CYBER DENTAL 2.0
(954) 639-7049

The nephew-does-the-IT myth

Love is not a BAA.

Journal · Florida · E·06 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida

Short answer: Many dental practices rely on a relative, friend or part-time tech for IT. It is well-meant and usually cheap, and it carries real risks: no Business Associate Agreement, no documentation, no after-hours coverage, a single point of failure and admin access held by one person. The fix is respectful: formalize the relationship or hand it to a managed provider.

At a glance

The myth A relative or friend can handle dental IT
Core risks No BAA, no documentation, single point of failure, no coverage
HIPAA issue Anyone with access to ePHI who is not workforce generally needs a BAA
Respectful path Formalize the role or transition to an MSP with a clean handoff

What is the nephew-does-the-IT myth?

It is the belief that a relative, a friend of the family or a part-time techie can handle a dental practice's IT, because they are smart, they care and the price is right. In the early life of a practice it is often the only option, and it often works, until it does not.

Why is it a risk?

This is not about talent. It is about structure.

  1. No BAA. Anyone who can access your ePHI on your behalf, other than your workforce, generally needs a Business Associate Agreement. A family favor does not change that. See Business associate agreements for dental practices.
  2. No documentation. The network, the passwords, the vendor contacts and the quirks live in one person's head. When they are unavailable or the relationship ends, so does the knowledge.
  3. Single point of failure. One person on vacation, in exams, in a new job or out of patience.
  4. No coverage. Nobody is watching at 2 a.m. or on Saturday. See When should a dentist call IT after hours?.
  5. No security stack. Unmanaged antivirus, no MFA, no tested backups, no patching schedule, and an administrator account that is also somebody's everyday login.
  6. No evidence. A risk analysis, patch logs and backup test records are what show OCR a program exists. A well-meaning favor rarely produces them. See Risk analysis vs risk management.
  7. Misaligned incentives, gently. If something goes wrong, a family relationship absorbs the damage on top of the practice.

Is this fair to the nephew?

Yes, and it is the reason to raise it kindly. Dental IT now carries obligations and liabilities that were not part of the original favor. A part-time helper should not be personally responsible for a ransomware response or a breach investigation.

What are the options?

  • Formalize it: a written agreement, a BAA, documented access, MFA on every admin account, and a defined scope.
  • Hybrid: the helper handles day-to-day convenience; an MSP owns security, backups, patching and compliance evidence.
  • Transition to a managed provider: with a planned handoff so nothing is lost, credentials move to a vault and the helper is thanked rather than blamed.

How do you have the conversation?

Lead with protection, not criticism: "The rules have gotten stricter, and I'd like to take pressure off you." Agree on a transition date, a credential handoff and a documented inventory. See The first week with a dental MSP.

What does it cost to get this wrong?

Not just the cost of an incident, but the loss of the relationship and the practice's reputation. See Why Florida dental practices get ransomed.

Frequently asked questions

Can a family member do IT for my dental practice?

They can help, but if they access ePHI on your behalf they generally need a BAA, and the practice still needs documentation, security controls and coverage that a part-time helper usually cannot provide alone.

Does a freelancer IT person need a BAA?

If a freelancer or relative can access ePHI while working for the practice and is not part of your workforce, a BAA is generally required. Confirm with your compliance advisor.

How do I move from a part-time IT person to a managed provider?

Plan a handoff: inventory systems, move credentials to a vault, set a transition date and ensure the new provider signs a BAA before starting.

Sources and further reading

Related in the Journal

About CyberDental

CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.

CALL TEXT