Twelve acquired practices, three PM systems, one standard.
A dental support organization had grown by acquisition for four years and inherited twelve environments nobody had ever standardized.
- 14 mo
- To a single standard across 12 sites
- −41%
- Tickets per location per month
- −28%
- IT cost per location
What we walked into
Twelve practices acquired over four years, each of which had kept whatever IT company it had at the time of acquisition. Three practice management systems. Five backup products, two of which had not completed a successful job in over ninety days. Four different firewalls. No inventory that matched reality at any site.
Nobody at the platform could answer the question “how many servers do we have,” which is the question that precedes every other question.
The order of operations
Inventory first, produced from the network rather than from the platform’s spreadsheet. It found 19 servers against a spreadsheet that listed 14, and 61 endpoints that nobody had patched in over a year.
Then identity: one Microsoft 365 tenant, one identity platform, MFA enforced on every path into ePHI including the two sites still reaching the PM system over an SSL VPN. Then endpoint and detection standardization. Then backup consolidation onto one immutable platform with quarterly restore tests. Then network standardization, one site at a time, on a schedule the practices could absorb.
Practice management consolidation was deliberately last. It is the most disruptive change and the least urgent from a risk standpoint, and doing it first is the most common integration mistake we see.
What the numbers did
Ticket volume per location per month fell 41% over the fourteen months, most of it in the first six as unpatched endpoints and failing backups stopped generating incidents. IT cost per location fell 28%, driven by consolidating five backup products into one and eliminating four separate incumbent contracts.
The number the platform’s CFO actually watched was neither of those. It was onboarding time for the next acquisition, which went from an eleven-week project to a nineteen-day checklist.
The compliance side
A single enterprise-wide risk analysis now covers all twelve entities with per-site findings, replacing the zero risk analyses that existed at engagement. The BAA register was assembled from scratch; it found four expired agreements and two vendors holding ePHI that nobody at the platform could account for.
That register is the artifact the platform’s own future buyer will ask for first.
The whole result, in one table.
Including the figures that are less flattering than the headline. A case study that only contains good numbers is an advertisement.
Two more, also with numbers.
An 11-location dental group, encrypted on a Thursday night.
Practice management server, imaging server, and the backup share, all encrypted. Chairs were seeing patients again in 31 hours.
Read it OCR data requestAn OCR data request answered in nine business days.
A specialty physician group received a data request following a business associate’s breach. The request had a thirty-day clock on it.
Read it