Guide
Dental office data backup: a practical guide
A sound dental office data backup plan lets you restore patient records, images and billing data after a failed drive, a power surge or a ransomware attack. This guide covers what to protect, the 3-2-1 rule, testing restores and keeping a copy where ransomware cannot reach it.
Your schedule, charts, X-rays, insurance claims and ledgers all live on computers that will fail sooner or later. Drives wear out, laptops get dropped, a power surge reaches the server closet, or someone opens the wrong email attachment. A good backup turns each of those from a crisis into an inconvenience.
The right setup depends on your software, computers and workflow, but the principles below apply in any practice.
What to include in your dental office data backup
Start with a list of everything your practice would need to reopen the day after a disaster. It usually falls into five groups.
Practice management database
This is the heart of the office: patient records, the schedule, treatment plans and clinical notes. It usually lives in a database on the office server; if your software is hosted online, ask the vendor how your data is backed up and how you could get a copy. Copying database files while the software is running can produce a backup that will not open, so use a method your practice software supports, such as its own backup tool.
Patient images and documents
X-rays, intraoral photos, scanned consent forms and referral letters often sit in folders separate from the main database, sometimes on a different computer. They are easy to miss, so find out where your software stores them and include every location.
Billing and accounting data
Claims, payments, ledgers and any separate accounting or payroll files. If billing runs in a different program from your practice software, list it as its own item so it is not assumed to be covered.
Email and shared files
Office email, shared folders on the server and files saved to individual desktops. Ask your team to save work to backed-up shared folders rather than their own computer.
Configuration and setup details
Software license keys, network, Wi-Fi and router settings, and a list of which programs run on which computer. Without these, rebuilding a failed server takes far longer, even when the data is safe.
The 3-2-1 backup rule for dental offices
The 3-2-1 rule is a widely used rule of thumb, designed so that no single event can wipe out every copy of your data.
- Three copies of your data: the live data on your server plus at least two backups.
- Two different kinds of storage: for example, a backup device in the office plus an online backup service or removable drives, so one hardware fault or software problem cannot ruin every copy.
- One copy away from the office, so a fire, flood or break-in at the practice does not take your backups with it.
A backup drive next to the server, on the same outlet, covers a failed server drive, but one surge, fire or theft can take both at once. The copy away from the office is the one that gets you running again.
- Office server
- Backup
- Away from the office
The 3-2-1 backup ruleIn short
- Three copiesYour live data plus at least two backups
- Two kinds of storageSo one fault cannot ruin every copy
- One copy elsewhereAway from the office, safe from fire or flood
No single event can wipe out every copy
Backup vs sync: why a synced folder is not a backup
File sync services keep the same files on several computers and online. They are built to copy every change everywhere, including the bad ones. If a file is deleted, damaged or encrypted by ransomware on one computer, sync can copy that damage to every other device.
| Question | Backup | Sync |
|---|---|---|
| What it is for | Getting data back after loss, damage or an attack | Keeping the same files on several devices |
| A file is deleted | Older copies are kept, so you can restore it | The deletion is copied to every device |
| Ransomware encrypts files | You can restore a clean copy the attack could not reach | Encrypted files can replace the good copies |
| Older versions | Kept for as long as you decide | Few or none, depending on the service |
| Practice database | Copied with a method suited to databases | Syncing an open database can leave an unusable copy |
Sync is fine for sharing documents, but do not count it as one of your three copies.
Versioning and retention: keep more than last night’s copy
Problems are not always noticed right away. A corrupted database, a file overwritten by mistake or an intruder who sat unnoticed on the network may only come to light days or weeks later, when last night’s backup holds the damage too.
Versioning keeps several restore points, so you can go back to a copy from before the problem started. Retention is how long those versions are kept. A sensible plan keeps frequent recent versions plus some older ones for longer. Choose the retention period on purpose, with your record-keeping obligations in mind, rather than accepting the software’s default.
Keep one backup copy out of reach of ransomware
Many ransomware attacks go after backups as well as live data, because a victim with no clean backup has fewer options. CISA’s #StopRansomware Guide recommends offline, encrypted backups of critical data that are tested regularly. If your backup drive is always connected and the server can write to it, assume anyone who gets into the server can reach the backup too.
Protect at least one copy in one or more of these ways:
- Offline: a copy that is disconnected from the network when it is not being written, such as a rotated drive kept in a secure place away from the office.
- Unchangeable: storage set so that backups cannot be edited or deleted for a fixed period, often called immutable storage.
- Separate logins: backup systems with their own passwords, not the accounts your team uses every day, and multi-factor sign-in where it is available.
For the habits that keep ransomware out in the first place, and what to do if it gets in, read our guide to ransomware protection for dental offices.
Encrypt every backup copy
Backups hold the same patient information as your server, so they deserve the same protection. A backup drive that is lost, stolen or left in a car is a privacy problem unless the data on it is encrypted.
- Encrypt backups where they are stored and while they travel over the internet.
- Keep the encryption key or password safe and separate from the backup. Without it, an encrypted backup cannot be restored, even by you.
- Limit who can open or delete backups to the few people who need to.
Test your dental office backups by restoring them
A backup proves nothing until you restore from it. Backup jobs can quietly skip a folder, copy a database that will not open or stop when the drive fills up, without anyone noticing.
Put restore tests on the office calendar and vary what you test:
- A single file: restore a document or image and check that it opens.
- The practice database: restore it to a test computer and confirm the software shows recent appointments and notes.
- A whole computer or server: now and then, find out how long a full rebuild really takes.
- Backup
- Restore
- Check it opens
- Write it down
A good restore testIn short
- Use a test computerNot the server your team works on
- Check it worksRecent appointments and notes should be there
- Write it downWhat you restored and how long it took
- Book the next onePut it on the office calendar
Vary what you test each time
Check backup reports or alerts regularly too, so a failed job is spotted the next day rather than the day you need it. Because backups usually depend on the office server, server monitoring for dental offices helps catch trouble with the machine itself.
Write down your recovery steps
In an emergency, nobody should have to recover from memory. Keep a short written plan you can reach when the server is down, including on paper. It should cover:
- Who to call for IT help, and how to reach them.
- Where each backup is, including the copy away from the office, and who can get to it.
- How to get in: where passwords and encryption keys are stored securely.
- What to restore first, usually the server and practice software, then front desk and operatory computers.
- How to keep seeing patients while systems are down, such as a printed schedule and paper forms.
Review the plan whenever your systems change. Power failures and surges are one reason you might need it, so read our guide to power outage and surge protection too.
What the HIPAA Security Rule says about data backup
If your practice is a HIPAA covered entity, backups are more than good practice. The HIPAA Security Rule (45 CFR Part 164, Subpart C) includes a contingency plan standard at 45 CFR 164.308(a)(7). It calls for policies and procedures for responding to an emergency, such as a fire, vandalism, system failure or natural disaster, that damages systems containing electronic protected health information.
The standard has five implementation specifications:
- Data backup plan (required): procedures to create and maintain retrievable, exact copies of electronic protected health information.
- Disaster recovery plan (required): procedures to restore any loss of data.
- Emergency mode operation plan (required): procedures to keep critical business processes that protect patient information running during an emergency.
- Testing and revision procedures (addressable): periodic testing and revision of your contingency plans.
- Applications and data criticality analysis (addressable): working out which systems and data matter most, which tells you what to restore first.
Addressable does not mean optional. You assess whether the measure is reasonable and appropriate for your practice; if it is not, you document why and use an equivalent alternative where that is reasonable. An IT company that creates, receives, maintains or transmits patient data on your behalf is generally a business associate, and HIPAA requires a written business associate agreement with it (45 CFR 164.502(e) and 164.504(e)). For the rest of the rule, see our HIPAA Security Rule IT checklist for dental offices.
A dental office data backup checklist
- Every data location is included.
- Three copies, two kinds of storage, one away from the office.
- One copy is offline or unchangeable.
- Backups are encrypted, and the key is stored safely.
- Several versions are kept for a period you chose.
- Restores are tested on a schedule.
- Recovery steps are written down and current.
- A business associate agreement is signed with any outside company that stores or manages your backups.
How My Dental IT helps
We set up backup systems to help your practice avoid losing vital data, and install and maintain the backup recovery software used to restore it. We also handle disaster prevention and recovery for power failures and electrical surges, and every customer has a signed HIPAA business associate agreement with us. See how our dental data backup and recovery service works.
Keep reading
Related dental IT guides
Guide
How to protect a practice from ransomware
The everyday habits and safeguards that make an attack less likely and recovery faster.
Guide
Power outage and surge protection
How surge protectors, battery backup and safe shutdowns protect your computers and server.
Guide
A HIPAA Security Rule IT checklist
The IT side of the Security Rule for a dental office, from risk analysis to business associates.
Not sure your backups would work tomorrow?
Tell us how your office is backed up today, and we’ll talk you through what a dependable backup and recovery setup looks like for your practice.