Category: Digital Forensics

  • How Dentrix / Open Dental / Eaglesoft audit trails can help expose embezzlement

    How Dentrix / Open Dental / Eaglesoft audit trails can help expose embezzlement

    When money goes missing from a dental practice, the theft almost never happens in the checkbook. It happens inside the practice management software, in the adjustments, deleted transactions, reversed payments, and quietly rewritten ledgers that hide the money before it ever reaches a bank statement. What most owners do not realize is that Dentrix, Open Dental, and Eaglesoft are all watching. Each one keeps an audit trail: a running record of who did what, and when. Read correctly, that record can expose an embezzler.

    What is an audit trail in dental practice management software?

    An audit trail is a log the software keeps in the background as staff use it. Every time someone posts a payment, edits a charge, deletes a transaction, changes a fee, or reverses an entry, the system can record three things: the action, the user account that performed it, and the date and time it happened. Unlike the printed day sheet, which shows the practice as the embezzler wants it to look, the audit trail shows what actually happened, including the entries that were later erased.

    That distinction is the whole game. A skilled embezzler can make today’s numbers balance. What they cannot easily do is erase the history of how those numbers got there.

    How does an audit trail expose embezzlement?

    Most dental embezzlement follows a small number of patterns, and each one leaves a distinct signature in the audit trail:

    • Deleted or reversed payments. A patient pays cash, the payment is posted, and then it is deleted so the money can be pocketed. The ledger looks clean, but the audit trail still shows the payment being entered and then removed.
    • Unwarranted adjustments and write-offs. Balances are written off as courtesy discounts, insurance adjustments, or bad debt to make a stolen payment disappear. A pattern of adjustments tied to one user account is a classic red flag.
    • Backdated or after-hours entries. Changes posted late at night, on days the office was closed, or backdated to an earlier period often signal someone covering their tracks when no one is watching.
    • Repeated edits to the same accounts. The same patients being touched over and over, especially cash-paying patients, can reveal where the money is being skimmed.

    Any one of these can be innocent. It is the pattern across hundreds or thousands of logged actions, correlated to a specific user and a specific time, that turns raw data into proof. That analysis is the heart of a digital forensic examination, and it is where the most common digital red flags surface.

    Where the audit trail lives in Dentrix, Open Dental, and Eaglesoft

    Dentrix

    Dentrix maintains an audit trail that records additions, changes, and deletions to ledger and account activity, along with the operator and timestamp. Reviewed properly, a Dentrix audit trail can reconstruct payments that were entered and then deleted, adjustments that do not match a legitimate business reason, and edits made outside normal hours. This is exactly the kind of review we perform in a Dentrix Audit Trail Review.

    Open Dental

    Open Dental keeps one of the more detailed audit trails in the industry. Its permission-based logging can capture a wide range of actions, including who inserted, edited, or deleted payments, adjustments, and appointments, each tied to a user and a date and time. That granularity makes Open Dental data especially useful for reconstructing exactly how a theft was carried out and concealed.

    Eaglesoft

    Eaglesoft records account and transaction history, including edits and reversals to ledger activity. As with the others, the value is not in any single entry but in the pattern of changes across time and across user accounts. A forensic review can surface where balances were manipulated and trace the activity back to the responsible login.

    One important caveat: audit trails vary by software, version, and configuration. Some can be limited by settings, retention windows, or how logins are managed, and the person committing the fraud is sometimes the same person who controls those settings. Knowing what a given system does and does not capture, and how to preserve it correctly, is part of the forensic work.

    Why shared logins can blind the audit trail

    An audit trail is only as good as the login attached to each action. When the front desk, the billing assistant, and the office manager all share one username and password, every entry points to the same account and no one can be individually identified. Shared logins are one of the most common ways a practice unknowingly destroys its own evidence before a case ever begins. We cover this in depth in the one password your entire practice relies on. Giving every team member a unique login is the single easiest step an owner can take to keep the audit trail meaningful.

    Can an audit trail be used as evidence in court?

