M&A due diligence · Clinical care providers
M&A Privacy & Security Due Diligence for Dental Practices
Privacy due diligence on a dental practice acquisition tells a buyer, usually a DSO or a dentist buying out a retiring principal, what privacy and security condition the target's charts, PMS and imaging systems are actually in before the deal closes. This matters because RCDSO expects a clean handover of records custody at the point of sale, and any incidents or shortcuts the seller hasn't disclosed become the buyer's problem the moment the deal closes. We review the target's systems, not just its financials.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What due diligence has to confirm before a dental deal closes
The financial and clinical review of a target practice is standard. The privacy and security review is what catches what those don't.
Chart custody and continuity
Confirming who legally holds custodian responsibility for the target's charts today, and what has to happen for that responsibility to transfer cleanly to the buyer at close.
The condition of the seller's PMS
Whether the practice-management platform is current, properly licensed and free of known security gaps, since an outdated or unsupported PMS becomes the buyer's problem the day after closing.
Undisclosed prior incidents
Whether the seller has experienced a breach, ransomware event or IPC complaint that wasn't surfaced during early conversations, and what obligations from that incident might still be open.
Claims and billing account continuity
How the target's CDAnet, ITRANS and Sun Life Direct CDCP billing accounts transition to the buyer, since a gap here can interrupt claims processing after close.
Regulatory map
The regulatory reasons diligence has to be dental-specific
Records custody on a practice sale is a specific, addressed question under professional dental regulation, not a generic corporate asset transfer.
RCDSO's custodian rules on sale
RCDSO's recordkeeping guidance sets out what happens to patient records and custodian responsibility when a practice is sold or closed, a question a buyer needs answered before, not after, closing.
PHIPA custodian obligations transferring with the practice
The buyer typically steps into custodian responsibility for the acquired patient records, making it essential to understand what state those obligations are in before assuming them.
The electronic audit-log duty as a diligence checkpoint
Whether the target's systems actually maintain the electronic audit logs PHIPA section 10.1 requires is a concrete, checkable item during diligence, not just a policy question.
Provincial variation across a multi-province roll-up
A target practice in Quebec carries Law 25 obligations distinct from an Ontario target's PHIPA obligations, and a DSO acquiring across provinces needs each target assessed against its own province's rules.
What goes wrong
What diligence catches before it becomes the buyer's liability
These are the specific conditions that turn a routine dental acquisition into a costly post-close surprise.
An unresolved incident inherited at close
A target practice that experienced a ransomware event or a benefits-administrator compromise before the sale, similar to what hit the Alberta Dental Service Corporation, may still carry open notification or remediation obligations the buyer inherits.
Retention practices that don't match RCDSO's rules
A target holding records past their proper disposal date, or missing the extended retention required for records made while a patient was a minor, creates a compliance gap the buyer takes on.
A legacy PMS with no security history
A target running an old, unsupported version of its practice-management software with no documented patching or access-control history is a common finding that changes both integration cost and risk.
Our m&a due diligence for dental practices
What the due diligence engagement delivers to a buyer
The output is written to be used directly in deal negotiations and post-close integration planning, not filed away after closing.

A chart-custody review
Confirmation of who holds custodian responsibility today and what steps are needed for a clean transfer at close, aligned with RCDSO's rules.
A PMS and imaging systems inventory
A clear picture of what platforms the target runs, their licensing and support status, and how imaging systems connect into them.
An RCDSO and PHIPA compliance snapshot
A review of the target's retention, disposal, access-control and audit-log practices against what RCDSO and PHIPA expect.
An incident history check
A review for prior breaches, ransomware events or regulatory complaints, and whether any obligations from them remain open.
An integration risk summary
A practical list of what needs to be standardized after close, whether that's PMS platform, security controls or documentation, sequenced by priority.
How the engagement runs
How the due diligence review runs
Step 1
Request the target's documentation
We request policies, PMS and imaging system details, and any known incident history from the seller or their representative.
Step 2
Assess systems and compliance status
We review what's provided against RCDSO and PHIPA expectations, flagging what's missing or inconsistent with the target's disclosures.
Step 3
Interview key staff where possible
A short conversation with the target's office manager or IT contact often surfaces gaps that documentation alone doesn't show.
Step 4
Deliver findings for negotiation
Results are summarized for use in deal terms, price adjustment discussions or post-close remediation planning, on the buyer's timeline.
What it costs
What affects the cost of dental practice due diligence
Cost depends on the number of locations involved in a single deal, how much documentation the seller can readily provide, whether an on-site systems review is included, and how quickly the diligence needs to be completed relative to the deal timeline.
A DSO running acquisitions regularly may prefer a standing diligence process applied consistently across every deal rather than scoping each one individually. A short call establishes which approach fits your acquisition pace.
Dental Practices: M&A due diligence questions, answered
Custodian responsibility for the target's existing patient records generally transfers to the buyer, along with any unresolved compliance gaps, such as missing retention or disposal procedures, and potentially any open obligations from a prior incident the seller hasn't fully closed out. Diligence exists specifically to identify these before the deal closes, so the buyer can price them into the transaction or address them in the purchase agreement rather than discovering them afterward.
RCDSO's recordkeeping guidance addresses this directly, and the answer generally depends on whether the buyer is continuing the practice or the practice is closing entirely. Where the practice continues under new ownership, custody typically transfers to the acquiring dentist or DSO along with the obligation to maintain the records for their required retention period. This needs to be documented as part of the transaction rather than assumed.
Check the platform's version and support status, whether licensing will transfer or needs to be renegotiated, what access-control and audit-log capabilities are actually enabled, and how imaging systems are connected. An outdated or unsupported PMS changes both the integration cost after close and the buyer's immediate compliance exposure, so this needs answering before the deal is finalized, not during onboarding.
Generally, custodian responsibility for the practice's records follows practice ownership rather than an individual associate's employment status, though associates continue to carry their own confidentiality duties regardless of who owns the practice. Diligence should clarify this explicitly for the specific deal structure, since ownership transitions can vary between an asset sale and other transaction structures.
Most DSOs bring each newly acquired practice up to a common baseline over a defined integration period: consistent PMS platform or configuration where feasible, shared policies, and aligned access controls. Diligence findings feed directly into that integration plan, so the practices needing the most work are identified and prioritized from day one rather than discovered gradually.
These accounts need to be explicitly addressed in the transition plan, since claims and CDCP billing continuity depends on them transferring or being re-established under the new ownership without a gap. An interruption here doesn't just create an administrative headache, it can delay insurer and federal payments to the practice during the sensitive early weeks after a sale.
More for dental practices
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.