A dental or medical group does not have one office network repeated at several addresses. It has a set of clinical endpoints with different imaging workloads, carrier options, cabling, inherited systems, and tolerance for disruption. A design that looks uniform on a diagram can behave very differently at the chairside or front desk.
The useful goal is a common operating model with site-specific access. Standardize how the group secures, monitors, and supports each office, while qualifying bandwidth and resilience from the applications and facilities at that address.
What HIPAA means for links between offices
The current HIPAA Security Rule summary from HHS requires covered entities and business associates to use reasonable and appropriate safeguards for electronic protected health information, or ePHI. Its technical safeguards include access control, audit controls, integrity, authentication, and transmission security. The broader obligation is to protect the confidentiality, integrity, and availability of ePHI based on the organization's risk analysis.
That has direct network consequences. The practice needs to know where ePHI travels, which systems can reach it, how users and devices authenticate, how traffic is protected in transit, what gets logged, and how access survives or recovers from failures. Those decisions and the reasoning behind them need to be documented and revisited when the group adds a location, changes a vendor, or moves a server.
HIPAA does not prescribe a carrier product, private WAN, firewall brand, topology, or bandwidth tier. It does not say that offices must be joined by MPLS, or that an internet-based VPN is inherently noncompliant. HHS says ePHI may cross an open network when it is adequately protected. Encryption is an addressable implementation specification, which means the practice must evaluate it and document its treatment. “Addressable” does not mean “ignore it if inconvenient.”
Nor does buying a circuit marketed for healthcare make the network compliant. A dedicated circuit may improve predictability, but it does not supply identity controls, correct firewall rules, endpoint security, audit review, contingency procedures, or vendor governance. Conversely, a well-designed encrypted connection over business internet can be part of a compliant environment when it follows the documented risk-management decision.
Segmentation is useful even though HIPAA does not dictate a particular VLAN plan. Clinical workstations, imaging devices, phones, building systems, staff devices, and guest Wi-Fi do not need identical reachability. Limit each zone to its required destinations, especially when an older modality or embedded device cannot run current endpoint controls. Treat a vendor tunnel as a scoped exception with an owner and logs, not as a permanent doorway into the clinical LAN.
Imaging changes the bandwidth calculation
Headcount is a weak sizing method for an imaging practice. Dental radiographs, cone-beam studies, ultrasound, and other DICOM workflows can create large bursts that ordinary browsing and scheduling do not reveal. The important questions are where the images originate, where they are stored, who reads them, and how quickly they must arrive.
| Workflow | Traffic pattern | Network implication |
|---|---|---|
| Modality to a local PACS | Mostly inside the office LAN | Switching, cabling, storage, and local segmentation may matter more than WAN speed |
| Office to a cloud PACS | Sustained or bursty upstream traffic | Upload capacity and congestion control become primary sizing inputs |
| Office to a PACS hosted at another practice | Upload at the sending site, download at the receiving site | Both offices and the inter-site security path become dependencies |
| Central archive to a remote clinician | Download to the reader, with possible retrieval bursts | Measure retrieval behavior and the effect of other site traffic |
| Backup or replication off site | Often scheduled upstream demand | Prevent it from competing uncontrolled with clinical and voice traffic |
Start with measurements from the firewall, PACS, and application owner. Record study sizes by modality, transfer frequency, concurrency, retransmissions, and observed completion time during a representative clinical load. Ask the vendor whether compression, caching, prefetching, and local buffering are supported and how they affect diagnostic workflow. Do not enable an optimization merely because it makes a speed test look better.
Symmetry matters when a site sends as much important data as it receives. A broadband plan may advertise ample download capacity while offering much less upstream capacity. That can be acceptable for a light satellite office, but it can be the wrong primary path for a location that uploads studies, hosts the practice server, replicates backups, or terminates remote desktop sessions. Compare the committed performance and service terms, not just the largest number in the offer.
Cloud software and the server in the closet create different risks
With cloud-hosted practice management or electronic health record software, each office reaches the vendor directly. The group no longer depends on a server room at a particular practice, but every office depends on its local internet, DNS, identity path, vendor availability, and supported browser or client. Local failover therefore protects clinical access instead of merely providing convenience.
Confirm what still lives locally. Imaging bridges, scanners, label printers, payment devices, directory services, and interface engines may rely on an on-site appliance even when the main application is called cloud based. Document what the office can do if either the internet or the vendor is unavailable, and make downtime procedures accessible without the failed system.
When software is hosted on a server at one practice, that site becomes a data center whether facilities intended it or not. Every other office depends on the host's circuit, upstream capacity, firewall, power, cooling, server, storage, backups, and remote-access design. Maintenance or an outage at the host has group-wide impact. The hub therefore needs stronger resilience and change control than a normal branch.
Before centralizing, have the software vendor validate the architecture. Some applications behave poorly across latency or packet loss, and some vendors support only specific remote-session or database arrangements. Never expose a database service directly between offices to avoid a slow client. Use a supported encrypted design, restrict source and destination access, and monitor the whole transaction path.
Front-desk voice needs predictable treatment
A front desk expects clean audio, immediate call setup, reliable transfers, working queues, and stable inbound routing while staff use the scheduling system. Those expectations are operational, not a promise that any circuit can deliver perfect calls.
Voice is sensitive to delay variation, packet loss, congestion, and brief path changes. Put managed phones on an appropriate voice segment, keep guest and imaging traffic from exhausting the uplink, and use quality-of-service controls where the practice controls the queue. Local QoS cannot repair congestion deep in a provider network, so carrier path quality and monitoring still matter.
Test calling during real office load. Include inbound and outbound calls, transfers, holds, queues, voicemail, remote users, and failover. A WAN change can alter NAT behavior or source addresses and cause registrations or inbound routing to fail. Confirm emergency calling location records for each office and for devices that can move. Expect an active call or application session to drop during some failovers even when new sessions recover quickly.
Redundancy for an office that cannot lose a business day
Redundancy begins with a business decision: which workflows must continue in degraded mode? Protect those first. A secondary connection does not need to carry guest Wi-Fi, bulk image replication, backups, and updates if schedules, records, phones, and essential clinical services can be preserved by restricting noncritical traffic.
The secondary path should avoid as many primary failure domains as practical. Different carrier logos are not enough if both services use the same street conduit, building entrance, riser, power source, or wholesale fiber. A wired primary paired with fixed wireless or cellular may improve physical diversity, but only after an on-site signal and capacity test. A diverse wired route may be stronger where the building can support it.
Include the firewall, switching, power, DNS, identity, and phone configuration in the failover plan. Use supported dual-WAN behavior, secure the backup to the same standard, and monitor data consumption or policy limitations. Test by removing the primary path, exercising the approved clinical workload, and restoring service. Record which sessions break, how staff recognize failover, who escalates, and when noncritical traffic is disabled.
Standardize controls, optimize the site
Acquisitions reward a clear baseline, but immediate uniformity can break an inherited workflow. Discover first: circuits and terms, demarcation points, subnets, wireless, servers, modalities, vendor tunnels, phone numbers, alarms, public IP dependencies, and undocumented equipment. Map those findings to a target design and a risk-ranked migration plan.
| Standardize across the group | Decide from each site's facts |
|---|---|
| Security policy and segmentation intent | Available carriers, access medium, and physical path |
| Firewall management, logging, and configuration backup | Primary and secondary circuit pairing |
| Identity, administrative access, and vendor-access process | Cabling, wireless placement, and telecom-room conditions |
| Network naming, documentation, and monitoring | Imaging volume, local cache, and host-site role |
| Voice configuration standards and escalation records | Landlord access, construction, and demarc extension |
| Acceptance tests and change control | Migration sequence around clinical operations |
Qualify every acquired address rather than extending the incumbent carrier by default. A provider that is strong at the parent practice may be off-net or dependent on construction at the next office. Submit several practice addresses in one request; checking several sites takes no longer than checking one at this stage, although engineering and installation remain site-specific.
Check every practice address against the design
Use the results when you check which carriers report service at several practice addresses to build a per-site shortlist, then require the carrier to confirm the exact suite, handoff, construction assumptions, and service terms. InventiveHQ sources quotes through carrier channel agreements; the selected carrier still installs and bills the service, and sourcing costs the buyer nothing because carriers fund the channel from the same budget as their own sales teams.
The network standard should tell the team what each practice must achieve; the address-level work determines how that outcome can actually be delivered.