IT support for dental practices is judged against a test almost no other small business faces: the record you created for a five-year-old today has to be readable, provable and secure when that child is twenty-five. A dental practice is a small business carrying a hospital’s retention obligation, a regulator’s evidence burden and a clinical diary that cannot slip, and good IT support for dental teams is designed backwards from those three facts rather than from headcount.

This guide is written for UK practice owners, practice managers and dental group operations directors — single sites, small groups and corporate estates alike — and for whoever signs the technology invoices. It covers what IT support for dental practices actually has to deliver: the practice management system and the imaging archive, the Data Security and Protection Toolkit, NHSmail and secure referral, backup designed against an eleven-year floor, identity control in a room where four people share one screen, and the cost of each shape written out.

Every legal and published figure below was read off source on 22 August 2026: the Care Quality Commission’s own register of locations and its Regulation 17 guidance, NHS England’s Records Management Code of Practice and the NHS Business Services Authority’s retention and claim rules, the Data Security and Protection Toolkit version 8 requirement workbook, the General Dental Council’s Standards for the Dental Team, the DSIT and Home Office Cyber Security Breaches Survey 2025/2026, the Information Commissioner’s Office enforcement record, and Microsoft’s published UK price list. Where a number is modelled rather than read off a page it is labelled modelled and the working is shown.

The worked example throughout is a four-practice UK dental group with 12 surgeries and 58 people — 38 clinical (dentists, hygienists, therapists and nurses) and 20 non-clinical (reception, treatment co-ordinators, finance and management), running mixed NHS and private work. Sector guides for neighbouring industries answer the same questions for different estates: IT support for accountancy firms and IT support for construction companies. What we deliver day to day sits on our managed IT services page.

Why IT Support for Dental Practices Is Its Own Discipline

it support for dental practices b funnel wide cone straight spout

Most providers design for an office: one system of record, one working pattern, one place where the work happens. A dental practice is a clinic, a laboratory interface, an imaging department and an NHS billing operation stacked into a building the size of a small shop, and the IT infrastructure has to serve all four from one comms cabinet. IT support for dental practices has to hold all four at once. That is why generic support so often arrives technically competent and still wrong.

IT support for dental practices starts at the chair, not the server room

The unit of production is a booked appointment. Every minute the practice management system is slow or unreachable is a patient sitting in a chair with a nurse and a clinician beside them, and the cost of that minute is the fully loaded cost of three people plus a lost slot. IT support for dental teams that treats the clinical system as a line-of-business application rather than a production system is measuring the wrong thing.

The retention floor is the design constraint for IT support for dental practices

NHS England’s Records Management Code of Practice sets the retention period for dental clinical care records at 11 years, reduced from 15 in August 2023. For children the record is kept for 11 years or until their 25th birthday, whichever is longer. That single sentence sets the storage plan, the backup plan, the migration plan and the exit plan, and IT support for dental practices that has not read it will size everything too small.

IT support for dental practices answers to three regulators at once

The Care Quality Commission registers the location and inspects it, the General Dental Council regulates the professionals, and the Information Commissioner’s Office regulates the data. Add NHS England’s Data Security and Protection Toolkit for anyone holding an NHS contract and IT support for dental practices is facing four separate evidence trails. IT support for dental practices is largely the work of producing those trails without asking clinicians to do it by hand.

The buyers of IT support for dental practices are overwhelmingly small

Counting the Care Quality Commission’s own published directory of locations dated 18 February 2026 gives 12,138 registered dentist locations in England, held by 8,786 distinct providers. Of those providers, 7,841 — 89.24% — run exactly one location. Only 945 providers hold more than one, so the buyer is usually one person wearing several hats. So the typical buyer of IT support for dental practices is a single site with no internal IT function at all. For that buyer, managed IT services is not a procurement category, it is the entire IT department.

Corporate consolidation is real but partial

The same directory shows 4,297 locations belonging to multi-site providers, 35.40% of the register, and the twenty largest groups between them hold 1,400 locations — 11.53% of all dentist locations in England. That two-speed market is why IT support for dental practices splits so cleanly into two products: a fully managed service for the independent, and a co-managed one for the group with a head-office team.

Who actually owns England’s dental practices (CQC register of locations, 18 February 2026 — 12,138 dentist locations, 8,786 providers)
Locations held by single-location providers 64.60% — 7,841
Locations held by multi-site providers 35.40% — 4,297
Of which: the twenty largest groups 11.53% — 1,400
Providers running exactly one location 89.24% — 7,841 of 8,786
Counted directly from the CQC’s published directory CSV dated 18 February 2026, filtering rows whose service type includes Dentist. Percentages are those counts over the 12,138 locations, except the last, which is over the 8,786 providers.

The Practice Management System: What IT Support for Dental Practices Must Own

it support for dental practices c lighthouse tapered tower flat cap

The practice management system is the business. Appointments, clinical notes, charting, recalls, treatment plans, estimates, NHS claims and the payment ledger all live in it, and in most practices it was bought by the principal, installed by the vendor and then left outside the scope of IT support for dental practices entirely. Closing that gap is the first job of IT support for dental practices.

IT support for dental practices begins with knowing which product you run

Software of Excellence Exact, Carestream R4, Dentally, Systems for Dentists and Kodak-lineage products dominate UK practices, and they split into two architectures: an on-premises database on a server in the back office, or a cloud-hosted tenant. IT support for dental practices means something completely different in each case, and the first question any provider should answer is which one you are running.

