Episode · August 26, 2026 Episode 763 Dentistry

Dental IT, Cybersecurity & HIPAA Essentials with Dr. Lorne Lavine

Dental practice cybersecurity is a patient-retention problem, not an IT problem. Health and Human Services counts a ransomware infection as a reportable breach, and Dr. Lorne Lavine has watched practices lose a quarter of their patients after mailing that letter. Naren also covers what AI search is doing to how patients choose a dentist and […]

Gary TakacsGary TakacsHost · 40+ yrs coaching
Naren ArulrajahNaren ArulrajahCEO, Ekwa Marketing

Complimentary for listeners — a $900 value · 6-hour competitive audit + action plan

763+ episodes published #1 dental practice-management podcast Weekly every Wednesday
Featured Episode

This week on the Thriving Dentist Show

763Thriving Dentist Show
August 26, 2026 Dentistry Gary Takacs & Naren Arulrajah

Dental IT, Cybersecurity & HIPAA Essentials with Dr. Lorne Lavine

Dental practice cybersecurity is a patient-retention problem, not an IT problem. Health and Human Services counts a ransomware infection as a reportable breach, and Dr. Lorne Lavine has watched practices lose a quarter of their patients after mailing that letter. Naren also covers what AI search is doing to how patients choose a dentist and […]

Show Notes

Everything covered in this episode

Dental practice cybersecurity is a patient-retention problem, not an IT problem. Health and Human Services counts a ransomware infection as a reportable breach, and Dr. Lorne Lavine has watched practices lose a quarter of their patients after mailing that letter. Naren also covers what AI search is doing to how patients choose a dentist and why so many now arrive already sold.

If you want to know how your practice shows up when a patient asks ChatGPT or Google’s AI for a dentist, book a complimentary marketing strategy meeting at ekwa.com/td and get a full competitive analysis. And if the practice you are protecting still is not the one you set out to build, Gary is taking new coaching clients at thrivingdentist.com/csm.

Resources & links mentioned

Full Transcript

Search every word of this episode

Read along, jump to any moment, or search the entire conversation by keyword.

  • 00:00:29 - From Periodontist to Dental IT: How Dr. Lorne Lavine Got Here
    • Lavine practiced periodontics for 10 years and has not picked up a 15 scalpel blade in 24 years.
    • He started helping an orthodontist with technology in the mid-nineties, long before Schein, Patterson and Carestream were major players.
    • Moderating Dentaltown forums for Howard Farran and writing the technology column for Dental Economics turned a planned Southern California business into a North America-wide one.
    • He has never met 98% of his clients in person.

    Naren Arulrajah: Hello everyone. Welcome to the Thriving Dentist Podcast. I am your co-host, Naren Arulrajah. Today we are excited to bring an expert, someone with decades of experience, both in dentistry and the topic we are gonna be talking about. So, Dr. Lavine, Dr. Lorne Lavine, I'm sure many of you know his name. If you don't, you really need to get to know him because technology and AI and all how technology's helping us is only accelerating. And there's no better expert to speak to, because Dr. Lavine has the insider's view because he is a dentist. Dr. Lavine, are you still a practicing dentist?

    Lorne Lavine: No. I practiced for 10 years as a periodontist, and I just found that it really wasn't what I wanted to be doing full-time. I loved working with dentists as a specialist, but didn't love doing perio. As you know, periodontal patients are tough and they're very non-compliant, which is how they end up in your office in the first place. And I transitioned about 25 years ago. My initial thought was I would do both. But I just got so busy doing this, and I realized there's no way I could do full-time practice and run a company that does IT for dental offices. So I haven't picked up a 15 scalpel blade in 24 years. So it's been a while.

    Naren Arulrajah: That's awesome, because I agree it's hard to be the best in the world at two things, so you need to focus, but you are serving the patients by serving the dentists, at least your companies. Right. So, and of course, as somebody who has been in the profession, you know the do's and the don'ts and the what works and what doesn't, and what are the traps and what are the concerns, and how do dentists think? So I hope that allows you to create a solution and provide outcomes that are much more in line with what works for a dental practice. So when you were practicing on your own, you said you did work with a lot of general dentists. Correct. So, were you working at different offices, so you really saw from the inside out what's going on?

    Lorne Lavine: A little bit. Back when I started my practice in '91, the way that most periodontists got patients was referrals from other offices. So I would meet with the dentist, we would do lunches, I would do educational things, but it was much more of a referral based relationship. Nowadays, periodontists, oral surgeons, maybe half of their patients come through other offices through general dentists, and half might come through their own marketing or other things that they're doing. And patients are becoming more sophisticated. They understand who does implants and they realize they don't necessarily have to go through a general dentist. So I think that relationship has changed. But yeah, so what happened is that I was working part-time with an orthodontist. He needed help with this technology. He knew that this was something I was into, and I helped him set up his office.

    Lorne Lavine: And I started getting a number of requests from other offices to come into their practices and help them, because this is, like I said, this is back in the mid nineties, late nineties. This is long before Schein, Patterson, Carestream were major players. It was all small companies and small products that people didn't have the knowledge or the skill to get them to interact with each other. That was something that I was able to do. So I did get to see firsthand what dentists were struggling with. And then when I did make the decision that I was gonna do this full time, I moved from, I was practicing in Vermont. I moved to Southern California thinking that I would have a local business just in Southern California, 'cause there's so many dentists here. It didn't work out that way because Howard Farran asked me to moderate a bunch of the Dentaltown forums. And Joe Blaes, who was editor of Dental Economics, he asked me to be the technology columnist. So my name was getting out all over North America. And to this day, most of our clients are all across North America. The vast majority of our clients, I'd say 98%, I've never met in person. It's all been through phone calls, Zoom calls, emails, whatever. But there's a few local here in Southern California that I know, but most of 'em are spread all over the place. And we've never met in person.

  • 00:04:56 - Why The Digital Dentist Started: A $50,000 Quote and a 2008 Pivot
    • The trigger was an orthodontist quoted $50,000 for two computers who did not know how to turn a computer on.
    • The business began as hardware — computers, networks, digital x-rays, cameras — at $50,000 to $60,000 per office.
    • When the economy bottomed out in 2008-2009, Lavine pivoted to services and became a managed service provider, trading one $50,000 sale for $2,000 to $5,000 engagements.
    • HIPAA compliance work followed the 2013 omnibus rules; ransomware later moved the business to cybersecurity.