    Yes, when it is collected and interpreted correctly. Practice management data and its audit trail can become part of the record in civil litigation, criminal referral, and insurance claims, but it has to be handled the right way. The data must be preserved without altering it, the analysis has to be defensible, and the findings usually need to be explained by a qualified expert who can withstand scrutiny in a deposition or at trial. See how electronic dental records become legal evidence for more on that process.

    This is where an investigation and an expert witness engagement differ. Finding the theft is one job. Proving it to a court, an insurer, or a regulator is another, and it is the work we do every day.

    What should you do if you suspect embezzlement?

    1. Do not confront anyone yet. Tipping off a suspect gives them time to delete records, change settings, or walk out with data.
    2. Do not start deleting or “cleaning up” the system yourself. Well-meaning changes can overwrite the very evidence you need.
    3. Preserve the data. The audit trail and underlying database should be captured intact by someone who knows how to do it without altering the record.
    4. Call a forensic examiner. A confidential, off-site review can confirm whether theft occurred and quantify it before you take any action.

    Since 2004, Hiltz & Associates has conducted hundreds of dental embezzlement and digital forensic investigations, quietly and off-site, and supported dentists and their attorneys through high-stakes litigation. If the numbers in your practice are not adding up, the answer may already be sitting in your audit trail.

    Frequently asked questions

    Can a dentist read the audit trail themselves?

    You can view parts of it, but interpreting it forensically is a different task. The logs can be long, and the meaningful signal is the pattern across many entries tied to a user and a time, not any single line. Handling the data the wrong way can also compromise it as evidence, so it is best reviewed by a forensic examiner in a way that will hold up under scrutiny.

    Can an embezzler delete the audit trail?

    It depends on the software, the version, and the settings, and the person committing the fraud is sometimes the one who controls those settings. Even so, deletions and gaps tend to leave their own traces, and other data sources can corroborate the record. That is exactly why preserving the system quickly, before anyone is alerted, matters so much.

    Which is better for catching embezzlement: Dentrix, Open Dental, or Eaglesoft?

    All three keep an audit trail that can help expose theft. Open Dental’s logging tends to be especially detailed, but the bigger factors are whether each staff member has a unique login and whether the data is preserved correctly once a problem is suspected. Good practices matter more than the brand.

    How far back does an audit trail go?

    That depends on the system’s retention settings and how long the practice has used the software. Some systems retain years of history, others are more limited. The sooner the data is preserved, the more complete the picture a forensic review can build.

    Concerned about what your audit trail might reveal? Start with a confidential Dentrix Audit Trail Review, or read our Dental Embezzlement FAQ.

  • How to maintain “forensic ready” electronic dental records.

    How to maintain “forensic ready” electronic dental records.

    How to keep your data “Forensic‑Ready”

    FOURTH IN A SERIES, PART 4 OF 5

    Digital forensics is only as strong as the technologies that enable it, and that technology is advancing at an exponential pace.

    Maintaining accurate, complete, consistent, and well-structured electronic patient records can help dental clinics defend themselves in lawsuits and avoid unwarranted regulatory scrutiny.

    By following these few simple steps will help make your electronic dental records “forensic ready”.

    Why is this #1?

    Judges, regulators and insurers seek transparency and rely on digital forensic experts to provide it. A forensic expert can establish the timing and authenticity of a clinical note or other recorded patient encounter.

    Consequently, regulators advise to use the addendum-based approach whenever changing or adding to a previously recorded note. Addendums to clinical notes preserve the original entry while clarifying changes or new information. Using addendums can help defend against allegations of record tampering.

    Consider as well that most dental regulators explicitly warn against overwriting or deleting clinical notes. Failure to do so can trigger professional conduct investigations.

    Moreover, most malpractice insurers now require addendum‑only corrections as part of their risk‑management protocols. They won’t insure you if you do use this approach.

    Best Practice:

    Create and use a standardized addendum template in your dental software. The addendum template must include:

    • the reason for the record change or addition.
    • what information is being clarified or added.
    • the date and time of the addendum
    • the name and User ID of the person recording the addendum.

