CYBER DENTAL 2.0
(954) 639-7049

What we keep, what we don't

Privacy of the house.

Journal · Trust · H·04 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida

Short answer: A dental MSP should keep what it needs to run and secure your environment (inventory, configuration, monitoring data, tickets, access logs) and should not collect, copy or retain patient records beyond what the work and the BAA require. Ask any provider what it stores, where, for how long, who can see it and what happens to it when you leave.

At a glance

MSPs typically keep Device inventory, configuration, monitoring telemetry, tickets, access logs, documentation
MSPs should not keep Patient charts or images beyond what a task requires
Governed by The Business Associate Agreement
Ask What, where, how long, who can see it, what happens at exit
Principle Minimum necessary

What follows describes principles and the questions to ask any provider. For CyberDental-specific retention periods and data locations, rely on your signed agreement and BAA.

Why does this question matter?

Because an IT provider sits inside your environment with broad technical access, and trust in that position should rest on specifics, not assurances. You are entitled to know what is collected about your practice, where it lives and when it is deleted.

What does a managed IT provider typically keep?

Operational data needed to run and secure the environment:

  • device and software inventory;
  • configuration and network documentation;
  • monitoring telemetry: health, performance, alerts, patch status, backup status;
  • tickets and communications;
  • access logs showing who did what and when;
  • credential records, stored in a controlled vault.

CyberDental's Smart Agent works at the level of device health and operational signals, not clinical content. See The self-healing practice.

What should a provider not keep?

Patient records beyond what a task requires. An engineer fixing a database fault may need technical access to a system that holds ePHI, but that does not mean the provider should export, copy or retain charts, images or patient lists. Access should follow the minimum necessary principle and be limited to the task.

What governs this?

The Business Associate Agreement. It defines permitted uses of PHI, required safeguards, breach reporting, subcontractor flow-down and return or destruction of PHI at the end of the relationship. See Business associate agreements for dental practices.

What questions should a practice ask?

  1. What data about us do you store, and where is it hosted?
  2. Do any of your tools collect or transmit patient information?
  3. How long do you retain logs, tickets and backups?
  4. Who on your team can access our systems, and how is that access logged and reviewed?
  5. Which subcontractors and tools touch our data, and are they under BAAs?
  6. How is our data separated from other clients'?
  7. What happens to everything when we leave: how do we get our documentation and credentials back, and what do you delete?
  8. Do you use our data for any purpose other than serving us?

How does that connect to offboarding?

A clean exit means the practice gets back its documentation, configuration and credentials; the provider's access is revoked the same day; and anything the provider holds is returned or destroyed as the BAA requires. See What does the front desk own, and what does IT own?.

How does CyberDental approach this?

CyberDental signs a BAA with every practice before it works on systems that contain ePHI and treats access as limited to what the work requires. Ask for the specific retention and location details for your plan in writing.

Frequently asked questions

Does a dental MSP keep copies of my patient records?

It should not retain patient records beyond what a task requires and the BAA allows. Ask your provider what it stores and for how long.

What data does a managed IT provider collect about my practice?

Typically device inventory, configuration, monitoring telemetry, tickets, access logs and documentation needed to run and secure your environment.

What happens to my data when I leave my IT provider?

It should be governed by your BAA: access revoked, documentation and credentials returned, and any PHI returned or destroyed as required.

Sources and further reading

Related in the Journal

About CyberDental

CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.

CALL TEXT