    Naren Arulrajah: That's awesome. So I know many people already know you, when we did events with you, hundreds of people attended and all of them know you by name. So, but for those who don't, I just want you to tell me a little bit about what made you start The Digital Dentist, what do you do now versus what did you start, in the early days, what were you doing? Just give us the story behind what are you up to and how did you get here?

    Lorne Lavine: Sure. So, as I said, the way it started is that when I worked with that orthodontist and helped him to set up his office, he had gotten a quote that I thought was very outrageous. It was like $50,000 for two computers, and this was a guy who didn't know how to turn on the computer. And I had this epiphany like, it's too bad that dentists don't have something that they can turn to that understands technology, but also understands things from a dentist standpoint. And all of a sudden this light bulb went on. I was like, well, I can do that. And like I said, it started off as a part-time thing, and it became so busy that I realized I had to make a decision. California had just passed licensure by credential. So I gave up my practice in Vermont, moved here.

    Lorne Lavine: So the focus of our business when we first started was just straight IT, purchasing computers, networking monitors, mounts, digital x-rays, cameras, more hardware focused. And that was fine for about five or six years. And then the economy dropped out. We were at 2008, 2009. And most of our, at the time, if someone came to me and said, Hey, I need a whole new office. I need x-rays, I need cameras. It was a 50, $60,000 investment. And when the economy bottomed out, most people were very hesitant to do that. So I came up with this idea relatively quickly. I said, well, it's gonna be hard to get them to do a $50,000 purchase, but maybe we can do a 2000 or a 3000 or 5,000. And we started focusing more on services, and I became what's called a managed service provider.

    Lorne Lavine: And MSP, it's basically a fancy way of saying automation, the things that we used to do manually. We now have systems so we can remotely log into people's computers. We can automatically patch their systems. We can get alerts when there's problems, things that we didn't have access to before. So I focused on that for a little bit. And then HIPAA, the final omnibus rules were passed in 2013. We focused a lot on HIPAA compliance, which we still do to this day. But we found that for whatever reason, a lot of practices, HIPAA didn't move the needle. They rightfully assumed that the chances of them being audited were low. They didn't feel that they were necessarily at risk, which of course is not true. But we still, we found that it just wasn't exciting.

    Lorne Lavine: The thing that really changed the equation for us in the model that we have now is ransomware. Once that became as prevalent as it is, we pivoted and really started focusing more on cybersecurity, on preventing ransomware infections, dealing with them once they do happen, recovering from them, if that happens. So that's been the focus. And I would say lately I'm starting, I haven't fully developed it yet, but I wanna start doing some type of AI consultancy as well. There's so many different AI products out there. Most dentists are hearing about it. They see some people are using it. In my experience, a lot of AI is not doing what it's supposed to do. It's not making life easier for dentists. So I think I can be beneficial in helping to guide people through the adoption of AI in their practices. So that's our focus. We work with offices all across the US and Canada to anything from computers, monitors, networks, backup disaster recovery, encryption, email, application whitelisting, staff training, anything IT related we do. So that's really what I've been doing for the last 20 plus years, with shifts along the way.

  • 00:09:28 - Why HIPAA Compliance Does Not Move the Needle for Dentists
    • "There’s no such thing as a hundred percent compliance. There’s 700 pages of rules and regulations."
    • Leading with HIPAA loses the client. Leading with ransomware, backup and data control wins it, and the same work delivers both.
    • Almost every dentist Lavine works with has been hit with ransomware or knows someone who has. Almost none know anyone who has been through a HIPAA audit.

    Naren Arulrajah: Perfect. I do have some questions around what is a managed service and all that stuff, but I'm gonna hold those for now. Okay. I'm gonna just jump into a comment you made before I talk about cybersecurity. You said HIPAA is not something that really is something that dentists are excited about, at least in 2026 as we are recording this. So is it like one out of a hundred who are into that kind of stuff right now? I'm just saying, what are you seeing versus your other services?

    Lorne Lavine: Yeah, so it's still critical and anyone that's gone through a HIPAA audit knows how bad it can be and is almost impossible to not go online and see news on a daily basis of some major organization that's been hit with some HIPAA fines and penalties for non-compliance. It's still very much a factor. What we have found from working directly with dentists is if I come in with the approach as, Hey, work with us and I promise we can get you more HIPAA compliant, 'cause there's no such thing as a hundred percent compliance. There's 700 pages of rules and regulations and impossible. If our approach to an office is, Hey, the reason you wanna work with me is I can get you more HIPAA compliant, I'm probably gonna lose that client because they just don't, it doesn't concern them as much as I think it should.

    Lorne Lavine: I think the ADA has done a somewhat mediocre job of educating dentists on HIPAA compliance and what needs to be done and what happens if you're not compliant. So our approach is to say, listen, we're gonna listen to what an individual client's needs are, but typically when they come to me they'll say, Hey, I'm worried about ransomware. I'm worried about my backup. I wouldn't be able to recover if there was a disaster. I'm worried that we don't have control over the data and what the staff are able to see. I'm worried about this and that. I can't sleep well at night and all about that. We'll come in with the approach, okay, we can absolutely help with all this. And oh, by the way, you're not HIPAA compliant. You're not doing the things that you should be.

    Lorne Lavine: The good news is that the things that I'm gonna do to get you more secure are also gonna get you more compliant. It's basically killing two birds with one stone because it's really the same set of rules and guidelines that you would use to get HIPAA compliant are also gonna get you more cyber secure and protect and secure that patient information. So they're very much interconnected. So HIPAA is still there. I think it's still an issue. But it's just not something that we push with our new clients as a reason to work with us because people, for whatever reason, like I said, it's not moving the needle. They don't like, oh my God, I'm gonna get fined by HIPAA. It's not that hard to find dentists who have been hit with ransomware or to know somebody that's been hit with ransomware. That's almost every dentist we work with says, yeah, we got hit with it, or the guy down the street got hit with it. But it's a lot less frequent for someone to say, yeah, I know somebody that went through a HIPAA audit. It's actually very infrequent.

