August 12th, 2026
Dental IT Support in Boston, MA (Practices & DSOs)
Industry Research — Service Areas
In May 2024, a Newton dental practice mailed a breach notice to just over a thousand Massachusetts residents. The intrusion had ended eleven months earlier.
Dental IT support in Boston runs into a Massachusetts rule that almost no practice owner knows about until the worst week of their year. When you report a breach here, the notice you send the Attorney General has to state whether your practice maintains a written information security program. Massachusetts has required you to have one since 2010. The state is not asking what happened. It is asking you to certify, in writing, whether you were already following a different regulation entirely.
Medix Dental IT has spent more than 20 years working exclusively in dentistry, supporting single offices through multi-location dental service organizations. That matters here because the Massachusetts question is not really a legal one. It is a question about what your IT provider has been doing for the last several years.
Massachusetts Asks You to Grade Your Own Security Program
Many states with a breach-notification law give HIPAA-covered practices some form of pass. Massachusetts does something different, and the difference matters.
M.G.L. c. 93H § 5 does deem you compliant if you follow federal breach procedures, but read the sentence to the end. That deemed compliance applies only if you also notify the Attorney General and the director of the Office of Consumer Affairs and Business Regulation, and the section closes by stating that if you do not actually comply with the applicable federal rules, you are subject to the state chapter after all. There is no resident threshold anywhere in it. Two Massachusetts patients or two thousand, the filing is owed.
Then comes the part that catches people. Section 3(b) lists nine things that notice must contain, and item eight is whether the practice maintains a written information security program. Separately, 201 CMR 17.03 requires every business holding personal information about a Massachusetts resident to develop, implement, and maintain exactly such a program, and lists ten required elements, including oversight of third-party service providers, regular monitoring, annual review of scope, and documented post-incident review. 201 CMR 17.04 adds the technical layer: secure authentication, access control, encryption on portable devices, current patching, monitoring, and employee training.
So the form asks a yes-or-no question about a rule that has been binding on your practice for over a decade and that the breach did not create. Answering no is a disclosure you would rather not make. Answering yes invites the follow-up question of whether the program actually met those two sections. We are not your lawyers, and how to answer is a conversation for your attorney. What we can tell you is that the honest answer is determined years before the breach, by whether anyone was maintaining the thing being asked about.
Massachusetts does not publish that answer. The annual breach report from the Office of Consumer Affairs lists the organization, the date, how many residents were affected and which categories of data were exposed, and the security-program disclosure is not among those columns. You answer it to a regulator rather than to the public, which is why so few practices learn it exists until they are answering it.
Five of the nine items § 3(b) requires, and where each answer actually originates:
| What the notice must state | Where the answer actually comes from |
|---|---|
| The nature of the breach | Forensic investigation, after the fact |
| How many Massachusetts residents were affected | A review of what was in the compromised system |
| The type of personal information compromised | The same review, which is the slow part |
| Whether you maintain a written information security program | Work done years earlier, or not done |
| Steps taken, including updating that program | Documentation kept before the incident |
Eleven Months to Answer One Question
The Newton case shows how long that middle column can take. Newton Centre Dental sent notices to affected residents on May 24, 2024, and the practice’s own notice letter lays out the timeline plainly.
According to that letter, an unauthorized person had access to a Newton Centre Dental email account between May 27 and June 21, 2023, and Affinity Dental Management, which provides the practice administrative services, was the party that became aware of suspicious activity concerning the account. The practice states it then undertook what it describes as a comprehensive and time-intensive review of every email and file in the mailbox, and that on April 29, 2024 it confirmed which individuals’ information was present.
Read the letter’s dates together. Access ended in June 2023, and the determination of whose information was involved came in late April 2024.
A long review is not proof that anyone did anything wrong, and a mailbox compromise is one of the harder cases to scope. That is the point worth taking from it. The gap was not a legal failure, it was an evidence problem, because the practice could not quickly say what had been in that account or whose records those were. Notice too that, according to the letter, detection came from the administrative services company rather than from inside the practice. Under 201 CMR 17.03 that vendor relationship is itself part of the program, since the regulation requires overseeing service providers by taking reasonable steps to select and retain ones capable of maintaining appropriate security measures, and by requiring those safeguards in the contract.
