This is a sample. It was prepared for a fictional dental practice so you can see exactly what you receive. Every finding below is illustrative. Yours reports what is actually visible about your domain on the day it is run.
Get yours, free Back to IT for medical and dental practices
IT First Response
Managed IT and security · Fort Myers, Lee County FL
Complimentary
Security Check

An attacker starts with what is already public. So do we.

Then the schedule stops

You cannot look up a patient, take an image into the record, or send a claim until it is back.

And it is a breach, not an outage

Patient data reached means notifying everyone affected. HHS publishes breaches of 500 or more.

We only looked at the public half

Nothing signed, nothing installed, no chart opened.

Prepared for Marlowe Family Dentistry, P.A.  ·  August 2026
by Mario Del Mazo
Overall standing
Not yet scored
Set each item below
The bottom line
Nine addresses at your domain are in public breach data, including one mailbox the front desk shares. That is the one to close first. Nothing stops a forged message reaching a patient as you either, and that is a same-day fix.

What we looked at

Standing derived from these three · never assigned by opinion
Email impersonation

Can a stranger send mail that looks like it came from you? SPF, DKIM, DMARC.

No DMARC record is published, and the SPF record ends in a soft fail. A message that appears to come from your front desk will usually reach a patient inbox rather than being rejected.
Look-alike domains

Has anyone registered a near-miss of your web address?

A near-miss of your web address is registered to someone else, with mail records already on it.
Exposed credentials

Do addresses at your domain show up in known public breach data?

Nine addresses at your domain appear in public breach data, including one shared front desk mailbox.

What only you can answer

Your answers, not our findings · does not affect the standing
Multi-factor sign-in on every account that can reach patient charts. §164.312(d)
The practice management backup restored and checked in the last year, not just running. §164.308(a)(7)(ii)(D)
Access removed the same day someone leaves, temps and hygienists included. §164.308(a)(3)(ii)(C)
A signed Business Associate Agreement with every vendor, imaging and billing included. §164.308(b)(1) Required
A written security risk analysis done or updated in the last year. §164.308(a)(1)(ii)(A) Required
Security training this year for everyone, front desk and part-time included. §164.308(a)(5)(i) Required

The first three things I would fix

In priority order
1
Force a password reset on the nine exposed addresses and give the front desk named accounts instead of one shared mailbox. A shared login means no one can tell who did what.
2
Publish a DMARC record at p=quarantine and change the SPF soft fail to a hard fail. Stops a forged message from your practice reaching a patient. About an afternoon.
3
Register the near-miss variants still available, and show the front desk what the taken one looks like.

Book a free 15-minute call

We walk through anything flagged above. Nothing to decide on the call.

Not your practice? This check is free

Forward it, or ask for your own. Any Lee County practice.

Registered Florida LLC Tech E&O and cyber liability insured No tier one, no ticket queue

A complimentary, outside-only snapshot based on public information as of the date shown; findings may change. No practice systems were accessed, scanned, or tested, and no protected health information was requested, received, or reviewed. It is not the security risk analysis required by 45 CFR §164.308(a)(1)(ii)(A), not a HIPAA compliance audit, and not legal advice. There is no government HIPAA certification, and no assessment alone makes a practice compliant.