute assessment.

Dental IT support questions

What does a dental IT support company do?

A dental IT support company keeps a practice's computers, network, imaging and practice management software running, backs up patient data, protects it against attacks and helps with the technical side of HIPAA.

How much does dental IT support cost?

At 360, most practices pay $100 to $200 per user per month plus a few flat costs. HIPAA work and the amount of equipment move a practice up or down that range.

Does our IT company need to sign a business associate agreement?

Yes, if it creates, receives, maintains or transmits patient data for you, which covers most IT providers that support your systems. HHS says this applies even when the provider stores encrypted data it can't read.

Is the new HIPAA Security Rule in effect?

Not yet. HHS proposed it in January 2025, and the federal regulatory agenda lists the final rule for July 2027. The current Security Rule is the one practices must follow today.

Can an IT company make our practice HIPAA compliant?

No. An IT company can close the technical gaps and keep the documentation ready, but compliance also depends on your policies, training and decisions, and no IT company can certify it.

Do you support dental offices outside Buffalo?

We do. Our team works out of Amherst, comes on site anywhere in Western New York, and handles the rest remotely.

Ready to Talk?

Your first conversation is on us.

Free 30-Minute Technology Assessment

  • Review your current IT setup
  • Identify compliance gaps and quick wins
  • Explore AI & automation opportunities
  • No pitch. No pressure. Just clarity.
Loading booking calendar...