Over the last five to seven years we have carried out on-site IT audits at 184 UK dental and orthodontic practices, 192 audit documents in all. We have now anonymised the lot, text-mined it, hand-checked it, and pulled it together into a white paper: an honest picture of what dental practice IT actually looks like behind the reception desk. The short version? Generally, not good enough. This article is the summary; the full paper is free to download at the bottom of the page.
One thing before the numbers. These are good clinics run by good people, who trusted whoever set their systems up. Nothing here identifies a real practice, every name in the stories is invented, and the figures are broad-brush estimates from working documents, not a precise census. If anything, they under-count the problems, because a thin audit note cannot report a fault it never examined.
The headline numbers
Across the 137 audits with enough detail to judge, the same findings came up again and again:
- 48% were running Windows or server software their auditor flagged as out of date at the time, judged on the day, not with hindsight.
- 45% flagged slow or unreliable internet, the single most common complaint. Where a speed was actually measured, the median download was just 14 Mbps, and 10 of the 22 measured sites were below 10 Mbps, for an entire clinic.
- Roughly 1 in 4 used generic shared logins or weak passwords. We have written before about why shared accounts quietly cost you; this data is why we keep banging that drum.
- 1 in 5 had a consumer router and no real firewall between the open internet and their patient records. A similar share had exposed or unmanaged remote access.
- 17% had backups that were failing, partial or simply absent.
- 29% had no proper server at all: a desktop PC pressed into service as the spine of the whole practice.
Tales from the server cupboard
Numbers describe the estate. The stories are what stay with you, and the paper has a full section of them, anonymised but real.
There is the practice that was under live attack while our engineer stood in the room: Remote Desktop left open to the entire internet, logs showing a constant stream of break-in attempts, "stopped" only by the antivirus. Like leaving your front door unlocked and relying on a guard inside to tackle whoever wanders in.
There are the backups that lied. One site's nightly backup completed successfully every night, and the log said the same thing every time: 0 files processed, 0 bytes backed up. Another's cloud backup had been quietly erroring since the previous April, with the local backup dead too, and nobody knew until we opened the logs. The recurring villain of the whole dataset is not dramatic failure; it is the green tick that lies. It is the same lesson as our piece on why an external hard drive is not a backup, written large.
There is the password hall of shame: whole practices on one shared password like Password1!, a router password handed out to patients who then sat on the same network as the patient records, and, across dozens of sites, the identical note: "generic accounts, same password everywhere."
And there is the saddest one: the practice that lost data months after being warned, in writing, exactly how it would happen. The files that vanished were precisely the ones the audit had flagged. The backed-up server data survived; the deferred decision did not.
The pattern, and the point
Read together, the audits sketch the anatomy of at-risk practice IT: ageing software and performance pain at the top, propped up by foundational weaknesses underneath (overdue hardware, no proper server, messy cabling, shared logins), with a smaller number of outright security gaps that are by far the most expensive when they go wrong. None of it fails dramatically, until the day it does.
The point of publishing this is not to frighten anyone, and it is certainly not to shame the practices involved. It is that the threats are arriving daily whether a practice is ready or not, and most of the findings above are fixable with unglamorous, well-understood work: a real firewall, individual logins, properly managed protection, backups that are tested rather than trusted, and a connection sized for how a modern practice actually works.
Download the white paper
The full paper covers everything here in more depth: the practice-management software league table, the connection and operating system breakdowns, the antivirus picture, telephony, the complete set of stories from the server cupboard, and an honest section on the limits of the data. Download it below, no email address required.
And if reading it leaves you wondering which of these findings would show up at your own practice, that is exactly what our audits are for. Get in touch and we will take an honest look, the same way we did for these 184.