Dental practice management is structurally worse than medical. That is not an opinion.
Dentrix, Eaglesoft, and Open Dental typically run on an on-premise SQL or Sybase server in a closet, not in a cloud tenant somebody else hardens for you. A compromised front-desk workstation has direct lateral access to the practice management database, the imaging server, and the SQL backups sitting on a shared drive. That is the structural driver of the 2024–2025 dental ransomware wave, and it is why dental groups carry the highest exposure per dollar of revenue in our book.
Eaglesoft historically shipped with the database username dba and the password sql. We check this on every dental assessment. We still find it.
The specifics a generalist has never had to learn.
These are the findings that come up repeatedly when a healthcare-specialized team assesses this kind of environment. None of them are theoretical, and none of them are in a generic managed services playbook.
Eaglesoft shipped with hardcoded database credentials
Username dba, password sql. Versions 17 and below stored passwords in plaintext. If nobody has changed it, the practice management database is readable by anything that reaches the server — which, on a flat network, is every workstation in the building.
Legacy Eaglesoft has neither granular permissions nor comprehensive access logging
That is a minimum-necessary problem under §164.502(b) and an audit-controls problem under §164.312(b), simultaneously. Compensating controls and a documented rationale are the honest answer; pretending the gap is not there is not.
Shared front-desk logins are defended as clinical workflow
They destroy unique user identification under §164.312(a)(2)(i) and audit controls under §164.312(b). The right answer is badge or proximity authentication with fast user switching — not refusing the workflow, and not pretending five people are one user.
Imaging servers are the forgotten half of the estate
Cone beam CT, intraoral sensors, and pan units all write somewhere. That destination is usually an unpatched Windows box with an open share. It goes in the inventory, on its own segment, with deny-by-default egress.
DSO affiliation turns five problems into one program
DSO affiliation is projected to move from 23% of practices in 2024 to roughly 39% by 2026, and 69% of DSOs expect to increase acquisition activity. Every affiliation produces a mismatched estate and a diligence event. We have integrated 27 practice acquisitions for platform clients.
We already know what these need.
And, more usefully, what each one breaks when you patch it wrong. This is not a partner list. It is the set of systems currently under management across our book in this segment.
- Dentrix
- Eaglesoft
- Open Dental
- Curve Dental
- Dexis
- Carestream
- Planmeca Romexis
- Sirona / Dentsply
- Weave
- Per-server documentation of practice management database credential rotation
- Compensating-control rationale for every logging gap the PM system cannot close
- Imaging and operatory device inventory with segmentation evidence
- Restore test results for the PM database, quarterly, with timings
Everything in the standard evidence file applies as well: risk analysis, risk management plan, MFA coverage, training records, restore tests, and the Recognized Security Practices attestation.
How the compliance program worksMost start at Secure.
Dental groups need segmentation, containment authority, and restore-tested backups first. Groups affiliating with a DSO move to Compliant, because diligence asks for the paper.
Chartline Core
Managed IT with a security baseline.
$135/ user / month
15-user minimum · 36-month term
Help desk, patching, EDR, Microsoft 365, enforced MFA, immutable backup, and the asset inventory. Everything a practice needs to be running and defensible.
What is in CoreChartline Secure
Everything in Core, plus 24/7 detection and response.
$189/ user / month
15-user minimum · 36-month term
For practices whose carrier, payer, or health-system affiliate has started asking questions. Containment authority, log retention, segmentation, and the exposure monitoring that finds what a scanner does not.
What is in SecureChartline Compliant
Everything in Secure, plus the HIPAA program and the evidence file.
$255/ user / month
25-user minimum · 36-month term
The security program and the paper trail that proves it existed. A named security officer, a real risk analysis, a dated remediation plan, and an evidence file built for an OCR data request.
What is in CompliantWe only do healthcare, but healthcare is not one thing.
Physician groups and specialty practices
Ortho, GI, ophthalmology, women’s health, and primary care. An Epic Community Connect affiliation inherits the host system’s security and audit obligations, and MIPS attestation is a hard annual deadline.
Behavioral health and SUD providers
42 CFR Part 2 civil enforcement went live February 16, 2026. Consent management, redisclosure controls, and disclosure accounting sit on top of HIPAA.
Ambulatory surgery centers
Anesthesia machines, monitoring equipment, and imaging on the same network as scheduling. IoMT segmentation is the whole job.