Anthropomorphic dogs and a tooth character in a meeting room reviewing a checklist with dental and tech icons.

What Should Be Included in a Quarterly IT Review for a Dental Practice?

July 24, 2026

What Should a Dental Practice Review With Its IT Provider Every Quarter?

A dental practice should review at least seven areas every quarter: cybersecurity risks, backup recovery, HIPAA-focused safeguards, recurring support issues, aging technology, vendor access and upcoming business changes.

A useful quarterly IT review should take approximately 45 to 90 minutes and produce three clear outcomes:

  1. A list of the practice’s top three technology risks
  2. A prioritized 90-day action plan
  3. An updated one-to-three-year technology budget

The meeting should not be a technical presentation filled with alerts, ticket counts and product names. Practice leadership should leave knowing what needs attention, what could interrupt patient care, how much recommended improvements may cost and who is responsible for each next step.

The most effective approach follows a seven-part Dental IT Leadership Review Framework: assess security, prove recovery, verify access, examine support performance, review technology health, prepare for business changes and document decisions.

The Seven-Part Dental IT Leadership Review Framework

1. Identify the Top Three Cybersecurity Risks

Every quarterly review should begin with a direct question: What are the three most important cybersecurity risks facing the practice today?

The IT provider should not respond with a generic statement that everything is secure. It should identify specific findings, affected systems, potential business impact and recommended corrective actions.

Examples may include:

  • Microsoft 365 accounts without multi-factor authentication
  • Unsupported workstations
  • Missing security updates
  • Former employee accounts that remain active
  • Unmanaged vendor remote-access software
  • Security protection missing from one or more devices
  • Weak administrative account controls
  • Backups accessible from normal user accounts
  • Guest Wi-Fi connected to business systems
  • Unresolved phishing or suspicious-login alerts

Each risk should be assigned:

  • A severity level
  • A responsible owner
  • A recommended deadline
  • An estimated cost
  • A temporary safeguard when immediate remediation is not possible

A useful discussion distinguishes among urgent, near-term and planned improvements.

Priority Expected Action Example
Critical Address immediately or within 30 days Compromised account, failed security agent or exposed remote access
High Resolve during the next quarter Unsupported clinical workstation or incomplete multi-factor authentication
Planned Include in the technology roadmap Firewall replacement or network segmentation project

Review cybersecurity services for more information about layered protection for dental practices.

2. Prove That Backups and Recovery Work

Leadership should not ask only whether backups completed successfully. The more important question is: When did we last prove that our critical systems could be restored?

The quarterly review should confirm the protection status of:

  • Dentrix, Eaglesoft or Open Dental databases
  • Dental images
  • Patient documents
  • Server configurations
  • Shared business files
  • Microsoft 365 information
  • Cloud applications
  • Accounting and administrative data

The provider should report:

  • Backup-job success rate
  • Unresolved backup failures
  • Date of the most recent restore test
  • Systems included in the test
  • Recovery time achieved
  • Data-loss exposure
  • Backup retention
  • Location and isolation of backup copies

Two numbers should be clearly defined:

  1. Recovery Time Objective: The longest acceptable period a critical system can remain unavailable.
  2. Recovery Point Objective: The maximum amount of recent data the practice can afford to lose.

For example, a practice may determine that its patient schedule and dental database should be recoverable within four hours with no more than one hour of recent data loss. Those business requirements should guide the backup technology and testing process.

If the provider cannot explain how long recovery would take, the practice has a backup process but not a complete business continuity plan.

Learn more about business continuity and disaster recovery services and backup and recovery planning for dental practices.

3. Verify User, Administrator and Vendor Access

Employee roles, vendors and technology change throughout the year. Access that was appropriate three months ago may no longer be necessary.

The quarterly review should examine:

  • Active employee accounts
  • Former employee accounts
  • Shared accounts
  • Administrative privileges
  • Microsoft 365 access
  • Remote-access accounts
  • Vendor accounts
  • Cloud application permissions
  • Inactive accounts
  • Multi-factor authentication coverage

The provider should be able to answer:

  1. Were all recently terminated employees removed promptly?
  2. Do employees have individual accounts?
  3. Who currently has administrative privileges?
  4. Which vendors can access servers or workstations remotely?
  5. Are any accounts inactive but still enabled?
  6. Which accounts do not have multi-factor authentication?
  7. Are access changes documented?

Access should follow the principle of least privilege. Employees and vendors should receive only the permissions required for their responsibilities.

The practice should also review the onboarding and offboarding process. Routine new-user requests may require three to five business days of notice, while an unexpected termination may require immediate coordination.

Access reviews support the practice’s broader technical safeguards. Explore HIPAA compliance services for additional guidance.

4. Examine Help Desk Performance and Recurring Problems

Ticket volume alone does not show whether IT support is effective. A practice can have a low ticket count because employees have stopped reporting problems, or a high count because the same issue keeps returning.

The quarterly review should examine:

  • Number of support requests
  • Most common request categories
  • Critical and high-priority incidents
  • Average initial response time
  • Tickets requiring escalation
  • Issues reopened after closure
  • Recurring workstation or application problems
  • Employee satisfaction
  • After-hours requests
  • Onsite service activity

The provider should identify the top three recurring issues and explain how each will be permanently reduced.

Examples may include:

  • A treatment-room workstation that repeatedly freezes
  • Frequent password resets
  • Unstable Wi-Fi in one part of the office
  • Recurring printer or scanner failures
  • Repeated Dentrix or imaging connection problems
  • Slow server performance
  • Microsoft 365 sign-in issues

A managed IT provider should look for patterns rather than treating every ticket as an isolated event.

For example, six tickets involving one imaging workstation may indicate failing hardware, insufficient capacity or an incompatible software configuration. Repeatedly restarting the computer may close individual tickets without resolving the underlying risk.

Leadership should ask:

  • What issue created the most employee downtime this quarter?
  • Which problem is most likely to return?
  • Which device generated the most support requests?
  • Which issue requires a permanent project rather than additional troubleshooting?
  • Are employees receiving timely updates during longer incidents?

Explore managed IT services for information about proactive monitoring, help desk support and recurring-issue management.

5. Review Technology Age, Health and Support Status

The practice should receive a current view of equipment approaching replacement or vendor end-of-support dates.

The quarterly review should cover:

  • Workstation age
  • Server warranty and support status
  • Firewall lifecycle
  • Network switch and Wi-Fi condition
  • Battery backup health
  • Available server storage
  • Operating-system support
  • Dental software compatibility
  • Imaging workstation requirements
  • Recurring hardware alerts

Equipment should be grouped into three categories:

  1. Replace now: Unsupported, failing or creating significant clinical and security risk
  2. Replace within 12 months: Approaching warranty expiration, capacity limits or software incompatibility
  3. Monitor and budget: Currently reliable but expected to require replacement in one to three years

Typical planning ranges may include:

Technology Planning Range
Business workstations 3 to 5 years
Servers 4 to 6 years
Firewalls 4 to 6 years
Wireless access points 4 to 6 years
Network switches 5 to 7 years
Battery backups 3 to 5 years

These are budgeting ranges rather than fixed expiration dates. Support status, business impact, performance and vendor requirements matter more than age alone.

The provider should give leadership enough notice to plan purchases rather than presenting every replacement as an emergency.

6. Prepare for Upcoming Business and Clinical Changes

Technology planning should follow the practice’s business plan. The IT provider cannot prepare effectively when it learns about major changes immediately before implementation.

Discuss planned changes during every quarterly review, including:

  • Hiring dentists or employees
  • Opening another location
  • Adding operatories
  • Purchasing a practice
  • Moving offices
  • Changing dental software
  • Upgrading imaging systems
  • Adding CBCT or intraoral scanning
  • Changing phone or internet providers
  • Starting construction
  • Adopting a new cloud application
  • Expanding remote work

Many technology projects require more lead time than leadership expects.

For example, opening a new location may require:

  • Internet service ordering
  • Cabling
  • Firewall and network equipment
  • Workstations
  • Dental software coordination
  • Imaging integration
  • Phone configuration
  • Backup design
  • Security controls
  • Testing before the first patient arrives

Internet installation alone may depend on carrier availability, construction and permits. Discussing the project six months in advance creates more options than notifying the IT provider two weeks before opening.

The quarterly meeting should record every expected change, the desired completion date, lead time, estimated cost and responsible owner.

7. Document Decisions and the 90-Day Action Plan

A quarterly review has little value when recommendations are discussed but never assigned or completed.

Every meeting should end with a written action plan containing:

  • The issue or opportunity
  • Business impact
  • Recommended action
  • Priority
  • Responsible person
  • Estimated cost
  • Target completion date
  • Current status

A practical plan should contain no more than three to seven major priorities for the quarter. A list of 40 recommendations without ranking or ownership creates confusion rather than progress.

Priority Action Owner Deadline
Critical Enable multi-factor authentication for remaining administrator accounts IT provider Within 14 days
High Replace three unsupported clinical workstations Practice manager and IT provider Within 60 days
High Complete a dental database recovery test IT provider Within 30 days
Planned Prepare server replacement options and budget IT provider Before next quarterly review

The next quarterly review should begin by revisiting the previous action plan. Unfinished items should not disappear merely because a new report has been created.

What Reports Should the IT Provider Present?

A quarterly IT report should be understandable to dentists, practice owners and office managers who are not technology specialists.

Useful reporting may include:

  • Executive summary
  • Top three current risks
  • Previous-quarter action status
  • Critical security findings
  • Multi-factor authentication coverage
  • Workstation and server protection coverage
  • Patch and update status
  • Backup and recovery results
  • Help desk trends
  • Recurring problems
  • Equipment lifecycle summary
  • Upcoming projects
  • Budget forecast

The report should explain the business meaning of each finding.

For example, “server storage is 91% utilized” is a technical fact. A leadership-ready explanation would state that continued database and imaging growth could cause application errors or downtime within the next quarter unless capacity is expanded.

What Metrics Should a Dental Practice Track?

Track a focused set of metrics that shows whether risk and performance are improving.

Metric What It Reveals
Multi-factor authentication coverage Whether important accounts are protected against stolen passwords
Managed endpoint coverage Whether every supported computer and server has active security protection
Critical patch compliance Whether important security updates are being completed
Backup success and restore testing Whether protected systems are recoverable
Unsupported-device count How many systems create lifecycle or security risk
Critical incident count How often major disruptions affected the practice
Recurring-ticket count Whether underlying problems are being permanently resolved
Initial response time How quickly the support process begins
Open high-priority recommendations Whether important risk-remediation work is progressing

A metric should lead to a decision. Reports containing hundreds of alerts without priorities can make the environment appear well monitored while leaving leadership unsure what to do.

Six Questions Every Dental Practice Should Ask Quarterly

  1. What are our top three technology and cybersecurity risks today?
  2. When did we last prove that our critical systems could be restored?
  3. Which recurring IT problems are costing employees the most time?
  4. Who has access to patient information, administrative systems and remote connections?
  5. What equipment or software must be replaced during the next 12 months?
  6. What business changes should IT begin planning for now?

These questions force the discussion to focus on evidence, accountability and preparation rather than reassurance.

Read six questions smart dental practices ask their IT provider every quarter for an additional review checklist.

What Are the Red Flags in a Quarterly IT Review?

Everything Is Reported as Green

No environment is permanently risk-free. A report showing no concerns quarter after quarter may indicate that the provider is not looking deeply enough or is avoiding difficult recommendations.

The Provider Cannot Prove Recovery

Backup success notifications are not the same as documented restore tests.

Technical Data Is Presented Without Business Impact

Leadership should understand whether a finding could cause downtime, data loss, security exposure or unexpected cost.

Recurring Tickets Are Not Discussed

The same issue appearing repeatedly should trigger root-cause analysis and a permanent remediation plan.

Old Recommendations Disappear

Unresolved high-priority items should remain visible until leadership accepts, completes or formally defers them.

There Is No Technology Budget

The provider should forecast likely hardware, software and infrastructure needs before they become emergencies.

Vendor Access Is Unknown

The practice should know which dental, imaging, payment and support vendors can connect remotely.

No One From Practice Leadership Attends

The meeting requires someone with authority to approve priorities, budgets and operational changes.

The Review Is Only a Sales Presentation

Recommendations should be connected to documented risk and business goals rather than a list of products the provider wants to sell.

Who Should Attend a Dental IT Review?

The meeting should include people who understand the practice’s operations, technology and decision-making process.

Participants may include:

  • Practice owner
  • Lead dentist
  • Practice manager
  • Operations leader
  • Compliance or privacy contact
  • Managed IT account manager
  • Technical lead or vCIO

Not every participant must attend the entire meeting. However, someone with budget authority and someone who understands day-to-day workflow should participate.

For larger practices, the office manager may provide operational feedback while the owner or executive approves the roadmap and budget.

How Long Should a Quarterly IT Review Take?

A well-prepared review for a 25-to-50-employee dental practice may take approximately 45 to 90 minutes.

A practical agenda might be:

Agenda Item Suggested Time
Previous action items 10 minutes
Security and access risks 15 minutes
Backup and recovery 10 minutes
Support trends and recurring issues 10 minutes
Equipment lifecycle and budget 15 minutes
Upcoming business changes 10 minutes
Decisions and next actions 10 minutes

The provider should distribute the report early enough for leadership to review it before the meeting.

How Is a Quarterly Review Different From a HIPAA Risk Assessment?

A quarterly IT review is an ongoing leadership and planning meeting. It examines operational performance, security trends, recovery readiness, technology lifecycle and business changes.

A security risk assessment is a deeper examination of risks to sensitive information and the safeguards used to address them.

The two processes support each other but are not interchangeable.

Quarterly IT Review Security Risk Assessment
Usually conducted every three months Conducted periodically and after significant changes
Focuses on current performance and priorities Focuses on identifying and evaluating security risks
Reviews support, projects and budgets Reviews safeguards, threats, vulnerabilities and remediation
Creates a 90-day action plan Creates or updates a risk-management plan

Quarterly reviews should track the status of important remediation items identified through previous assessments.

How Should Multi-Location Dental Groups Conduct Reviews?

A multi-location dental group should review both the overall organization and individual office performance.

The report should identify:

  • Security controls consistent across all locations
  • Location-specific risks
  • Internet and network performance
  • Equipment requiring replacement
  • Recurring support issues by office
  • Vendor differences
  • Backup and recovery coverage
  • Standardization opportunities
  • Upcoming location openings or expansions

A group may discover that one office has current workstations and secure Wi-Fi while another uses unsupported systems and unmanaged network equipment.

Standardization should address:

  • Approved workstation specifications
  • Firewall and network platforms
  • Security controls
  • Microsoft 365 configuration
  • Backup policies
  • Onboarding and offboarding
  • Vendor remote access
  • Technology replacement cycles

A Realistic Quarterly Dental IT Review

Consider a 32-employee dental practice using Dentrix, Microsoft 365, digital imaging and an onsite server.

During its quarterly review, the provider reports:

  • Two former employee accounts remain active in a cloud application
  • Three treatment-room computers are approaching end of support
  • One backup job failed twice during the quarter
  • A successful database restore test was completed in 52 minutes
  • Wi-Fi instability generated eight support requests
  • The server warranty expires in nine months
  • The practice plans to add two operatories during the next six months

The resulting 90-day plan includes:

  1. Disable the two former employee accounts immediately
  2. Investigate and permanently correct the backup failures
  3. Replace the three unsupported workstations within 60 days
  4. Complete a wireless site review and propose improvements
  5. Prepare server replacement and cloud-hosting options
  6. Design the network, cabling and workstation requirements for the new operatories

The meeting converts several disconnected technical findings into a prioritized business plan.

What Should a Dental Technology Budget Include?

The quarterly review should maintain a rolling one-to-three-year budget that includes both recurring and project costs.

Recurring expenses may include:

  • Managed IT services
  • Microsoft 365 licenses
  • Cybersecurity tools
  • Backup and recovery services
  • Internet and phone services
  • Dental software subscriptions
  • Cloud hosting

Project expenses may include:

  • Workstation replacement
  • Server replacement
  • Firewall and network upgrades
  • New-location technology
  • Dental software migrations
  • Imaging upgrades
  • Cloud projects
  • Security remediation
  • Cabling

Each expected investment should include a target quarter, estimated cost range and business reason.

For example, rather than listing “replace server,” the roadmap should state that the server warranty expires in nine months, current storage will reach capacity within approximately one year and the practice should compare replacement and cloud options during the next quarter.

How Should the Practice Evaluate Its IT Provider During the Review?

The quarterly meeting is also an opportunity to determine whether the provider is delivering the promised service.

Ask:

  • Are urgent requests receiving an appropriate response?
  • Are employees kept informed?
  • Are recurring problems being permanently resolved?
  • Are backups tested?
  • Are security findings clearly explained?
  • Are recommendations prioritized?
  • Are projects planned before they become emergencies?
  • Does the provider understand dental software and workflows?
  • Does it coordinate effectively with other vendors?
  • Are invoices consistent with the agreement?

If the provider cannot supply meaningful reporting, recovery evidence or a technology roadmap, the relationship may be limited to reactive support.

Learn how to switch IT providers without disrupting patient care when recurring service gaps remain unresolved.

Why Dental Practices Choose 911 IT for Strategic Reviews

911 IT helps dental and healthcare organizations connect technical findings to patient care, employee productivity, cybersecurity and long-term budgeting.

Quarterly strategic reviews can include:

  • Cybersecurity risk prioritization
  • Backup and recovery validation
  • Help desk trend analysis
  • Employee and vendor access reviews
  • Equipment lifecycle planning
  • Dentrix, Eaglesoft and Open Dental coordination
  • Microsoft 365 planning
  • HIPAA-focused technical safeguards
  • Technology budgeting
  • New-location and expansion planning
  • A documented 90-day action plan

“They don’t just fix problems; they prevent them, which gives us real confidence in our IT operations.”

— Health and research client

“When hiring 911 IT, we didn’t realize it would be like having an in-house IT department without the overhead cost that comes with an in-house department. They are part of our team.”

— Owner and 911 IT client

Explore healthcare IT support, managed IT services and Salt Lake City IT support.

Frequently Asked Questions About Quarterly Dental IT Reviews

How often should a dental practice meet with its IT provider?

Quarterly meetings are a practical baseline for reviewing cybersecurity, backups, support performance, equipment and upcoming changes. High-growth or multi-location practices may need more frequent planning meetings.

Who should lead the quarterly IT review?

The provider’s strategic account manager or vCIO should guide the review, while the practice owner or manager makes business and budget decisions.

Should the provider charge separately for quarterly reviews?

Some managed IT agreements include strategic reviews, while others price them separately. Confirm the frequency, attendees, reports and planning services included in the agreement.

What is the most important quarterly IT question?

Ask the provider to identify the top three current risks and provide evidence supporting each answer. This creates focus and accountability.

Should ticket counts be included?

Yes, but ticket totals should be paired with recurring issues, response performance, business impact and permanent corrective actions.

How often should backups be tested?

The testing schedule should reflect the importance and complexity of each system. Critical dental databases and server recovery should be tested through documented restoration rather than relying only on automated backup reports.

Should cybersecurity be discussed every quarter?

Yes. Accounts, devices, vendors, threats and configurations change throughout the year, so security should not be reviewed only once annually.

How far ahead should technology budgeting look?

Maintain at least a one-year detailed budget and a broader three-to-five-year lifecycle roadmap for major equipment and infrastructure.

What happens when leadership rejects a recommendation?

The provider should document the decision, explain the risk, recommend temporary safeguards and establish a date for reconsideration.

Should every employee attend the review?

No. Include the practice leaders who understand operations, compliance and budgeting. Employee feedback can be collected before the meeting.

What should happen after the meeting?

The provider should distribute the action plan, begin approved work and provide progress updates. The next review should begin by examining the status of those commitments.

Schedule a Dental IT Leadership Review

A quarterly review should give dental practice leadership more than reassurance. It should provide evidence of security, proof of recovery, visibility into recurring problems and a clear plan for upcoming investments.

911 IT can evaluate your current technology, identify priority risks and build a practical 90-day action plan around your dental software, employees, locations and growth plans.

To discuss a dental IT review, schedule a discovery call or contact 911 IT.