Ask a dental practice owner for their security risk analysis and you usually get one of three answers. A blank look. A binder of policies somebody bought a few years ago, still in the shrink wrap of its own table of contents. Or, most often, a confident "our IT company handles that," which on inspection means the IT company sold a firewall and a backup and has never once asked what a dental practice is on the hook for.
The risk analysis is the piece of HIPAA work small practices skip more than any other, and the piece that gets named first when something goes wrong. It also cannot be bought, because the raw material is your building, your systems, your vendors and your people. This article covers what the exercise is, how to run it in an office with no compliance department, and what makes the result credible if somebody asks to see it.
The Quick Answer
A security risk analysis is not a form and it is not a certificate. It is an exercise you perform on your own practice: list everywhere electronic patient information lives, moves through, or gets copied to; for each of those places, name what could realistically go wrong; judge how likely each of those things is and how badly it would hurt; decide what you are going to do about each one, including the ones you decide to accept; write all of it down with dates and names attached; and revisit it when the practice changes.
A product can give you a framework, a questionnaire, and somewhere to store the answers. It cannot supply the answers, because the answers are facts about you. What makes the finished analysis credible later is that it is unmistakably about your office rather than a generic one, that the decisions it produced actually got carried out, and that a named human being can walk somebody through how it was done.
This article is not legal or compliance advice, and it is not a substitute for a professional. It describes the general shape of an exercise so you can have a better conversation with the people who advise you. What applies to your practice depends on your circumstances and on rules that change. Read the government's own material at the HHS Security Rule pages, and get a healthcare attorney and a security professional who works with medical or dental practices. Nothing here settles anything.
What the Exercise Actually Is
The idea is simpler than the vocabulary around it. You hold electronic information about patients. It can be seen by people who should not see it, changed by people who should not change it, or become unavailable to the people who need it. A risk analysis asks, in an organized way, where those three things could happen to you and how worried you should be about each.
Two words get used interchangeably and should not be. The risk analysis is the assessment: what could happen, how likely, how bad. Risk management is what you do about it: the decisions, the fixes, the money spent, the things consciously left alone. Practices that do the first and skip the second end up with a written record of problems they did nothing about, which is worse than not looking. It is a common failure mode among offices that bought a tool, ran it once and filed the output.
It also helps to know what the analysis is not, because every item on this list gets offered as a substitute for it:
- A policy binder is not a risk analysis. Policies are what you decided. The analysis is why.
- Training records are not a risk analysis. They are evidence of one control.
- A vulnerability scan or a penetration test is not a risk analysis. Those are technical inputs, and they say nothing about the paper on the counter, the vendor with a shared password, or the laptop that goes home.
- A stack of signed business associate agreements is not a risk analysis, though the vendor list behind it is a good starting point.
- A certificate from a training platform is not a risk analysis, whatever the certificate says.
Why "we bought the compliance program" is not an answer
A purchased program is a container. The good ones give you structure, prompts you would not have thought of, and somewhere to store evidence so it does not live in three people's email. That is worth paying for. What no product can do is walk your hallway, notice the sterilization computer stays logged in all day where patients walk past, and decide whether that matters in your layout. A tool filled in by somebody clicking through it produces a document describing a practice that does not exist, and that is the version that falls apart under scrutiny.
Step One: Inventory Where the Data Actually Lives
Almost every weak analysis is weak here, because the inventory is short. The real list in a dental office is long, and the surprises are never the server.
Work through it in categories and be literal. Devices: the server or hosted practice management system, every workstation, the imaging computers, laptops, tablets, phones carrying email or a texting app, the scanner and cone beam workstations, and anything else with a hard drive including the copier at the front desk. Storage: local backups, offsite backups, cloud backups, external drives that live in somebody's bag, and archives from the software you replaced four years ago and never decommissioned.
Then the flows, which people forget entirely. Information arrives through online forms, phone calls, referrals and payer portals. It moves to the lab, to specialists, to the clearinghouse, to a billing service, to a recall platform, to a payment processor, to your accountant as reports. It leaves through email, e-fax, texts, portals and printouts. Each one is somewhere something can go wrong, and each usually corresponds to a vendor who belongs on your business associate list. Building the inventory and auditing that list are the same job from two directions.
