How should vendors behave in the server closet?
A Patterson or Henry Schein visit is not a hall pass to disable EDR and add a switch from the trunk.
Journal · Chairside Manners · D·07 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida
Short answer: Any vendor visit to a dental practice's IT should follow rules: advance notice to your IT provider, an escort, a written scope, no disabling of security tools, no unmanaged devices added to the network, a change list afterward, a BAA where ePHI is accessible, and removal of remote-access tools when the job ends. A vendor visit is not a hall pass.
At a glance
| Before | Notify IT; agree scope; confirm BAA if ePHI is accessible |
| During | Escort; no disabling EDR or firewall; no unapproved devices |
| After | Written change list; remove remote tools; verify imaging and PMS |
| Who owns the environment | The practice, through its MSP |
Why do vendor visits need rules?
Equipment installers, software trainers, dealer technicians and ISP crews are often legitimate, helpful and necessary, and they routinely have more access in an hour than an employee has in a year. They plug into switches, install software, ask for administrator passwords and, in the interest of finishing the job, sometimes turn off the thing that is getting in the way, usually security software. Left unmanaged, each visit leaves the environment slightly less documented and slightly less safe.
What are the rules of engagement?
Before the visit
- Tell your IT provider the date, the vendor and the scope. No surprises.
- Confirm paperwork. If the vendor can access ePHI during the work, a BAA is generally needed. See Business associate agreements for dental practices.
- Agree on scope in writing: what will be installed, where and what is out of bounds.
During the visit 4. Escort the vendor and sign them in. Keep the server closet locked otherwise. 5. Do not disable endpoint protection or firewall rules. If the product conflicts with security tools, IT adjusts the policy; the vendor does not turn off protection. 6. Do not add unmanaged devices (a switch, a router, an access point) to the network. Every device goes through IT so it is placed, secured and documented. 7. Do not hand over shared administrator passwords. Give temporary, individual, logged access that is revoked afterward. 8. No personal remote-access tools left behind.
After the visit 9. Get a written list of everything installed or changed. 10. Remove or disable vendor remote-access software and accounts when the work is done. 11. Test the PMS, imaging and a backup. 12. Update documentation (diagrams, inventory, credentials vault).
What does this look like when the vendor is a supply dealer?
The same, and with respect: dealer technicians are skilled at their equipment. They are not responsible for your whole environment; your MSP is. The best installs are collaborative, with the vendor handling the device and IT handling the network and security around it. See CyberDental vs dealer IT.
What if a vendor insists that security must be turned off?
Pause and call your MSP. In most cases the real requirement is a specific exclusion or port, not "turn everything off." If a product genuinely cannot work with basic security controls, that is a risk to record and plan around. See What EDR does in an operatory.
What is the cost of getting this wrong?
An unmanaged switch that "temporarily" connects two networks, a remote tool left running for years, or a disabled firewall rule that stays disabled is exactly the sort of finding that appears in a post-incident review.
Frequently asked questions
Should a vendor technician be allowed to disable antivirus or EDR?
No. If a product conflicts with security software, your IT provider should adjust policy or add specific exclusions rather than turning protection off.
Does a dealer technician need a BAA?
If they can access ePHI during their work, a BAA is generally required for that relationship. Confirm with your compliance advisor.
What should I get from a vendor after a visit?
A written list of everything installed or changed, removal of remote-access tools and credentials, and confirmation that imaging and the PMS were tested.
Sources and further reading
Related in the Journal
- CyberDental vs dealer IT (Patterson, Schein, and the truck)
- Business associate agreements for dental practices
- What does the front desk own, and what does IT own?
- What EDR does in an operatory
About CyberDental
CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.
- HelpDesk: (954) 639-7049
- Email: support@cyberdental.co
- Address: 480 W 84th Street, Suite B106, Hialeah, FL 33014
- Website: cyberdentalgroup.com