Dental IT support dashboard on dual monitors in a Seattle dental practice with the Seattle skyline and Mount Rainier visible through the window

Washington publishes the breach notices dental practices file with the state. 32 Pearls, which runs offices on Lake Washington Boulevard in Seattle and in University Place near Tacoma, filed one on June 21, 2025 after a ransomware attack, and the state’s public record lists 23,550 Washington residents affected, a three-day intrusion in May, and thirty days elapsed before the Attorney General was notified. Most practice owners do not know that record exists, or that the filing behind it can be downloaded by anyone.

Dental IT support in Seattle has a compliance detail that almost nobody explains correctly. Washington dental practices are told that following HIPAA covers them under state breach law, and that is half true. RCW 19.255.030(1) does deem a compliant covered entity to have satisfied the chapter. The same subsection then says covered entities shall notify the Attorney General regardless, on the federal timeline. The exemption is real, and it does not extend to the filing itself, which is the part that ends up on a state website with your practice’s name on it.

Medix Dental IT has spent more than 20 years working exclusively in dentistry, supporting single offices through multi-location DSOs. That focus is the entire point. A generalist provider reads the HIPAA safe harbor, stops reading, and never tells you what the state publishes about you afterward.

Washington’s HIPAA Exemption Changes Your Deadline, Not Your Filing

Read RCW 19.255.030(1) to the end of the subsection. Sentence one: a HIPAA covered entity “is deemed to have complied with the requirements of this chapter with respect to protected health information” if it complied with HITECH section 13402. Sentence two: “Covered entities shall notify the attorney general pursuant to RCW 19.255.010(7) in compliance with the timeliness of notification requirements of section 13402… notwithstanding the timeline in RCW 19.255.010(7).”

Both halves matter, and most compliance summaries quote the first and stop. The federal timeline replaces the state’s, so a covered entity works to HITECH’s 60 days rather than Washington’s 30. What it does not do is remove the filing. The Attorney General still has to be notified.

That duty triggers at more than 500 Washington residents, and RCW 19.255.010(7)(a) is specific about what the filing must contain. Not just a count. It requires “a summary of steps taken to contain the breach” and “a single sample copy of the security breach notification,” excluding personally identifiable information. Your containment response, described in writing, and the letter you sent patients.

Then the Attorney General posts it, in a public directory of filed notices with an open dataset behind it. It is worth seeing how unpolished those documents can be. The 32 Pearls submission is headed “Summary for Submission to the Washington Attorney General,” and the copy on the state’s site still carries its template brackets: “Number of Affected Washington Residents: [Insert total number here],” plus placeholders for the mailing date and the business contact block, and an unmerged mail-merge token in the patient letter. That is a vendor worksheet, mid-completion, hosted permanently on a state website.

So the practical question is not whether you are exempt. It is what your containment summary would say. A practice that can describe isolating an endpoint, revoking sessions, and restoring from a verified backup is writing a different document than one whose honest answer is that the server was encrypted before anyone noticed. The filing does not create that difference. It records it.

What the Washington Breach Registry Shows About Detection

The state’s registry is unusually useful because it records timing, not just totals. Every entry carries the date the practice became aware and the days elapsed before notification. Reading down the dental entries, about half sit past sixty days, and the ones that do are not close: they run from 102 days to over 300. Most of those are large multi-state groups and dental insurers rather than independent practices. The statute permits delay while a practice determines the scope of a breach, so a long gap is not proof of a violation. It is a measure of how long it took to answer the question the filing asks, which is what was actually accessed. That is a detection problem before it is a compliance problem.

Two Kirkland practices show the quieter version of the same problem. Bridle Trails Family Dentistry, in its own notice, said it learned in March 2026 that a single employee email account had been accessed and dated that access to November 2024. Totem Lake Family Dentistry, in its notice, said it detected unauthorized access to one employee email account on or about June 2, 2025, and determined on March 31, 2026 what the affected files contained. Neither was ransomware. One mailbox, in each case, and a long stretch before anyone could say what had been in it.

Ransomware announces itself. A compromised mailbox does not, and the clock the statute cares about does not start until someone discovers it. Detection is the whole game, which is why the useful question is not whether antivirus is installed, but whether anyone is watching the Microsoft 365 tenant where the mailboxes live. Microsoft’s own guidance treats mailbox audit logging as the starting point for investigating a compromised account, and it has to be running before the incident to be useful after it. A cybersecurity assessment largely tests one thing: if a mailbox in your practice were accessed tonight, how long before anyone knew.

