Dental IT support in Des Moines, Iowa

Medix Dental IT has been based in Iowa since 2003. Des Moines is not a market we expanded into from a coast, it is the metro down the road, and we have spent two decades supporting practices here.

Dental IT support in Des Moines has to account for something most practice owners are told backwards: Iowa’s breach notification statute does not add a second deadline on top of HIPAA for a dental practice, but that exemption is conditional, and losing it is easier than it sounds. That single detail changes how a practice here should handle compliance, documentation, and incident response.

We have worked exclusively in dental for more than 20 years, supporting single offices through multi-location DSOs. Here is what running dental IT in the Des Moines metro actually requires.

The Iowa Exemption Most Practices Misread

Search “Iowa breach notification law” and you will find a five-business-day deadline to notify the Attorney General. That rule is real, but for a dental practice it is usually not the one that applies.

Iowa Code § 715C.2(7)(d) states that the chapter does not apply to a person “who is subject to and complies with” the HIPAA and HITECH breach regulations. A dental practice that is genuinely compliant answers to HIPAA’s 60-day clock, not to a separate Iowa timeline.

The trap is in the words “and complies with.” The exemption is not automatic because you are a covered entity. It depends on actually meeting the federal requirements. A practice that cannot produce a current risk analysis, documented policies, or evidence of its breach-assessment process does not get to lean on the exemption, and it lands back under Chapter 715C, where § 715C.2(9) makes a violation an unlawful practice under Iowa’s consumer fraud statute.

There is a related documentation duty worth knowing. Under § 715C.2(6), if you determine a breach carries no reasonable likelihood of financial harm and skip notification, that determination has to be in writing and kept for five years. Most practices we assess have never written one down.

The Breach That Started at a Billing Vendor

In January 2025, a filing with the Iowa Attorney General notified roughly 2,382 Iowa residents of a breach at Medusind, a dental and medical billing company. The exhibit listed one organization: Aspen Dental. Nationwide the incident affected more than 360,000 people.

Two details matter for any practice in this metro. First, the breach did not happen at a dental office. It happened at a vendor that dental offices hand patient data to every single day. Second, Medusind identified the activity on December 29, 2023, and patient notices went out in January 2025, more than a year later.

Your business associates are part of your attack surface whether or not you have ever audited them. A signed BAA is a contract, not a control. A vendor risk register belongs in every practice’s compliance file, because the question is not only whether your network is secure, it is who else is holding your patient data and what happens when they are the ones who get hit.

Central Iowa Weather Is a Continuity Problem

On March 5, 2022, an EF4 tornado tracked through Madison County and destroyed much of Winterset, killing six people. The same outbreak produced a tornado at Pleasant Hill, inside the metro. Two years earlier, the August 10, 2020 derecho pushed 85 mph winds through Urbandale and knocked out power to roughly 101,000 MidAmerican customers in the Des Moines area.

A server in the back room of a Waukee or Ankeny office does not survive a direct hit, and it does not run without power either. Untested backups are not backups. The practices that reopen fastest are the ones running cloud-hosted data with a documented and tested recovery plan.

Our assessments start with a blunt question: if your building were gone tomorrow, could you still see patients on Monday? In central Iowa that is not hypothetical.

Dental IT Services for Des Moines Practices and Groups

The metro’s growth is concentrated in the western and northern suburbs. Waukee grew to 31,823 residents in its 2024 Special Census, up about a third since 2020, and Ankeny reached 76,207, now Iowa’s fifth-largest city. Group practices are opening where the rooftops are, and every new location adds identity, security, and standardization work a break-fix contract cannot carry. Iowa remains a largely independent market, with 7.9% of dentists DSO-affiliated in 2024 against 16.1% nationally per ADA Health Policy Institute data, which means most owners here are making these decisions without a corporate IT department behind them.

What we provide, framed for the Des Moines operating reality:

  • Enterprise-grade cybersecurity. Managed detection and response, identity governance, and tenant-level monitoring inside Microsoft 365 or Google Workspace. Antivirus is not a cybersecurity program.
  • Backup and disaster recovery built for tornado and derecho country, tested rather than assumed. See our take on dental data backup.
  • Dental software expertise across Dentrix, Eaglesoft, and Open Dental, including cloud deployments that scale across locations.
  • Vendor and BAA risk management so a billing or imaging partner is not an unmonitored hole in your compliance posture.
  • IT KPI reporting on uptime, MFA adoption, endpoint compliance, and backup health. If your IT partner cannot show you a dashboard, they are not managing anything.

We support practices across the metro, including West Des Moines, Ankeny, Urbandale, Clive, Waukee, Johnston, Altoona, Norwalk, Grimes, Pleasant Hill, Windsor Heights, and Indianola.

Multi-factor authentication reduces the risk of account compromise by 99.22%, and a meaningful share of the practices we assess still treat it as optional. That is not a technology gap, it is a leadership gap.

Lifecycle planning belongs in the same conversation. A workstation stretched to year eight does not fail on a convenient Tuesday, it fails during a full hygiene schedule and turns into an emergency purchase at full price. Planned replacement on a five-year cycle is boring, and boring is cheaper than chaos.

If you are scaling a group and want to standardize IT across locations, we publish DSO technology playbooks and are happy to compare notes.

Des Moines Dental IT Support FAQs

What areas around Des Moines does Medix Dental IT support?

We support dental practices across the Des Moines metro, including Des Moines, West Des Moines, Ankeny, Urbandale, Clive, Waukee, Johnston, Altoona, Norwalk, Grimes, Pleasant Hill, Windsor Heights, and Indianola. Medix is based in Iowa, so central Iowa practices get a mix of remote response and on-site visits when hardware needs hands on it.

How does Iowa breach notification law differ from HIPAA?

For most dental practices it does not add a separate deadline. Iowa Code § 715C.2(7)(d) exempts an entity that is subject to and complies with the HIPAA and HITECH breach rules, which leaves HIPAA’s 60-day notification clock as the operative one. The exemption depends on actual compliance, though. A practice that cannot demonstrate it meets the federal requirements falls back under Chapter 715C, which requires written notice to the Iowa Attorney General within five business days of notifying consumers when more than 500 Iowa residents are affected.

Why does a vendor breach matter if our own network is secure?

Because your patient data does not stay on your network. Billing companies, imaging vendors, and claims processors all hold it. The Medusind incident notified about 2,382 Iowa residents through a billing vendor, not through a dental office, and more than a year passed between the vendor detecting activity and patients being told. Auditing who holds your data, and what their security actually looks like, is part of protecting it.

Do you support Des Moines DSOs and multi-location dental groups?

Yes. Multi-location groups are where dental-specific IT matters most, because every new office multiplies the identity, security, and standardization work. We build one security baseline and unified governance across locations rather than managing each office as its own island, and we report IT KPIs at the group level.

How often should a Des Moines practice replace workstations?

Plan on a five-year refresh cycle, with seven years as the outer limit. Most practices we assess are running at least one machine well past that, usually on an unsupported operating system with an expired warranty. The cost of stretching it is not the hardware, it is the emergency replacement at full price plus the production lost while a schedule sits idle. A funded lifecycle plan turns an unpredictable surprise into a line item.

What dental software does your Des Moines team support?

We support the platforms Des Moines practices run, including Dentrix, Eaglesoft, and Open Dental, along with the imaging systems that move large files across the practice network. For groups consolidating onto a cloud platform, we handle Open Dental cloud deployments that scale across multiple locations.

Posted in Service Areas

Filter By: