9 min read
Three cheers for modern technology. That's what patients, doctors, and hackers alike say.
Timo Imbrogno
:
August 27, 2026
*Hooray for modern technology. That’s what patients, doctors, and hackers alike say
A first-hand account from a modern dental practice about digitization, trust, and why cybersecurity is no longer just an IT issue.
“The dentist will be right with you.”
A phrase that probably everyone has heard at some point. So I took a seat in the dental chair and waited. The practice made an excellent impression. Modern furnishings, state-of-the-art equipment, digital processes. Next to me was an intraoral scanner, which would later be used to create a highly precise 3D model of my teeth. The website advertised state-of-the-art technology, digital treatment planning, and Invisalign treatments. In short: exactly the kind of dental practice patients want today.
The dentist was still busy. And I was alone. My gaze wandered to the computer in front of me. It wasn’t locked. My patient file was open on the screen: dental status, documentation, treatment history, notes, and planned procedures. Nothing out of the ordinary. Things got more interesting, however, in the left sidebar. There, the most recently opened patient records were listed—with full names. A whole list. A single mouse click would likely have been enough to switch between different records.
Of course, I didn’t click on anything. But that is precisely the essence of information security. It’s not about what actually happened. It’s about what could have happened.

(AI-generated image to illustrate the situation and to protect the anonymity of the dental office visited; image credit: Adobe Stock #976135953)
More Than Just Teeth
A few minutes earlier, various photos had been taken for my planned Invisalign treatment. Not just of my teeth, but of me as well—from the front, from the side, with my mouth open, with my mouth closed, and, of course, with as friendly a smile as possible. After all, you want to be able to document later just how successful the treatment was. The classic before-and-after photo. My starting point. My crooked teeth. My face. My—admittedly—beautiful smile.
The photos were transferred directly from the camera to the practice’s system. Shortly afterward, I was sitting in front of a computer that stored not only medical data but also, potentially, high-resolution portrait photos of my face. Right next to me was the scanner, which, just a few minutes later, would generate a three-dimensional model of my entire set of teeth. As I sat there, I became increasingly aware of just how much sensitive information a modern dental practice actually collects about its patients these days.
-
Health data.
-
Photos.
-
3D scans.
-
Insurance information.
-
Billing information.
-
X-rays.
-
Treatment records.
And much of this at a single workstation.
The Yellow Post-it

While I was still thinking about it, my gaze fell on a small yellow Post-it note. It was stuck right on a cabinet next to the dental chair. A combination of symbols was handwritten on it. When a staff member briefly came into the room, I asked jokingly:
“Is that the password for the computer?”
She laughed.
“Yes, actually. Otherwise, no one here could ever remember it.”
A charming comment. And at the same time, probably the shortest summary of many security issues. The yellow Post-it note almost seemed like a symbol of the digital transformation of many organizations. On the one hand, cutting-edge technology. Digital patient records. 3D scanners. Cloud applications. AI-supported treatment planning. On the other hand, a password on a sticky note.
Why this probably stands out more to me than to others
To be fair, I need to put this into context. For one thing, I’ve been working in the IT industry for many years. For another, I’m married to a dentist. So I know many of the challenges of everyday practice life firsthand:
-
Staff shortages.
-
Documentation requirements.
-
Continuing education.
-
Quality management.
-
Data protection.
-
Billing systems.
-
Regulatory requirements.
And, of course, patients should receive the best possible care.
This article is therefore explicitly not a criticism of any single practice. On the contrary, it describes a structural problem. After all, doctors and dentists undergo years of training to become excellent medical professionals. They learn anatomy, therapy, diagnostics, surgical procedures, treatment planning, and patient care.
What they typically do not learn: business management. Cybersecurity. IT risk management. Cloud security. Digital marketing. Data protection impact assessments.
Nevertheless, many practice owners today run medium-sized businesses with several employees, complex IT systems, and vast amounts of highly sensitive personal data. They are expected to be doctors, managing directors, data protection officers, marketing managers, and IT directors all at once. It’s actually astonishing that this works so well at all.
Why Pictures Are More Than Just Pictures Today
The photos, in particular, gave me pause. After all, just a few years ago, such images would likely have been viewed as completely uncontroversial. Today, however, we live in a world of deepfakes, AI-generated identities, and biometric authentication. Faces unlock smartphones. Fingerprints authorize banking apps. Biometric features are increasingly being used as digital identities. And that’s exactly why modern patient photos have become significantly more valuable than they used to be.
If my password is compromised, I can change it. If my credit card is compromised, I can block it. But what happens if my face is compromised? Or my biometric features? This is precisely where the real challenge of the coming years begins.
The Selfie Problem
Anyone who thinks this is an exaggeration should take a look at current developments. The German Federal Office for Information Security points out that modern camera technology and AI systems can extract biometric features from high-resolution images. Even well-known selfies featuring the popular peace sign can become problematic if fingertips are visible in sufficient detail. The more and better-quality images that are available, the easier it is to reconstruct fingerprints. 
(Stock photo, credit: Adobe Stock #260520503)
At first, this sounds like science fiction. But it hasn’t been for a long time. Anyone who stores thousands of high-resolution patient photos today isn’t just collecting documentation of tooth alignment or treatment outcomes. They’re collecting biometric data. And biometric data has one major drawback: it can’t be reset.
“I’ll just quickly send this to a colleague”
The situation becomes even more critical with a behavior that likely occurs in many dental practices. An unusual finding. An interesting image. A question for a colleague. So, quickly take a photo. Send it quickly via WhatsApp. “Can you take a look at this?” The motivation behind this is usually completely understandable. The problem begins behind the scenes.
Suddenly, a patient’s image is stored on a personal smartphone. Maybe even on several. In a personal device backup. In a messaging history. Possibly even years later. And at some point , an uncomfortable question arises: Can the practice actually still track where this data is located?
On top of that, more and more platforms are integrating AI features and processing data for various purposes, depending on usage, configuration, and contract terms. The real danger, therefore, often isn’t a single messaging app. It’s that at some point, no one will know where all the sensitive data has ended up.
The cloud is closer than many realize
Many practice owners would probably say off the top of their heads, “Our patient photos are stored on our practice server.” The uncomfortable truth is often: Maybe. And maybe not. Because modern cameras, smartphones, and image management programs are designed for convenience.
Adobe Lightroom. iCloud. Google Photos. OneDrive. Dropbox. Creative Cloud. Synchronization services of all kinds. A photo is taken. Imported. Edited. Saved. Synchronized. Backed up. And appears on multiple devices simultaneously just a few seconds later.
The problem isn’t the technology. The problem is transparency. Let’s imagine the following scenario: The yellow Post-it note in the treatment room contains the computer’s password. For convenience, the same password is also used for other services—for Lightroom, for Adobe, for Microsoft, for the email address, for cloud storage, for practically everything.
Suddenly, it’s no longer just about a single computer in the treatment room. Suddenly, it’s about a cloud that may contain thousands of patient photos. Before-and-after documentation. Portrait shots. Intraoral images. Treatment histories. Collected over the years. The crucial difference: To gain access, no one would even need to be physically present at the practice. No one would need to compromise the practice network. No one would even need to enter the building. An attacker could theoretically be sitting on the other side of the world—with just a username and password. That’s precisely why cloud services are often the more attractive target.
While modern practice management software is hopefully accessible only through controlled channels, cloud applications are usually available around the clock, worldwide. And if the password is the same one that’s already written on a Post-it note stuck next to the dental chair, a local vulnerability can very quickly turn into a global problem.
The Problem with the “IT Guy”
Added to this is another phenomenon that many practice owners are likely familiar with. Someone has to take care of the IT. So you hire someone. The local freelancer. An acquaintance. A student. A neighbor. The cheapest provider. The person who “does something with computers.”
And suddenly, this person is responsible for everything:
-
The printer isn’t printing.
-
The Wi-Fi isn’t working.
-
The scanner is having problems.
-
The computer won’t start up.
-
The website needs to be updated.
-
The email inbox is causing problems.
-
The calendar isn't syncing.
-
The phone system is acting up.
-
The new employee needs an account.
-
The telematics infrastructure is reporting errors.
-
The camera isn't transmitting images.
(Stock photo, credit: Adobe Stock #2160160711)
And on top of that, this service provider is, of course, expected to ensure all IT security as well. The problem often isn’t these people’s skills. The problem is reality. Most of their time is spent dealing with operational issues. The printer. The cable. The scanner. The website. The Outlook inbox. Cybersecurity often becomes an afterthought. Not because it’s unimportant, but because it rarely seems urgent—until something happens.
Yet modern dental practices today are hardly any different from medium-sized companies. They have customer data. Cloud systems. Digital production processes. Remote access. Mobile devices. Online services. Complex software landscapes. The only difference is this: medium-sized businesses above a certain size employ their own security officers. Dental practices, on the other hand, often rely on an overburdened service provider whose most recent task was to plug back in a power cord that had come loose during cleaning.
“But that computer isn’t even connected to the internet”
That’s why you hear this phrase so often:
“That computer isn’t even connected to the internet.”
As if that ruled out any danger. In fact, some practices deliberately operate certain systems in isolation. No internet. No hackers. The logic sounds reasonable. Unfortunately, the reality is more complicated.
That’s because modern attacks often don’t require an active network connection at all. They simply need access. And as a patient, I ultimately had exactly that. Modern tools like Rubber Ducky or Bash Bunny look like ordinary USB flash drives. In fact, they masquerade as a keyboard to the computer and automatically execute commands—all within a matter of seconds. But even that is no longer the most concerning aspect. Many similar devices have their own radio modules or wireless communication capabilities.
Put simply, this means: The USB drive is plugged in. Screenshots are taken. Patient records are read. Screen contents are copied. And the information is transmitted wirelessly to another device. All the while, the supposedly harmless USB drive remains plugged into the computer. In this scenario, it’s virtually irrelevant whether the computer itself is connected to the Internet. Because the real problem was never the Internet. The real problem was uncontrolled access.
An Uncomfortable Thought
Perhaps the most unsettling realization from my visit to the dentist is this: The greatest risk factor often isn’t found in a foreign country. Sometimes it’s right there in front of the screen. With an invitation. With patient status. With access to the treatment room. With a ten-minute wait.
When the dentist finally came in, the treatment began as usual. My teeth were scanned, the next steps were discussed, and a short time later I left the office. One thought, however, lingered. Digitalization in medical and dental practices has made impressive strides. 3D scans, digital patient records, cloud applications, AI-supported planning, and modern image processing are already part of everyday life in many places. However, the attack surface is growing at least as fast. And that’s not a criticism.
It’s the consequence of a system that turns highly qualified medical professionals into entrepreneurs, marketers, data protection officers, and IT managers all at once. Perhaps that is why every practice should ask itself a single question: If an external specialist were to spend a whole day tomorrow trying to access your data, could you say with absolute certainty that they would not succeed?
If the answer isn’t “yes” immediately and without hesitation, there’s no shame in that. But it might be a good time to take a critical look at your own security strategy. Because modern technology delights patients. It delights doctors. And, unfortunately, sometimes hackers as well.
A first line of defense for open network connections: Interested parties can orderthe RJ45 Port Buddies from RIEDEL Networks on our website
*This article was created with the help of Copilot, taking current market developments into account. The author, whose views are represented herein, was responsible for crafting the prompts and supervising the article.
About the Author:
Timo Imbrogno is Director of Marketing at RIEDEL Networks—certainly not an IT expert, but a nerd at heart who enjoys taking a peek behind the scenes every now and then. He found his first bug right at the start of his career, back when Facebook was still all the rage. Back then, it was in the publishing feature of fan pages and custom apps, which were still really (!) all the rage at the time.
From time to time, he gets the itch to explore things not just from a marketing perspective, but through his own unique lens. In doing so, he likes to use unconventional approaches to illustrate his point of view or spark some thought. One example worth mentioning here is the IT-SA 2024 advertising material exchange station.
His contributions deliberately straddle the line between expertise and humor—and invite readers to view even complex topics from an unfamiliar perspective.
About RIEDEL Networks
RIEDEL Networks is a privately held, global network provider focused on customized networks. We are listed in the Gartner Magic Quadrant for Global WAN Services as a niche player specializing in mid-sized international companies and the media and events sectors. With our own global backbone, we help companies stay connected worldwide. Our services include Internet connectivity, MPLS, SD-WAN, SASE, Cloud Connect, security, and much more. Our customers come from a variety of industries and value quality, security, and reliability. RIEDEL Networks is a wholly owned subsidiary of the RIEDEL Communications Group in Wuppertal, Germany, and is entirely privately owned by Thomas Riedel.