Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
SECTOR 21 MAR 2026 · 3 MIN

Dentists, imaging systems and patient records

A dental practice holds some of the most sensitive data there is, often on an imaging system the supplier stopped updating two years ago.

RHODRI EMRYS · ASSURANCE
SHARE LinkedIn X Email
SECTOR cover image

A dental practice sits on special category data: health records, images, sometimes children's records too. That is the most sensitive tier the law recognises, and it comes with real duties. Yet the practice management and imaging software that holds it is often a specialist system, bought once, and left on whatever version it shipped with because touching it feels risky.

The recurring problem we see is a system the supplier has not meaningfully updated for a couple of years, running on a computer that cannot be updated either without breaking the software. That machine then quietly becomes the weakest point in the building, holding the most sensitive data, precisely because nobody wants to be the one who breaks the X-rays.

This is not a reason to panic, but it is a reason to plan. The first step is knowing exactly what you have: which system holds patient data, what version, whether the supplier still supports it, and what they will do if it is attacked. If the honest answer is that support ended, that is a business conversation to have with them now, not during an incident.

In the meantime there is sensible containment. Keep the vulnerable machine off the general internet where you can, restrict who can sign into it, make sure there is a genuine backup of the records held somewhere separate, and ensure a lost or stolen device cannot simply be read. None of that fixes the ageing software, but it limits the blast radius while you sort a proper answer.

If patient data is ever exposed, you also have reporting duties, and a tight window to meet them. Knowing in advance who you would call and what you would report turns a frightening morning into a procedure. That preparation is cheap. The alternative is not.

WHAT TO DO
  • ✓List every system holding patient data, its version, and whether the supplier still supports it.
  • ✓Ask the supplier in writing what happens if the system is attacked or unsupported.
  • ✓Keep a separate, tested backup of patient records off the vulnerable machine.
  • ✓Know in advance who you would report a data breach to, and within what deadline.