IT Services of Utah blog logo

A dental practice should back up critical data multiple times per day when losing a full day of information would significantly disrupt operations. Backups should also be monitored regularly, and recovery should be tested periodically.

For dental practices using Dentrix®, Open Dental®, Eaglesoft®, Dexis®, digital imaging, and other clinical systems, simply having a backup is not enough.

A strong backup strategy follows three principles:

Back up frequently. Keep protected copies. Test recovery.

1. Back Up Critical Data Frequently

Ask one question:

How much data could our practice afford to lose?

If your backup runs only once each night, a failure late in the day could potentially put that day's changes at risk.

Critical systems may require backups multiple times throughout the day, depending on the technology and business requirements.

Your IT provider should identify what needs protection, including:

  • Practice management data
  • Dental imaging
  • Server data
  • Business files
  • Critical application data

The backup schedule should be based on how much data the practice can realistically afford to lose.

2. Don't Keep Your Only Backup in the Dental Office

A backup stored beside the server can still be affected by the same event that damages the server.

Examples include:

  • Ransomware
  • Theft
  • Fire
  • Flooding
  • Hardware failure
  • Electrical problems

A better strategy maintains multiple protected copies, including a copy isolated from the primary production environment when appropriate.

The goal is simple:

One incident shouldn't be able to destroy both your production data and your recovery copy.

3. Test Whether Your Backups Can Actually Be Restored

A successful backup notification doesn't prove that your dental practice can recover.

Backups should be monitored and recovery should be tested periodically.

Your IT provider should be able to answer:

  1. What are we backing up?
  2. How frequently are backups occurring?
  3. Where are the backups stored?
  4. Are backup failures monitored?
  5. When was recovery last tested?

If nobody knows the answer to question #5, that's a warning sign.

Backup vs. Disaster Recovery: What's the Difference?

A backup is a protected copy of your data.

Disaster recovery is the plan for restoring your systems and getting the practice operational again.

You need both.

For example, having a backup of your Dentrix data is valuable. But your practice also needs to know:

  • Where Dentrix will be restored
  • Whether replacement server resources are available
  • How long restoration may take
  • How workstations will reconnect
  • How imaging will be restored
  • Which vendors need to be involved

The goal isn't simply to save files.

The goal is to restore business operations.

How Much Downtime Can Your Dental Practice Tolerate?

Every practice should establish two recovery objectives.

Recovery Point Objective

The RPO answers:

How much recent data could we afford to lose?

If the answer is one hour, your backup strategy needs to support approximately that recovery objective.

Recovery Time Objective

The RTO answers:

How long can we operate without this system?

A practice may tolerate several hours without one noncritical application but have very little tolerance for losing its primary practice-management system.

These two numbers help determine the right backup and disaster recovery strategy.

Are Cloud Dental Systems Automatically Backed Up?

Don't assume they are.

If you use a cloud-based dental or business application, ask the vendor:

  • What data is backed up?
  • How frequently?
  • How long is it retained?
  • Can deleted data be restored?
  • What happens after a ransomware incident?
  • How long does recovery take?
  • Can the practice obtain an independent copy of its data?

Moving an application to the cloud changes who manages parts of the infrastructure.

It doesn't eliminate the need for a recovery plan.

What About Ransomware?

Backups are an important part of ransomware recovery, but they should not be your only cybersecurity control.

Dental practices should use multiple security layers, including:

  • Multi-factor authentication
  • Endpoint protection
  • Email security
  • Patch management
  • Employee training
  • Network security
  • Protected backups

The objective is to prevent the attack when possible and maintain a recovery option when prevention fails.

The 5-Question Dental Backup Test

Ask your IT provider these five questions today:

  1. What exactly are we backing up?
  2. How often is it backed up?
  3. Where are the backup copies stored?
  4. Who receives an alert when a backup fails?
  5. When did we last successfully test a restore?

A dental practice should be able to get clear answers to all five.

Why Dental Practices Choose IT Services of Utah

IT Services of Utah has been helping businesses for more than 30 years and supports dental practices throughout St. George and Washington County, Utah.

Our dental technology experience includes:

  • Dentrix
  • Dexis
  • Open Dental
  • Eaglesoft
  • Dental imaging
  • Servers and networks
  • Backup and recovery
  • Cybersecurity

Our approach combines fast remote support, local on-site technicians, live phone answering, internal support, HIPAA-focused IT expertise, and cybersecurity-first managed services.

Backup and recovery are part of a larger objective: keeping your practice's technology secure, reliable, and recoverable.

Frequently Asked Questions

How often should a dental practice back up its server?

The appropriate frequency depends on how much data the practice can afford to lose. For critical systems, that may mean multiple backups per day rather than a single nightly backup.


Is one backup enough?

No. A single backup can create a single point of failure. Critical data should generally have multiple protected copies appropriate to the practice's recovery requirements.


How often should backups be tested?

Recovery should be tested periodically according to the importance of the system and the practice's recovery plan. The key is having a defined testing schedule rather than assuming successful backup notifications guarantee recovery.


Does HIPAA require dental practices to back up data?

HIPAA's Security Rule includes contingency-planning requirements for covered entities, including establishing and implementing procedures to create and maintain retrievable exact copies of electronic protected health information.

Could Your Dental Practice Recover Tomorrow?

Having backups and being able to recover are not the same thing.

Start with five questions:

What is backed up? How often? Where is it stored? Who monitors it? When was it last tested?

If your dental practice in St. George or Washington County, Utah cannot confidently answer those questions, IT Services of Utah can evaluate your current backup and disaster recovery strategy.

Schedule a Dental IT Assessment with IT Services of Utah to determine whether your critical systems and data are prepared for a server failure, ransomware incident, or other unexpected outage.