Dental IT support dashboard on dual monitors in a Denver dental office overlooking the skyline and Front Range

On December 30, 2021, a wind gauge in Arvada recorded a 115 mph gust at 12:06 in the afternoon. By the end of that day the Marshall Fire had destroyed 1,084 homes, and roughly 37,500 people had been evacuated in three to four hours.

Dental IT support in Denver has to account for a state law that works differently from the one most practice owners think they are under. Colorado gives you 30 days to notify patients after a breach, not the 60 that HIPAA allows. The part almost nobody is told is when that clock starts. Colorado does not start it for you. You start it, and you start it by producing evidence.

We have worked in dentistry and nothing else for more than 20 years, from solo practices to multi-location dental service organizations. Colorado’s rule turns out to be less a legal problem than an infrastructure one, decided by what your systems were recording long before anything went wrong.

In Colorado, You Start Your Own Clock

Most breach-notification statutes start counting at discovery. Colorado counts from something it defines much more precisely.

C.R.S. § 6-1-716(1)(c) defines a determination that a security breach occurred as “the point in time at which there is sufficient evidence to conclude that a security breach has taken place.” Both deadlines in the statute run from that moment. Patients get notice within 30 days of determination under subsection (2)(a), and if 500 or more Colorado residents are affected, the Attorney General gets notice within 30 days of the same moment under subsection (2)(f).

HIPAA’s 60-day clock runs from discovery of the breach. Colorado’s 30-day clock runs from sufficient evidence. Those are not the same event, and the shorter deadline is the one with the later start. A practice can be well inside the federal window and have a Colorado problem, or the reverse, depending entirely on how quickly it could establish what actually happened.

There is an uncomfortable version of this. If nobody is retaining audit logs, there is no sufficient evidence, so arguably there is no determination and no clock. Read as protection, that gets the risk backwards. The question a regulator asks later is not what you knew, it is when you had enough to conclude something. A practice that could have answered in week one with mailbox audit logging and did not answer for five months is in a much worse position than one that determined quickly and notified on time. Whether that exposure amounts to a violation is a question for your attorney, not for us. What we can tell you is that the evidence either exists before the incident or it does not.

There is a second Colorado rule worth knowing, because it removes the escape most practices assume they have. Subsection (3)(b) says a covered entity following its federal regulator’s breach procedures is in compliance with the state statute. Read to the end of that subsection, though: “In the case of a conflict between the time period for notice to individuals that is required pursuant to this subsection (3) and the applicable state or federal law or regulation, the law or regulation with the shortest time frame for notice to the individual controls.” Following HIPAA correctly does not buy you 60 days in Colorado. It leaves you with 30.

Question the statute asks What answers it
When did you have sufficient evidence? Audit logs, and how far back they go
Whose records were involved? A review of what the compromised account could reach
Did 500 or more Coloradans get affected? The same review, which sets whether the AG is notified
Which 30-day deadline applied? The date of determination, which you established

Colorado Publishes Almost Nothing, With One Exception

Some states put breach filings on a public website. Washington publishes the filed notice. Massachusetts publishes an annual report. Colorado does neither, and the exception it does carve out lands in an awkward place.

The Attorney General’s office states that a submitted breach form and uploaded consumer notices “may be subject to disclosure under the Colorado Open Records Act”, meaning members of the public can file an open-records request for a copy. The office then names which fields those are: contact information, the fields indicating the type of affected personal information, and “the dates the breach began and ended.” Everything else, it says, is withheld under the Attorney General’s discretion to keep investigative records confidential.

Read that list against the section above. The parts of your filing a stranger can request are the categories of data exposed and your dates. The dates are the thing a practice without logging cannot establish confidently in the first place, and they are the specific field Colorado has decided the public may see.

Every one of those disclosable fields is produced by logging you either kept or did not. That makes the determination date an infrastructure question, and it is the one a cybersecurity assessment is built to answer: not whether the practice owns security tools, but whether the record of who touched what still exists far enough back to matter. Retention that stops at 30 or 90 days cannot describe an intrusion that began in the spring. Enforced multifactor authentication is the cheaper end of the same problem, since Microsoft’s research found it reduces the risk of account compromise by 99.22% across the population studied.

The Marshall Fire poses the same question from the other direction. The National Weather Service in Boulder logged that 115 mph gust in Arvada and a 110 mph gust where Highway 93 meets Highway 72, and Boulder County’s after-action report puts the loss at two lives, 1,084 homes and 7 commercial structures. The property question is the smaller one and worth stating plainly anyway: if a practice’s only copy of its records sat on a server inside one of those buildings, the records that would answer Colorado’s question did not survive either.

Dental IT Services for the Denver Market

Colorado is one of the two most DSO-affiliated states in the country. ADA Health Policy Institute data for 2024 puts Colorado and Nevada level at roughly 27%, against a national rate of 16.1%. The metro is also unusually local about it: Espire Dental lists 11 offices inside the metro, Perfect Teeth lists 12, and Comfort Dental, whose partner development center is on Kipling Street in Lakewood, lists around 50 across the same counties. More than a quarter of Colorado dentists answer to somebody, and the determination question gets harder when it has to be answered once for a group.

  • Evidence retention built for the question you will be asked. Audit logging on mailboxes and file stores, kept long enough to outlive an intrusion that began months before anyone noticed, so a determination date is defensible rather than estimated.
  • Threat detection that shortens the gap. Managed detection and response plus identity governance, aimed at the interval between when something starts and when you can prove what it touched.
  • Recovery sized to losing a building, not a hard drive. Offsite copies and a restore that has been timed, rather than a backup nobody has run in anger. See backup and disaster recovery.
  • Practice software supported by people who only do dentistry, covering Dentrix, Eaglesoft, and Open Dental, including cloud-hosted Open Dental.
  • Reporting a corporate parent will ask for. Uptime, multifactor coverage, endpoint compliance, and verified backup health, per location.

We support practices across the Denver-Aurora-Centennial metro, including Aurora, Lakewood, Thornton, Arvada, Westminster, Centennial, Broomfield, Commerce City, Parker, Littleton, Brighton, Northglenn, Englewood, Wheat Ridge, Golden, and Lone Tree.

Across a group, a uniform logging standard beats a better tool at one office, because the determination has to hold for the whole organization and an acquired practice running its own retention policy sets the weakest date. Our DSO tech playbook covers building that baseline, and you can get in touch if you would like us to look at what your systems currently keep.

Denver Dental IT Support FAQs

We follow HIPAA. Do we still have 60 days in Colorado?

As we read the statute, no. C.R.S. § 6-1-716(3)(b) says following your federal regulator’s procedures puts you in compliance, but the same subsection ends by saying that where the time periods conflict, the law with the shortest time frame for notice to the individual controls. Colorado’s is 30 days. How that applies to your practice is a question for your attorney, but planning around 60 days is planning around the wrong number.

When does the 30-day clock actually start?

At determination, which § 6-1-716(1)(c) defines as the point when there is sufficient evidence to conclude a breach took place. That is a different event from discovery, which is what HIPAA’s 60-day clock runs from. In practice the date is set by what your systems recorded, so two practices discovering the same incident on the same day can have different determination dates.

Does Colorado publish our breach filing like some states do?

Not as a published list or a posted notice letter. The Attorney General’s office says a submitted form and uploaded consumer notices may be subject to disclosure under the Colorado Open Records Act, so the public can request them. It identifies the disclosable fields as contact information, the type of affected personal information, and the dates the breach began and ended, with other fields withheld.

When do we have to notify the Colorado Attorney General?

Under § 6-1-716(2)(f), within 30 days of determination when the breach is reasonably believed to have affected 500 or more Colorado residents. Above 1,000 residents, subsection (2)(d) also requires notifying the nationwide consumer reporting agencies. As we read subsection (3), the attorney general obligation survives the federal-procedures provision, since the subsection carves it out by name.

Do you support Denver DSOs and multi-location dental groups?

Yes, multi-location groups are most of what we do, and Colorado is among the most DSO-affiliated states in the ADA’s 2024 data at roughly 27%. For a group the practical goal is one logging and backup standard across every address, so an incident at one office does not become a separate investigation at each of them.

What dental software does your Denver team support?

The major practice management platforms, Dentrix, Eaglesoft and Open Dental, along with cloud-hosted Open Dental and the imaging systems that feed them. Because dentistry is the only vertical we serve, we also know which of these retain usable audit trails and which need help to produce one.

Posted in Service Areas

Filter By: