Switching dental IT providers can be completed with minimal disruption when a practice inventories every system, confirms ownership of administrator credentials, validates a recoverable backup, assigns vendor responsibilities, and completes the final cutover outside patient hours. The safest transition is planned before the former provider's access is removed.
This article is only about the transition itself. If you are still deciding whether to change at all, or comparing candidates and pricing, those questions are covered separately in our dental IT provider evaluation guide and the dental IT support cost guide.
Key takeaways
- Do the discovery and documentation work before you give notice, not after.
- Administrator ownership of tenants, domains, backups, and security tools belongs with the practice, not with any provider.
- A backup is only useful if a test restore has been documented; assume nothing.
- Cutover work belongs outside patient hours, with written rollback criteria.
- Old remote access should be removed on a defined schedule once the new environment is verified.
When switching becomes the safer option
Changing providers carries real risk, so the reason should be structural rather than a single bad week. Common signals that the current arrangement has stopped working:
- The same tickets keep reappearing without a root-cause fix.
- Nobody can say clearly who owns the Microsoft 365 tenant, the domain, or the firewall.
- There is no evidence of a successful restore test, only assurances that backups run.
- HIPAA and security documentation is thin, out of date, or absent.
- Vendor coordination keeps landing on the office manager instead of the provider.
- The practice has grown, added locations, or added imaging that the current provider cannot support.
If you are still weighing whether the problems are severe enough, 10 signs your dental office needs IT support covers the operational symptoms in more detail.
The four transition risks to control
Almost every difficult provider change traces back to one of four issues.
Loss of administrative access. If the outgoing provider holds the only global administrator account for a tenant, or the only firewall credential, the practice is negotiating from a weak position.
Unverified backups. Recovery assumptions that have never been tested are the single most expensive item on this list. Validate before anything changes.
Clinical disruption. Imaging acquisition, the practice management database, phones, internet, and claims submission all depend on network and identity settings that a rushed cutover can break.
Residual access. Remote access tools, VPN accounts, and management agents belonging to the former provider can outlive the contract. Under HIPAA, access to protected health information must be governed and revoked deliberately; see the HHS Summary of the Security Rule and the guidance on covered entities and business associates.
Before giving notice: dental IT ownership checklist
Work through this list while the current relationship is still normal. The goal is to confirm that the practice owns or controls each item, or has documented access to it. Credentials themselves should be exchanged through a password manager or another secure channel, never by email and never written into this checklist.
| Owner | Item | Verified | Notes |
|---|---|---|---|
| Practice | Microsoft 365 or Google Workspace tenant | Global admin held by the practice | |
| Practice | Domain name and DNS registrar | Registrar login, not provider-held | |
| Practice | Internet provider account and static IP details | Circuit ID, account number | |
| Practice | Firewall, switches, Wi-Fi, VPN | Admin access, config backups | |
| Practice | Servers, hypervisors, workstations | Local admin, BIOS, encryption | |
| Practice | Backup platform, encryption keys, retention, restore reports | Keys stored by the practice | |
| Practice | Practice-management and imaging vendor portals | Account owner on file | |
| Practice | EDR or antivirus, email security, MFA, password manager | Tenant ownership and license count | |
| Practice | VoIP and phone portal | Number ownership, porting contact | |
| Practice | Cloud applications and billing ownership | Cards and invoices in practice name | |
| Practice | Line-of-business vendors and support PINs | Authorized contacts list | |
| Practice | Network diagrams, asset inventory, warranties, licenses | Current as of the transition date |
Anything you cannot verify becomes a task in the transition plan rather than a surprise on cutover night.
A seven-step dental IT provider transition plan
Step 1: confidential current-state discovery. The incoming provider documents the network, servers, workstations, identity platform, imaging, backups, and security tooling. This can be done without touching the incumbent relationship.
Step 2: confirm contracts, notice periods, BAAs, and data-return obligations. Read the existing agreement for notice windows, offboarding fees, and what documentation and data must be returned. HHS has published guidance on whether a business associate may block or terminate access to PHI; it is worth reading before any dispute begins.
Step 3: validate backups with documented test restores before changes. Restore a representative set of data, including the practice-management database and imaging, and record the date, scope, and result. NIST's guidance on protecting data from ransomware and data loss is a reasonable reference for what testing should cover. Our backup and disaster recovery page describes how this is handled in practice.
Step 4: map dental vendors and escalation contacts. Practice management, imaging, sensors and CBCT, claims clearinghouse, e-prescribing, payment terminals, and the internet provider each need a named contact and an authorized caller on file.
Step 5: stage security tools and remote support without conflicting agents. Two endpoint protection products or two remote-monitoring agents on the same workstation cause more outages than they prevent. Sequence installation and removal deliberately.
Step 6: perform the cutover after patient hours with rollback criteria. Write down in advance what "good" looks like, what triggers a rollback, and who makes that call.
Step 7: remove old access and validate every clinical workflow. Revoke former-provider accounts, VPN profiles, and management agents on a scheduled basis once the new environment is confirmed working.
What to test the next morning
Have someone walk the building before the first patient. Test at each operator and at the front desk. These are workflow checks; they do not imply that any specific software vendor is supported under contract.
- Staff logins and multifactor authentication.
- The practice management system: Dentrix, Eaglesoft, Open Dental, or whichever platform the practice runs.
- Imaging acquisition from each sensor and retrieval of prior images.
- Printers, scanners, and card terminals.
- Claims submission, e-prescribing, and patient messaging.
- Phones, voicemail, and call routing.
- Backup job status and monitoring alerts.
- Remote access and a live vendor support call.
Anything that fails should go straight into the ticket queue with an owner, not into a group chat. Day-one issues are normal; unowned day-one issues are not. Ongoing coverage for this kind of work is described on our help desk page.
Questions to ask the incoming provider before signing
Selection criteria are covered in the provider evaluation guide. These questions are specifically about how the transition will be executed.
- Who owns the onboarding project, and who is the day-to-day contact?
- What do you need from the incumbent, and what happens if you do not get it?
- How do you verify backups and restore capability, and what evidence do we receive?
- How do you coordinate with dental software and imaging vendors?
- How are privileged credentials transferred and stored afterward?
- What is the rollback plan if cutover does not go as expected?
- When is the old provider's remote access removed, and who confirms it?
- What documentation will the practice own at the end of onboarding?
- Will you sign a business associate agreement where applicable?
- What does the first 30 days include, and what is out of scope?
Budget questions belong alongside these. The dental IT support cost guide sets out how onboarding is usually priced relative to ongoing managed IT services.
30-day post-transition stabilization plan
Day 1. Confirm monitoring is reporting from every endpoint and server. Triage anything raised during the morning walkthrough. Verify the first backup job under the new configuration.
Week 1. Review ticket volume and themes daily. Apply the security and patching baseline. Produce the first documented restore test under the new provider. Close out any credential handovers still outstanding.
Days 8 to 30. Clean up the asset inventory and network documentation. Review staff accounts and remove former employees and stale service accounts. Confirm licensing counts match reality. Deliver a written roadmap listing the priority risks found during onboarding, with rough sequencing. Practices with compliance obligations should also confirm the safeguards documentation is current; see HIPAA compliance support.
CISA's risk considerations for MSP customers is a useful checklist for the access and oversight questions that should be settled during this window.
Why dental-specific transition experience matters
A dental transition is not a generic office migration. The practice management database, imaging software, sensors and CBCT units, the claims path, VoIP, and the network all interact, and each has its own vendor with its own authorization process. Imaging in particular is sensitive to workstation, driver, and share-path changes that are invisible on a spreadsheet.
Scheduling matters just as much. Cutover windows have to fit around patient hours, and the acceptable amount of morning disruption is close to zero. A provider that has done this in dental environments plans the sequence around the schedule rather than around convenience. Our dental IT support page covers what that coverage looks like day to day.
Planning to Change Dental IT Companies?
Legend Networking can review your current environment, identify transition dependencies, and build a phased takeover plan before any access is changed. You keep the findings whether or not you move forward.
Frequently Asked Questions
Can a dental practice switch IT providers without downtime?
Most of the work can be staged with no patient impact, and the disruptive steps can be scheduled outside patient hours. No provider can guarantee zero downtime, but planning, tested backups, and a rollback plan keep the exposure small and short.
Who should own the administrator credentials?
The practice. Tenants, domains, backup platforms, security tools, and network devices should be owned by the practice, with the provider holding delegated administrative access that can be revoked.
Should we tell our current IT provider before choosing a replacement?
Complete discovery, contract review, and backup validation first. Giving notice before the plan exists shortens the window in which you can gather documentation and confirm ownership.
What happens if the former provider will not release documentation?
Start from the contract and any business associate agreement, which usually address data return and offboarding. HHS has published guidance on business associates blocking or terminating access to PHI. In parallel, the incoming provider can rebuild documentation from the environment itself, which takes longer but does not depend on cooperation.
How long does a dental IT provider transition take?
It depends on the number of locations, the state of the documentation, and vendor response times. Discovery and preparation usually take longer than the cutover itself, and stabilization continues through the first month.
Does a new IT provider need a business associate agreement?
If the provider creates, receives, maintains, or transmits protected health information on behalf of the practice, a business associate agreement applies. HHS explains the covered entity and business associate relationship in its published guidance.
When should the old provider's remote access be removed?
On a scheduled basis once the new environment has been verified working, not before and not indefinitely afterward. Removal should include remote support tools, VPN accounts, management agents, and any shared administrative accounts.

