This is a sample. It was prepared for a fictional dental practice so you can see exactly what you receive. Every finding below is illustrative. Yours reports what is actually visible about your domain on the day it is run.
Managed IT and security · Fort Myers, Lee County FL
Complimentary Security Check
An attacker starts with what is already public. So do we.
Then the schedule stops
You cannot look up a patient, take an image into the record, or send a claim until it is back.
And it is a breach, not an outage
Patient data reached means notifying everyone affected. HHS publishes breaches of 500 or more.
We only looked at the public half
Nothing signed, nothing installed, no chart opened.
Prepared for Marlowe Family Dentistry, P.A. · August 2026
by Mario Del Mazo
Overall standing
Not yet scored
Set each item below
The bottom line
Nine addresses at your domain are in public breach data, including one mailbox the front desk shares. That is the one to close first. Nothing stops a forged message reaching a patient as you either, and that is a same-day fix.
What we looked at
Standing derived from these three · never assigned by opinion
Email impersonation
Can a stranger send mail that looks like it came from you? SPF, DKIM, DMARC.
No DMARC record is published, and the SPF record ends in a soft fail. A message that appears to come from your front desk will usually reach a patient inbox rather than being rejected.
Look-alike domains
Has anyone registered a near-miss of your web address?
A near-miss of your web address is registered to someone else, with mail records already on it.
Exposed credentials
Do addresses at your domain show up in known public breach data?
Nine addresses at your domain appear in public breach data, including one shared front desk mailbox.
What only you can answer
Your answers, not our findings · does not affect the standing
Multi-factor sign-in on every account that can reach patient charts. §164.312(d)
The practice management backup restored and checked in the last year, not just running. §164.308(a)(7)(ii)(D)
Access removed the same day someone leaves, temps and hygienists included. §164.308(a)(3)(ii)(C)
A signed Business Associate Agreement with every vendor, imaging and billing included. §164.308(b)(1) Required
A written security risk analysis done or updated in the last year. §164.308(a)(1)(ii)(A) Required
Security training this year for everyone, front desk and part-time included. §164.308(a)(5)(i) Required
The first three things I would fix
In priority order
1
Force a password reset on the nine exposed addresses and give the front desk named accounts instead of one shared mailbox. A shared login means no one can tell who did what.
2
Publish a DMARC record at p=quarantine and change the SPF soft fail to a hard fail. Stops a forged message from your practice reaching a patient. About an afternoon.
3
Register the near-miss variants still available, and show the front desk what the taken one looks like.
Book a free 15-minute call
We walk through anything flagged above. Nothing to decide on the call.
Forward it, or ask for your own. Any Lee County practice.
●Registered Florida LLC●Tech E&O and cyber liability insured●No tier one, no ticket queue
A complimentary, outside-only snapshot based on public information as of the date shown; findings may change. No practice systems were accessed, scanned, or tested, and no protected health information was requested, received, or reviewed. It is not the security risk analysis required by 45 CFR §164.308(a)(1)(ii)(A), not a HIPAA compliance audit, and not legal advice. There is no government HIPAA certification, and no assessment alone makes a practice compliant.