    Why is this important?

    Forensic timelines fall apart when timestamps don’t match up. Judges, regulators and insurers can interpret inconsistent or unusual timestamps as intentional record manipulation. When a devices time is off by a minute or two, it can create suspicion.

    Digital forensic experts are often engaged in such cases to reconstruct a timeline of events by comparing dental software logs, imaging metadata, billing and other timestamps.

    Best practice:

    This will sound obvious, but make sure that automatic time synchronization is enabled across all digital devices. (servers, images, workstations, digital cameras, backups, communication systems, phones, alarm systems)

    Why is this important?

    Shared logins can be one of the biggest forensic liabilities in dentistry. When people share the same login, it makes it difficult or impossible to determine who did what.

    Consider this:

    • HIPAA requires unique user IDs and access controls.
    • Plaintiffs’ attorneys routinely request user access logs to look for suspicious activity.
    • Regulators expect clinics to demonstrate role‑based access to PHI.

    Best practice:

    • Unique logins for every staff member
    • Automatic logout after inactivity
    • Role‑based permissions.
    • Perform a Quarterly review

    Why is this important?

    Imaging is often the most objective evidence in a dental case.

    Imaging inconsistencies often become the focal point of expert testimony and erasing or overwriting images can severely damage credibility.

    Consider this:

    • Metadata is increasingly used in regulatory reviews. Altered or missing images can be argued as spoliation of evidence.
    • DICOM metadata is frequently subpoenaed in malpractice cases.
    • Many regulators expect full retention of original images, including retakes. Missing images can lead to quality‑of‑care investigations.

    Best practice:

    • Store original images in a read‑only archive
    • Avoid exporting images to consumer apps or devices
    • Document retakes and failed images
    METADATA. WHAT IS IT? <Click Here to Find Out>

    Meta-data is data about other data. It is the structured, behind‑the‑scenes information that describes a file, image, chart entry, or digital record so your systems know what it is, where it belongs, and how it should be used.

    Here are a few everyday dental examples:

    Radiographs: Metadata includes date/time, tooth number, exposure settings, operator ID, and device used. Without this, the image is just a floating JPEG with no clinical value.

    Intraoral photos: Metadata tags identify patient, arch, orientation, and capture device.

    Chart notes: Metadata includes author, timestamp, and modification history.

    CBCT scans: Metadata stores voxel size, field of view, machine model, and patient identifiers.

    Why this matters

    Defense Attorney: “Your honor, it seems my client no longer possesses the data demanded by the court.”

    Yes, data loss is one of the fastest ways to escalate a complaint into a crisis.

    Judges, regulators and insurers expect clinics to maintain reliable backups; data loss can be interpreted as negligence or spoliation. A digital forensic expert is often engaged in such cases to examine backup logs and device histories to confirm events. Moreover, most insurers nowadays require clinics to demonstrate that their backups were tested and functional, otherwise coverage will be denied.

    Related post -> Dentist-loses-three-months-of-data-and-stomach-lining

    Best practice:

    • Daily encrypted backups
    • Off‑site redundancy
    • Quarterly restore‑tests
    • Documented backup log

    Clinics that implement the practices outlined in this article will likely be more equipped, better protected, and less prone to experiencing escalated disputes.

    Key takeaways. Forensic‑ready documentation means:

    1. professional protection
    2. regulatory compliance
    3. patient trust and goodwill
  • The Most Common Digital Red Flags in Dental Lawsuits

    The Most Common Digital Red Flags in Dental Lawsuits

    In litigation, these tiny anomalies can snowball into major credibility problems.

    THIRD IN A SERIES, PART 3 OF 5

    Digital red flags often do not appear as the proverbial “smoking gun.” Red flags are usually found as small inconsistencies, such as a timestamp that doesn’t line up, a missing image, a late entry with no addendum, or a log-in at an unusual time of day.

    This post focuses on the red flags that most often escalate routine complaints into full‑blown legal disputes, with a clear comparison of how these issues play out under American and Canadian regulatory frameworks.

    In 80% of the cases where defense counsel retained me as an expert, I discovered that the dentists had made late and backdated entries.

    William Hiltz

    Late entries can be a big red flag

    Courts and regulators assume that contemporaneous notes are accurate. When entries appear days or weeks after treatment, opposing counsel often argues that the record was “cleaned up” after the fact. Courts take a dim view in this regard.

    Forensic tools can detect:

    • Edits made after a complaint was filed
    • Deleted entries, and attempts to overwrite or hide data
    • Metadata inconsistencies

    Even innocent, well-intended corrections can appear suspicious without proper analysis.

    U.S.ACANADA
    HIPAA doesn’t prohibit late entries, but audit logs must show the true timestamp.

    Many states (e.g., California, Texas, New York) treat backdating as professional misconduct.

    Malpractice insurers routinely request audit logs when late entries appear.
    Provincial colleges emphasize addendum‑based corrections, not overwrites.

    Backdating can trigger professional conduct investigations, even without a lawsuit.

    Canadian regulators can request entire audit trails, not just the electronic dental chart.

    Imaging is often the most objective evidence in a dental case.

    Missing images or metadata inconsistencies raise immediate suspicion.

    U.S.A.CANADA
    Imaging metadata is frequently subpoenaed in malpractice cases.

    Plaintiffs’ attorneys often hire forensic experts to analyze DICOM metadata.

    Deleting or modifying images can be argued as spoliation of evidence, which can shift the burden of proof.
    Provincial regulators expect full retention of original images, including failed or retaken shots.

    Missing images can lead to quality‑of‑care investigations, even if the clinical outcome was reasonable.

    Canadian courts are increasingly receptive to digital forensics in imaging disputes.

    Audit logs are the digital equivalent of security camera footage. Unusual patterns can imply tampering or unauthorized access.

    Forensic analysts can reconstruct minute‑by‑minute sequences of events, showing exactly when:

    • Notes were entered
    • Images were captured
    • Billing codes were applied
    • Records were accessed
    • Records were deleted or modified

    Audit logs are used to establish a timeline trail of evidence to demonstrate “who accessed what, and when”, which in many cases becomes the entire legal argument.

    U.S.A.CANADA
    Unauthorized and suspicious access can lead to:
    Civil penalties
    OCR investigations

    Plaintiffs’ attorneys often request full access logs to check for post‑incident chart activity.
    Unauthorized and suspicious access can trigger:
    Regulatory discipline
    Privacy commissioner investigations

    Plaintiffs’ attorneys often request full access logs to check for post‑incident chart activity.

    When a dentist claims “my system crashed” or “the backup failed,” courts and regulators want proof.

    U.S.A.CANADA
    Data loss can be interpreted as negligence or spoliation if backups weren’t properly maintained.If backups weren’t kept up to date, data loss might be considered negligence.

    Why it’s a red flag

    When timestamps in the practice management system don’t match imaging software or billing logs, it suggests tampering, even if the cause is innocent (e.g., a workstation with the wrong clock).

    U.S.A.CANADA
    Digital forensic experts often reconstruct timelines across PMS logs, Imaging metadata, Billing submissions, Email servers, Windows Event logs

    Timeline inconsistencies can undermine the dentist’s credibility.
    Lawyers and regulators frequently request multi‑system timelines during investigations.

    Even minor inconsistencies can be interpreted as poor record-keeping, which is a standalone offense in many provinces.

    Both America and Canada are tightening their expectations around digital integrity:

    U.S.A.CANADA
    America has seen an increase in litigation, aggressive discovery by plaintiffs, and federal enforcement.Canada has strong privacy laws, more active regulatory involvement, and growing use of digital forensics in investigations.

    The message is clear for dentists on both sides of the border: your digital footprint is now part of your legal defense plan.

    [publishpress_authors_box layout=”ppma_boxes_15840″]

  • How Electronic Dental Records Become Legal Evidence

    How Electronic Dental Records Become Legal Evidence

    A Forensic Breakdown

    SECOND IN A SERIES – PART 2 OF 5

    Electronic dental records have surpassed the paper chart as primary medium for patient documentation.

    Back in the day, when a paper note was contested in court, handwriting experts and ink analysts were called in to assess whether the chart additions were late or fraudulent.

    Nowadays, digital forensics is used to evaluate the data and meta data surrounding the chart note to detect late or false entries.

    So, it’s no surprise when a legal dispute arises, many attorneys engage digital forensic experts look at the data first, rather than witness statements or depositions.

    Every click, entry, and image in a dental system becomes part of a factual timeline that courts rely on to determine what truly happened.

    This post breaks down how ordinary electronic dental records become powerful legal evidence.

    Clinical Notes: The First Line of Defense

    Clinical notes are often the most scrutinized component of a dental chart.

    Digital forensic experts examine:

    • Timestamps (determine creation, modification, and deletion dates and times)
    • User IDs tied to each entry.
    • Addendum vs. overwrite behavior
    • Consistency between imaging and treatment events

    A note that appears to be written days after treatment, or edited after a complaint, can dramatically shift the legal narrative.

    Imaging Files and Metadata

    Radiographs, CBCT scans, and intraoral photos contain hidden metadata that can confirm or contradict clinical claims. Analysts look for:

    • Capture date and time
    • Device identifiers
    • Software version
    • Modification history
    • Missing or overwritten images

    If a patient alleges a missed diagnosis, metadata can prove whether the dentist had the relevant image at the time of treatment.

    Billing and Insurance Records

    Billing logs often reveal intent, timing, and workflow patterns. Forensic experts  focuses on:

    • Code changes after treatment
    • Deleted or reversed claims
    • User‑level billing activity
    • Timing of submissions relative to chart entries

    In fraud or upcoding allegations, these logs can become central evidence.

    Access (Audit) Logs and User Activity Trails

    Practice management systems can quietly record every login, logout, and chart access. These logs can help answer questions such as:

    • Who viewed the chart
    • Whether unauthorized chart access occurred
    • If a staff member altered a record
    • Whether a dentist was logged in at the time of an alleged entry

    These digital event trails often resolve “he said, she said” disputes.

    Device and Network Logs

    Servers, firewalls, and workstations generate logs that can reveal:

    • Remote access attempts
    • USB device usage
    • Data transfers

    These are especially relevant in privacy breach cases or allegations of intentional (malicious) data destruction.

    Why This Matters

    Courts increasingly rely on digital evidence because it is:

    • Objective
    • Timestamped
    • Hard to manipulate without leaving traces
    • Consistent across systems

    For dental professionals, this means that your digital footprint is your legal shield, or your liability.

    Related Posts:

  • The Role of Digital Forensics in Dental Lawsuits

    The Role of Digital Forensics in Dental Lawsuits

    Why Digital Forensics Matters in Dentistry

    FIRST IN A SERIES – PART 1 of 5

    Digital evidence has quietly become one of the most decisive factors in dental litigation.

    Whether a case involves alleged malpractice, billing irregularities, privacy breaches, or employment disputes within a clinic, digital forensics now plays a central role in uncovering what actually happened.

    Dental practices generate and store enormous amounts of digital information, often without realizing how legally significant it can become. When a lawsuit arises, this data becomes a factual record that can either support or undermine a dentist’s position.

    Digital forensics helps to answer critical questions such as:

    • Who accessed a patient chart, and when
    • Whether clinical notes were altered after the fact
    • Whether diagnostic images were modified or deleted
    • How billing codes were applied and by whom
    • Whether a device or system was compromised
    • Whether financial transitions were deleted or modified to conceal dishonesty

    We live in an era where almost every action leaves behind a digital footprint, and those footprints can make or break a case.

    Sources of Digital Evidence used in Dental Litigation

    Here are some of the most common sources of forensic evidence:

    Practice Management Systems

    Platforms like Dentrix, Open Dental, Eaglesoft and others maintain audit logs which can show::

    • User access trails
    • Timestamped chart entries
    • Audit logs for edits, deletions, and overrides
    • Billing and insurance submission histories

    These logs often used in forensic reconstruction.

    Digital Imaging Systems

    CBCT scans, intraoral photos, and radiographs carry metadata such as:

    • Image capture time
    • Device identifiers
    • Software version
    • Modification history

    Consistencies in metadata can help exonerate a provider while metadata inconsistencies are red flags

    Email, Messaging, and Internal Communications

    Internal communications can clarify help demonstrate intent, timelines, and decision-making. For example:

    • Instructions to staff
    • Patient communication threads
    • Discussions about treatment planning
    • HR or disciplinary correspondence

    These records often reveal context that clinical notes alone cannot.

    Network and Device Logs

    Firewalls, servers, and workstations generate logs that can show:

    • Unauthorized access attempts
    • Remote logins
    • Data transfers
    • Use of USB devices

    These are especially relevant in data tampering allegations.

    How Digital Forensics can Strengthen a Legal Case

    Digital forensics can provide clarity in situations where memories differ or documentation is incomplete.

    Its value lies in its objectivity.

    Establishing a Reliable Timeline

    Forensic analysts can reconstruct minute‑by‑minute sequences of events, showing exactly when:

    • Notes were entered
    • Images were captured
    • Billing codes were applied
    • Records were accessed
    • Records were deleted or modified

    In a negligence claim, digital forensics is used to examine data and metadata surrounding clinical records, radiograph images, patient encounters and system logs to establish a timeline trail of evidence to demonstrate “who did what, and when” – which in many cases becomes the entire legal argument.

    Detecting Alterations or Backdating

    Courts take a dim view of altered records. Forensic tools can detect:

    • Edits made after a complaint was filed
    • Deleted entries, and attempts to overwrite or hide data
    • Metadata inconsistencies

    Even innocent well-intended corrections can appear suspicious without proper analysis.

    Validating Clinical Decisions

    Digital evidence can support a dentist’s clinical judgment by showing:

    • Diagnostic images available at the time
    • Treatment planning notes
    • Patient consent documentation
    • Communication history

    This helps demonstrate that decisions were reasonable and well‑documented.

    Did you know that “documentation issues” account for 1 in 3 negligence claims and account for one-third of the money paid out to settle dental negligence claims? (Medpro)

    Supporting Regulatory Compliance

    Privacy and record‑keeping regulations require strict controls. Forensics can confirm whether a clinic:

    • Followed access protocols
    • Maintained proper backups
    • Secured patient data
    • Complied with retention requirements

    Non‑compliance can escalate civil lawsuits and regulatory investigations.

    Protecting Your Practice: Proactive Forensic Readiness

    The best time to think about digital forensics is before a lawsuit emerges. Dental practices can reduce risk by adopting forensic‑friendly habits:

    • Enable and preserve audit logs in all clinical and administrative systems
    • Standardize documentation practices to reduce ambiguity
    • Train staff on proper charting, access protocols, and digital hygiene
    • Implement secure backups with verifiable integrity
    • Avoid altering records after an incident without proper addendum procedures
    • Engage IT professionals who understand healthcare compliance

    A clinic that maintains clean, consistent digital records is far better positioned to defend itself.

    As dental technology evolves, so does the sophistication of forensic analysis. Emerging trends include:

    • AI‑driven anomaly detection in audit logs
    • Automated integrity checks on imaging files
    • Enhanced metadata standards for dental devices

    These tools will make it even harder to manipulate records and easier to validate legitimate clinical care.

    Final Thoughts

    Digital forensics has become a quiet but powerful force in dental litigation. It brings objectivity to emotionally charged disputes and ensures that facts, not assumptions, guide legal outcomes.

    The Future: AI, Automation, and Advanced Forensics

    As dental technology evolves, so does the sophistication of forensic analysis. Emerging trends include:

    • AI‑driven anomaly detection in audit logs
    • Automated integrity checks on imaging files
    • Enhanced metadata standards for dental devices

    These tools will make it even harder to manipulate records and easier to validate legitimate clinical care.

