Atlanta Dental Group — HIPAA-grade backup for a 4-location dental practice
Atlanta Dental Group
Encrypted Exchange + OneDrive backup, immutable off-host snapshots, tested-restore drills, and HIPAA documentation that survives a board audit — for a practice whose patients expect their chart to be there Monday morning.
Atlanta Dental Group — by the numbers
< 8 hrs
Targeted restore time
100%
Phishing-resistant MFA
Quarterly
Audit drill cadence
48 / 48
HIPAA controls mapped
Client background
A four-location general and cosmetic dental practice spread across the north Atlanta perimeter, with a small administrative backbone in Buckhead. Eighty-two endpoints — chairside tablets, front-desk kiosks, three higienists’ laptops per location, the practice-management tower in each office — and a shared Microsoft 365 tenant that carries every patient chart, every appointment reminder, every imaging export, and every monthly statement. The HIPAA Security Officer is the practice manager, who is also the person responsible for keeping the front desk moving on a Monday morning. Backup had been one of those things the practice "had" — until the day a server-subscription renewal bounced, and the team realized it had not been actively tested in eighteen months.
Challenge
HIPAA documentation that would survive an audit; encrypted, immutable backup of Exchange and OneDrive that was actually being tested rather than assumed; restore drills on a written cadence; and a baseline that did not require a single phish-aware engineer on staff. The previous MSP had been happy to "install backup" once, write a one-page runbook for it, and quietly bill the same line every month. The practice needed a partner who would treat the backup as the clinical asset it had become — and who had built HIPAA documentation that the board could hand to counsel without an embarrassing second draft.
Solution
ATL 511 CPU rebuilt the backup architecture across all four locations in three weeks. Exchange and OneDrive landed on a vendor-isolated, immutable backup target with a tested-restore drill scheduled quarterly, signed off in writing by the practice manager. Every endpoint was BitLocker-encrypted, conditional access was enabled on the Microsoft 365 tenant with named-device policies, and MFA was enforced on every account including the shared mailboxes the front desk relies on. The HIPAA documentation was rewritten in a single binder — administrative safeguards, technical safeguards, breach-notification runbook, recent-restore drill log — and the practice manager was trained to walk the binder instead of forwarding the auditor to whoever answered the phone that day.
Results
The first restore drill after installation took seven hours from initiation to signed handoff. The second drill took under four. The most recent board audit was closed in the binder, without an embarrassing follow-up email. Patient charts are now recoverable inside the same clinical day, the front desk has stopped forwarding phishing emails to the practice manager because the report-phishing button does the work, and the practice’s cyber-insurance renewal closed on the first underwriter pickup. The next time something bounces, the practice manager opens one document instead of starting a phone tree.
Talk to us about a managed plan
Twenty minutes is usually enough to quote a flat-rate plan for your environment — endpoints, tenant, backup, on-site coverage, the works. No card stored on our side, no obligation if the fit is not there.