  • 00:12:40 - Who Actually Audits a Dental Practice, and What the Fines Look Like
    • HIPAA is enforced by the Office for Civil Rights at Health and Human Services, plus every state dental society and state board.
    • Practices used to compare HIPAA to OSHA. With OSHA the worst offenses get a slap on the wrist. With HIPAA, "it’s not unusual for us to see hundreds of thousands, seven figure fines or settlements."
    • The premise: patients hand over name, address, phone, social security numbers and credit card information, and reasonably expect you to protect it.

    Naren Arulrajah: Right. So let me just one last question on HIPAA. So is it some kind of a government department that does these audits?

    Lorne Lavine: Yeah, well, it could be a few things. So HIPAA is run by the Office for Civil Rights, Health and Human Services. You could certainly get dinged by them. Every state dental society, state board has mechanisms in place as well that if a patient has had an experience at an office that they feel that their data was at risk, they can reach out to those individual state licensing boards, and you would still be the subject of, whether it's an actual in-office audit or there's other things that they can do to try to gather the information that they need. But between national and state and local, there's no escape, one way or the other, if they are worried about what you're doing, because the whole premise of HIPAA is that patients are giving us their most critical data, their name, their address, their phone number, oftentimes their social security numbers, credit card information.

    Lorne Lavine: They have a reasonable expectation that you're gonna do everything within your power to protect and secure that. That's the whole premise of HIPAA. Of course the devil's in the detail and the real issue with HIPAA from dental offices is not so much are you doing what you should be doing, it's what are the consequences if you don't do it? And that's where HIPAA has a lot of teeth. When we first started implementing HIPAA services for our clients, a lot of them compared it to OSHA. But the difference is that OSHA, even with the worst offenses, you're typically only getting a slap on the wrist. HIPAA fines and penalties, it's not unusual for us to see hundreds of thousands, seven figure fines or settlements, because they take it pretty seriously.

  • 00:14:35 - Ransomware Is a Reportable Breach, and the Letter Costs You Patients
    • Health and Human Services ruled in 2016 that a ransomware infection is a breach, because a breach is loss of control of your data and ransomware locks the files.
    • The breach notification rule is not ambiguous: you go on the public "Wall of Shame," you notify local news media, and you notify every patient in writing.
    • Insurance does not fix that. "That’s not gonna help you if you lose 20, 25% of your patient population."

    Naren Arulrajah: Yeah, fair enough. Let's jump into cybersecurity, right? Sure. So I want to talk about, from a 10,000 foot view, one option is buy insurance, right? So that's one way to protect yourself, and both HIPAA and cybersecurity, like you said, there's no hundred percent, you can improve, right? So give us the broad strokes on how do you attack this? Like, if I'm a practice owner, how do I think about this? How do I attack it? Am I just buying insurance and forgetting about everything? Or is it more than that?

    Lorne Lavine: No, and the problem with insurance is, I mean, most insurance will cover you, but if you get hit with a virus, number one, you're gonna be down for multiple days. It's not enough for us to just restore data, which is typically the way that we would do it. You have to make sure that you've eliminated that virus from every possible location in the practice. That takes a long time. Another thing that a lot of people don't know, and this was from a Health and Human Services release back in 2016, is that they consider a ransomware infection to be a breach. Even though most of us don't think of a breach in those terms, we think of a breach as, oh, someone hacked into my network, or I lost my laptop, or a thumb drive, or something like that.

    Lorne Lavine: The way that Health and Human Services looks at a breach is loss of control of your data, which is exactly what a ransomware does. It locks the files. So unless you can establish there's a very low chance of a compromise, which is almost impossible to do, then you suffered a breach. And unlike a lot of HIPAA, which is somewhat ambiguous and open to interpretation, the breach notification rule is not, it says very clearly that if you suffered a breach, you have to be listed on their website. It's called the Wall of Shame. You have to notify the local news media. But the absolute worst part is you have to notify all your patients in writing. So having that insurance might be great. That's not gonna help you if you lose 20, 25% of your patient population, 'cause you had to send out a letter to all of them that said, oops, sorry.

  • 00:16:44 - Dental Practice Cybersecurity, Layer One: Firewalls, Patching and the Server Everyone Forgets
    • A business-class hardware firewall — Sophos, SonicWall, WatchGuard — not the one built into Windows or your cable modem.
    • Anti-ransomware software on every workstation and on the server. "A lot of people forget to do the server, which is the most critical one."
    • Running an operating system past end of life is a HIPAA violation by definition. Windows 7, Windows 10 and Server 2012 are already there; Server 2016 goes end of life this coming January.
    • Application whitelisting stops zero-day attacks a firewall and antivirus cannot see, because anything not on the approved list is stopped before it runs.

    Lorne Lavine: But somebody now has your credit card information and your driver's licenses and, sorry that it happened. So our approach, to answer your question, is more of a three-pronged approach. Our first approach is prevention. What can we do to make sure that you keep the patient information secure? And the one that we've always used in the past, which we continue to use, is firewalls. A hardware firewall. Not the one that's built into Windows, a business class firewall. Even though all routers and cable modems have a mediocre firewall built into them. We want a real business class one from Sophos or SonicWall or WatchGuard or ones like that. Secondarily, we're doing some type of anti-ransomware or anti-malware software. We install it on every workstation. A lot of people forget to do the server, which is the most critical one.

    Lorne Lavine: You have to have it on the server. The third thing that you have to do is to make sure that your operating system, Windows in most cases, is current and patched. And that's why anyone that works with an IT person, they knew that every few years the IT guy is coming to you and saying, Hey, you need to replace your computers, 'cause Windows 7 is going to end of life, or Windows 10. And recently it was when it was Server 2012 and coming, this coming January is gonna be Server 2016. And the issue isn't that you lose support to Microsoft, 'cause most people never call them. It's that you no longer have security patches. Which means you're at risk. By definition, it's a HIPAA violation if you are running an outdated operating system that's no longer patched.

    Lorne Lavine: So if you're still running Windows 7, Windows 10, Server 2012 and 2016 in a few months, I highly recommend that you replace those. The problem with all of that is that a lot of the newer viruses are what's known as zero day. And there's different definitions for zero day. Zero day technically means that the antivirus companies have had zero days to find a cure for that virus that you're being hit with. What it really means is that that virus is exploiting a vulnerability that nobody knew existed beforehand. And the problem with that is that your firewall, your antivirus software, your operating system, it doesn't know that it's a virus. It doesn't know what to do with it. So there's a newer type of software that we've been recommending called application whitelisting. Basically, we create a list of all the programs that are on your network that are good to run.

  • 00:19:24 - Layer Two: Cyber Liability Insurance, Backups in Minutes, and Staff Training
    • Cyber liability insurance covers lost revenue during downtime, the ransom if it comes to that, and patient lawsuits after the notification letter.
    • Backup and disaster recovery must be well tested, and recovery is "measured in minutes, not days."
    • Most infections trace back to a person: a link in an email that looked like it came from a colleague, or a sketchy website.
    • Restoring a backup before the virus is fully removed just brings it straight back.

    Lorne Lavine: And if a program tries to run, and all viruses are just tiny little programs, just a series of instructions that tells us what to do, if that tries to run and it's not on that approved list, it gets stopped in its tracks. So that's all the preventative. The reality is, no matter how good your firewall is or anti-malware or application whitelisting, stuff is gonna get through eventually, the criminals are always usually one step ahead. So that's phase two for us, is making sure that you can recover. You mentioned one of 'em, which we highly recommend, is some type of cyber liability insurance that's gonna cover you for your lost revenues. If you're down for a number of days, God forbid, you have to pay the ransom. It'll cover you for that. God forbid you get sued by patients because you have to send them that letter.

    Lorne Lavine: It'll cover you for that as well. The second, and I briefly talked about this before, is that you have to have a really good, well tested backup and disaster recovery system, that you know that if you get hit with a virus or if your server goes down for whatever reason, that you can get back up and running. And we measure that in minutes, not days. So that's the most critical. And the third would be just more staff training, just because more often than not, we find that when someone gets hit with a ransomware, it's because you or your staff did something you shouldn't have. You clicked on a link in an email that you thought was from a colleague, or you went to a website that was a little sketchy. That's how these things happen.

    Lorne Lavine: So that's kind of our approach. It's almost like a funnel, that we wanna catch as much as we can at the beginning, which is the firewall and the antivirus. But if that gets through, then we want to have the application whitelist to stop it in its tracks. And if that still doesn't work, then we need to make sure we've got a really good backup that we can restore once we've of course removed any traces of that virus. 'cause restoring it back, that doesn't do you any good if the virus is still in your network. It's just gonna come right back.

  • 00:21:33 - AI in Dental Practices: Never Put Patient Information Into a Public AI
    • ChatGPT, Gemini, Copilot and Claude are public AI. They will not sign a business associate agreement, and by law anyone with access to patient information must.
    • These services keep your data and use it to train their models. You do not know where it goes or whether it is encrypted.
    • HIPAA lists 18 identifiers — name, date of birth, chart ID, phone number, address, a full facial photo. Any one of them makes it electronic protected health information.

    Naren Arulrajah: This is awesome. Thank you so much. Sure. I have a question on AI because I know it's a hard topic and everybody is probably thinking about AI. And you made a comment during our earlier conversation, there's a lot of things that call themselves AI, but they're not necessarily good for you. Either they don't do what they're supposed to, or they do such an inferior job, you might as well not have it because it's not helping you, it's hurting you. Right? Yeah. Your take on AI, any nuggets you wanna leave our audience with?

    Lorne Lavine: I think the one most critical takeaway is that a lot of people are using AI for good reasons. First of all, there's clinical AI, there's Overjet, there's Pearl, there's all these clinical programs. Where we're seeing a lot of development now is more administrative insurance, submissions and estimations and virtual office managers and assistants, and all these different things that make your life easier. It's important to understand that under no circumstances should you be putting patient information into a public facing AI. ChatGPT, Gemini, Copilot, Claude, those are all public AI things, and a lot of things that they do would not be ideal or even legal from a HIPAA standpoint. A lot of these AI companies will keep the data that you, because these are mostly cloud-based services. They'll keep the data and use it for training the AI models.

    Lorne Lavine: They might send it to another server. If they have access to patient information, they will not sign a business associate agreement, which is by law, anyone that has access to your patient information, you have to have a signed business associate agreement with them. They will not sign anything like that. They're not necessarily encrypting the data. You have no idea what happens to that data. You can certainly use AI to maybe create a merge or a letter that would go out to all patients, but you can't put anything in there. HIPAA has 18 different identifiers that if any one of those are in there. And that would include things like the patient's name, date of birth, chart ID, phone number, address, obviously a full facial photo. Any of that is considered electronic protected health information. And it's subject to all the rules of HIPAA as far as encryption and backup and who has access to it. So if there's any takeaways from AI, there's nothing wrong with tools like ChatGPT, but if you're gonna use it, you can't put anything that is patient information into them.

  • 00:24:11 - Where AI Works, and Why Six AI Systems Is More Work Than None
    • Clinical AI works. Lavine names Overjet and Pearl. Administrative AI "still has a little ways to go."
    • Offices running four, five or six AI systems are doing more clicking, more segmentation and more dashboard management than they were before AI.
    • Vet the vendor: certifications, what they do with the data, and a signed BAA. "I haven’t found that one killer AI system."

    Naren Arulrajah: Fair enough. Totally, totally makes sense. So you're saying that's the first thing they need to be careful of. But let's go back to where is AI working? I'm a fan of Overjet. Is there anything, having been doing, I mean, you have been doing this for a long time, but you're like, yep, that's good. Yep. So even if you don't name the bad ones, just name the good ones.

    Lorne Lavine: Yeah, no, I love Overjet. I love Pearl. I love the clinical ones. I think some of the administrative ones still have a little ways to go. I worry about people using AI as a crutch. It is not really what it's there for. It's to make my life easier. In my experience, we've worked with offices that are using multiple AI systems, and my thought process with AI is supposed to make your life more efficient, that you should have less things to worry about, that things are happening behind the scenes. In my experience, for these offices that might have 4, 5, 6 different AI systems going, it is way more work than what they had without the AI. They're doing way more segmentation, they're doing a lot more clicking. There's a lot more systems and dashboards that they have to manage.

    Lorne Lavine: That's not, in my mind, a better scenario. It's harder on your team if they have to know how to be proficient in five or six different systems and have all these different portals and dashboards and software systems that they have to learn and become proficient at. So I take it with a grain of salt. Like I said, clinically, I think it makes perfect sense. I haven't found that one killer AI system. And like I said, you can't use a public facing one. You have to do a really good job of vetting these vendors. You need to make sure that they have all the appropriate certifications. You need to understand what they do with the data. They need to be willing to sign a BAA with you, a business associate agreement. But I think that the one company that finds a single AI platform that can handle everything for an office, they will be very, very successful.

  • 00:26:14 - The AI Hardware Shortage: Server Prices Doubled in Six Months
    • A server that cost $3,800 to $4,000 six months ago now costs $7,800, and Dell is not shipping until late September or early October.
    • Refurbished servers through certified resellers now run close to $5,000 for roughly $2,500 of parts and software.
    • Lavine sees no relief on memory and enterprise drives until at least 2030. Budget hardware replacement accordingly.

    Lorne Lavine: But right now we're not seeing that. They're very limited in the scope of what each individual AI system can do. And I think it's not necessarily making life better for dental offices yet. We'll get there. And I'm not a huge fan of AI. I mean, I like the concept. As an IT provider, we can't stand it because they are gobbling up all the RAM and enterprise hard drives that we normally use. So any of my clients are well aware of this because a server that we would purchase for somebody six months ago was coming in at 3,800, maybe 4,000 give or take for that server. The exact same server, exact same specs are now 7,800 and Dell, which is what we use mostly, they're not shipping until late September, early October. I mean, you just can't get it, even refurbished ones, which that's what we've started doing for our clients, just because they come through Dell certified resellers.

    Lorne Lavine: So it has the same parts, the same warranty, just some of the parts are used. But even those are, the best price we can get now for a refurbished server is close to 5,000 for what really should be $2,500 worth of parts and software. So as much as I like the concept of AI and what it can do, we're seeing this massive shortage of memory and hard drives that I don't see any relief in sight to at least 2030, if that, maybe longer. It is gonna be a while.

    Naren Arulrajah: Wow. So you're saying buy those stocks.

    Lorne Lavine: Well, yeah. If you had Nvidia, my wife was smart enough to buy Nvidia years ago. That's huge. My son was on my case to buy Bitcoin back when it was at 5,000. And we bought a little, we bought a little Doge, and of course that exploded, but it's come down to Earth, it's half of what it was back in October, November. So

    Naren Arulrajah: Yeah,

    Lorne Lavine: from my, from my liked .

  • 00:28:21 - Naren’s Marketing Tip: AI Search Is Changing How Patients Choose a Dentist
    • AI has increased how much people use their devices to find a dentist, because they can now ask very specific questions and get a shortlist back.
    • Patients treat AI recommendations as if an expert human wrote them.
    • Doctors report that patients arriving from Google AI Overviews, AI Mode, ChatGPT and Perplexity are already convinced. "The sale is already done."
    • Naren’s CTA: book a marketing strategy meeting at ekwa.com/td to see how the practice is showing up in AI search.

    Naren Arulrajah: Yeah. Fair enough. Before we jump into this, I really want to thank you for your comments on AI because that's the number one question I also get, like, how is AI search changing the way patients find us, how is AI changing marketing? And I just want to share a tip because we are on the topic of AI. What I have found is AI has increased how much people use the internet or their devices to find the right dentist. Because now you can ask very, very specific questions. I'm this kind of a person, I'm looking for this type of a dentist, and AI will figure it all out and give you the top three recommendations. And the other funny thing is, patients trust these recommendations as if it was written by some expert human being, right?

    Naren Arulrajah: Right. Even though, like you said, it's made up and a lot of times it's nonsense, but the consumers think it's important. So one of the things we are doing internally is we are of course leaning into Google's AI, right? Google AI Overviews and AI Mode, but also ChatGPT and Perplexity. Because we are hearing from our doctors that patients, when they come from these AI platforms, whether it is Google or ChatGPT, they tend to almost, the sale is already done. They don't need to do any selling. Patient's already convinced. It's kind of an interesting phenomenon that we are noticing. So by the way, if anyone is interested in learning about how you are doing in the world of AI, book a marketing strategy meeting, it's how give

    Lorne Lavine: To you. I wanna book that with you. 'cause for my business, I'm tired of doing all the marketing and all the email blasts that I do and webinars, but yeah, sign me up,

    Naren Arulrajah: Absolutely. It's ekwa.com/td. E-K-W-A.com/td. Of course, Dr. Lavine, we will book that strategy meeting with you and we would love to help you as well. Lemme switch gears a little bit. I know you kind of talked about this $50,000 check and people didn't wanna, couldn't afford it. So you went into this word you threw at me again, I'm, of course I'm a novice because I haven't run a company like yours, nor do I know a lot about what you do. But as a novice, what is managed services? Like, okay, I'm a dentist, I know dentistry. I don't know anything about tech. I don't know anything about anything. So if I come and ask you, Dr. Lavine, what can you do for me? Right? What do you do for me? Is it I just pay you, just like a subscription, I pay you a monthly amount and you take care of it. What happens to the hardware? Again? Can I buy it as a subscription or do I buy it upfront? Oh, maybe I don't need as much hardware as I used to because everything is in the cloud. So help me understand, what, like, why do I need someone like you and how does it all work?

  • 00:30:59 - What Managed IT Services Cover, and How Dental Practices Pay for Them
    • Patching, backup and antivirus used to be manual and billable by the hour. "Tons and tons of billable hours. We loved it. Our clients not so much."
    • Automatic Windows updates are turned off for clients, because Microsoft patches are sometimes more trouble than what they fix and you lose control of the timing.
    • Monthly subscription, or prepay: one year earns a discount, two years doubles it, three years triples it. Providers pay their own vendors upfront, which is why contracts exist.

    Lorne Lavine: Right. So first off, every IT person, every IT company is different. In the past, there were a lot of services that we had for our clients, backup and patching and antivirus. Those all needed to be updated on a regular basis. There was no way to automate that process. So one of the things that we would do for our clients is on a regular basis, usually weekly, sometimes once a month, we had an inventory of all the programs on their network. We would go out, find the patches, apply the patches, reboot the computers, tons and tons of billable hours. We loved it. Our clients not so much, 'cause it was tons and tons of billable hours. And maybe like 10 years ago, a little bit less, this whole concept of automation came into play where software systems were developed that could do the things that we used to have to do manually on an automatic basis.

    Lorne Lavine: So most people are familiar with the fact that Windows and Office, for the most part, you can set up automatic updates. And we don't do that for our clients just because we know that Microsoft's patches are sometimes more trouble than what they're trying to fix. And you have no control over the timing of that. We typically turn that off for our clients and have our own patch management that we set the schedule on which patches we're going to apply. We want to have a little more control over it. But we have all kinds of systems in place that we don't have to charge the patient on a per hour basis. They can pay monthly. Now, I know a lot of dentists are somewhat not a big fan of subscriptions. They don't like the monthly payment.

    Lorne Lavine: And then we say, great, you can pay us upfront for the whole year or for two years or three years and we'll get this different discounts. And the reason that we do that is that most of the vendors that an IT or an MSP, managed service provider, would use, they charge us upfront for that year. If we buy a year's worth of their software, a year's worth of storage on a HIPAA compliant server, whatever, we have to pay it upfront. So we have to have a contract with that client because if the client decides after a month, you know what, I think I'm just gonna do this on my own. Thanks very much. I've bought all this software and all these services for somebody on their behalf that I'm no longer being paid for. So we have to protect ourselves from that.

    Lorne Lavine: And we know people hate that, but we do have a large number of our clients who will prepay us for a year, 'cause we give them a discount for one year. And if they commit to two years, we double the discount and triple it for three years. So we try to give them a reason to do that. There's no cookie cutter approach. And what we have found, the way that we approach, when someone calls me up or they see me on Dentaltown or see my articles in Dental Economics, or they're gonna listen to this podcast and they say, Hey, I have questions, I'm not sure what I need for my office. Am I doing everything within reason to protect the patient information and am I HIPAA compliant?

  • 00:34:18 - The Free Security Audit: 30 Minutes, Zero Cost, Zero Obligation
    • "You can’t treatment plan unless you diagnose first." The audit checks operating systems, backup, encryption, firewall, and when the last risk assessment was done.
    • It takes 30 to 40 minutes, runs with your permission, and you can watch the whole thing. Offered to listeners at no cost and no obligation.
    • If you already have a local IT person, Lavine’s team fills the gaps rather than replacing them. "We learned a long time ago how to play nicely with others."

    Lorne Lavine: What we have started doing, what we've done for a long time, what we started doing is not charging for it, is to offer them a, we call it a security audit or a technical audit where, listen, as any dentist knows, you can't treatment plan unless you diagnose first. And that's the exact same approach that I take. But what we have been doing lately, and we're happy to do this for anyone that's listening to this podcast, is to eliminate that barrier to entry. To say, Hey, we will log into your network. We're gonna see AMP with, with your permission, you can watch what we're doing. We're gonna gather data, we're gonna see what operating systems you're running, what are you doing for backup? Do you have encryption in place? Do you have a firewall? When's the last time you did a risk assessment?

    Lorne Lavine: If ever. Let's do a full evaluation. And it doesn't take long. Usually about 30, 40 minutes tops. And based on that, we can then sit down with the client and say, okay, here's what we found. Here's our concerns and here's what we think is the best way to deal with this. Here are your options. Here's what the different options would cost. That whole process, we're happy to offer that to your listeners at no cost. So there's zero cost, zero obligation. Anyone that's ever worked with me knows I'm not about the hard sell. I'm about educating people to let them know, this is where you're at. This is where you're at risk. Whether you believe me or not, that's up to you. But these are things that we can help with. We of course would love to work with you, but if not, you've got the information to go out and find someone else.

    Lorne Lavine: One of the most common questions we get is that, Hey, I've got a local IT guy. He's been good for us for the little things, but I know he doesn't understand HIPAA or he doesn't really know cybersecurity. Can you work with him? And the answer is absolutely. We learned a long time ago how to play nicely with others. And we're more than happy to have a local IT person that handles the day-to-day IT. And we fill in the gaps. We handle the backup, we handle the cybersecurity, we handle the insurance, we handle all the things. And we work with the IT person so that they know what we're doing. And they can try to do some troubleshooting themselves or we'll hop onto a Zoom call with them or get on the phone with them to help 'em through an issue.

    Lorne Lavine: It's collaborative. 'cause at the end of the day, for most of our clients, what they care about is sleeping well at night, knowing that they've got things under control. And however that looks like, we're happy to do it. We're not, oh, it's us or nothing. That's just not the approach that we take. But as I said, our overall approach to things is let us help you to figure out where you're at risk and let you know what your options are. At the end of the day, it's your practice, your money, you decide what's best. And of course, either way, we're more than happy to be part of that.

  • 00:37:24 - Why DIY Dental IT Falls Apart the Day Something Breaks
    • The DIY approach works "until the day something goes wrong" — a full schedule, no access to it, no x-rays, and no one to call because you are the IT person.
    • Two or three days of downtime typically costs more than six or seven months of managed services.
    • When one client questioned renewing, the report showed 37 separate logins to fix issues they never knew about, because it all happened after hours.

    Naren Arulrajah: That's brilliant. So let me kind of paraphrase what I understand, right? So if I am a practice owner, somebody has to do all of this stuff, keep things updated, keep things compliant proactively, make sure I have insurance, make sure my team is trained. So you are like a done for you. We'll take care of this for you. Of course, if they have their own IT guy, you'll work with the IT. So you augment the IT person, but if they don't, you'll take care of the whole thing. And of course, there are different options with different pros and cons or different, right. We're turnkey. They can pick and choose.

    Lorne Lavine: We're a one stop shop. We work with dentists occasionally who, some of 'em are very computer savvy and a lot of them say, Hey, I think I wanna do this myself. This may not be the right fit. That's fine. All the power to you. And that's what we've typically found. That's a great philosophy. Until the day something goes wrong. Yes. And then you've got a day full of patients, then you don't have the time to deal with it. And all of a sudden you don't have access to your schedule. You can't take x-rays, you're dead in the water and you don't have anyone you can turn to because you're the IT person. You don't have someone else. So even though I understand maybe it sounds self-serving, I think that IT managed services for dental offices have become so complex, and you mix in HIPAA compliance and you mix in AI.

    Lorne Lavine: And I just don't think it's something that most dentists should be doing on their own. They really would benefit. It doesn't have to be us, it can be anybody. But to work with a managed service provider, an IT provider that knows healthcare, that knows dentistry, that can be there to help guide them and resolve any problems. And we'll tell people, listen, yeah, we're not cheap. We understand that. But when you look at, well, what did that two days or three days of downtime cost you because you couldn't function? And in almost all cases, it cost them more to be down for a few days than it did for six, seven months of our services. So we can always justify the cost, or at least I can justify it. And that's honestly one of the other issues that we run into, is that if it's done properly, if things are set up properly and managed and monitored, you shouldn't need to be calling your IT company on a daily basis or a weekly basis.

    Lorne Lavine: It should be behind the scenes and you're not even aware of it. So one of the more common scenarios that we see is we'll get to the end of that contract. It's been a year, two years or whatever. And we'll call 'em up and say, listen, we can keep the fees the same or we've gotta bump it up two or 3%. Our prices went up a little bit. And they'll say to me, well, we love your team, but we didn't really think we needed you that much this year. So we're not sure if we're gonna renew. Of course, we have a full report of the 37 times that we had to log into their network to deal with issues that they weren't even aware of because it was all done after hours or behind the scenes. But if it's done right, you shouldn't really be dealing with IT issues on a regular basis. It really should, it's there to help you, not to give you more frustration.

  • 00:40:35 - What a Dental-Only IT Provider Does Differently
    • The firm works only in dental. First hire January 2004, second May 2004, third 2012 — all still there, alongside the office manager who replaced the original one 15 years ago.
    • Few dental IT providers run a HIPAA risk assessment, even though the law requires one and it typically surfaces five to ten hours of fixable problems.
    • Every service in the stack maps to a HIPAA requirement. Only the cyber liability insurance is genuinely optional.
    • Lavine writes for Dental Economics, answers questions on Dentaltown and lectures at every major meeting. Few dental IT people teach at all.

    Naren Arulrajah: Right. Great. It is. You don't even know they're there. Right? That's the best. Pretty much you are doing your job. They should never have to think about you. The only time they have to think about is somebody messed up somewhere, whether it's some problem came in and nobody was catching it and so forth. So, one last question before I ask you to help our listeners book that meeting or get that free audit you talked about, and of course your socials and whatnot. I know there are other players who quote unquote specialize in dentistry, right? I mean IT companies. Yes. But being a dentist, you have a different viewpoint, different perspective. How would you say, how has that shaped you or why do you think you are different from quote unquote IT companies that help dentists?

    Lorne Lavine: Right. So first off, a lot of IT companies that work with dental are not exclusive to dental. They might do medicine, they might do law, they might do whatever. That's all we do. We know dental systems inside and out. My very first hire was in January of 2004. He's still with me. My second hire was in May of 2004. He's still with me. My third one was in 2012, I think. He's still with me. I hired a guy to handle just the backups for us, like right around COVID. He's still with me. My first office manager left. She moved outta state 15 years ago. The person that replaced her is still with me. I mean, we keep the same team intact and all we know is dental. So I think the approach that I took with my business is because when I was in practice, and again, this was back in the early nineties, this was long before you had any consolidation.

    Lorne Lavine: So there was nobody, I mean, I had so many different systems. I had a digital x-ray system, I had my practice management software system, I had my image management, I had other things that I was doing in the office, and there was no one person that I could turn to that could be the quarterback that could say, okay, I'm gonna take charge of all these. And that's what I think we bring to the table. The other approach that I've taken is to really be comprehensive. We know a ton of other dental specific, dental focused managed service providers out there. Few, if any, do a HIPAA risk assessment. It makes no sense to me. There's a HIPAA law that says you have to do a risk assessment. When we do it, we find all kinds of issues. And typically when we do a risk assessment, there's gonna be at least five to 10 hours of labor involved to resolve those issues.

    Lorne Lavine: So as an IT provider, we get to charge for the risk assessment, we get to charge for our time to fix the problems. Why wouldn't an IT company offer this to their clients? Because how are you supposed to know where you're at when it comes to HIPAA compliance and cybersecurity readiness if you don't look? And it just baffles me that there aren't more dental IT companies that do risk assessments, that do HIPAA management plans, that offer cyber liability insurance, that offer HIPAA manuals. I mean, these are all things that offices need. It's right up our alley. You can't do a HIPAA risk assessment without looking at the IT. It's a critical part of all that. So that's kind of been another difference that I think we have, is that I'm comprehensive. Our typical client is gonna get a full suite that has every service, unlimited IT support, there's no stone unturned.

    Lorne Lavine: There isn't a single thing that's not in that that you need on a daily basis, just 'cause like I said, we don't want them to be at risk. As much as I wish there was just one product or one piece of hardware you could buy and be done, you can't. In the IT world, we call it a stack, a set of services, hardware components, that allows us to get to the desired end result, which is security, compliance, peace of mind. And my approach is we need to have everything we can possibly have in that stack that you would need. So there's nothing that we provide to our clients that they don't need, other than the insurance, which I guess is optional, which we obviously don't recommend that you go without insurance. But other than that, every single service that we do for our clients has an associated HIPAA law. It's mandatory. They're not really optional. So now do all of our clients do that? No. I wish they would. But again, our approach is we're gonna educate them and let them know where they're at risk. And at the end of the day, it's their practice. They can decide what's the best path forward.

    Naren Arulrajah: Fair enough. I think one thing you forgot to name, which is obvious to me, is you teach. I mean, that's really like, you are right here teaching people. I don't see your competitors doing that. Maybe because like you said, for them it's just a client. For you, this is a group of people you care about. So it's about giving them everything, not just giving them the bare bones or the minimum required, but just doing everything and giving them the choice, what they want to pick from that everything, right? So, and you do that willingly in webinars and podcasts. Yeah. Thank you.

    Lorne Lavine: Yeah. I think I'm unique that way. I mean, I talk to a lot of my colleagues. Most IT guys, most IT people, they love the operations part. They love the nuts and bolts of running their business. They hate sales, they hate marketing. I'm literally the op. Well, no, I love, I enjoy the technical parts as well. I love doing webinars. I write for Dental Economics. I do webinars for other companies. I'm always on Dentaltown answering questions. I lecture all over. I've lectured at every major meeting. I love this part. I love the teaching aspect of it. So yeah, you're right. There's not a lot of people who do dental IT that are out there on the lecture circuit or writing for dental journals.

  • 00:47:03 - How to Reach Dr. Lavine and Claim the Audit
    • thedigitaldentist.com  has a contact form and live 24/7 human chat, not AI bots.
    • thedigitaldentist.com/call goes straight to his Calendly. Toll-free 866-204-3398 extension 200 reaches office manager Candace.
    • Findable as Digital Dentist or Lorne Lavine on LinkedIn, Facebook, and X. Mention the podcast to claim the audit offer.
    • Coverage runs 5:30am to 5:00pm Pacific, with weekend project scheduling available.

    Naren Arulrajah: Thank you. So as we bring this to a close, Dr. Lavine, can you please help our listeners to get that audit? That would be a huge, sure, huge benefit to our listeners. Tell us how they can go about doing that. And also if somebody's curious, they wanna follow you, tap into your education, how they can do that as well.

    Lorne Lavine: So if you go into Google and enter my name, my company's name is The Digital Dentist. So if you went to thedigitaldentist.com, there's a few ways there. On my website, there's a form that you can fill out that you want information. A few months ago, I actually hired a company to have live 24/7 real humans, not AI bots, managing my website. That if you're on there, someone, Dee, Gary, there's a few other different people depending on their shift, will actually come on and say, Hey, can I help you? Are you a client? What do you need? How can we help you here? If it's after hours, they'll just refer you back to the office, they'll gather your information. But a lot of times they can get you in touch with my office manager, get you in touch with me.

    Lorne Lavine: So if they want to do a call, if you go to thedigitaldentist.com/call, that'll take you right to my schedule, my Calendly schedule. You can book it right on there. We have a toll free number, which is 866-204-3398 extension 200. Gets you to my office manager, Candace, she'll be happy to book a call with you. I'm on Facebook, I'm on X, I'm on LinkedIn. If you search for Digital Dentist or Lorne Lavine on any one of those, you can DM me through X or Facebook or LinkedIn or whatever. I'm gonna get all those as well. So between my website, the phone, social media, there's lots of ways to get ahold of me and just tell me that you are listening to the podcast. You would like to take advantage of the offer and we'll find a time.

    Lorne Lavine: We're very flexible. Even though we're based in Southern California, most of our clients are on the East Coast and Midwest. So my first technician usually comes in around 5:30 in the morning, our time. The next side comes on at seven, the next side comes on at eight, and then they start taking off towards the end of the day. It varies. So we basically have coverage from 5:30 in the morning to 5:00 PM Pacific time. So typically we're there when you're there. And we can always, if someone has a large project that needs to go over a weekend, you can easily schedule that with our team, that they'll be available on weekends as well. We're not typically monitoring the calls on weekends, looking for emergencies. We all have families, but if you say, Hey, I'm planning to upgrade my computers, we're doing a major overhaul of the software, it's gonna happen on the weekend. You can actually schedule the time with our technician to be there. So we work every day.

    Naren Arulrajah: That's amazing. Dr. Lavine, I really enjoyed our conversation, and I think, thank you. Your perspective, being able to explain things in layman's terms is very, very valuable. And I think some of the people I've heard, they just make it like, my eyes start spinning, like my head starts spinning. They throw all these buzzwords and they kind of confuse you. So anyways, thank you for doing that. And I think, but the smartest people in the world, they can explain things in a way that a 10th grader can understand. So you definitely have that gift. No, thank you. Appreciate what you're doing. And I also wanna take a minute to thank our listeners. Please take advantage of Dr. Lavine's personal offer to talk to you, do the audit for you. So we'll put all those links in the show notes. So if you go to the podcast and look at the show notes, you will get all of that. But of course, just Google Dr. Lavine, you will figure it out. It's not too complicated. So in case you forget, just need to remember his name. So thank you Dr. Lavine, and thank you everyone for listening.

No matches found. Try a different word.
Your Hosts

Four decades of practice growth, one conversation

Gary Takacs, Dental Practice Coach

Gary Takacs

Host · Dental Practice Coach

40+ years helping dentists build thriving practices that deliver personal, professional, and financial satisfaction.

Naren Arulrajah, CEO, Ekwa Marketing

Naren Arulrajah

Founder & CEO · Ekwa Marketing

Leads a team that grows dental practices through search visibility, review systems, and high-converting websites.

Keep Listening

More episodes to grow your practice

Thriving Dentist EP 764
Dentistry

Dental IT, Cybersecurity & HIPAA Essentials with Dr. Lorne Lavine

Dental practice cybersecurity is a patient-retention problem, not an IT problem. Health and Human Services counts a ransomware infection as a reportable…

Aug 26 Play
Thriving Dentist EP 762
Dentistry

Dental IT, Cybersecurity & HIPAA Essentials with Dr. Lorne Lavine

Dental practice cybersecurity is a patient-retention problem, not an IT problem. Health and Human Services counts a ransomware infection as a reportable…

Aug 26 Play
Thriving Dentist EP 761
Dentistry

Dental IT, Cybersecurity & HIPAA Essentials with Dr. Lorne Lavine

Dental practice cybersecurity is a patient-retention problem, not an IT problem. Health and Human Services counts a ransomware infection as a reportable…

Aug 26 Play
Never Miss a Wednesday

Get every new episode in your inbox

Join thousands of practice owners getting the show notes, action steps, and growth tips delivered weekly.

No spam. Unsubscribe anytime.