On-premises means IT support for dental practices owns the failure surface

If the database sits on a server in a cupboard, then the server, its disks, its operating system version, its backup, its power and its air are all yours. That server is usually the single point of failure for the entire practice. IT support for dental teams running this shape has to treat one box as a clinical dependency, with monitoring, a spare, and a restore that has actually been performed. Server management stops being an abstraction the moment that box is the practice.

Cloud-hosted moves the failure surface to the network

Move to a hosted practice management system and the server problem becomes a connectivity problem. A single broadband line with no failover turns a line fault into a closed practice. The fix is unglamorous and cheap: a second circuit on a different carrier, ideally 4G or 5G, with automatic failover at the firewall. That is the whole of resilience for a cloud-first practice, and it belongs inside IT support for dental practices from day one.

The vendor’s support boundary is not your support boundary

Every practice management vendor supports its own application and nothing underneath it. Windows, the database engine, the backup, the network, the workstations and the imaging bridge sit outside that line. Practices routinely discover the gap during an incident, when IT support for dental practices and the vendor are both pointing at the other. Sound IT support for dental practices puts the boundary in writing before anything breaks, and names who owns each side.

Integration is where the real work of IT support for dental practices sits

The practice management system talks to the imaging software, the digital scanner, the payment terminal, the recall messaging service, the patient portal and the NHS claiming route. Each integration is a small piece of software with its own version, its own credentials and its own failure mode. IT support for dental practices should hold a written map of every one of them, because nobody else will.

Exports, ownership and exit belong in the contract

Ask three questions before renewing: can we export every field including clinical notes, charting and attachments without a professional-services charge; what format is the export; and how long after termination does read access survive. Given an eleven-year retention floor, a thirty-day read window after termination is not an inconvenience but a compliance failure waiting to happen, so IT support for dental practices should read the renewal before it is signed.

SystemWhat it holdsWhat stops when it failsWho normally owns it
Practice management systemDiary, clinical notes, charting, ledger, recallsEverything — the practice cannot safely treatVendor for the app, you for the platform
Imaging software and archiveIntraoral, OPG, CBCT, intraoral scans, photosNo radiographs taken, no diagnosis recordedImaging vendor, often nobody in practice
NHS claiming routeFP17 claim data, contract performanceClaims stall against a two-month deadlinePractice manager, unsupported
Card and payment terminalPatient payments, plan collectionsNo revenue collected at receptionAcquirer, plus your network
Patient messaging and recallReminders, confirmations, recall listsFailure-to-attend rate climbs within daysMessaging vendor
Email and file storageReferrals, lab work, correspondence, HRReferrals and lab jobs stop movingYou

Imaging, CBCT and the Storage Problem IT Support for Dental Practices Underestimates

it support for dental practices d strongbox arched lid flat clasp

Radiographs are the part of the estate that grows without anyone deciding it should. A practice that adds a cone beam scanner changes its storage curve permanently, and nobody tells the IT provider. Sizing this properly is one of the clearest tests of whether IT support for dental practices has understood the building at all.

Two-dimensional imaging is the volume IT support for dental practices assumes

Intraoral radiographs and panoramic images are measured in low single-digit megabytes each. At that scale, a decade of imaging fits comfortably on any modern server or cloud tier, and nobody worries. This is the volume most providers of IT support for dental practices quietly assume when sizing an estate, which is exactly why the next paragraph catches them out.

Cone beam changes the arithmetic for IT support for dental practices

A single cone beam study is commonly a few hundred megabytes, and a large field-of-view scan can exceed a gigabyte. One CBCT scan can therefore be worth two hundred intraoral radiographs. Storage and bandwidth requirements for cone beam are an order of magnitude above two-dimensional imaging, which is why cloud-native archives exist at all.

A modelled year of imaging for the worked example

Twelve surgeries seeing eight patients a day across roughly 230 working days is 22,080 patient visits a year. Assume 40% involve radiographs — 8,832 imaging events at an average 2 MB — that is 17.66 GB. Add four cone beam scans a week for 48 weeks at 260 MB each: 192 scans, 49.92 GB. Total new imaging: 67.58 GB a year, all of it modelled, and none of it visible unless somebody asks.

Multiply by the retention floor, not by the year

Because none of it can be deleted for eleven years, the real planning number is 67.58 GB multiplied by 11 — 743.42 GB of imaging the group can never throw away, before a single email or document. IT support for dental practices that sizes backup on this year’s data rather than on the retention floor will be re-quoting the storage every eighteen months.

Intraoral scanners and clear-aligner cases add a third curve

Digital impressions, clear-aligner planning files and laboratory exchange files are large, are clinical records, and frequently live in a vendor portal rather than in the practice. Whether those files form part of the dental record — and who is holding them — is a question IT support for dental practices should raise long before an auditor does.

The archive has to be searchable a decade later

A radiograph you cannot associate with a patient, a date and a justification is not a record. The practical requirements IT support for dental practices should specify are three: images written back into the patient record rather than a loose folder, an export path that survives a change of imaging vendor, and a documented process for retrieving a 2027 radiograph in 2037 without the original software.

Modelled imaging growth for the 12-surgery worked example (67.58 GB a year, shown against the 11-year retention floor of 743.42 GB)
Year 1 9.09% — 67.58 GB
Year 3 27.27% — 202.75 GB
Year 6 54.55% — 405.50 GB
Year 9 81.82% — 608.26 GB
Year 11 — nothing yet deletable 100.00% — 743.42 GB
Modelled: 12 surgeries x 8 patients x 230 days = 22,080 visits; 40% imaged at 2 MB = 17.66 GB; plus 192 cone beam scans at 260 MB = 49.92 GB. 1 GB is treated as 1,000 MB throughout.

The Data Security and Protection Toolkit: 45 Mandatory Items for IT Support for Dental Practices

it support for dental practices e anvil flat top tapered horn

Any practice holding an NHS dental contract must complete the Data Security and Protection Toolkit annually, and it is also the gateway to an NHSmail account. It is the single largest piece of documented evidence a dental practice produces, and the part of IT support for dental practices most often sold vaguely and delivered thinly.

Version 8, the June deadline and IT support for dental practices

The 2025/26 toolkit — version 8 — went live on 18 September 2025 and aligns with version 3.4 of the Cyber Assessment Framework. The submission deadline is 30 June 2026. A practice that misses it, or publishes a status below the required standard, puts its NHS contract at risk, which makes the date a commercial deadline for IT support for dental practices rather than an administrative one.

Dentists are Category 3, and that is heavier than a GP practice

The toolkit assigns organisation types to categories, and a dentist providing NHS or private dental services is Category 3. Counting the published version 8 requirement workbook directly: the toolkit carries 134 evidence items across 10 standards and 36 assertions, of which 76 are shown to a Category 3 organisation and 45 are mandatory.

The comparison nobody buying IT support for dental practices expects

The same workbook makes a general practice — Category 4 — mandatory on 29 items, and a large IT supplier — Category 2 — mandatory on 103. So a dental practice, typically with no IT staff at all, carries 45 mandatory evidence items against a GP surgery’s 29. That is 55.17% more mandatory evidence produced by a smaller organisation, and it is the clearest single argument for buying IT support for dental practices rather than improvising.

Where the burden actually sits

Counted by standard, the 45 mandatory items for a dentist break down as 16 under Standard 1, six under Standard 7, five each under Standards 4 and 6, three each under Standards 3 and 8, two each under Standards 2, 9 and 10, and one under Standard 5. Standard 1 alone — data protection, records and accountability — is 35.56% of the entire burden.

Certification is not the shortcut it is sold as

The workbook marks 26 of the 134 evidence items as exempt if you hold Cyber Essentials Plus and 25 if you hold ISO 27001. But intersect those exemptions with the 45 items a dentist must answer and Cyber Essentials Plus removes only three — 6.67% — while ISO 27001 removes ten, or 22.22%. Buy either on its merits, and never let a provider of IT support for dental practices sell one as a toolkit shortcut.

For IT support for dental practices this is documentation, not technology

Of the 45 mandatory Category 3 items, 29 are yes/no answers, 11 require free text and five require an uploaded document. That balance tells you what good IT support for dental practices looks like here: the technical controls are the easy part, and the work is producing, dating and storing the evidence that they exist.

Mandatory DSPT evidence items by organisation category (version 8, 2025/26 requirement workbook — 134 evidence items in total)
Large IT supplier (Category 2) 103 items — 76.87% of all 134
Dental practice (Category 3) 45 items — 33.58% of all 134
General practice (Category 4) 29 items — 21.64% of all 134
Counted directly from the published version 8 workbook by tallying rows flagged mandatory in each category column. A dental practice therefore answers 55.17% more mandatory items than a GP practice.

The ten standards in plain language

Standard 1 covers lawful basis, individual rights, governance and records. Standards 2 and 3 cover staff obligations and training. Standard 4 is access control. Standard 5 is process review. Standard 6 is malware, phishing and breach reporting. Standard 7 is continuity and incident response. Standard 8 is unsupported software and patching. Standard 9 is technical security, and its assertion 9.2 expects a penetration testing exercise to have been scoped and undertaken. Standard 10 is suppliers. Taken together they are the working syllabus for IT support for dental practices.

StandardSubjectMandatory items for a dentistShare of the 45
1Lawful basis, rights, governance, records1635.56%
7Continuity and incident response613.33%
4Identity and access management511.11%
6Malware, phishing and breach reporting511.11%
3Training and awareness36.67%
8Unsupported systems and patching36.67%
2Staff obligations and contracts24.44%
9Technical security and firewalls24.44%
10Supplier management24.44%
5Process review12.22%

NHSmail, Secure Referral and Why IT Support for Dental Practices Runs Two Mail Systems

it support for dental practices f envelope rectangle triangular flap

Almost every practice ends up with two email systems, and almost nobody has decided which correspondence belongs in which. Sorting that out is quick, cheap and one of the highest-value things IT support for dental practices does inside the first month.

NHSmail is earned through the toolkit

NHSmail accounts are available to dental practitioners delivering NHS and private services in England, and completing the Data Security and Protection Toolkit is the precondition for registering. Practices are set up with a shared practice mailbox and can register up to ten individual accounts. Communications from NHS England are issued to that account, so it cannot be ignored.

The shared mailbox is a governance problem in waiting

A shared practice mailbox that four receptionists open with one password is exactly the pattern the toolkit’s Standard 4 exists to stop. Shared mailboxes should be delegated to named individual accounts, never accessed with a shared credential. This is a five-minute configuration change that closes a genuine audit finding.

Secure referral is the reason NHSmail exists

The General Dental Council’s Standard 4.5.2 states that if you are sending or storing confidential information electronically, you should ensure that it is encrypted. NHSmail to NHSmail satisfies that end to end. Referrals to secondary care, safeguarding correspondence and anything containing clinical detail belong on that route, and IT support for dental practices should make the rule explicit.

Microsoft 365 carries everything IT support for dental practices controls

Lab correspondence, supplier invoices, marketing, HR, rotas and internal documents belong in the practice’s own Microsoft 365 tenant, where you control retention, legal hold, device policy and multi-factor authentication. Splitting the two mail systems by purpose rather than by habit gives IT support for dental practices a defensible answer when an inspector asks where clinical correspondence lives.

Deliverability still matters for recalls

Recall reminders, appointment confirmations and treatment-plan emails are revenue systems. They need SPF, DKIM and DMARC configured on the practice’s own domain, and a sending reputation that is not shared with a bulk marketing tool. A recall run that lands in junk is indistinguishable, in the diary, from a recall run that was never sent, which is why IT support for dental practices should own the sending domain.

The four toolkit items NHSmail does not solve

The version 8 workbook exempts four evidence items for organisations using NHSmail — but none of those four is mandatory for a Category 3 dentist. In other words, NHSmail is genuinely useful for secure referral and unhelpful as a compliance shortcut, and any provider of IT support for dental practices selling it as the latter has not read the workbook.

Backup and Recovery Against an 11-Year Floor

Backup is where the retention rule, the imaging curve and the ransomware threat all meet IT support for dental practices at once. It is also the area where the gap between what practices believe they have and what they actually have is widest, and where IT support for dental practices earns or loses its fee.

The retention floor is not a backup policy

Keeping records for 11 years is a records-management obligation, not a backup one. Backup answers “can I get yesterday back”; archive answers “can I produce a 2027 radiograph in 2038”. A practice needs both, and IT support for dental practices that conflates them produces either a backup set that is absurdly expensive or an archive that quietly does not exist.

Three copies, two media, one off site — and one tested

The old rule still holds, with an addition that matters: at least one copy must be immutable or otherwise beyond the reach of an attacker who has your administrator password. Ransomware operators delete backups first. A backup that a compromised domain account can erase is not a backup at all, and IT support for dental practices should say so plainly.

Restore is the only test of IT support for dental practices that counts

The General Dental Council’s Standard 4.5.3 says that if clinical records are computerised, you should make back-up copies of clinical records, radiographs and other images. It does not say verify them, but a restore you have never performed is a hypothesis. A quarterly test that recovers a real patient record, a real radiograph and the whole database to a spare machine is the minimum.

Microsoft 365 is not backed up by Microsoft in the way you think

Retention policies and recycle bins are not backup. Mailboxes, SharePoint sites and OneDrive folders holding referrals, consent forms and HR records need a third-party backup with a retention window that matches your obligation, and IT support for dental practices should size it against 11 years rather than the 30 or 93 days a tenant offers by default.

IT support for dental practices sets recovery targets per system

A practice does not have one recovery time objective, it has six. The diary and clinical notes need to be back in minutes. Imaging can tolerate hours. Payroll can tolerate a day. Writing those numbers down converts an argument about cost into an engineering specification, which is exactly what good IT support for dental practices should force.

SystemSuggested RTOSuggested RPOWhy
Diary and clinical notesUnder 1 hour15 minutesPatients are in the building now
Imaging and CBCT archive4 hours24 hoursLarge, mostly historic, rarely re-taken
NHS claim data24 hours24 hoursA two-month claim deadline gives slack
Email and referrals4 hours1 hourSafeguarding and urgent referral traffic
Card payments1 hourNot applicableReception cannot take money without it
Payroll and finance24 hours24 hoursMonthly cycle absorbs a day

The claim deadline turns downtime into permanent loss

NHS practices have two months from the completion date of a course of treatment to submit the FP17. Claims received after that are disallowed and marked as a late submitted claim. Downtime that delays a claim batch past that window does not defer revenue, it destroys it, which is a very unusual property for an outage to have and the sharpest commercial case for IT support for dental practices there is.

Modelled: what a month of unsubmitted claims is worth
Take the worked example’s four contracts at a combined 24,000 units of dental activity a year, valued at £32.50 per unit — an annual contract value of £780,000. That is 2,000 units a month, or £65,000.
A practice management failure that leaves one month of claims unsubmitted past the two-month rule therefore puts 8.33% of the annual contract value beyond recovery. The same £65,000 would fund the group’s entire Microsoft 365 estate for roughly four and a half years at the licensing shape costed later in this guide.
Modelled. The 24,000 units and the £32.50 unit value are illustrative; the two-month deadline and the disallowance are published NHS BSA rules. Substitute your own contract figures — the ratio is what matters.

Microsoft 365 Licensing for a Dental Practice, Costed

Licensing is where IT support for dental practices either overspends quietly or underspends dangerously. The Microsoft 365 Business plans are not interchangeable, and the difference between them is precisely the security tier that a practice holding special category health data most needs.

The published UK prices IT support for dental practices should quote

Microsoft’s UK list price, per user per month on an annual subscription excluding VAT, is £5.40 for Business Basic, £9.80 for Apps for business, £18.10 for Business Standard with Copilot and £24.60 for Business Premium with Copilot. Only Business Premium includes Entra ID P1, Intune device management and Defender for Office 365, which is the tier that matters to IT support for dental practices.

The three shapes, costed for the worked example

For 58 people: all-Premium is 58 x £24.60 x 12 = £17,121.60 a year. Premium for the 20 non-clinical staff plus Standard for the 38 clinical is £5,904.00 + £8,253.60 = £14,157.60, or 82.68% of all-Premium. Premium for 20 plus Basic for 38 is £5,904.00 + £2,462.40 = £8,366.40, or 48.87%.

Why the cheapest shape is wrong for IT support for dental practices

That third option looks like a £8,755.20 saving — 51.13%. What it actually does is remove Intune, Defender and Entra ID P1 from the 38 clinical staff, 65.52% of the workforce, who are the people opening laboratory attachments and referral emails on shared surgery machines. The saving is real, the exposure is concentrated exactly where the risk is, and IT support for dental practices should say which of the two it is being paid to manage.

Frontline plans are worth a conversation, not an assumption

Microsoft’s frontline plans exist for shift-based staff who do not need a full desktop, and a dental nurse who only touches the practice management system may fit. But frontline licensing carries mailbox and feature limits that catch practices out, and the UK list prices are not published on the same page as the Business plans. Price it deliberately.

Count the licences you are already paying for twice

Practices routinely pay for a standalone antivirus product, a standalone multi-factor authentication tool and a standalone patch agent while holding Business Premium licences that include all three. Reconciling the tool list against the licence entitlement is a one-hour exercise that frequently pays for a whole year of IT support for dental practices on its own.

Annual Microsoft 365 cost for the 58-person worked example, three licensing shapes (Microsoft UK list, annual, ex VAT)
All 58 on Business Premium 100.00% — £17,121.60
Premium for 20 back office, Standard for 38 clinical 82.68% — £14,157.60
Premium for 20 back office, Basic for 38 clinical 48.87% — £8,366.40
Modelled from Microsoft’s published UK list prices applied to a 20/38 split. The third shape saves £8,755.20 — 51.13% — by removing the security tier from the 65.52% of staff who work chairside.

Identity, Access and the Shared Surgery Login

The single most common finding in a dental practice is a surgery workstation logged in as “Surgery 3” with a password taped inside a drawer, used by whichever clinician and nurse are in the room. Every access-control obligation in the toolkit and every audit trail in the practice management system dies at that point, which makes this the first thing IT support for dental practices should fix.

Named accounts are not optional in IT support for dental practices

Toolkit Standard 4 requires management of identity and access, and the practice management system’s own audit trail is worthless if four people share one identity. Named accounts for every person who touches a clinical record is the baseline, and IT support for dental practices should treat any shared clinical credential as a defect to be scheduled out.

Fast switching is what makes named accounts survive

The reason shared logins exist is that logging in takes too long between patients. Solve the real problem: smart-card or badge tap, Windows Hello, or fast user switching with a locked shell. If signing in takes three seconds, the shared account disappears without an argument. If it takes forty, no written policy will hold.

Multi-factor authentication everywhere that faces the internet

The Information Commissioner’s Office fined Advanced Computer Software Group £3,076,320 on 27 March 2025 after attackers reached its health and care systems through a customer account without multi-factor authentication, exposing information belonging to 79,404 people — including how to enter the homes of 890 people receiving care at home. The Commissioner’s instruction was to secure every external connection, which is as close to a direct instruction to IT support for dental practices as a regulator gets.

Privileged access is a separate problem for IT support for dental practices

Standard 4.4 concerns privileged user access specifically. In a practice this means the practice management system administrator account, the tenant global administrator and the backup console. Those three should not be daily-use accounts, should not be shared with the vendor permanently, and should be reviewed whenever anyone leaves.

Leavers are the most reliable failure of IT support for dental practices

Associates move, nurses move, receptionists move. A leaver process that revokes the Microsoft 365 account but leaves the practice management login, the imaging software, the messaging portal and the payment terminal untouched is the norm rather than the exception. A single written list of every system holding accounts is the whole fix.

Conditional access earns its licence here

With Business Premium you can require managed devices for access to clinical email, block sign-in from outside the UK, and force re-authentication on risky sign-ins. These are the controls that separate an attacker with a stolen password from an attacker inside the tenant, and they are already paid for.

Cyber Security Controls IT Support for Dental Practices Should Insist On

Dental practices are attractive targets for a boring reason: they hold special category health data, they pay for continuity, and they are small enough to be under-defended. The controls that matter in IT support for dental practices are unglamorous and mostly already licensed. Practical cybersecurity for a practice is a short list, done properly.

The sector’s own breach numbers are misleading in an important way

In the Cyber Security Breaches Survey 2025/2026, 33% of health or social care businesses identified a breach or attack in the last 12 months, against 43% of businesses overall — apparently one of the safer sectors. But 20% of health or social care businesses experienced a cyber crime, against 19% overall. Read those two together and the picture inverts.

What the ratio actually says

Crimes as a proportion of identified breaches works out at 60.61% for health or social care against 44.19% for businesses overall. A sector reporting fewer incidents but a higher share of serious ones is not safer, it is less likely to notice the minor ones. That is a detection gap, and detection is a capability IT support for dental practices can simply be asked to supply.

Health or social care against all UK businesses (DSIT Cyber Security Breaches Survey 2025/2026, published 30 April 2026)
Identified a breach or attack — health or social care 33%
Identified a breach or attack — all businesses 43%
Experienced a cyber crime — health or social care 20%
Experienced a cyber crime — all businesses 19%
Crimes as a share of identified breaches — health or social care 60.61%
Crimes as a share of identified breaches — all businesses 44.19%
The four percentages are published survey figures. The final two bars are those figures divided — 20/33 and 19/43 — and are modelled arithmetic on the survey’s own numbers, not a published statistic.

Phishing is the threat, not ransomware

Phishing remained the most prevalent type of attack by far, experienced by 38% of businesses, and was named the most disruptive by 69% of those breached. Ransomware, by contrast, fell to 1% of businesses. Spending on phishing-resistant sign-in and mail filtering therefore beats spending on exotic ransomware tooling in almost every practice budget.

The unglamorous baseline for IT support for dental practices

Updated malware protection, secure cloud backup, a password policy, a network firewall and restricted administrator rights are held by roughly three-quarters of UK businesses. Two-factor authentication sits at only 47%. A practice that has all five plus MFA is already ahead of most of the economy, and every one of them is a toolkit evidence item too.

Cyber Essentials is worth holding, for the right reason

Only 5% of UK businesses hold Cyber Essentials, up from 3%, while 24% report having the technical controls in all five areas. For a dental practice the certificate is useful for supplier assurance, tenders and insurance — not, as shown earlier, as a way to shorten the toolkit. Our IT security work usually starts by mapping the two together.

Patching and unsupported software

Toolkit Standard 8 is entirely about knowing what you run and whether it is supported. Practices often run an old practice management version pinned to an old Windows build because an imaging bridge will not certify on anything newer. That is a legitimate constraint and an illegitimate excuse for leaving it undocumented and unsegmented.

IT support for dental practices should segment the clinical network

Imaging hardware, cone beam scanners, digital x-ray sensors and intraoral scanners frequently run embedded operating systems that cannot be patched. Put them on their own network segment with tightly controlled routing, and IT support for dental practices has turned the unpatchable device into a dead end rather than a route to the patient database. Guest wi-fi belongs on a third segment entirely.

Ransomware, Continuity and Incident Response in a Chairside Business

A practice cannot work from home. When systems stop, the building empties and the day is gone. That makes continuity planning less abstract in IT support for dental practices than almost anywhere else, and it is the second-largest block of toolkit evidence.

Continuity planning is where IT support for dental practices is tested

Only 25% of UK businesses had a formal incident response plan, against 57% of medium and 76% of large businesses. Given that Standard 7 makes continuity and incident response six of a dentist’s 45 mandatory items, a practice whose IT support for dental practices has produced no plan is failing a contract obligation and an inspection question simultaneously.

Write the plan for a receptionist at 8am

The plan that works is one page: who to call, in what order, what to tell patients, how to run a paper day, where the printed day-list is, and who authorises the decision to close. A forty-page document in a folder nobody can reach because the file server is encrypted is not a plan. Our incident response approach starts from that one page.

Run a paper day deliberately, once

Print tomorrow’s list tonight as a standing habit. Then, once, run a half-day on paper on purpose. Practices discover in that half-day that they cannot take payment, cannot verify medical histories and cannot find the emergency contact — all cheap to fix in advance and impossible to fix during an incident.

The recovery expectation is not what you think

Of businesses that identified a breach, 87% restored operations within 24 hours and 72% said it took no time at all. That is the ordinary case, and it is reassuring. The distribution’s tail is what IT support for dental practices is really bought for: the 12% that took more than a day are where a practice’s diary, claims and reputation actually get damaged.

Report the breach on the right clock

A personal data breach likely to result in a risk to people’s rights and freedoms must be reported to the Information Commissioner’s Office within 72 hours of becoming aware of it. Clinical data raises that likelihood considerably. The practice needs to agree who makes that call before the clock starts, not during it.

Supply chain is a toolkit standard for a reason

Standard 10 requires that you can name your suppliers, what they deliver and what basic due diligence you have done. For a practice that means the practice management vendor, the imaging vendor, the messaging service, the payment provider and the IT provider. Sound vendor management is a compliance control here, not just good housekeeping.

UK GDPR, Special Category Data and Subject Access

Dental records are special category data under UK GDPR, which raises the standard of protection and narrows the lawful bases available. Most of what IT support for dental practices needs here is documentation rather than technology, but the documentation has to actually exist.

Health data needs an Article 9 condition as well as a lawful basis

Processing health data requires both an Article 6 lawful basis and an Article 9 condition, most commonly the provision of health care, plus a Data Protection Act 2018 Schedule 1 condition and, for many of those, an appropriate policy document. IT support for dental practices does not write these, but it should know whether they exist.

Registration with the Information Commissioner’s Office is the first toolkit item

Evidence item 1.1.1 of the toolkit asks for the practice’s Information Commissioner’s Office registration reference, and registration is a legal requirement. It is a trivial thing to get wrong at renewal and an embarrassing thing to be missing when the toolkit is due.

Subject access has a one-month clock and no fee

Patients have a right to their dental records, and the General Dental Council’s Standard 4.4 requires practices to arrange access promptly. The statutory response period is one month. A practice that cannot assemble notes, charting, radiographs and correspondence for one patient inside that window has a systems problem, not an administrative one.

The request that exposes the architecture

A subject access request is the single best test of whether the record is really one record. If notes are in the practice management system, radiographs in imaging software, referrals in NHSmail, consent forms in a filing cabinet and orthodontic files in a vendor portal, the practice will discover it under a one-month deadline. Better to discover it deliberately, in a rehearsal.

For IT support for dental practices retention is a deletion obligation too

Keeping records for 11 years is a floor; keeping them for thirty is a breach of the storage limitation principle unless justified. Practical data protection here means a documented disposal schedule that actually runs, and evidence that it ran.

Photographs and social media

Clinical photography is a dental record. Standard 4.2.3 is explicit that practitioners must not post patient information on social networking sites even where cases are anonymised. Before-and-after images taken on a personal phone are simultaneously a marketing asset, a clinical record and an unmanaged copy of special category data that IT support for dental practices has never seen.

ObligationPeriodSourceAs a share of the 11-year floor
Report a notifiable breach to the ICO72 hoursUK GDPR0.07%
Respond to a subject access request1 monthUK GDPR0.75%
Submit an FP17 after treatment completes2 monthsNHS BSA1.51%
Retain NHS dental finance records2 yearsNHS BSA18.18%
Retain PAYE records3 years from end of tax yearHMRC27.27%
Retain adult dental clinical care records11 yearsNHS Records Management Code100.00%
Retain a child’s record treated at age five20 years, to their 25th birthdayNHS Records Management Code181.82%

CQC Regulation 17 and What Inspectors Look For

Registration with the Care Quality Commission is a condition of providing dental treatment, and the regulation that bites hardest on records is Regulation 17. Understanding what it says makes the requirement on IT support for dental practices obvious.

What Regulation 17 requires of IT support for dental practices

Regulation 17(2)(c) requires providers to maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided and of decisions taken. Regulation 17(2)(d) extends that to staff and management records. “Securely” and “contemporaneous” are both technology requirements in a computerised practice.

The regulation does not set a retention period

Regulation 17 says records must be created, amended, stored and destroyed in accordance with current legislation and guidance — which is what routes you back to the Records Management Code and its 11 years. Practices sometimes look for a CQC retention number and, finding none, invent one, which is a question IT support for dental practices should settle in writing.

Good governance is the most-breached regulation in dentistry

When the Care Quality Commission reported on its first year of the current dental inspection methodology, Regulation 17 accounted for 82% of the breaches found, and Regulation 12 for 45%. Among the common problems it listed were incomplete or out-of-date dental care records — a records problem before it is a clinical one, and therefore squarely a matter for IT support for dental practices.

Records must be accessible only to authorised people

Records must be kept secure at all times and only accessed, amended or destroyed by people authorised to do so. In a computerised practice that phrase means named accounts, role-based permissions and an audit trail, which is precisely the same control set the toolkit’s Standard 4 asks for. Doing the work once satisfies both.

Paper and electronic are held to the same standard

Both formats are acceptable provided they meet the Data Protection Act 2018. Practices running hybrid records — electronic notes, paper consent forms, scanned medical histories — have to say where the authoritative version of each record lives, and IT support for dental practices should answer that before an inspector asks it.

Evidence beats assertion when IT support for dental practices is inspected

An inspector asking about record security is satisfied by artefacts: an access-control list, a leavers log, a restore test report, the toolkit submission, the disposal schedule. All of these are outputs a competent provider produces as a by-product of normal work, which is why IT support for dental practices should be delivering them monthly rather than assembling them annually.

IR(ME)R 2017, Radiography and the Audit Trail

Dental radiography sits under the Ionising Radiation (Medical Exposure) Regulations 2017, enforced in England by the Care Quality Commission. It is a clinical governance regime, but its evidence requirements land squarely on IT support for dental practices.

The employer’s written procedures are a records obligation

Regulation 6 requires employers to establish written procedures covering the matters in Schedule 2, written protocols for every type of standard radiological practice, referral guidelines, quality assurance programmes and diagnostic reference levels that are maintained and regularly reviewed. Every one of those is a controlled document that IT support for dental practices has to keep current, findable and version-controlled.

IT support for dental practices has to link justification to the image

Each exposure needs a recorded justification and an identified practitioner and operator. If the imaging software records the exposure but the practice management system records the justification, the two have to be reliably linked for the life of the record. That link is an integration, and integrations are the responsibility of IT support for dental practices.

Significant accidental exposures are notifiable

Clinically significant unintended or accidental exposures must be investigated and reported to the enforcing authority. The Care Quality Commission received 611 statutory notifications of significant accidental and unintended radiation exposures in the year ending 2022, across all providers. A practice needs to reconstruct what happened, which means IT support for dental practices has to keep the imaging audit log alive for the life of the record.

Training records are part of the evidence

Regulation 6 requires continuing education and training after qualification for everyone involved in exposures. Those certificates are staff records under Regulation 17(2)(d) as well, so they need the same retention, access control and retrieval treatment as anything else — not a folder on the practice manager’s desktop.

Quality assurance produces data that must be kept

Routine image quality audits, sensor checks and reject analysis generate records that demonstrate the programme exists. Storing them inside the document management that IT support for dental practices already runs, rather than in a spreadsheet on one machine, is a five-minute decision with a ten-year consequence.

Multi-Site Groups: What Changes When IT Support for Dental Practices Scales

With 945 providers running more than one location and 1,400 locations inside the twenty largest groups, a meaningful slice of the market is buying for an estate rather than a building. Almost everything above still applies at that scale, and four things change.

IT support for dental practices at scale means one tenant, many sites

Groups that grew by acquisition typically inherit a Microsoft 365 tenant per practice, each with its own domain, its own licences and its own administrator. Consolidating to one tenant with site-based groups is the single highest-value project available to IT support for dental practices in a growing group, and it gets harder with every acquisition.

The toolkit is per organisation, not per site

How a group submits depends on how its NHS contracts are held. Getting that structure right early avoids either duplicated effort across sites or a single submission that cannot evidence what happens in each building. It is worth confirming with the commissioner rather than assuming.

Standardise the practice management system or accept the cost

Running three different clinical systems across four sites means three integration maps, three backup designs, three training programmes and no group-level reporting. Consolidation is expensive and disruptive; not consolidating is expensive and permanent. Either way it is a change management exercise before it is a technical one, and whichever is chosen should be a decision, not a drift.

Acquisition due diligence is a technology exercise

Before buying a practice, establish which practice management system it runs, whether the data can be exported, how many years of records exist, whether the toolkit is current, whether records were ever migrated from an older system, and what happens to the seller’s email. The answers change the price, and someone technical should be in the room when they are asked.

Central monitoring, local hands: co-managed IT support for dental practices

The workable group model is co-managed: central identity, central backup, central security monitoring and central procurement, with a defined route for a practice manager to get someone on site quickly. Uniform device management across every site is what makes the central half of that possible.

What to Ask a Provider of IT Support for Dental Practices

Most providers will say yes to everything on a first call. These questions have answers that are either specific or absent, and for IT support for dental practices the difference tells you everything you need to know.

Ask about the practice management system by name

“Which version of our practice management system are we on, and what does the vendor support boundary cover?” A provider of IT support for dental practices that cannot answer this in the first month is supporting the office, not the practice. It is the single most diagnostic question on this list.

Ask when the last restore test was, and what was restored

Not “do you back us up” — everyone says yes. Ask for the date of the last test, what was recovered, how long it took and who witnessed it. Ask specifically whether a radiograph was restored, because imaging is the part of IT support for dental practices most often left outside the backup set.

Ask who completes the toolkit and what happens if it fails

Establish whether the provider completes the submission, contributes evidence to it, or simply hopes the practice manager does it. Given 45 mandatory items and a 30 June deadline tied to the NHS contract, “we help where we can” is not an answer.

Ask how many dental practices they actually support

Sector experience is not a marketing claim here, it is the difference between a provider who has migrated an imaging archive and one who has not. Ask for the number, the systems, and whether they have ever moved a practice between practice management vendors.

Ask what happens at 8am on a Monday

Response times mean nothing without context. Ask what IT support for dental practices does when the diary will not open at five to eight with a full day booked: who answers, how fast, what they do first, and what the escalation looks like at fifteen minutes.

Ask what the exit looks like

Notice period, data return format, documentation handover, administrative credentials and how long transition support lasts. A provider comfortable with that conversation is usually comfortable being measured. Our guide to switching providers covers the same ground from the other direction.

SectionWhat it measuresWeightFails below
Clinical system competenceNamed product, version, support boundary, integrations2513
Backup and restore evidenceTested restores, immutability, imaging included2010
Compliance supportToolkit, CQC evidence, IR(ME)R documents, retention2010
Security controlsMFA, conditional access, segmentation, patching158
ResponsivenessStart-of-day cover, escalation, on-site route105
Commercials and exitTransparent pricing, notice, data return, handover105

Scoring the hundred points

Score each section out of its weight, add them up, and set the pass mark at 70. Any section scoring below half its weight is a fail regardless of the total, because the failure modes in IT support for dental practices are not additive — perfect responsiveness does not compensate for an untested backup against an eleven-year retention obligation.

Costing IT Support for Dental Practices

Pricing varies by region, estate and scope, so what follows is a structure rather than a rate card. The important part is knowing which costs of IT support for dental practices are per user, which are per site, which are per system and which are one-off.

Per-user costs scale with headcount

Microsoft 365 licences, endpoint protection, backup for cloud data, security awareness training and the support element itself generally price per user. For the worked example that is 58 users, and the licensing shape chosen earlier moves the annual figure between £8,366.40 and £17,121.60 before any support fee.

Per-site costs scale with buildings

Firewalls, network equipment, a second broadband circuit, on-site server hardware and network segmentation price per building. Four practices means four of everything, which is why the group economics of IT support for dental practices are worse than headcount alone suggests and why estate consolidation projects pay back slowly.

Per-system costs scale with complexity

Practice management hosting, imaging archive storage, integration maintenance and the toolkit submission are per system or per organisation. The imaging archive in particular grows on the curve modelled earlier, so IT support for dental practices should price it as a growing line rather than a fixed one.

One-off costs are where the estate gets fixed

Tenant consolidation, a practice management migration, network segmentation, an identity clean-up or a first toolkit submission are projects, not service lines. Bundling them into the monthly fee makes both sides unhappy; quoting them separately with a defined outcome is how they actually get done.

What good value in IT support for dental practices looks like

The right benchmark is not the lowest monthly fee. It is whether the provider can produce, on request, a restore test report, a current asset list, a toolkit evidence pack and a leavers log. A practice paying slightly more for IT support for dental practices that produces those four artefacts is buying the thing it actually needs.

Where automation genuinely helps IT support for dental practices

Recall messaging, appointment confirmation, document filing and clinical note dictation — which increasingly uses natural language processing to turn spoken notes into structured text — are all candidates for automation. Each removes reception keystrokes rather than clinical judgement, which is the right side of the line.

A 90-Day Plan for IT Support for Dental Practices

Nothing above needs to happen at once, and trying to do it at once is how practices end up doing none of it. This is the order in which IT support for dental practices resolves the most risk soonest.

Days 1 to 30: IT support for dental practices starts with an inventory

Inventory every system, every device and every account. Establish the practice management version and hosting model, the imaging archive location and size, who holds administrative credentials, and when the backup was last restored. IT asset management starts here: produce a written asset list and a leavers log. Nothing in this first month costs money.

Days 31 to 60: close the identity gaps

Retire shared clinical logins, enable multi-factor authentication on everything internet-facing, delegate the NHSmail shared mailbox to named accounts, remove standing vendor administrator access and reconcile licences against tools already paid for. This is the block that removes the most risk per pound spent.

Days 61 to 90: prove the recovery and the evidence

Run a real restore including a radiograph, write the one-page incident plan, run a half-day on paper, complete or refresh the toolkit submission and assemble the CQC and IR(ME)R evidence pack. At the end of this, IT support for dental practices can answer any inspector’s records question with an artefact rather than an assurance.

After 90 days: the recurring rhythm of IT support for dental practices

Quarterly restore tests, monthly licence and leaver reconciliation, annual toolkit submission, annual paper-day rehearsal and an annual review of the retention and disposal schedule. That rhythm is what IT support for dental practices should look like once the backlog is cleared, and it is what keeps the estate from drifting back.

The one thing to do first

If you only do one thing after reading this, ask your current provider for the date and contents of the last successful restore test — and ask specifically whether a radiograph was included. The answer to that question predicts almost everything else about the quality of IT support for dental practices you are receiving.

References and Further Reading