A Washington dental practice needs HIPAA IT support that goes well beyond a working Dentrix or Eaglesoft server. You need encrypted workstations and laptops, a documented annual risk analysis, audit logging on every system that touches patient data, signed business associate agreements with every vendor that can see ePHI, and an imaging environment (CBCT, intraoral cameras, pano units) that is segmented and patched. Most dental offices we assess in Western Washington are missing at least four of those — and OCR has stopped giving dentists a pass for being “just a small practice.”
Why Are Dentists Suddenly in the OCR Crosshairs?
For a long time, small dental practices assumed HIPAA enforcement was a hospital problem. That assumption is no longer safe.
The peer-state enforcement signal that should get every Washington dentist’s attention came out of Indiana, where Westend Dental was sanctioned by the state Attorney General over a 2020 ransomware incident the practice did not report as a breach. The settlement framed the case around failure to notify and failure to maintain reasonable security — the exact two failures we see in Pacific Northwest dental offices every quarter. Washington’s Attorney General has parallel authority under the state Consumer Protection Act, and Washington’s breach notification law (RCW 19.255.010) gives you only 30 days, not the 60 you get under federal HIPAA.
OCR has also signaled that the HIPAA Security Rule is being modernized. The December 2024 Notice of Proposed Rulemaking (NPRM) would tighten technical safeguards — mandating encryption rather than treating it as “addressable,” requiring MFA, and mandating annual technical testing. As of May 2026 the NPRM is still proposed, not final, so do not let a vendor sell you “mandatory” controls that have not been adopted yet. But the direction of travel is obvious, and a Washington dental practice planning equipment refreshes in the next 18 months should plan as if those controls are coming.
What Does HIPAA IT Look Like Inside a Dental Office?
Dental practices have a specific IT footprint that creates predictable HIPAA gaps. We see the same shape repeatedly across Snohomish, Skagit, and Whatcom county offices:
- Practice management server running Dentrix, Eaglesoft, Open Dental, or Curve — usually on-prem, sometimes hosted.
- Imaging workstations at every operatory, driving sensors, intraoral cameras, and panoramic/CBCT units.
- A separate imaging server or NAS that almost no one has patched in three years.
- Front desk PCs that handle scheduling, insurance verification, and statement printing.
- A wireless network that the practice management software, the imaging gear, the staff phones, and the patient guest network all share.
That last bullet is where a surprising number of practices fail their first real assessment. A flat network where the guest Wi-Fi can reach the imaging NAS is not a HIPAA-compliant network. The general technical-safeguard expectations are the same ones outlined in HIPAA IT requirements for Washington state — the dental-specific challenge is that imaging vendors often refuse to support modern segmentation, and the practice has to push back.
What Should a Dental Office’s BAA Stack Look Like?
A dental practice typically needs business associate agreements with more vendors than the owner realizes. The ones we routinely find missing in Washington offices:
- The practice management vendor (Dentrix/Patterson, Henry Schein One, Carestream, Curve, Open Dental hosting providers)
- The imaging software vendor and any cloud image-sharing service
- The IT provider — yes, including ROI, and including the prior guy who “just fixed computers”
- The patient communication platform (text reminders, online forms, online intake)
- The cloud backup provider
- The shredding vendor
- The off-site server hosting provider, if any
If a vendor can see, store, transmit, or even access ePHI in the course of supporting you, you need a signed BAA before they touch your systems. “We’ve worked with them forever” is not a defense OCR accepts.
What About the Imaging Network?
Dental imaging is the silent compliance problem. CBCT units, pano machines, and intraoral sensor drivers often run on outdated Windows builds because the vendor never certified the software on a newer OS. Practices are told they cannot patch, cannot run EDR, and cannot move the device to a newer machine. That advice protects the vendor — not the practice.
What works in the real world:
- Network segmentation that isolates imaging devices on their own VLAN with no internet egress and tight ACLs to the practice management server.
- A documented exception in the risk analysis explaining why the imaging device cannot be patched, what compensating controls are in place, and when it will be replaced.
- Replacement on a roadmap. If the vendor will not let you patch a clinical Windows 10 box past October 2025, that device is end-of-life from a HIPAA perspective regardless of what the vendor says.
What Does an Annual HIPAA Risk Analysis Look Like for a Dental Practice?
The risk analysis is the single most cited deficiency in OCR enforcement actions, including in small-practice settings. For dental offices, a credible annual risk analysis covers:
- An ePHI inventory that lists every system, device, and cloud service that touches patient data — not just the practice management server.
- A threat model that includes ransomware, phishing, lost or stolen laptops, vendor compromise, and physical theft.
- A controls inventory documenting what is actually in place today (encryption status, MFA coverage, EDR deployment, audit logging, backup verification).
- A risk-ranked gap list with owner and target date for each item.
- A remediation log that proves you are working the list.
If your “risk analysis” is a PDF a vendor sent you in 2022, it is not a risk analysis. It is a sales artifact. Auditors check dates.
ROI Technology Inc. supports dental practices across Western Washington with HIPAA-aligned IT — encrypted endpoints, segmented imaging networks, BAA management, and annual risk analyses your auditor will accept. Contact us or call (888) 707-3652 for a compliance assessment that finds the gaps before OCR does.