The question a cybersecurity assessment asks is not whether you own security tools. It is whether, six weeks after an incident, anyone can reconstruct which accounts touched which files and when. Mailbox-level audit logging, retention long enough to cover a months-old intrusion, and enforced multifactor authentication are what turn an eleven-month review into a shorter one. Microsoft’s research found that multifactor authentication reduces the risk of account compromise by 99.22% across the population studied, and 201 CMR 17.04 is one of the few state regulations naming secure authentication as a requirement rather than a suggestion.
Dental IT Services for the Boston Market
Boston has significant group practices headquartered in Massachusetts rather than out of state. 42 North Dental operates from Waltham across the metro and well beyond it under the Gentle Dental brand, and Affinity Dental Management runs from Holyoke. At the same time, ADA Health Policy Institute data puts Massachusetts DSO affiliation at 14.9% against a national rate of 16.1%. Most practices here remain independently owned, so most owners face 201 CMR 17.00 without a corporate compliance department deciding it for them. What we handle across the metro:
- Enterprise-grade cybersecurity. Managed detection and response, identity governance, and tenant-level monitoring in Microsoft 365 or Google Workspace. Mailbox compromise is the vector in this metro’s most instructive dental case, and identity is where that fight is won.
- Written information security program support. 201 CMR 17.03 names ten elements and 17.04 names eight technical controls. We map what you actually have against that list, so the answer to the question on the state’s form is a document rather than a guess.
- Backup and disaster recovery. Tested recovery with a measured restore time, because untested backups are not backups.
- Dental software expertise across Dentrix, Eaglesoft, and Open Dental, including cloud-hosted Open Dental.
- IT KPI reporting on uptime, multifactor adoption, endpoint compliance, and backup health, so posture is something you can show rather than something you assert.
We support practices throughout the Boston-Cambridge-Newton metro, including Cambridge, Newton, Somerville, Waltham, Framingham, Woburn, Malden, Medford, Quincy, Brookline, Needham, Dedham, Braintree, and up through Lynn, Peabody, and Salem, along with the southern New Hampshire communities in Rockingham and Strafford counties that fall inside the same metro area.
If you run more than one location, the version of this that scales is one security baseline and one documented program across every address, not a different setup at each. Our DSO tech playbook covers how that gets built, and you can get in touch if you want someone to walk your current environment.
Boston Dental IT Support FAQs
We follow HIPAA. Is that enough in Massachusetts?
Probably not on its own, though how these apply to your practice is a question for your attorney rather than for us. As we read it, M.G.L. c. 93H § 5 deems you compliant only if you also notify the Attorney General and the Office of Consumer Affairs, and 201 CMR 17.00 imposes a written information security program requirement that reads as independent of HIPAA and applies to any business holding personal information about a Massachusetts resident. The practical version is that a practice can run a clean federal process and still have a state obligation nobody has looked at.
What is a WISP, and does my dental practice actually need one?
A written information security program is a documented set of administrative, technical, and physical safeguards, and under 201 CMR 17.03 it is required. The regulation lists ten elements it must contain, including designating someone to maintain it, assessing foreseeable risks, overseeing third-party service providers, regular monitoring, reviewing scope at least annually, and documenting post-incident review.
Does Massachusetts publish whether my practice had a security program?
No. The Office of Consumer Affairs publishes an annual breach report listing the organization, date reported, number of residents affected, and which categories of data were exposed. The security-program disclosure required by § 3(b) goes to regulators and is not among those published columns. It is still a written statement to the Attorney General.
How long do I have to report a breach in Massachusetts?
The statute says as soon as practicable and without unreasonable delay rather than setting a fixed day count, and notice is owed to the Attorney General, the Office of Consumer Affairs, and affected residents with no minimum number of residents. Notice also cannot be delayed on the grounds that the total number affected is not yet known. If Social Security numbers were involved, § 3A requires offering at least 18 months of free credit monitoring.
Do you support Boston DSOs and multi-location dental groups?
Yes, multi-location groups are most of what we do. For a group the practical goal is one documented security program and one backup standard covering every location, so an incident at one office does not become a discovery exercise across all of them.
What dental software does your Boston team support?
Dentrix, Eaglesoft, and Open Dental, including cloud-hosted Open Dental, plus the imaging and practice systems alongside them. We work in dentistry only, so the software conversation does not start from scratch.
Posted in Service Areas