Dental office IT dashboard on dual monitors with the Philadelphia skyline in the window behind

When 360 Dental PC in Philadelphia found its server encrypted on November 16, 2025, the 11,273 people in those files were the practice’s problem. Where those people lived was a second problem, and a less obvious one.

Dental IT support in Philadelphia has to account for something dental IT support in most cities does not. This metro spans eleven counties across four states, and a practice that runs a textbook HIPAA breach response can violate New Jersey law by doing it well. Not by being slow or sloppy. By promptly notifying a patient, which is exactly what the federal process tells you to do.

Medix Dental IT has spent more than 20 years working exclusively in dentistry, supporting single offices through multi-location DSOs. That focus is why we read state breach statutes at all. Most IT providers never do, and their dental clients find out what the rules were after they have already broken them.

Why Following HIPAA Correctly Can Break New Jersey’s Law

Start with Pennsylvania, because that is the one most practices here assume covers them.

Act 151 of 2022 rewrote Pennsylvania’s Breach of Personal Information Notification Act and added Section 5.3. It says that a covered entity or business associate “subject to and in compliance with” the HIPAA privacy and security standards, along with HITECH, “shall be deemed to be in compliance with the provisions of this act.” For a Pennsylvania dental practice genuinely running a HIPAA program, the federal process satisfies the state one. There is no separate Pennsylvania clock to miss.

Read the condition again, though. Not subject to HIPAA. Subject to and in compliance with HIPAA. Every dental practice in Philadelphia is subject to it. Compliance is the part you have to evidence, and a practice with no current risk analysis and no documented breach-assessment process has not earned that treatment. It just has not been asked to prove it yet.

Now cross the Delaware River. New Jersey’s breach statute, N.J.S.A. 56:8-163, never mentions HIPAA or federal regulators at all. It does contain a deemed-compliance clause at subsection (e), but that one covers a business following its own internal notification policy, which is not the same thing. New Jersey grants dental practices no federal safe harbor.

What it does require is in subsection (c)(1). A business must, “in advance of the disclosure to the customer,” report the breach to the Division of State Police in the Department of Law and Public Safety. In advance. There is no minimum number of affected residents that triggers this. One New Jersey patient in the affected file set is enough.

Delaware runs a third way. 6 Del. C. § 12B-103(b) names HIPAA expressly, by public law number, and sends a regulated entity back to its federal procedures. But § 12B-102(d) adds that above 500 affected Delaware residents, the Attorney General must be notified no later than the residents are.

Here is the part that should bother you. The practice with the best federal process is the one most likely to get New Jersey wrong. A well-drilled HIPAA workflow notifies patients promptly, and doing exactly that for a single Camden or Cherry Hill patient inverts the order New Jersey requires. Competence at the federal level is what walks you into the state-level mistake.

What the November 2025 Ransomware Case Actually Shows

Back to that November incident. It was reported to the Department of Health and Human Services on January 15, 2026. The exposed data included names, dates of birth, chart numbers, clinical records, treatment history, x-rays, insurance member IDs, and for a limited number of people, Social Security numbers.

In its public notice, the practice said it had strengthened its systems by replacing affected computers, rebuilding the server, updating all software, and implementing additional firewalls, antivirus protection, multi-factor authentication, and VPN-only access.

Read that as a shopping list and it is unremarkable. Read it as a sequence and it tells you what was not in place on November 15. Multi-factor authentication and VPN-restricted remote access are not incident response. They are controls that belong in a practice beforehand, and they get bought at emergency speed afterward at a considerably worse price.

Antivirus is not a cybersecurity program. The gap in most dental practices is not the perimeter, it is the Microsoft 365 tenant nobody is watching, the former employee whose account still authenticates, and the shared login six people use because it is easier.

The honest question a cybersecurity assessment asks is not whether you own security tools. It is whether anyone reviewed a sign-in log last month, and whether you could produce the risk analysis that Pennsylvania’s Section 5.3 quietly assumes you have.

Dental IT Services Across the Philadelphia Market

The four-state structure is not a technicality here, it is how groups actually operate. Dental Solutions runs eleven offices across Pennsylvania and New Jersey, eight on the Pennsylvania side including three in Philadelphia proper, and three in Blackwood, Deptford, and Voorhees. A group like that does not have a New Jersey patient problem and a Pennsylvania patient problem. It has one patient database that crosses a state line, so both statutes apply to a single incident.

Pennsylvania is 14.2% DSO-affiliated according to ADA Health Policy Institute 2024 data, with New Jersey at 12.5% and Delaware at 13.5%. All three sit below the national rate of 16.1%. This is still largely an owner-operated market, so these decisions land on a practice owner rather than a corporate compliance department. That is precisely why the multi-state exposure goes unnoticed for so long.

What we provide practices and groups here:

  • Enterprise-grade cybersecurity. MDR, identity governance, and tenant-level monitoring across Microsoft 365 or Google Workspace, with attention to the cloud identity layer where dental breaches actually start.
  • Backup and disaster recovery with verified restores, not just completed jobs. Untested backups are not backups. See our approach to dental data backup and disaster recovery.
  • Dental software expertise across Dentrix, Eaglesoft, and Open Dental, including large-scale Open Dental cloud environments built to support many locations under one architecture.
  • Multi-state breach readiness. A documented incident response plan that knows which patients live in which state, and what order the resulting calls have to happen in. In this metro that is not paperwork, it is the difference between a compliant response and a violation.
  • IT KPI reporting on uptime, MFA adoption, endpoint compliance, and backup health. If your IT partner cannot show you a dashboard, they are not managing anything.

We support practices throughout the metro, including Philadelphia, Bala Cynwyd, Jenkintown, Media, Springfield, Wyncote, King of Prussia, Doylestown, West Chester, Norristown, Camden, Cherry Hill, Voorhees, Deptford, and Wilmington.

Microsoft research puts the reduction in account compromise risk from multi-factor authentication at 99.22%. Most dental organizations still treat it as optional. In a metro where a single compromised account can trigger notification duties in three states at once, that is not a technology gap. That is a leadership gap.

If you are running or building a group here, our DSO tech playbook covers how standardization changes what is possible operationally. If you would rather just talk through where your practice actually stands, get in touch.

Philadelphia Dental IT Support FAQs

What areas around Philadelphia does Medix Dental IT support?

We support the full Philadelphia-Camden-Wilmington metro, which the Census defines across eleven counties in four states. On the Pennsylvania side that includes Philadelphia, Delaware, Montgomery, Bucks, and Chester counties. In New Jersey it covers Camden, Burlington, Gloucester, and Salem counties. It also includes New Castle County in Delaware and Cecil County in Maryland.

We follow HIPAA carefully. Is that enough on the New Jersey side?

No, and this is the most common misunderstanding in this metro. New Jersey’s statute contains no HIPAA exemption. Following HIPAA well does not satisfy N.J.S.A. 56:8-163, which separately requires reporting the breach to the New Jersey State Police before you notify affected patients. A practice that runs a textbook federal process and skips that step has still missed a state obligation.

Does Pennsylvania give dental practices extra time to report a breach?

It is better than extra time. Under Act 151 of 2022, a covered entity subject to and in compliance with HIPAA and HITECH is deemed compliant with the Pennsylvania act, so the federal process governs and there is no separate state deadline. The condition is the important half of that sentence: it requires actual compliance, not just being subject to the rules. Act 151 also moved the trigger from discovery of a breach to determination that one occurred.

Our office is in Philadelphia but some patients live in New Jersey. Which law applies?

Both. State breach notification duties follow the residency of the affected individuals, not the address of your practice. A Philadelphia practice with patients in Cherry Hill and Wilmington can find one incident triggering Pennsylvania, New Jersey, and Delaware obligations at once, each with different requirements about who gets notified and in what order.

Do you support Philadelphia DSOs and multi-location dental groups?

Yes, and multi-location groups here are exactly where the state-line issue bites hardest. Standardized systems, centralized identity management, and a single documented incident response process across all sites matter more in this metro than they would in a single-state market. Fragmented IT does not show up on the IT invoice, it shows up in your multiple.

What dental software does your Philadelphia team support?

Dentrix, Eaglesoft, and Open Dental, along with the imaging and integration tools around them. We have built large-scale Open Dental cloud environments supporting hundreds of practices with centralized architecture and reporting, so a group standardizing across state lines is not limited to one platform.

Posted in Service Areas

Filter By: