Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
6 client organizations

Dental practice management is structurally worse than medical. That is not an opinion.

Dentrix, Eaglesoft, and Open Dental typically run on an on-premise SQL or Sybase server in a closet, not in a cloud tenant somebody else hardens for you. A compromised front-desk workstation has direct lateral access to the practice management database, the imaging server, and the SQL backups sitting on a shared drive. That is the structural driver of the 2024–2025 dental ransomware wave, and it is why dental groups carry the highest exposure per dollar of revenue in our book.

Eaglesoft historically shipped with the database username dba and the password sql. We check this on every dental assessment. We still find it.

What is actually different here

The specifics a generalist has never had to learn.

These are the findings that come up repeatedly when a healthcare-specialized team assesses this kind of environment. None of them are theoretical, and none of them are in a generic managed services playbook.

01

Eaglesoft shipped with hardcoded database credentials

Username dba, password sql. Versions 17 and below stored passwords in plaintext. If nobody has changed it, the practice management database is readable by anything that reaches the server — which, on a flat network, is every workstation in the building.

02

Legacy Eaglesoft has neither granular permissions nor comprehensive access logging

That is a minimum-necessary problem under §164.502(b) and an audit-controls problem under §164.312(b), simultaneously. Compensating controls and a documented rationale are the honest answer; pretending the gap is not there is not.

03

Shared front-desk logins are defended as clinical workflow

They destroy unique user identification under §164.312(a)(2)(i) and audit controls under §164.312(b). The right answer is badge or proximity authentication with fast user switching — not refusing the workflow, and not pretending five people are one user.

04

Imaging servers are the forgotten half of the estate

Cone beam CT, intraoral sensors, and pan units all write somewhere. That destination is usually an unpatched Windows box with an open share. It goes in the inventory, on its own segment, with deny-by-default egress.

05

DSO affiliation turns five problems into one program

DSO affiliation is projected to move from 23% of practices in 2024 to roughly 39% by 2026, and 69% of DSOs expect to increase acquisition activity. Every affiliation produces a mismatched estate and a diligence event. We have integrated 27 practice acquisitions for platform clients.

Systems we run

We already know what these need.

And, more usefully, what each one breaks when you patch it wrong. This is not a partner list. It is the set of systems currently under management across our book in this segment.

  • Dentrix
  • Eaglesoft
  • Open Dental
  • Curve Dental
  • Dexis
  • Carestream
  • Planmeca Romexis
  • Sirona / Dentsply
  • Weave
What the evidence file contains for this segment
  • Per-server documentation of practice management database credential rotation
  • Compensating-control rationale for every logging gap the PM system cannot close
  • Imaging and operatory device inventory with segmentation evidence
  • Restore test results for the PM database, quarterly, with timings

Everything in the standard evidence file applies as well: risk analysis, risk management plan, MFA coverage, training records, restore tests, and the Recognized Security Practices attestation.

How the compliance program works
Where this segment usually lands

Most start at Secure.

Dental groups need segmentation, containment authority, and restore-tested backups first. Groups affiliating with a DSO move to Compliant, because diligence asks for the paper.

Chartline Core

Managed IT with a security baseline.

$135/ user / month

15-user minimum · 36-month term

Help desk, patching, EDR, Microsoft 365, enforced MFA, immutable backup, and the asset inventory. Everything a practice needs to be running and defensible.

What is in Core

Chartline Secure

Everything in Core, plus 24/7 detection and response.

$189/ user / month

15-user minimum · 36-month term

For practices whose carrier, payer, or health-system affiliate has started asking questions. Containment authority, log retention, segmentation, and the exposure monitoring that finds what a scanner does not.

What is in Secure
Most multi-location groups land here

Chartline Compliant

Everything in Secure, plus the HIPAA program and the evidence file.

$255/ user / month

25-user minimum · 36-month term

The security program and the paper trail that proves it existed. A named security officer, a real risk analysis, a dated remediation plan, and an evidence file built for an OCR data request.

What is in Compliant
Dental practices and DSOs

See where you stand in about eight minutes.

Fifteen questions mapped to Security Rule citations, scored, with the specific §164 requirement named behind every gap. Nothing is gated and no call is required to see the result.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.