Finally the physical and human layer: who has keys, who has logins, who has a login and no longer works here, where screens face, what is audible in an open bay, where paper piles up before scanning, and what happens to a device when somebody leaves. Our walkthrough of dental office IT setup is a useful map when you are trying to list the technical side.
Build it as a table and keep it alive. One row per system or flow, with columns for what it holds, who owns it, which vendor is behind it, whether a business associate agreement exists, and where the data ends up. Every later step reads off this table, and it is the most reusable thing the exercise produces. Update it the day you add a vendor.
Step Two: Name What Could Go Wrong, One Row at a Time
Now walk the inventory and, for each row, ask what could realistically happen to it. The categories are easy to remember: human causes, accidental or deliberate, from inside or outside; environmental causes such as fire, water, storm and power loss; and technical causes such as hardware failure, software corruption and malicious code.
What separates a useful analysis from a generic one is specificity. "Portable devices may be lost" is a sentence from a template. "The laptop the associate takes home on Thursdays holds imaging software with a cached login" is a finding, and it practically writes its own remediation.
Pair each threat with the weakness that lets it land. A thief is a threat everywhere; the back door propped open for summer deliveries is what makes it matter at your address. Ransomware threatens everyone; a backup nobody has ever restored from is what turns it into an existential event. The threat is the world. The vulnerability is you.
Ask the boring questions
The findings that matter most in small practices tend to be unglamorous and slightly embarrassing, which is exactly why they survive for years.
- Who has an active login who no longer works here, across every system, including the imaging portal and the payer websites?
- Has anyone actually restored from the backup, on purpose, and watched it come back?
- Does a vendor's remote access tool use a shared password, and does anybody know when it was last used?
- Is the guest Wi-Fi the same network as the sensors and the server?
- Do staff use personal phones for patient communication, and what happens to those messages when they leave?
- Has anyone looked at who can see what inside the practice management software since it was installed?
- What does the team do when a patient asks for records by email, and who decided that?
For the technical threat side specifically, our realistic cybersecurity threat list for dental practices covers what actually happens to offices rather than what makes for exciting headlines, and ransomware in dental practices covers the one event most likely to test your backup assumptions.
Step Three: Judge Likelihood and Impact, Honestly
Every row needs two judgments: how likely, and how much damage. Keep the scale simple. Low, medium, high is enough. The purpose is to sort the list, not to produce a number that looks scientific. An office that builds a weighted scoring model with decimal places has usually substituted arithmetic for thinking.
Be concrete about impact in your own terms. How many patients. How many days you could not see them. What recovery would cost, including the days the schedule sits empty. What it would take in effort and attention if the information had to be treated as exposed. What it would do to referrals in a town where everyone talks. An owner who has genuinely pictured a week of cancelled schedule rates things differently than one who has not.
One principle changes the shape of the whole analysis: whether the information would be readable by whoever ends up with it. Data unreadable to an unauthorized holder sits in a very different position than data that is not, and that one characteristic influences how an entire category of scenarios plays out. It is the reasoning behind the standard advice to encrypt everything portable, and it is worth raising specifically with your security advisor and your attorney rather than assuming any particular result.
Honest beats flattering. An analysis where every row is rated low risk tells a reader you were grading your own homework. The credible version contains unflattering findings, because a real practice has some, and right next to them, what you decided to do and when.
Step Four: Decide What You Are Doing About Each One
This is risk management, and it is where the exercise stops being academic. For every row there are four honest choices. Fix it, so the risk largely goes away. Reduce it. Transfer part of it, through insurance or a vendor contract. Or accept it deliberately, because the cost of addressing it is out of proportion to the risk in your circumstances.
Accepting a risk is a legitimate decision. Accepting it silently is not. The difference is a sentence of reasoning and a date, so that later somebody can ask whether the reasoning still holds. "Accepted for now: replacing this would mean replacing the imaging hardware, revisit when that equipment is due" is a defensible position. A blank row is not.
