Dental and orthodontic practices
One to five locations, practice management software on site or hosted, front desk handling insurance attachments all day.
Medical and dental practices lose money to security incidents in a specific way: the schedule stops, the phones still ring, and the notification clock starts. PikeShield works on the five failures that actually cause that, for practices in Florida and across the US.

One to five locations, practice management software on site or hosted, front desk handling insurance attachments all day.
Small clinical teams, an outside IT provider, and a billing company that touches patient data.
Telehealth in the mix, remote clinicians, and records that carry more sensitivity than most.
A phishing email that someone clicked, a vendor breach notice, or an audit question nobody could answer.
These are the ones that actually close practices for a day, not the ones that make headlines.
Hygienists, temps, associates and front desk staff rotate, and practice management logins are shared to keep the day moving. Access is granted verbally and almost never removed, so the list of people who can open a chart is longer than the payroll.
Reception opens insurance attachments, referral PDFs and imaging links from strangers as a core job function. That is exactly the behaviour phishing depends on, and MFA is often enabled but not enforced on the accounts that matter most.
Billing company, IT provider, imaging cloud, transcription, recall service. Each one reaches patient data, each one needs a signed BAA on file, and in most practices nobody can produce the list, let alone the agreements.
The backup job reports success for years. Nobody has ever run a test restore, so the first real test happens on the worst morning, and the recovery time is discovered rather than planned.
The HIPAA Breach Notification Rule sets obligations and deadlines, but the practice has no written incident plan, no escalation list, and no agreed answer to who calls counsel, the carrier and the affected patients.
Each capability answers one failure above, in the same order.
Access inventory across practice management, email, imaging and finance, least-privilege roles, and an offboarding runbook that can be tested rather than remembered.
MFA enforced tenant-wide including the legacy paths that bypass it, plus ongoing phishing simulations aimed at the workflows reception really handles.
Inventory of every third party touching patient data, which agreements exist, which are missing, and what each vendor can actually reach.
Test restores with a measured recovery time, so the practice knows in advance how long a bad morning lasts.
Written incident response plan, escalation path with names and numbers, and a tabletop exercise so the plan has been used once before it matters.
Most practices buy prevention and skip recovery. The two are different jobs and only one of them is tested on the day it matters.
Prevention decides how likely the incident is. Recovery decides how expensive it is: how many hours the schedule is down, whether the notification clock starts, and whether anyone can prove what was and was not reached. A practice with average prevention and rehearsed recovery loses a morning. A practice with good prevention and untested backups loses a week.
Security work for practices is confidential by nature. Instead of borrowed logos, here is how the engagement behaves.
The assessment phase changes nothing. Access is read-only and scoped, and the scope is agreed in writing before it starts.
Findings describe systems, settings and exposure. Patient information is not copied, exported or pasted into a report.
A finding that stops the schedule outranks a high severity score on a system nobody uses. Both the practice owner and the IT provider get a version they can act on.
Documentation is written so another provider could pick it up. A security posture that depends on us being reachable is a weak posture.
A finding is an event. A verified re-check is a result. What the exact model looks like depends on your practice management system, your IT provider and the boundaries your compliance officer sets, so it is agreed during scoping rather than assumed.
Where an engagement involves systems that contain protected health information, a business associate agreement is executed before any access is granted.
Under NDA, with the systems in scope named in writing. Nothing is modified during assessment.
The form on this page is for practice contact details only. Do not include patient names, records or clinical detail.
Findings map to HIPAA Security Rule safeguards and NIST CSF so your compliance officer and counsel can act on them. The compliance determination is theirs, not ours.
What it is: a scoped look at how your practice runs and where the exposure sits. What it is not: a generic sales deck. What you leave with: a clear next step, or an honest answer that we are not the right fit.