Dental IT Services Built for the Seattle-Tacoma Market

Washington is a more independent dental market than the country as a whole. ADA Health Policy Institute data for 2024 puts Washington at 13.9% of dentists affiliated with a DSO against 16.1% nationally, so most Puget Sound practices make these decisions without a corporate compliance department behind them.

Group practices are here in force, and nearly all are run from somewhere else. Pacific Dental Services supports offices from Seattle and Bellevue to Tacoma and Everett out of Irvine, California. InterDent’s Gentle Dental runs its Washington offices from El Segundo. Willamette Dental Group is the closest thing to a regional operator, and it sits in Hillsboro, Oregon.

What Medix delivers across the metro:

  • Enterprise-grade cybersecurity. Managed detection and response, identity governance, and tenant-level monitoring in Microsoft 365 and Google Workspace. The biggest blind spot in dentistry is cloud identity, not hardware, and both Kirkland incidents above started in a mailbox. Microsoft Research puts the risk reduction from multifactor authentication at 99.22% against account compromise, and it is still optional in a lot of practices.
  • Backup and disaster recovery built so a ransomware event is a restore rather than a negotiation. As Tom Terronez puts it, untested backups are not backups. Verified, monitored recovery is what lets a containment summary describe a clean restore.
  • Dental software expertise across Dentrix, Eaglesoft and Open Dental, including Open Dental cloud hosting.
  • Breach-response readiness for Washington specifically. Documented incident response, retained evidence, and a containment record you would be comfortable seeing published, because in this state it will be.
  • IT KPI reporting on uptime, MFA adoption, endpoint compliance and backup health, so the answer to “are we covered” is a dashboard rather than an opinion.

We support practices across Seattle, Bellevue, Tacoma, Kirkland, Redmond, Renton, Kent, Federal Way, Everett, Lynnwood, Bothell, Puyallup, Auburn and Issaquah.

Tom Terronez makes a point about group practices that applies to a single office too: an IT provider has two customers, leadership and the practice. Plenty of providers report uptime to an owner while the front desk submits the same ticket three times. In a state that publishes your containment summary, that gap eventually shows up in writing.

If you are evaluating providers, our DSO technology playbook covers how we standardize multi-location environments. Or contact our team and we will walk your environment with you. We do this every week.

Seattle Dental IT Support FAQs

What areas around Seattle does Medix Dental IT support?

We support dental practices throughout the Seattle-Tacoma-Bellevue metro, including King, Pierce and Snohomish counties. That covers Seattle, Bellevue, Tacoma, Kirkland, Redmond, Renton, Kent, Federal Way, Everett, Lynnwood, Bothell, Puyallup, Auburn and Issaquah, with remote support and coordinated onsite work.

We follow HIPAA. Is that enough under Washington law?

Not entirely. RCW 19.255.030(1) deems a HIPAA-compliant covered entity to have complied with the chapter, and it lets that entity work to the federal HITECH timeline of 60 days rather than Washington’s general 30-day rule. It does not remove the obligation to notify the Washington Attorney General for a breach affecting more than 500 Washington residents. The exemption changes your deadline, not whether you file.

Can we delay notification while we investigate?

Within limits. RCW 19.255.010(8) allows delay at the request of law enforcement, or for measures needed to determine the scope of the breach and restore the integrity of the system. That is why filings in the state registry often land well past the nominal deadline. The delay has to be tied to that work, not to indecision.

What does a Washington practice actually have to send the Attorney General?

RCW 19.255.010(7)(a) requires the number of Washington consumers affected, the types of personal information involved, the timeframe of exposure including breach and discovery dates, a summary of the steps taken to contain the breach, and a sample copy of the notification letter sent to patients. The Attorney General publishes these filings, so the containment summary becomes a public record.

Do you support Seattle DSOs and multi-location dental groups?

Yes. Multi-location groups are the core of our work, and the Seattle metro is dominated by operators headquartered in California and Oregon. We standardize practice management systems, imaging, identity and security across locations so a group operates as one environment rather than a set of offices sharing a logo.

What dental software does your Seattle team support?

Dentrix, Eaglesoft and Open Dental, along with the imaging and integration systems built around them. We also handle Open Dental cloud hosting for practices moving off aging on-premise servers.

Posted in Service Areas

Filter By: