Medical and dental · Who's allowed to read it

Your IT company manages the laptop, not the decision

Your managed services contract covers endpoints, patching and backup. It almost certainly does not say which chatbot the front desk may open. Those are different objects, and in most small practices the second one has no owner at all.

We build software. Not legal or compliance advice; sources at the foot of the page.

Before anything else: this is not a complaint about IT providers. The good ones are very good and the argument here does not depend on anyone doing their job badly. It depends on scope, which is a boundary rather than a failing.

The sentence that describes the problem was written by the ADA

In February 2026 the American Dental Association wrote to HHS in response to a request for information on AI in the health sector. On who makes the call, ADA News reports the letter saying adoption decisions are:

"most influenced by practice owners/clinical leadership, in coordination with IT/informatics, compliance/privacy, and legal/risk management"

Read that as an org chart and it is completely sensible. Read it against a six-person practice and it describes four functions that are one person, and that person is usually holding an instrument.

The same letter named the barriers for small and rural practices as "limited technology infrastructure, workforce readiness gaps, high upfront costs and regulatory uncertainties". Three of those four are things a small practice already knows about itself. The fourth is the one nobody can price.

Attribution, precisely: these are ADA News's quotations of the ADA's own 20 February 2026 letter. We did not retrieve the letter itself, so we are quoting the report of it rather than the document. Both links are below.

Two different objects

What a managed IT provider is genuinely good at is the inventoriable layer. The network. The devices. Patching. Backup and restore. Who has an account and who used to. All of it real, all of it necessary, and all of it about things you can enumerate.

An AI programme decides something different in kind: which tools may touch patient information, what may be pasted into what, who approves a new one, and what happens when somebody gets it wrong. Those are decisions about material and about people. There is no console that shows them to you.

A provider can absolutely help you write that down, and some will. But it is not what the contract you already signed is about, and reading a typical scope of services will make that obvious in about five minutes.

The bit that surprises people

If your IT provider handles protected health information, they are themselves a business associate. 45 CFR 164.308(b)(1) says a covered entity may permit a business associate to create, receive, maintain or transmit electronic PHI on its behalf only if it obtains satisfactory assurances that the associate will appropriately safeguard it. So you have an agreement with them, and you should.

That agreement covers their services. It does not stretch over a tool they did not procure, do not manage, and have not been told exists. A business associate agreement is a contract with one party about specific work. It is not an umbrella over the practice.

This is the single most common misreading we run into, and it is an easy one to make, because "we're covered, our IT company handles compliance" is a sentence that feels true and is doing an enormous amount of unexamined work.

Why nothing went wrong on purpose

Nobody in this story is careless. The provider is doing the work in their scope. The owner is seeing patients. The front desk found something that saved them forty minutes and told two colleagues, which is what helpful people do.

What is missing is a line in anybody's job description that reads decide which of these is allowed. So it was never decided, and the answer became whatever each person happened to open. That is not a failure of diligence. It is a gap between two contracts, and gaps between contracts do not announce themselves.

What to do

Open your IT agreement, find the scope section, and then put one question to your provider in writing:

"Under our current agreement, is approving new software your responsibility or ours — and does that include AI tools staff sign up for themselves?"

Send it as an email, so the answer comes back as a document rather than as something somebody remembers hearing on a call.

Either answer is fine. If it is theirs, send them the grid from the previous post in this series and ask them to mark it up. If it is yours, you now know that, which is more than most practices know on a Tuesday afternoon.

This one belongs to an operations lead end to end — the entire task is sending an email and filing the reply next to the contract. Ask for the provider's answer in their own words rather than a summary of it, because the wording is the whole point.

The failure state is not "the wrong person owns it". It is that everybody assumes somebody else does, and that assumption costs a scramble: two organisations, months later, each explaining why it reasonably believed the other one was watching. Five minutes with a PDF and one email prevents the entire conversation.

Replies to that question often come back ambiguous, because most of these contracts were written before anyone thought to ask it. Working out what the wording actually covers is something we can look at with you. Send the email regardless — the answer is useful in your hands whether or not it ever reaches ours.

Sources

Want this running in your own practice? Let's talk.