Dental IT support dashboard on dual monitors with the Baltimore Inner Harbor skyline behind, dental operatory at left

In July 2024, a dental practice based in Oregon filed a formal breach notice with the Maryland Attorney General because the incident touched exactly one Maryland resident.

Dental IT support in Baltimore has to account for a rule most practice owners get backwards. In Maryland, the Attorney General is notified before your patients are, on every breach, with no minimum number of people involved. There is no small-incident exception to fall back on, and the state has no HIPAA exemption to fall back on either. This is statutory background rather than legal advice, and your own counsel should read it against your facts.

Medix Dental IT has worked exclusively in dental for more than 20 years, from single offices to multi-location groups and DSOs. The Maryland rule below is the one practices are least often walked through, and the one that shapes what an incident response actually has to look like.

Maryland Notifies the Attorney General First, on Every Breach

Most states set a floor. Notify the Attorney General if the incident reaches 500 people, or 1,000, or if you decide the risk is high enough. Maryland does neither of those things.

Commercial Law section 14-3504(h)(1) reads: "Prior to giving the notification required under subsection (b) of this section… a business shall provide notice of a breach of the security of a system to the Office of the Attorney General." Two things are doing work in that sentence. The word "prior," which fixes the order. And the absence of any threshold anywhere in the section, which means the duty attaches to a breach involving one patient exactly as it attaches to one involving fifty thousand.

Sequence matters more than most owners expect. On the face of the statute, a practice that discovers an incident on a Friday, calls its patients over the weekend to get ahead of it, and files with the state the following week has been responsive, transparent, and out of order. How that plays out in a real incident is a question for counsel, but it is not the order the text describes.

What the state asks for is also more than a heads-up. Under section 14-3504(h)(2), the notice must include the number of affected Maryland residents, a description of the breach "including when and how it occurred," the steps the practice has taken or plans to take, and the form of notice that will go to patients along with a sample of it. The state reads your patient letter before your patients do.

Then there is the deadline. Section 14-3504(b)(3) requires patient notice as soon as reasonably practicable and no later than 45 days after the business discovers or is notified of the breach. Subsection (d) allows that notification to be delayed in narrow circumstances, including to determine the scope of the breach or restore the system, but the default a practice should plan against is 45 days from discovery. That is 15 days tighter than the federal 60-day expectation, and Maryland provides no exemption for HIPAA-covered entities. Section 14-3504(k) says so directly: compliance with the state law "does not relieve a business from a duty to comply with any other requirements of federal law relating to the protection and privacy of personal information." The obligations run in parallel rather than one substituting for the other.

One subsection deserves its own attention, because it is the one that turns compliance into an IT question.

Section 14-3504(b)(1) requires a "reasonable and prompt investigation" into whether the information has been or will be misused. If that investigation concludes notification is not required, section 14-3504(b)(4) requires the practice to keep records reflecting that determination for three years.

Read that again from the practice’s side. Deciding not to notify is not the end of the matter, it is the beginning of a three-year retention duty, and the decision is only as defensible as the logs, access records and forensic detail sitting behind it. A practice with thin logging does not get an easier outcome here. It gets the same obligation with nothing to support it. Section 14-3504(j) closes the last door: a waiver of any provision "is contrary to public policy and is void and unenforceable."

What Maryland Publishes About Practices Like Yours

The Maryland Attorney General maintains a public listing of security breach notices, and it is unusually specific. Each entry carries the business name, the date, the number of residents affected, the specific categories of information involved, and a plain description of how it happened, with the filed notice letter attached.

Two dental filings show the rule operating at both ends of the scale.

In a notice dated July 17, 2024, counsel for a dental practice reported an incident "involving 1 Maryland resident," caused by what the letter calls malicious file encryption. The same letter states that the practice is based in Oregon. A single Maryland patient in an out-of-state practice’s records was enough to create a Maryland filing obligation, and the letter notes that the affected patients "will be forwarded letters shortly," confirming the state was told first.

A second notice, dated August 6, 2024, reported an incident affecting 12 Maryland residents at another dental practice. Its timeline is the useful part: systems were accessed on June 15, the investigation determined the scope on July 2, and the Attorney General was notified on August 6, with patient notice going out after that letter. Roughly seven weeks passed between the intrusion and the state filing, nearly all of it spent establishing what had actually happened.

That gap is where the real work sits. The statutory question is not difficult to understand, it is difficult to answer: which records were reachable, by whom, and when. Practices that can answer it quickly have logging that was already running and retained before anything went wrong. Practices that cannot spend the 45 days reconstructing rather than notifying. Determining scope is the part of an incident that consumes the calendar, and it is decided by decisions made long beforehand, which is what a cybersecurity assessment is meant to surface while there is still time to change the answer.

Dental IT Services for the Baltimore Market

The Baltimore-Columbia-Towson metro covers seven jurisdictions, including Baltimore City and Anne Arundel, Baltimore, Carroll, Harford, Howard and Queen Anne’s counties, and a practice near the edges of it routinely treats patients who live in another state entirely. Maryland’s zero-threshold rule means a handful of out-of-state patients does not simplify anything; it adds a second rulebook. Maryland runs slightly below the national rate on group-practice ownership, with a DSO affiliation rate of 13.6% of dentists against a national 16.1% in the ADA Health Policy Institute‘s 2024 practice-modalities data, so most Baltimore owners are making these calls without a corporate compliance department.

What this work covers for a Baltimore-area practice:

  • Evidence you can actually produce. Logging and retention set up so that scope questions, and the three-year record of a no-notification determination, can be answered from real data rather than recollection.
  • Incident response with the order written down. A response plan that names who files with the Attorney General, who drafts the patient letter, and in which sequence, because Maryland fixes that sequence by statute.
  • Backup and recovery built for encryption events specifically, with restores tested rather than assumed. Both dental filings above began with an attacker reaching systems, and recovery speed and forensic clarity are separate problems that need separate preparation. Backup and disaster recovery covers the first half.
  • Dental software expertise across Dentrix, Eaglesoft and Open Dental, including hosted Open Dental, plus the imaging systems attached to them.
  • Identity controls. Microsoft Research found that multifactor authentication reduces the risk of compromise by 99.22% across the entire population studied, and by 98.56% where credentials had already leaked. The cheapest Maryland filing is the one never triggered.
  • Reporting you can hand to an owner on uptime, MFA coverage, endpoint compliance and backup health, in numbers rather than reassurance.

We work with practices across the metro, including Towson, Columbia, Ellicott City, Glen Burnie, Annapolis, Bel Air, Westminster, Owings Mills, Catonsville, Dundalk, Severna Park, Pikesville, Hunt Valley and Aberdeen.

If you run several locations and want the operating model rather than a product list, the DSO tech playbook lays it out. If you would rather find out where your own practice stands, get in touch.

Baltimore Dental IT Support FAQs

Which areas around Baltimore does Medix Dental IT cover?

The full Baltimore-Columbia-Towson metro area: Baltimore City and Anne Arundel, Baltimore, Carroll, Harford, Howard and Queen Anne’s counties. That takes in Towson, Columbia, Ellicott City, Glen Burnie, Annapolis, Bel Air, Westminster, Owings Mills, Catonsville, Dundalk, Severna Park, Pikesville, Hunt Valley and Aberdeen, along with the surrounding communities in those counties.

Do we really have to tell the Maryland Attorney General before our own patients?

Yes, and that ordering is written into the statute. Commercial Law section 14-3504(h)(1) requires notice to the Office of the Attorney General "prior to" the notification given to affected individuals. There is no threshold attached, so it applies whether the incident touches one Maryland resident or thousands. The state’s own published listing includes a dental filing made over a single resident. Practices that instinctively call patients first are being responsive in a way the statute does not permit.

We are HIPAA compliant. Does Maryland law still apply to us?

It does. Maryland’s breach statute contains no HIPAA safe harbor, which sets it apart from the jurisdictions around it. The District of Columbia deems a HIPAA-compliant entity to have satisfied its resident-notice duty, and Pennsylvania, Delaware and Virginia each carry some form of exemption for entities complying with the federal rules. Maryland’s section has no equivalent provision anywhere in its text. Section 14-3504(k) states that compliance with the section "does not relieve a business from a duty to comply with any other requirements of federal law relating to the protection and privacy of personal information," so the two sets of obligations run alongside each other. The practical consequence is the calendar: Maryland requires individual notice no later than 45 days after discovery, where the federal expectation is 60. Planning around the federal deadline leaves you roughly two weeks late in Maryland.

If we decide an incident does not require notifying patients, is that the end of it?

No, and this is the subsection most often missed. Section 14-3504(b)(1) requires a reasonable and prompt investigation into the likelihood that personal information has been or will be misused. If that investigation concludes notice is not required, section 14-3504(b)(4) requires the business to keep records reflecting the determination for three years. In practice that means a decision not to notify has to be evidenced, and the evidence is technical: access logs, system records, and the forensic findings behind the conclusion. A practice without that data has a judgment call rather than a record.

Do you support Baltimore DSOs and multi-location practices?

Yes. Multiple locations make the Maryland sequencing harder rather than easier, because one incident can span offices, systems and state lines while a single 45-day clock runs across all of it. We standardize identity, logging, backup and monitoring so the scope question can be answered once for the whole group instead of office by office, and so the person responsible for filing knows it is theirs before anything happens. That is the difference between a group that has scaled and a group that has simply repeated itself in more buildings.

Posted in Service Areas

Filter By: