Dental IT support dashboard on dual monitors in a Detroit dental practice with the Detroit skyline and Renaissance Center visible through the window

Michigan lets a dental practice decide for itself whether a breach requires telling anyone. That is not a loophole. It is the plain text of the statute, and it puts a judgment call with real legal consequences in the hands of the person least equipped to make it at the worst possible moment.

Dental IT support in Detroit has to account for a state law that works differently from the ones in the compliance guides. Michigan’s breach statute has no attorney general filing, no state agency that reviews your decision, and no deadline expressed in days. What it has instead is a standard of care, applied to a decision you make internally, and reviewed only if someone later decides to challenge it.

We have worked in dentistry and nothing else for over 20 years, from single offices up to multi-location DSOs. That focus matters here, because the Michigan question is not what the deadline is. It is whether you can defend the call you made.

In Michigan, the Attorney General Is Not Who You Notify

Read MCL 445.72 and the structure is unusual in two ways.

First, the notice duty in subsection (1) is conditional on your own assessment. You must notify affected residents “unless the person or agency determines that the security breach has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to” a Michigan resident. If you conclude it is not likely, no notice is required. Subsection (3) then sets the standard for that conclusion: you must “act with the care an ordinarily prudent person or agency in like position would exercise under similar circumstances.”

Second, there is no state agency on the receiving end. Michigan requires no attorney general notification at any threshold. The attorney general appears in the statute exactly once, in subsection (13), and not as a recipient: the attorney general “or a prosecuting attorney” may bring an action to recover a civil fine of up to $250 for each failure to notify, capped at $750,000 per breach under subsection (14). So the state never reviews your determination in advance. It evaluates it afterward, as an opponent, if it evaluates it at all.

The HIPAA provision follows the same shape. Subsection (10) deems you compliant if you are “subject to and complies with” HIPAA and the regulations at 45 CFR parts 160 and 164. That is a conditional safe harbor, not an exemption for being a dental practice, and it turns on whether you actually met the federal standard.

Side by side, the two regimes ask different things of a dental practice:

Michigan (MCL 445.72) HIPAA Breach Notification Rule
Who decides if notice is owed The practice, under subsection (1) The practice, via a four-factor risk assessment
Who receives a report Affected residents only. No state agency at any threshold Affected individuals and HHS
Deadline No fixed number of days. “Without unreasonable delay” 60 days for individuals; 60 days for HHS above 500
Standard applied Ordinarily prudent person in like position, subsection (3) Low probability of compromise, documented
If you get it wrong Up to $250 per failure, capped at $750,000 per breach, in an action brought by the attorney general or a prosecuting attorney OCR enforcement and civil monetary penalties

The practical consequence is specific. If that determination is ever questioned, what exists is whatever your IT provider logged at the time. An ordinarily prudent judgment about whether patient data was accessed requires knowing what was accessed, and that is a technical question answered by evidence, not by recollection.

A Michigan Breach You Can Only Read About in Washington

Great Expressions Dental Centers is headquartered in Southfield, in Oakland County, and its own location finder lists metro offices in Detroit, Dearborn, Livonia, Westland, Canton, Southfield, Troy, Novi, Farmington Hills, Warren, Sterling Heights, Clinton Township and Roseville, among others. In 2023 it disclosed a data breach affecting more than 1.9 million people.

Here is the part worth noticing. The most precise public account of what happened to a Southfield company is a notice filed with the Washington Attorney General, which records the intrusion as ransomware with unauthorized access between February 17 and February 22, 2023 and the company aware of it on February 22. Washington required that filing. Michigan required nothing, so Michigan has no equivalent record of it.

That is the self-regulating structure made visible. A Michigan practice’s account of its own incident exists only where some other state compelled it, or in litigation. In this case both: the Eastern District of Michigan case settled for $2.7 million, with the final approval hearing held on December 12, 2024.

Six days of access, at an organization with a corporate compliance function. A single-location practice making the subsection (1) call carries the same obligation with considerably less to work with, and what makes that call possible is having logs, retained and reviewable, from before the incident. A cybersecurity assessment is largely an inventory of whether that evidence would exist.

Dental IT Services for the Detroit Metro

Michigan runs slightly below the national rate of DSO affiliation. ADA Health Policy Institute data for 2024 puts Michigan at 14.8% of dentists affiliated with a DSO against 16.1% nationally, so the subsection (1) judgment usually lands on an owner rather than a compliance department. Great Expressions is headquartered here; Aspen Dental, run from outside Michigan, operates offices in Livonia, Canton, Taylor, Allen Park, Novi, Royal Oak, Lake Orion, Roseville, Sterling Heights and Chesterfield.

What Medix delivers across the metro:

  • Enterprise-grade cybersecurity. Managed detection and response, identity governance, and tenant monitoring across Microsoft 365 and Google Workspace. Prevention still does most of the work here: Microsoft Research measures multifactor authentication at 99.22% risk reduction against account compromise, and the incident you prevent needs no determination at all.
  • Logging and evidence retention. MCL 445.72(1) asks a practice to determine whether an incident was likely to cause substantial loss. We are not your lawyers and that call belongs with counsel, but the records it rests on are an IT question, and they either exist before the incident or they do not.
  • Backup and disaster recovery built so a ransomware event is a restore rather than a negotiation. As Tom Terronez puts it, untested backups are not backups, and verified recovery is the difference between a bad week and a closed practice.
  • Dental software expertise across Dentrix, Eaglesoft and Open Dental, including Open Dental cloud hosting.
  • IT KPI reporting on uptime, MFA adoption, endpoint compliance and backup health, so the answer to “are we covered” is a dashboard rather than an opinion.

Most IT providers can tell you whether the server is up. Fewer can tell you, six weeks after the fact, which accounts touched a particular file and when. Under a statute that asks you to make a defensible determination about exactly that, the second capability is the one with legal weight, and it is not something you can add after an incident starts.

Our DSO technology playbook covers how we standardize multi-location environments. If you would rather start with your own setup, reach out and we will go through what your current provider is actually retaining.

Detroit Dental IT Support FAQs

What areas around Detroit does Medix Dental IT support?

We support dental practices throughout the Detroit-Warren-Dearborn metro, including Wayne, Oakland, Macomb and Livingston counties. That covers Detroit, Southfield, Troy, Livonia, Dearborn, Warren, Sterling Heights, Novi, Farmington Hills, Rochester Hills, Clinton Township, Canton, Royal Oak and Birmingham, with remote support and coordinated onsite work.

Does Michigan require us to notify the attorney general after a breach?

No. MCL 445.72 contains no attorney general notification requirement at any threshold, which is unusual. The attorney general appears in the statute only in subsection (13), where the attorney general or a county prosecuting attorney may bring an action to recover civil fines of up to $250 for each failure to provide a required notice, with aggregate liability for a single breach capped at $750,000. Separately, subsection (8) requires notice to the nationwide consumer reporting agencies above 1,000 Michigan residents, but that is not a government agency filing.

We follow HIPAA. Does that cover us under Michigan law?

Conditionally. MCL 445.72(10) says an entity that is “subject to and complies with” HIPAA and the regulations at 45 CFR parts 160 and 164 is considered to be in compliance with the section. On its face the safe harbor turns on actual compliance rather than on simply being a dental practice, which is why a current risk analysis and documented breach-assessment procedures matter. Whether it applies to a given incident is a question for your attorney.

Can we decide on our own that a breach does not require notification?

Under MCL 445.72(1), no notice is required if you determine the breach is not likely to cause substantial loss or injury or result in identity theft, but that determination is only valid if it meets subsection (3)’s standard of care. In other words the statute permits the conclusion and simultaneously sets a bar for reaching it. Subsection (3) requires you to make that determination with the care an ordinarily prudent person in a similar position would use. How that standard applies to a specific incident is a question for your attorney. What we can tell you is that the technical records available at the time are what any such review would draw on, and those are created long before anyone needs them.

Do you support Detroit DSOs and multi-location dental groups?

Yes, and group practices raise a specific Michigan problem. A breach that crosses several offices still produces one determination under MCL 445.72(1), which means the evidence has to be consistent across every site. Where each location was set up by a different vendor at a different time, assembling that picture is the hard part. We standardize systems, identity and security across locations so the answer comes from one environment.

Which practice management systems do you work with in Michigan?

Dentrix, Eaglesoft and Open Dental, plus the imaging and integration systems around them, including Open Dental cloud hosting for practices retiring aging on-premise servers. The logging and audit capability differs meaningfully between these platforms and how they are configured, which is worth knowing before you need it.

Posted in Service Areas

Filter By: