Your practice runs on trust. Your technology should pass the same standard.
67% of dental practices fail their first HIPAA technology audit. The other 33% had help before the auditor arrived.
"Will my Dentrix data survive the migration?"
Every practice owner asks this first — and they should. The difference between a compliant migration and a catastrophic one is the protocol used before a single record moves. Here is exactly what changes.
| Dimension | Unmanaged Migration What most practices attempt | Comply Migration Protocol What every migration should be |
|---|---|---|
| Data transfer | Manual CSV exports prone to encoding errors and field-mapping failures | Automated schema-mapped extraction via certified PMS API connectors — zero manual touch |
| Downtime window | Practices typically close 2–5 days; staff retrained mid-migration | Parallel-run migration: new system live before legacy decommission — 0 days closure |
| Image archives | Bitewing and panoramic archives left on local server or burned to DVD | DICOM-compliant cloud transfer with SHA-256 integrity verification per file |
| Audit trail | No migration log; no way to prove chain of custody if audited | Timestamped migration manifest signed by Comply engineer — audit-ready on day 1 |
| Rollback | Legacy system wiped before go-live; rollback means recreating from backup tapes | Legacy system preserved read-only for 90 days post-migration; instant rollback available |
| PMS systems | Vendor migration tools only work within their own ecosystem | Dentrix, Eaglesoft, Open Dental, Curve, Carestream — all covered under one protocol |
The verdict: In 847 migrations completed since 2019, Comply has recorded zero data loss incidents. The protocol is the reason — not luck.
"What happens to patient records during the switch?"
The moment records leave a paper chart or a local drive, they enter HIPAA-regulated territory. Most practices don't know what that requires until an auditor explains it — at $50,000 per violation. Here is the difference between a Paper Referral Loop and an Encrypted Digital Handoff.
| Dimension | Paper Referral Loop The legacy standard | Encrypted Digital Handoff The compliance standard |
|---|---|---|
| Referral pathway | Paper referral form faxed to specialist; no delivery confirmation | Encrypted HL7 FHIR message with delivery receipt and read timestamp — HIPAA §164.312(e) |
| Record access | Patient records locked in local server; inaccessible if server fails | Role-based cloud access with MFA; available from any operatory in under 3 seconds |
| Imaging pipeline | X-rays stored as unencrypted JPEG on workstation C:/ drive | AES-256 encrypted DICOM vault; BAA executed with storage provider on day 1 |
| Breach surface | Fax machines, USB drives, and email attachments — each a reportable breach vector | Zero-trust architecture: every data path encrypted, logged, and anomaly-monitored |
| Transition window | Paper charts coexist with digital indefinitely; staff maintain both systems | 72-hour structured cutover with Comply engineer on-site — no hybrid limbo |
| Patient notification | No formal notification process; practices unaware of HIPAA notice requirements | Comply drafts and delivers compliant patient notification as part of standard protocol |
The citation: HIPAA §164.312(a)(2)(iv) requires encryption of ePHI in transit. A fax line does not satisfy this requirement — regardless of how many years your practice has used it.
"How do we stay compliant during the transition?"
The transition period is the highest-risk window — when two systems coexist and neither is fully governed. The practices that pass audits are the ones that treated compliance as the starting point, not an afterthought. Here is the comparison between a Manual Recall Spreadsheet and an Automated 90-Day Recall Engine.
| Dimension | Manual Recall Spreadsheet The status quo | Automated 90-Day Recall Engine The Comply standard |
|---|---|---|
| Recall method | Staff manually calls patients from a spreadsheet; 60–70% of calls go unanswered | Automated 90-day sequence: SMS → email → voicemail drop — 34% higher recall rate |
| Audit trail | No record of recall attempts; untestable if audited for standard-of-care compliance | Every patient touchpoint logged with timestamp, channel, and outcome — audit-ready |
| Compliance posture | No formal HIPAA risk assessment; practices rely on "we haven't been audited yet" | Comply conducts a full NIST-framework risk assessment before any system goes live |
| Staff training | One-time training at PMS purchase; no refresher schedule, no documentation | Annual HIPAA training module per staff member; completion certificates auto-generated |
| BAA coverage | Business Associate Agreements missing or unsigned for cloud vendors used daily | Comply audits and executes BAAs with every vendor in the practice's technology stack |
| DSO readiness | Each location runs different software; consolidation requires negotiating 30 contracts | Single-platform rollout: Comply standardizes all locations onto one system by target date |
The closing argument: After three questions, the only variable still unresolved is when your practice starts. The assessment below takes 45 minutes. The audit you're currently exposed to does not give you a warning.
The only question left is when.
Every day without a compliance assessment is a day the 67% statistic applies to your practice. The assessment is complimentary. The risk of skipping it is not.
Book Your Compliance Assessment
What the assessment includes
- 45-minute technology audit of your current PMS and imaging stack
- HIPAA risk assessment scored against NIST SP 800-66r2 framework
- Written findings report with prioritized remediation roadmap
- BAA gap analysis — every vendor in your stack reviewed
- Migration feasibility estimate with timeline and zero-downtime plan
Download the HIPAA Technology Checklist
Not ready to book? Get the 47-point checklist practices use to self-audit before an OCR investigator does it for them.
"We were three weeks from an OCR audit when Comply found the BAA gaps. The assessment paid for itself before we even started the migration."
Dr. Marcus Reinholt, DDS
Reinholt & Associates Dental Group — 4 locations, Phoenix AZ