Quick answer: A dental practice acquisition is the purchase of an existing practice’s assets or equity — but the part most buyers underestimate is the technology they inherit. Before closing, audit seven things: practice management software licensing and data ownership, every software contract and auto-renewal, the HIPAA risk analysis and breach history, phone numbers and call routing, the website and domain registrar, the Google Business Profile, and the network and backup setup. Each one can cost five figures to fix after closing and almost nothing to negotiate before it.

Why technology due diligence gets skipped — and what it costs

Most dental practice acquisition checklists are written by accountants and attorneys. They cover collections history, payer mix, lease assignment, staff contracts, and equipment appraisals. That work matters. But it leaves a gap: nobody is assigned to the systems that actually run the practice on Monday morning after you take over.

The result is predictable. A buyer closes, walks in on day one, and finds the practice management server is running an unsupported operating system. Or the seller’s nephew registered the domain and nobody can reach him. Or the main phone number is tied to a contract in the seller’s personal name. None of these are deal-breakers on their own. All of them are cheaper to solve as a negotiating point than as a post-close emergency.

Technology due diligence is not about finding reasons to walk away. It is about knowing what you are buying, pricing the remediation into your offer, and having a cutover plan before the wire transfer clears.

The 7-point technology due diligence checklist

1. Practice management software: licensing, version, and data ownership

Start here, because everything else depends on it. Establish in writing:

  • Which system and which version. A legacy server-based system several versions behind often cannot be upgraded without a paid migration.
  • Whether the license transfers. Some licenses are tied to the selling entity and require a transfer fee or a new agreement at current pricing — which may be materially higher than what the seller pays.
  • Who owns the data, and how you get it out. Ask for a written statement of the export format available to you. Cloud systems vary widely in what a full export actually contains. Clinical notes, images, and scheduling history do not always travel together.
  • Whether a migration is planned or likely. If you intend to move the practice onto your own platform, price that in now. Our dental software migration guide covers what actually converts and what does not.

Request a test export during diligence, not after. A seller who cannot produce one is telling you something important.

2. The full software contract inventory

Ask for every active subscription, with the annual cost, renewal date, and cancellation terms. In a typical practice this list runs eight to twelve vendors: practice management, imaging, patient communication, phones, payments, insurance verification, forms, marketing, website hosting, backup, and a few orphaned tools nobody uses anymore.

What you are looking for:

  • Auto-renewing annual contracts that lock you into a vendor you plan to replace
  • Multi-year agreements with early-termination penalties
  • Subscriptions billed to a personal card or a personal email address
  • Duplicate tools doing the same job

This inventory also gives you a real baseline for what the practice’s technology should cost going forward. Typical practices run technology at roughly two to four percent of collections; see our breakdown of dental practice technology costs to sanity-check what you inherit.

3. HIPAA posture: risk analysis, BAAs, and breach history

When you acquire a practice, you generally acquire its patient records — and, depending on deal structure, meaningful exposure tied to how those records were handled. Ask for:

  • The most recent documented HIPAA security risk analysis and the remediation plan that followed it
  • Signed business associate agreements for every vendor that touches patient data
  • A written representation regarding any past breach or OCR complaint
  • Evidence of workforce HIPAA training

In practice, many independent practices cannot produce a current risk analysis at all. That is not necessarily a reason to walk — it is a reason to budget for one in your first 90 days and to negotiate appropriate representations and indemnities with your attorney. Our HIPAA compliance checklist for dental practices lays out what a complete program looks like.

4. Phone numbers and call routing

The practice’s main phone number is one of its most valuable assets, and it is routinely mishandled in transitions. Verify:

  • Which entity or individual is the account holder of record with the carrier
  • Whether the number can be ported and what the carrier requires to release it
  • Whether any tracking numbers used in marketing forward to the main line, and who controls them
  • Where after-hours and overflow calls currently go

Losing the main number in a transition means every legacy patient, every referral source, and every directory listing points at a dead line. Make the port authorization a closing deliverable, not a post-close favor.

5. Website, domain, and hosting

Confirm who holds the domain registrar account — this is the single most common orphaned asset in a dental practice acquisition. Also confirm hosting credentials, whether the site was built by an agency that retains ownership of the platform or templates, and whether analytics and Search Console properties can be transferred rather than rebuilt.

Get registrar and hosting logins transferred at closing. A site you cannot edit is a site you will end up rebuilding.

6. Google Business Profile and local listings

The Google Business Profile carries the practice’s review history, which is frequently a large share of what you are paying for. Ownership transfers by adding the buyer as an owner inside the profile — it does not transfer automatically with the business.

Have the seller add you as an owner before closing. Then plan changes carefully: name, category, and address edits can trigger re-verification and temporary visibility loss. Our guide to Google Business Profile optimization for healthcare practices covers how to make those edits safely.

7. Network, backup, and security

Walk the server closet, or have someone do it for you. Document operating system versions and support status, the age and warranty status of the server and workstations, whether backups exist, whether anyone has ever tested a restore, firewall and Wi-Fi configuration, and how many people know the administrator password.

An untested backup is not a backup. Practices that discover this during a ransomware incident discover it at the worst possible moment — see our dental practice cybersecurity guide for the layered defenses worth having in place before you take the keys.

Building your first 90 days

Diligence produces a punch list. Sequence it so patient-facing continuity comes first:

  1. Days 1–7: Confirm phones ring, the practice management system logs in, payments process, and backups run. Change administrator credentials. Take ownership of the domain, hosting, and Google Business Profile.
  2. Days 8–30: Cancel duplicate and unused subscriptions. Put every vendor on the practice’s own billing. Execute missing BAAs.
  3. Days 31–60: Commission a HIPAA security risk analysis. Test a full backup restore. Patch or replace unsupported systems.
  4. Days 61–90: Decide on any platform migration with real data in hand rather than on assumptions made before closing.

Resist the urge to change the practice management system in month one. Staff are already absorbing a new owner; a simultaneous platform change is how transitions lose people and production.

When to bring in outside help

For a single-location acquisition, an experienced buyer with a good IT partner can work this list themselves. For multi-location deals, for buyers acquiring several practices, or where the seller’s documentation is thin, a fractional CTO or dedicated technology advisor pays for itself by pricing remediation into the offer.

Discover Solutions does this work for dental buyers as part of our fractional CTO engagements for dental practices and DSOs, and carries it through to Day-1 cutover and ongoing managed IT. If you are under LOI or evaluating a practice now, book a free 20-minute call and we will walk your diligence list with you.

Frequently asked questions

What is technology due diligence in a dental practice acquisition?

Technology due diligence is the review of the systems a buyer inherits: practice management software and its data, all software contracts, HIPAA documentation, phone numbers, website and domain assets, the Google Business Profile, and the network and backup setup. It runs alongside financial and legal diligence and typically takes one to two weeks.

Does the Google Business Profile transfer when you buy a dental practice?

Not automatically. The seller must add the buyer as an owner within the profile before the account is handed over. If that is missed and the seller becomes unreachable, recovering the profile — and its review history — can take weeks through Google’s reclaim process.

Can you keep the practice’s phone number after an acquisition?

Usually yes, but only if the carrier account holder authorizes the port. Confirm who holds the account and make signed port authorization a closing deliverable, because the request is much harder to get after the seller has moved on.

Should you migrate practice management software right after closing?

Generally no. Most buyers are better served stabilizing operations for 60 to 90 days first, then deciding on a migration with real data and staff input. The exception is a system that is unsupported or non-compliant, where the risk of waiting outweighs the disruption.

How much should a buyer budget for technology remediation?

It depends entirely on what diligence finds. Common line items include a HIPAA risk analysis, server or workstation replacement, backup and security tooling, and any practice management license transfer or migration fee. The point of diligence is to convert those unknowns into specific numbers you can negotiate against before closing.

Who should run technology due diligence — the buyer’s IT vendor or an advisor?

An IT vendor can inventory hardware and networks well. A technology advisor or fractional CTO adds the contract, data-ownership, and migration analysis that determines what the stack will cost you over the next three years. On larger or multi-location deals, that second layer is where the savings are.