    Final thoughts

    Digital forensics has become a quiet but powerful force in dental litigation. It brings objectivity to emotionally charged disputes and ensures that facts, not assumptions, guide legal outcomes.

    RELATED POSTS

    https://www.dentalfraudbusters.com/are-you-ready-for-a-lawsuit/
  • 4 Reasons Why Cyber Insurance is Essential for Dental Offices.

    4 Reasons Why Cyber Insurance is Essential for Dental Offices.

    Dental practices in are increasingly vulnerable to cyberattacks. With patient health information stored digitally, a single breach can lead to devastating financial and reputational consequences.

    Here are the top four reasons why cyber insurance is essential for dental offices.

    1. Financial Protection Against Cyber Incidents

    Cyberattacks like ransomware and phishing can cost tens of thousands in recovery, legal fees, and lost revenue.

    Cyber insurance helps cover data recovery, legal defense, and business interruption losses.

    Industry insight: The average cost of healthcare data breaches in the U.S. remains among the highest across industries, making proactive coverage and controls critical.

    In the news: Watson Clinic data breach: Patients may claim up to $75,000 in $10M settlement after dark web exposure

    Case Study: https://cdn.intelligencebank.com/us/share/NMXD/6Kq3/VYNaD/original/Coalition_Case-Study_+Dental-OneSheet

    2. Compliance with HIPAA

    HIPAA mandates strict safeguards for patient health information.

    Cyber insurance underwriters require (i) encryption, (ii) multi-factor authentication (MFA), and (iii) regular security audits, controls that align with HIPAA’s Privacy, Security, and Breach Notification Rules.

    3. Stronger Security Posture

    Cyber Insurers enforce best practices including: secure, offsite backups; employee phishing awareness training; endpoint protection; and incident response playbooks. These measures reduce vulnerability and improve resilience against attacks.

    …. drum roll…. and the main reason why cyber insurance is a good move.

    A breach can severely damage your reputation and patient confidence.

    Cyber insurance typically provides crisis management, public relations support, breach notification assistance, and credit monitoring for affected patients.

    Bottom Line: cyber insurance goes beyond being merely a policy; it represents a proactive measure for ensuring legal compliance and building patient trust.

    Cyber Insurance Requirements

    Here is list of common mandatory requirements for a dental practice to qualify for cyber insurance:

    • Implementation of basic cybersecurity controls such as:
      • Firewalls and antivirus software
      • Multi-factor authentication (MFA) for access to sensitive systems
      • Regular software patching and updates
    • Secure handling and encryption of patient data, both at rest and in transit
    • Employee cybersecurity training and awareness programs
    • Incident response plan in place for cyber events or data breaches
    • Regular data backups with secure storage and tested recovery procedures
    • Risk assessment and vulnerability scanning to identify and mitigate cyber risks
    • Compliance with relevant healthcare privacy regulations (e.g., HIPAA in the U.S., PIPEDA in Canada)
    • Use of secure networks and Wi-Fi configurations
    • Access controls and user privilege management to limit data exposure
    • Documentation of cybersecurity policies and procedures

    These requirements help reduce the risk profile of the dental practice and demonstrate to insurers that the practice is proactively managing cyber risks.

    Some insurers may have additional or slightly different criteria depending on their underwriting guidelines.


    Authoritative References

    America

    Canada

  • Digital Exoneration for Dentists

    Digital Exoneration for Dentists

    Dentistry is one of the most litigated professions.

    It’s true…

    The reality for most dentists is that they can expect to be named in two or more lawsuits during their career with most involving negligence claims related to the delivery and management of patient care.

    Documentation issues account for nearly 1/3 of all dental negligence claims paid.

    Today, more dental practices use digital technology to document and deliver patient care than ever before – and the “electronic dental record” has virtually replaced traditional paper and film as the preferred documentation choice.

    When defending a negligence claim, every dentist is required to provide copies of the patient’s dental records.

    The patient’s attorneys will examine the dental records to look for any inaccurate, incomplete, or false entries that can be contested in court or used to argue for the negligence claim?

    In every case, the dentist’s electronic dental records are questioned. 

    In many cases, the dentist’s electronic records are contested. 

    Dentists who can demonstrate that their electronic dental records are a complete, accurate and faithful representation of events will likely have a more favorable outcome in a legal challenge.

    Documentation Issues in Negligence Claims.

    Did you know that a lack of effective documentation was cited in 32% of dental malpractice claims, and that omissions, gaps, and timing issues were the primary causes?

    Many of these documentation issues could have been avoided. 

    So, before a legal challenge comes knocking on the door, every dentist should have established written procedures regarding how their electronic dental records are managed and stored. (i.e.: conduct an audit of the current documentation procedures and develop/implement a remediation plan)

    Digital Forensics meets the Digital Dental Office

    Through my company Hiltz & Associates, I provide expert services to dental attorneys in litigation matters involving malpractice, unethical business conduct and misrepresentation.

    Using digital forensics techniques to extract and examine data to determine who did what, and when on a computer.

    IMPORTANT LESSONS LEARNED FROM MALPRACTICE CASES

    Today’s decisions are based more and more on electronic charts, digital clinical notes and the meta-data surrounding those records.

    Here are the two most important “digital” things that dentists can do ensure they can defend against a malpractice challenge when it knocks on their door.

    sign (“lock”) your clinical notes, every day, without fail.

    Be sure to lock (digitally sign) your electronic clinical notes in a consistent and timely manner. (i.e.: on the same day or within 48 hours)

    An unsigned or an unlocked clinical note can be an open-door for plaintiff arguments in a malpractice claim.

    By electronically signing (thus locking) your clinical notes, you are attesting to the authenticity and accuracy of the transcript and that the notes were NOT modified or altered since they were first entered.

    Unsigned (or “unlocked”) clinical notes are likely to be contested. Signing you clinical notes every day can prevent an unnecessary challenge.

    archive YOUR DATA, monthly is good, weekly is better.

    A data archive IS NOT the same as a backup of your Dentrix, Open Dental or other software..

    A data archive should have snapshots of your data taken at various given times. If you create a monthly archive, then you will make archival copies of the data (and metadata) each month. A syslog server is also recommended.

    By the end year 1, your data archive will have 12 archival copies, one for each month of the year.

    By the end of 4 years, you will have 48 archival copies. You get the idea.

    A data archive is a “snapshot in time” that cannot be recreated at a future date.
  • Dentist Exonerated

    Dentist Exonerated

    Paying Attention to Details

    This was a case of finding needles in a haystack – literally.

    This civil litigation case involved a dental practice transaction dispute in excess of $1.2M.

    The Seller had agreed to work in the practice for 8 months after closing.

    Once the Seller completed the eight-month work commitment, the Buyer promptly submitted a claim, claiming that the Seller had erased hundreds of patient records during the designated work time-frame, thereby sabotaging the value of the practice.

    The Plaintiff produced over 8,000 pages of PDF documents to support its claim for damages; comprised of detailed software audit logs and patient scheduling reports.

    The documents identified and showed that the user ID assigned to the Seller had deleted over 800 patient records during the Seller’s 8 month work term. At no time was this fact disputed.

    To find the ‘needle in the haystack’, I transformed the Plaintiff’s PDF documents into a database for auditing purposes. (resulting in over 100,000 records)

    I compared the date and time stamps for each of the 800+ record deletions against email, appointment, text message and geolocation data to develop a timeline of events that clearly demonstrated the Seller could not have performed the record deletions.

    The evidence was compelling and showed that all deletions occurred on dates and times when the Seller was either,

    (i) engaged in surgery,
    (ii) was not working in the practice or
    (iii) was out of town.

    The only conclusion was that someone else in the practice had used the Defendant’s user ID to perform the record deletions.

    The results of my analysis were presented to the Plaintiff six weeks before trial.  

    Two weeks before trial, the Plaintiff withdrew its claim and agreed to compensate the Seller for legal fees and damages.