Patch Management for Dental Practices. How Skipped Updates Invite Ransomware

Patch Management Banner Image

The computer most likely to get your practice ransomed probably isn’t your server. It’s the workstation in op 3 that nobody has updated since the sensor was installed, because the last time someone updated it, the sensor stopped working.

I get it. I’ve spent over 20 years doing dental IT, and I’ve watched a bad Tuesday-morning update take down a full schedule. That memory sticks. So offices quietly decide the safest move is to leave everything alone.

Here’s the problem. Leaving everything alone is now the riskiest thing you can do.

Why Dental Offices Skip Updates

The fear is rational. Your practice runs on software that has to work every single hour patients are in chairs. A patch that breaks Dentrix or your imaging bridge at 9 AM on a Monday creates real chaos, real refunds, and real stress for your team.

So the logic becomes simple. Updates caused pain once. Skipping updates avoids pain. Done.

Except that logic only counts the disruptions you can see. It ignores the one you can’t. Ransomware crews are counting on exactly this reasoning, and unpatched systems remain one of their most reliable ways into a network.

What Patch Management Actually Covers

Patch management is the process of finding, testing, and applying software updates across every device in your practice. Not just Windows. Everything.

There are three layers, and most offices only think about the first one.

The Windows layer covers your server and workstations. This is what people picture when they hear “updates.”

The third-party layer covers Chrome, Adobe Reader, remote access tools, Java, and the dozens of small programs sitting on every desktop. These update on their own schedules, outside Windows Update, and they are the most commonly ignored layer in dentistry. A front desk PC can be fully current on Windows and still be running a browser version with a known, actively exploited hole.

The clinical layer covers your practice management software, imaging software, and the bridges between them. This layer needs the most care, because version mismatches here are what actually cause the horror stories.

Attackers don’t need a fancy new exploit to hit a dental office. In most ransomware cases, the entry point was a vulnerability that had a fix available for months. The protection existed. Nobody installed it.

Dentrix, Eaglesoft, and Open Dental Each Break Differently

This is where generic IT advice falls apart. The three big platforms in dentistry don’t respond to updates the same way, and your patching policy has to know the difference.

Dentrix

Dentrix expects the server and every workstation to run matching versions. When an update goes out, it needs to be coordinated across the whole office at once, not trickled out machine by machine. A half-updated office is an office where random workstations can’t open the schedule. Dentrix updates get planned as an event, after hours, with a rollback path.

Eaglesoft

Eaglesoft is the pickiest of the three about its environment. It cares about your Windows version and your SQL version, and Patterson certifies specific combinations. Pushing a major Windows upgrade to an Eaglesoft server without checking compatibility first is how a practice ends up on the phone with support while patients wait. On Eaglesoft, Windows patches get held until compatibility is confirmed, then deployed.

Open Dental

Open Dental ships updates frequently and is generally the most forgiving of the three. That sounds like good news, and mostly it is. The trap is complacency. Because updates feel easy, offices sometimes stop testing them, then an imaging bridge or eServices connection hiccups after a version jump. Easy is not the same as unattended.

If your IT provider treats all three the same way, they’re guessing.

Imaging Systems Deserve Their Own Rules

CBCT units, panos, and intraoral sensors run acquisition software that is often certified against one specific Windows build. Update past it and you can lose a driver, and with it, your ability to take images.

The answer is not freezing those machines forever. A frozen imaging PC becomes the softest target on your network, sitting there with years of unpatched holes while it stays connected to everything else.

The answer is a separate lane. Imaging computers get patched on their own schedule, only after compatibility is verified with the manufacturer, and with the ability to roll back. Slower, yes. Skipped, never. This is the part of dental IT where patience and process matter most.

The Process That Works

Every practice we protect runs the same four-step cycle.

Inventory everything. Servers, workstations, imaging PCs, and the software on each. You can’t patch what you don’t know exists, and every office has a forgotten computer in a back room.

Test the risky updates. Anything touching the practice management software, imaging, or the server gets verified before it touches production.

Automate the routine. Browser updates, PDF readers, and standard Windows patches deploy automatically, overnight, when no one is in a chair.

Verify compliance. Someone actually checks that every machine took its updates. Deployed is not the same as installed.

Run this cycle and patching becomes boring. Boring is the goal.

What Attackers Actually Look For

Ransomware crews don’t hand-pick victims. They run automated scans across the internet looking for specific unpatched software, all day, every day.

When a vendor announces a security fix, they’re also announcing the flaw. Working exploit code often shows up within days of that announcement, sometimes within hours. From that moment, every system without the patch is on a list.

Healthcare gets hit hard because the data is valuable and the downtime is intolerable, which makes practices more likely to pay. Your size doesn’t hide you. A scanner can’t tell a 4-op practice from a hospital. It only sees the open hole.

Security and Stability Are Not a Trade

You don’t have to choose between a network that’s safe and software that works. That choice only exists in offices where patching is either ignored or done carelessly.

Tested, scheduled, automated updates happen quietly in the background. Your schedule runs. Your images acquire. And the unpatched entry point ransomware needs simply isn’t there.

If you don’t know when your systems were last patched, or whether your imaging PCs have been frozen since installation, that’s worth finding out before someone else does. We run practice risk assessments that answer exactly that question. One phone call, and you’ll know where you stand.


Michael Amador is the owner of Willamette Valley IT, a dental-only IT company serving practices from Longview, WA to Salem, OR.