System Failure: When Buying a Dental Practice, Check Aging Operating Systems and Other Tech to Avoid Costly HIPAA Violations

Jordan Uditsky • August 5, 2026

System Failure: When Buying a Dental Practice, Check Aging Operating Systems and Other Tech to Avoid Costly HIPAA Violations

The purchase of a dental practice involves a lot of due diligence and checking under its financial, operational, and clinical hoods. Underlying all of those aspects of the practice is a technology infrastructure critical to supporting the practice, including the operating systems running on workstations, servers, and other devices that store or access protected health information (PHI). If the practice you are purchasing runs on an outdated or unsupported operating system, you could also find yourself acquiring significant legal, financial, and operational risks and liability related to HIPAA non-compliance.

 

This includes Microsoft Windows 10. As of October 14, 2025, Microsoft no longer provides software updates, security fixes, or technical assistance for that version of Windows. And that is a big HIPAA problem. But this compliance concern is not just limited to Windows – it is a consideration for any practice that relies on aging hardware and legacy software. Accordingly, operating system compliance should be an important component of every dental practice purchaser's due diligence process.


Are you interested in speaking with one of our attorneys? Click here to contact us now.

 

Unsupported Operating Systems Create Security Risks

 

The HIPAA Security Rule requires covered entities and business associates to implement reasonable and appropriate safeguards to protect electronic protected health information (ePHI). While HIPAA does not mandate the use of any particular operating system, it does require organizations to protect against reasonably anticipated threats and vulnerabilities.

 

When an operating system, such as Windows 10, reaches the end of its supported life cycle, the manufacturer typically stops providing security updates and patches. Newly discovered vulnerabilities may remain unaddressed, making systems more susceptible to malware, ransomware, and unauthorized access. Continuing to use unsupported software in an environment containing ePHI may make it difficult to demonstrate that reasonable security measures are in place.

 

For example, a dental practice that continues to operate multiple Windows 10 computers after support has ended could face increased cybersecurity risks if those devices are connected to the practice management system or electronic health records platform.

 

Buyers Should Include Technology in Due Diligence

 

Prospective dental practice purchasers understandably spend a great deal of time, effort, and focus on financial statements, patient volume, payer mix, and employment agreements as part of their due diligence. But many buyers either overlook the practice’s information technology infrastructure or lack the knowledge or resources needed to understand where that infrastructure may fall short from a compliance perspective.

 

As with any aspect of due diligence, tech due diligence starts with asking thoughtful, probative questions. Examples of such questions include:

 

  • What operating systems are currently deployed on desktops, laptops, and servers?
  • Are all systems still receiving vendor security updates?
  • Does the electronic health record or practice management software support newer operating systems?
  • Have security patches been applied consistently?
  • Are any devices nearing end-of-life or no longer supported?
  • Are encryption, multifactor authentication, and endpoint protection properly implemented?
  • Has the practice experienced prior cybersecurity incidents or HIPAA breaches?

 

The answers to these questions may reveal substantial post-closing expenses that should be reflected in credits or adjustments to the purchase price or addressed through other contractual provisions, as discussed below.

 

HIPAA Liability Does Not End at Closing

 

Even after a practice sale, both parties may have continuing obligations regarding patient information. Sellers frequently retain copies of financial records, tax documents, or limited patient information for legal or business purposes. Buyers assume responsibility for securing the records they acquire.

 

If outdated operating systems contribute to a data breach before or shortly after closing, disputes may arise regarding who bears responsibility. Asset purchase agreements and transition documents should clearly allocate cybersecurity responsibilities, identify required remediation measures, and specify each party's obligations regarding retained data.

 

Budget for Any Needed Hardware Replacement Costs

 

In some transactions, the existing computers may not meet the technical requirements needed to run supported operating systems efficiently. As a result, a buyer may need to replace not only the software but also significant portions of the hardware infrastructure.

 

These costs can include:

  • New desktop and laptop computers.
  • Server replacements or cloud migration expenses.
  • Updated backup systems.
  • Software licensing fees.
  • IT consulting and migration services.
  • Employee training and implementation downtime.

 

Proper budgeting can prevent unpleasant surprises after closing and facilitate a smoother operational transition.

 

Negotiate Appropriate Contract Protections

 

Buyers should address technology risks identified during due diligence in the purchase agreement and other transaction documents. Depending on the circumstances, buyers may seek representations and warranties concerning HIPAA compliance, cybersecurity practices, software licensing, and system maintenance.

 

Indemnification provisions, escrow arrangements, or purchase price adjustments may also be appropriate where significant remediation is anticipated. In some cases, the seller may agree to complete specified upgrades before closing as a condition of the transaction.

 

You’re Not Supposed to Be an IT Expert, But You Are Supposed to Hire One.

 

The takeaway here for putative practice purchasers is that ignorance is far from bliss when it comes to the technology that drives the practice they’re buying. Unsupported operating systems, such as Windows 10 after end-of-support, along with other obsolete platforms, may expose a practice to cybersecurity vulnerabilities and complicate compliance with HIPAA's security requirements.

 

This is not to say that a purchaser needs to become an IT expert during the transaction. It is to say that buyers and their experienced counsel should retain and coordinate with qualified IT professionals and cybersecurity specialists who can evaluate operating systems, identify compliance gaps, and allocate technology-related risks appropriately in the purchase agreement.

 

If you are considering the purchase of a dental practice, please call ddslawyers.com at (630) 833-5533 or contact us online to arrange for your complimentary initial consultation.

 

We focus a substantial part of our practice on providing exceptional legal services for dentists and dental practices, as well as orthodontists, periodontists, endodontists, pediatric dentists, and oral surgeons. We bring unique insights and deep commitment to protecting the interests of dental professionals and their practices and welcome the opportunity to work with you.

 

Jordan Uditsky, an accomplished businessman and seasoned attorney, combines his experience as a legal counselor and successful entrepreneur to advise dentists and other business owners in the Chicago area. Jordan grew up in a dental family, with his father, grandfather, and sister each owning their own dental practices, and this blend of legal, business, and personal experience provides Jordan with unique insight into his clients’ needs, concerns, and goals.

Speak to an Attorney

Related Posts
By Jordan Uditsky July 1, 2026
As Corporate Practice of Dentistry Concerns Escalate, Colorado Enacts Stricter Regulations Over DSO Involvement in Dental Practices
By Jordan Uditsky June 3, 2026
Algorithm v. Attorney: Dental Practice Owners Who Look to AI For Legal Advice Are Looking For Trouble
By Jordan Uditsky May 20, 2026
DSOs and the Corporate Practice of Dentistry: Aspen Dental Settlement in California Illustrates The Dangers to Practice Owners of DSO Overreach
Show More
By Jordan Uditsky July 1, 2026
As Corporate Practice of Dentistry Concerns Escalate, Colorado Enacts Stricter Regulations Over DSO Involvement in Dental Practices
By Jordan Uditsky June 3, 2026
Algorithm v. Attorney: Dental Practice Owners Who Look to AI For Legal Advice Are Looking For Trouble
By Jordan Uditsky May 20, 2026
DSOs and the Corporate Practice of Dentistry: Aspen Dental Settlement in California Illustrates The Dangers to Practice Owners of DSO Overreach
Show More