By Industry

Internet for Medical and Dental Offices: Uptime, Imaging and HIPAA Network Basics

The circuit is rarely the compliance problem. The choices around it are: what shares the network, who stores patient data, and what happens when the line goes down.

A medical or dental office needs a connection that keeps the practice management system, imaging, phones and card payments running, a network inside the office that keeps patient systems apart from guest Wi-Fi and gadgets, and vendors that will sign a business associate agreement where HIPAA calls for one. The circuit itself is rarely the compliance problem; the choices around it are.

This article describes common network practice for healthcare offices. It is not legal or compliance advice. Your practice's HIPAA risk analysis, and the advisor who helps you with it, decide what you must do.

What runs on a practice's connection

Ten years ago a practice could lose the internet and keep seeing patients, because the schedule and charts lived on a server in the back room. Today much of that has moved to the cloud, and the connection carries far more:

  • Practice management and electronic health records, often cloud-hosted.
  • Insurance eligibility checks and claims through a clearinghouse.
  • E-prescribing and lab orders.
  • Imaging: digital X-rays and intraoral scans in dental offices, and larger files such as CBCT scans or studies sent to a radiologist or specialist.
  • Telehealth video visits.
  • The phones, which are now usually VoIP, and in many practices, fax.
  • Card terminals and patient payment portals.
  • Check-in tablets, guest Wi-Fi for the waiting room, cameras and door access.

When the connection drops in a cloud-based practice, the front desk cannot see the schedule, verify insurance or take a card. That is the reason uptime planning comes first.

HIPAA and the network, in plain terms

The HIPAA Security Rule requires covered entities and their business associates to protect electronic protected health information (ePHI) with administrative, physical and technical safeguards, based on a risk analysis of their own environment. It does not name products or brands. The technical safeguards include access controls, audit controls, integrity protections, authentication and transmission security.

Some safeguards in the current rule are "addressable" rather than "required," which is widely misread. Addressable does not mean optional. It means you implement the safeguard if it is reasonable and appropriate for your practice, or document why not and what you do instead. Encryption of data in transit is the common example, and in practice most offices encrypt. HHS proposed changes to the Security Rule in 2025 that would make several safeguards stricter; ask your compliance advisor what is final and what applies to you.

Business associates and the conduit exception

A business associate is a vendor that creates, receives, maintains or transmits ePHI on your behalf. HIPAA requires a business associate agreement (BAA) with them. HHS treats pure transmission services, such as an internet provider that carries data without storing it beyond what transmission needs, as conduits that generally do not need one. The exception is narrow, and many "telecom" vendors store data.

Vendor typeStores or accesses patient data?BAA usually expected?
Internet circuit onlyTransmits, does not storeGenerally no (conduit)
Hosted phones or UCaaS with voicemail, recording or faxOften yes: voicemails, recordings, faxesUsually yes
Answering service or AI receptionist taking patient messagesYes: caller details and reasons for callingUsually yes
Managed IT or managed firewall providerOften has access to systems holding ePHIUsually yes
Cloud EHR, imaging or backup serviceYesYes

Treat the table as a starting point for questions, not a ruling. If a vendor that will touch patient data declines to sign a BAA, that is usually the end of the conversation.

A network checklist for a practice

  • Segmentation. Separate networks (VLANs) for clinical workstations, business systems, card terminals, imaging devices, guest Wi-Fi and internet-of-things devices such as cameras and TVs. Guest Wi-Fi should never be able to reach a workstation.
  • A business-grade firewall with logging kept long enough to be useful in an investigation, and updates applied on a schedule.
  • Secure remote access. Multi-factor authentication and an encrypted VPN or equivalent for anyone reading charts or images from home.
  • Wi-Fi security. WPA2-Enterprise or WPA3 for staff, with individual logins rather than one shared password that former employees still know.
  • Backups that are encrypted, kept off site and tested by actually restoring something.
  • Power. A UPS on the firewall, switches and phone system so a brief power blip does not reboot the office.
  • Documentation. A simple diagram and inventory, so your risk analysis describes the network you actually have.

Our managed network and Wi-Fi service designs segmentation from the start, and cybersecurity and DDoS protection covers managed firewalls and monitoring.

Choosing the circuit

A single-provider office with a modest schedule is often well served by good shared fiber with a backup underneath. A multi-provider or multi-specialty practice that lives in cloud systems all day usually belongs on dedicated internet access, with a written SLA, symmetrical upload and a static IP block for remote access and imaging links. In both cases, the backup matters more than the headline speed: a second connection on a different path, with failover that switches automatically. Coax or a cellular link under a fiber primary is a common pairing. We cover the design in does your business need backup internet.

A worked example

A hypothetical dental practice, invented to show the arithmetic. Your numbers will differ.

A four-operatory practice has three providers and ten staff. On a busy morning, eight workstations use the cloud practice management system, two telehealth consults run at once, six phone calls are active and the waiting room has a dozen phones on guest Wi-Fi. The steady traffic is modest: six calls at roughly 100 kbps each is well under 1 Mbps, and two video consults at a few megabits each add little more.

The spike is imaging. Suppose the practice sends a 500 MB CBCT scan to an oral surgeon. That is about 4,000 megabits. On a connection with 20 Mbps of upload, it takes over three minutes at full speed while competing with everything else. On a 500 Mbps symmetrical circuit, it takes around eight seconds in theory. Neither figure is a crisis on its own, but a thin upload means every large send slows the phones and the front desk for the duration. The same method works for your own office: add up what runs at the same time, then look hard at the largest single upload.

Now the downtime side. If the practice sees a hypothetical 30 patients a day and a two-hour outage stops check-in, eligibility checks and payments, the cost is not just the lost appointments. It is the rescheduling calls, the claims that go out late and the patients kept waiting. That is the case for the backup circuit, more than for a bigger primary.

The systems people forget

When we map a practice's network, a few items almost always turn up late:

  • Fax. Healthcare still runs on it for referrals, records requests and pharmacy traffic. Fax over VoIP can be unreliable on a poorly tuned network, and cloud fax services store documents, which brings the BAA question back.
  • Imaging and lab devices that phone home to their manufacturer for updates or remote support. Put them on their own segment and know who can reach them.
  • Old workstations kept alive to run one piece of legacy software. They are often the weakest machine on the network and should be isolated.
  • The waiting-room TV and music, which belong on the guest or device network, never the clinical one.
  • Remote vendors with standing access for support. Keep a list, and remove access that is no longer needed.

Write a downtime plan before you need it

Even with a backup circuit, plan for the day both fail or the cloud system itself is down. A one-page plan covers most of it: how the front desk sees the day's schedule (a printed or exported copy each morning), how to record visits and payments on paper and enter them later, who calls patients if appointments must move, and which number to call for support. Test the failover every few months by unplugging the primary during a quiet hour. A backup that has never been tested is a hope, not a plan.

The phones deserve their own plan

Front desks in healthcare handle a heavy mix of scheduling, refills, billing questions and urgent calls. Good call flows route each type sensibly, send after-hours urgent calls to whoever is on call, and keep lunch-hour callers from hitting voicemail. Hosted phones make those rules easy to change. If you record calls, remember that several states require every party's consent, and that recordings and voicemails containing patient information are ePHI. An AI receptionist can take overflow and after-hours calls, but because it will collect patient details, ask the BAA question before it goes live.

Questions to ask your carrier and vendors

  • Is this circuit dedicated or shared, and what is the upload speed on its own?
  • Is there a written SLA with a repair window, and does it cover nights and weekends?
  • Can the backup enter the building on a different path from the primary?
  • For phone, fax, answering and IT vendors: will you sign a business associate agreement?
  • Where are voicemails, recordings and faxes stored, for how long, and who can access them?
  • Is data encrypted in transit and at rest, and can you document it for our risk analysis?
  • How are firewall and Wi-Fi updates applied, and who is notified when something fails?

Getting the practice connected

We price circuits, backups, phones and network services for your exact address across several carriers, and we are straightforward when a smaller product is the right fit. The carrier pays FiberX, so the invoice is not marked up, and the quote is free with no obligation. See how we design for healthcare on the industries page, send us your address, call 478-758-8091 or text (347) 870-0965. You will usually hear back the same day.

// QUESTIONS

Frequently Asked Questions

01Does my internet provider need to sign a HIPAA business associate agreement?

Usually not, if it only transmits data. HHS treats pure transmission services as conduits that generally do not need a BAA. Vendors that store or access patient information, such as hosted phone systems with voicemail or recording, answering services and managed IT providers, usually do. This is general information, not legal advice.

02What internet speed does a dental office need?

Steady traffic is usually modest. The spikes come from imaging, such as sending CBCT scans or large studies to specialists, so upload speed matters more than the download figure. Many practices do well with symmetrical fiber, while a backup connection on a separate path often matters more than extra speed.

03Should guest Wi-Fi be separate in a medical office?

Yes. Guest Wi-Fi should be on its own network segment that cannot reach workstations, imaging devices, card terminals or anything holding patient data. Segmentation is standard practice and makes a HIPAA risk analysis much simpler.

04Does HIPAA require encryption?

Under the current Security Rule, encryption is an addressable safeguard, which means you implement it where reasonable and appropriate or document why not and what you do instead. In practice most offices encrypt data in transit and at rest. HHS has proposed stricter rules, so check the current requirements with your compliance advisor.

05Do medical offices need backup internet?

Most practices that rely on cloud practice management, e-prescribing and card payments benefit from one. When the connection drops, the front desk may be unable to check patients in, verify insurance or take payment. A second connection on a different path with automatic failover keeps those systems reachable.

06Can an AI receptionist be used in a medical or dental practice?

It can handle overflow and after-hours calls, but it will collect patient details, so treat it as a vendor that handles patient information. Ask where call data is stored, how long it is kept, who can access it, and whether the provider will sign a business associate agreement.

// FREE · NO OBLIGATION · SAME-DAY RESPONSE

Want This Priced for Your Address?

Reading is cheap; a real number for your building is better. Pick a time below, or call and we will talk it through.

EMAIL INFO@FIBERXINTERNET.COM · TEXT (347) 870-0965

FIBERX · APPOINTMENT CONSOLE
Book an Appointment

Talk to Phil. Pick a Time.

A quick call with your dedicated agent — internet quotes, AI automation, or both. No obligation, same-day response.

Pick your 30-minute slot ALL TIMES ET
or call 478-758-8091

REQUEST GOES STRAIGHT TO PHIL · SAME-DAY CONFIRMATION