Your CBCT Got an Upgrade. Did Your WiFi Encryption?

WiFi Encryption Banner Image

Most dental offices upgrade their CBCT before they upgrade their WiFi encryption.

That’s not a criticism. It’s just how it goes. Dentists will spend months researching imaging systems, comparing software, evaluating ROI, and confidently making a six-figure investment. But ask what WiFi encryption the office is running and the answer is usually some version of “I’d have to check.”

I’m Michael Amador. I own Willamette Valley IT, and dental IT is all we do. My wife is a dentist. My father-in-law is a dentist. I’ve spent over twenty years inside dental practices, and I can tell you the network is quietly becoming the most important system in the building and the least reviewed one.

Let’s fix that in about five minutes of reading.

Your WiFi Is Clinical Infrastructure Now

Your wireless network stopped being “just internet” a long time ago.

Today it carries your practice management software, your digital imaging, your cloud backups, your credit card processing, your VoIP phones, staff laptops and tablets, and every patient phone in your waiting room. If the WiFi is weak, everything riding on it inherits that weakness.

There’s a compliance angle too. HIPAA expects you to protect patient data while it moves across your network, not just while it sits on a server. Patient records crossing a poorly encrypted wireless network isn’t only a technical problem. It’s a compliance exposure with your name on it.

The Four Encryption Types in Plain English

Open your router or firewall settings and you’ll see one of four options. Here’s what each one actually means.

WEP

Broken. Completely. WEP can be cracked in minutes using free tools, and it’s been considered insecure for roughly two decades. If you see WEP anywhere in your settings in 2026, stop reading and call someone. Seriously.

WPA

WPA was the emergency patch that replaced WEP. It was better. It is no longer good enough, and it hasn’t been for years. If your office is still on original WPA, you’re overdue for an upgrade, and it’s probably a sign your equipment is old enough to replace anyway.

WPA2

The industry standard for most of the last fifteen years. Properly configured with a strong passphrase, WPA2 is the minimum I want to see in a dental practice. One caveat most people don’t know about. In 2017, researchers found a flaw in WPA2 itself called KRACK. The fix was a firmware update. If nobody has updated your router firmware since you bought it, that patch may have never landed.

WPA3

Current best practice. WPA3 has stronger authentication and much better resistance to brute-force attacks, which is when hackers repeatedly guess passwords until one works. Here’s the part I find genuinely impressive. Under WPA2, an attacker can record your encrypted traffic, take it home, and try to crack the password offline at their leisure. WPA3 shuts that down. The captured traffic is useless without breaking the handshake in real time.

If you’re buying new networking gear, WPA3 support should be on the requirements list. Full stop.

The SSID Myth and Other Things That Don’t Protect You

Your SSID is your network’s broadcast name. It’s what shows up when you tap the WiFi icon on your phone.

A surprising number of offices believe that hiding the SSID makes the network secure. It doesn’t. Free scanning tools reveal hidden networks in seconds, and hiding your SSID can actually make things slightly worse, because your devices then go around actively asking for that network by name everywhere they travel.

Same goes for “we have a password, so we’re encrypted.” A password and strong encryption are two different things. WEP has a password too, and it’s about as protective as a screen door.

Rename your SSID to something that doesn’t advertise your practice, sure. Just don’t confuse that with security.

Encryption Is Step One, Not the Finish Line

This is where most practices stumble. They see WPA2 or WPA3 in the settings and mentally file network security under “handled.”

Encryption protects your data while it’s in the air. It does nothing about the humans holding the password. The problems I see over and over in dental offices look like this.

  • The WiFi password has been shared with dozens of people and hasn’t changed in years
  • Former employees still know it
  • The same password gets reused for other systems in the building
  • Patient devices and clinical systems share one network

Even excellent encryption can’t survive weak operational habits. Real security is layered. Modern encryption, WPA2 at minimum and WPA3 preferred. Passwords that rotate on a schedule, and immediately when someone leaves. A guest network fully separated from the network your practice management and imaging systems live on. Ongoing monitoring so problems get caught early instead of after.

Security isn’t a switch you flip once. It’s a habit your practice keeps.

One Question Every Practice Should Be Able to Answer

What encryption is your office running right now?

Not what it was set to when the router was installed. Not what you assume it’s running. What is it actively configured to use today?

Site Icon

If you don’t know, you’re in good company. Most owners don’t. But “most people don’t know” is a reason to verify, not a reason to relax.

Modern dentistry runs on connected technology. Imaging, charting, scheduling, payments. All of it touches the network. Your network deserves the same level of investment and attention as your clinical equipment. Upgrading your digital tools while ignoring the network underneath them is like installing new software on a ten-year-old computer. It works for a while. Then one day it doesn’t, and it picks the worst possible day.

Verify It This Week

Strong WiFi encryption isn’t hard. It isn’t expensive. It’s just invisible, which is why it gets skipped.

Checking what your office is running takes minutes. Any competent dental IT provider can confirm your encryption type, review your password practices, and separate guest traffic from clinical traffic in a single visit. If your current provider can’t answer those questions quickly, that tells you something too.

Your practice runs on technology. Make sure the network underneath it is built to carry the weight.


Michael Amador is the owner of Willamette Valley IT, a dental-focused IT company serving practices across the Pacific Northwest.