CYBER DENTAL 2.0
(954) 639-7049

Cloud backup that is actually HIPAA-shaped

Encrypted, tested, off-site, and covered by a BAA. 'We use OneDrive' is not a strategy.

Journal · Academy · C·03 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida

Short answer: HIPAA-shaped backup is encrypted, kept off-site, covered by a Business Associate Agreement with the backup vendor, protected against ransomware, and restore-tested against defined recovery targets (RTO and RPO). File sync tools like OneDrive are not backups, and a backup that has never been restored is an assumption, not a control.

At a glance

HIPAA basis Contingency plan: data backup plan, disaster recovery plan, emergency mode operation plan (45 CFR 164.308(a)(7))
Must-haves Encryption, off-site copy, BAA, access control, tested restores
Not a backup File sync (OneDrive, Dropbox) on its own
Rule of thumb 3 copies, 2 media types, 1 off-site, 1 immutable or offline
Targets Define RTO and RPO first

What does HIPAA require for backups?

The Security Rule's contingency plan standard (45 CFR 164.308(a)(7)) requires covered entities and business associates to establish and implement a data backup plan, a disaster recovery plan and an emergency mode operation plan, and to consider testing and revising them. It does not prescribe a product. It does require that you can get ePHI back, and that you have thought through how.

What makes a backup "HIPAA-shaped"?

  1. Encrypted in transit and at rest, with keys managed so the vendor cannot casually read your data.
  2. Off-site, so a fire, flood, theft or hurricane at the office does not take the backup with it.
  3. Covered by a BAA. Any vendor that stores your ePHI is a business associate. No BAA, no backup. See Business associate agreements.
  4. Ransomware-resistant. At least one copy that an attacker with your network credentials cannot delete or encrypt: immutable, versioned or offline.
  5. Complete. It captures the PMS database and the image store and configuration, consistently. See Dentrix, Eaglesoft, Open Dental — the IT differences.
  6. Monitored. Failed jobs generate tickets the same day, not discoveries during a disaster.
  7. Restore-tested. Evidence of an actual restore, on a schedule, with the time it took.

Why is "we use OneDrive" not a backup strategy?

Sync is not backup. A synced folder faithfully replicates a deleted file or an encrypted file to the cloud. It also typically does not capture a running PMS database or imaging store in a consistent state. OneDrive and similar tools are useful for documents; they are not a disaster-recovery plan for a dental practice. See Microsoft 365 for dental practices.

What are RTO and RPO and why set them first?

RTO (Recovery Time Objective) is how long the practice can be down. RPO (Recovery Point Objective) is how much recent data it can afford to lose. A practice that can tolerate losing one day of data but not three days of downtime needs a different design from one that can tolerate neither. Set the targets, then buy the architecture that meets them, not the reverse. The cost of an hour of downtime helps put numbers on RTO.

How should restore tests work?

  • Restore a full practice dataset (database plus images) to a separate environment.
  • Open the PMS and imaging, and pull up real, non-sensitive test records.
  • Record the time it took and compare it to the RTO.
  • Keep the result as evidence. OCR investigations ask for documentation, not good intentions.

On CyberDental's Ultimate plan, backup verification and disaster-recovery testing are part of the service. See Remote, Priority, Ultimate, Concierge.

What is the single most common backup failure?

Jobs that have been failing silently for weeks. A backup dashboard that nobody reads is the most expensive kind of green light.

Frequently asked questions

Is OneDrive a HIPAA-compliant backup for a dental practice?

OneDrive can be used with a BAA under a properly configured Microsoft 365 plan, but file sync is not a backup or disaster-recovery plan. It does not reliably capture PMS databases and imaging stores or protect against synced deletions and encryption.

Does HIPAA require cloud backup?

HIPAA requires a data backup plan, disaster recovery plan and emergency mode operation plan. It does not mandate cloud specifically, but an off-site, encrypted copy is the practical standard.

How often should dental backups be tested?

Regularly, with documented results. A full restore test at least annually is a common minimum, and more often for critical systems. Test frequency should follow your risk analysis.

Sources and further reading

Related in the Journal

About CyberDental

CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.

CALL TEXT