Every decision needs an owner, an action, a target date and somewhere completion gets recorded. Sequence the work by putting the likely, damaging and cheap items at the top, because nothing builds momentum like closing six findings in an afternoon for the price of a service call. The expensive structural items go on a longer timeline, which is fine as long as the timeline exists.
The underlying standard is one of reasonableness for an organization of your size, complexity and capability. A four-operatory practice is not expected to build what a hospital system builds. It is expected to have thought about its own situation and to be able to explain the thinking. Our free HIPAA for Dental Practices course covers that framing, and the Security Rule lesson walks through how the safeguard categories fit together.
Step Five: Write It Down So It Can Be Read by a Stranger
The written analysis should stand on its own for somebody who has never been in your building. At minimum: what was assessed and what was left out and why, when, who did it and who took part, how, what was found, how each finding was rated, what was decided about each, and what changed since the last version.
Version it and keep the old copies. The trail is a large part of the value, because it shows something a single document cannot: that this is a process the practice runs rather than a paper it once produced. A first version with real findings, then a second showing most of them closed and two new ones added after you changed imaging systems, tells a story no polished single document tells.
What makes it credible, and what makes it fall apart
| Credible | Falls apart |
|---|---|
| Names your actual systems, vendors and layout | Generic language that could describe any office in the country |
| Dated, with named participants | No date, or a date added after something went wrong |
| Contains unflattering findings | Everything rated low, nothing outstanding |
| Each finding links to a decision and evidence it was carried out | Findings with no decisions, or decisions with no evidence |
| Revised when the practice changed | One version, years old, describing software you no longer run |
| A named person can explain how it was done | Nobody in the building knows who produced it |
When to Revisit It, and Who Might Ask
Set a cadence with your advisors and keep it, but do not let the calendar be the only trigger. The events that should prompt a fresh look are the ones that change the inventory: new practice management software or a move to a hosted system, new imaging, a new location, a new vendor with access, a change in how you reach patients, staff working remotely, a merger, a change in who administers your systems, and any incident or near miss, including the ones that turned out to be nothing.
As for who asks: a regulator is the obvious one and usually the least likely. Far more often it is a cyber insurance carrier, on the application, where questions are frequently yes or no and answering yes when it is not true creates its own problem, or at claim time, when the same question gets asked with much more attention. It is also standard in transition due diligence, and a practice that cannot produce one hands the other side something to negotiate with. Our due diligence checklist shows where it sits, and the compliance chapter places it among the other obligations an owner carries.
Running the exercise in a small office
- Name one person who owns this, with the owner's backing and time on the calendar
- Build the inventory table of systems, devices, flows and vendors, and do not stop at the server
- Walk the building with fresh eyes and write down what you see, not what you expect
- For each row, name specific threats and the specific weakness that lets them land
- Rate likelihood and impact simply, and resist the urge to grade generously
- Record a decision on every finding: fix, reduce, transfer or accept, with reasoning
- Give each action an owner, a target date and somewhere completion gets logged
- Write it so a stranger could follow it, date it, and keep every prior version
- Agree a review cadence and the events that trigger an off-cycle review
- Have your attorney and a security professional tell you what you missed
THE CHAIRSIDE TAKE
Block half a day, print your vendor list, walk your own hallway, and start the inventory. You will find four or five things in the first hour that you already suspected and never wrote down, and writing them down is most of the point. Then do the unglamorous part: close the cheap fixes this month, put the expensive ones on a real timeline, and write down the ones you are consciously living with and why. Have your attorney look at it. Do it again when something changes. The practice that can hand someone a dated document and say "here is what we did about each of these" is in a completely different position from the practice holding a binder it bought, and the difference cost a half day and some honesty.
Educational only. Not legal, compliance or security advice, and nothing here establishes what your practice is required to do. Requirements depend on your circumstances and change over time. Work from the primary government material and from a healthcare attorney and security professional who know your situation.
Educational content only. It is not legal, financial, tax, or clinical advice. Prices and ranges are approximate and vary by region, condition, and year. Verify current rules with your state dental board and qualified professionals. ChairsideSource is not affiliated with any manufacturer, the ADA, or the DAT.