Serving DC · Maryland · Virginia

Your dental practice handles sensitive patient data.
We make sure it stays protected.

Flat-rate HIPAA security services built for small dental practices — risk assessments, security plans, and penetration testing. No IT jargon. No surprises. Just compliance you can count on.

#1
Healthcare is the most targeted sector for ransomware attacks
$9.8M
Average cost of a healthcare data breach (2024)
86%
Of dental practices have never had a formal security assessment
🔐 CISSP Certified
⚔️ CEH Certified
🏛️ Federal IT Background
🏥 HIPAA Specialist
📋 NIST / FISMA Aligned

Why PentestDC, LLC

Security expertise built for healthcare — not retrofitted to it.

Most IT security firms serve everyone. We focus on one thing: keeping dental practices HIPAA-compliant and cyber-resilient in the DC metro area.

🏛️

Federal-Grade Security

Our team brings hands-on experience with DC government IT systems. We apply NIST 800-series standards — the same framework federal agencies use — to protect your practice.

📝

Plain-English Reports

We write every report for practice owners, not IT staff. You will always know exactly where you stand, what is at risk, and what to do next — without needing a translator.

💰

Flat-Rate Pricing

No hourly billing surprises. Every engagement is scoped and priced upfront so you can budget with confidence. Small practice pricing designed for small practice budgets.

🦷

Dental-Specific Knowledge

We know Dentrix, Eaglesoft, and Open Dental. We understand how dental billing, imaging systems, and patient communication tools create HIPAA exposure — and how to close it.

⚔️

Real Offensive Testing

Our CEH-certified testers think like attackers. We don't just scan for known vulnerabilities — we actively attempt to breach your systems the way a real threat actor would.

🤝

Long-Term Partnership

HIPAA compliance isn't a one-time project. We build lasting relationships with our clients, providing ongoing support, annual updates, and a direct line when questions arise.

The Reality for Dental Practices

Hackers target small dental practices because they're small.

Dental offices store two types of highly valuable data: protected health information and payment data. Combined, that makes you a premium target — and your lean IT setup makes you easier to breach than a hospital.

Your EHR vendor being "HIPAA compliant" does not make your practice compliant. HIPAA requires you to conduct your own risk assessment, train your staff, and document your policies — regardless of what software you use.

$100
Minimum fine per HIPAA violation — up to $50,000 per violation for willful neglect
60
Days to notify HHS and patients after a breach — missing this deadline is a separate violation
30%
Of patients change providers after a publicized data breach
0
Size exceptions in HIPAA — solo practices face the same requirements as large health systems

Get Started Today

Find out where your practice stands — free.

Schedule a complimentary 30-minute HIPAA Health Check call. We'll walk through your biggest risks and tell you exactly what you need to address. No obligation, no sales pressure.

Book Your Free HIPAA Health Check ›

What We Do

Three services. Complete HIPAA coverage.

Everything a small dental practice needs to be secure, compliant, and audit-ready — delivered in plain English by certified security professionals.

SERVICE 01

Vulnerability Assessment

Think of a vulnerability assessment as a security check-up for your practice. We systematically scan every device, system, and access point to find the weak spots before a hacker does — then give you a plain-English report showing exactly what to fix and in what order.

Unlike a penetration test, we're not trying to break in — we're cataloguing every door and window that could be opened. It's the fastest way to get a complete picture of your security posture.

What's included

External network and internet-facing system scan
Internal network, workstation and device scan
EHR and dental software access point review
Manual validation — no false positives
HIPAA-mapped findings report with prioritized fix list
30-minute results walkthrough call

Pricing Tiers

Starter
External scan + summary report
$1,500 – $3,000
Standard
Full internal + external + HIPAA report
$3,000 – $5,000
Quarterly Program
4 scans/year + annual summary
$4,000 – $8,000/yr
Get a Quote ›

SERVICE 02

Penetration Testing

A penetration test goes further than a vulnerability assessment — we actively attempt to break into your systems the same way a real attacker would. Our CEH-certified testers use manual techniques to find vulnerabilities that automated tools miss.

The HHS proposed HIPAA Security Rule update will require penetration testing at least once per year. Getting ahead of this now means you'll be ready when it becomes mandatory — and you'll have a signed attestation letter for your records.

What's included

External network penetration test
Internal network and EHR access path testing
Wi-Fi security and segmentation testing
Social engineering / phishing simulation (HIPAA+ tier)
Written report with HIPAA-mapped findings
Signed attestation letter for auditors

Pricing Tiers

External
Internet-facing systems only
$3,500 – $6,000
Full Test
External + internal network
$6,000 – $10,000
HIPAA+
Full test + social engineering + attestation
$10,000 – $18,000
Get a Quote ›

SERVICE 03

Security Plan Development

HIPAA requires every dental practice to have a written security plan documenting how you protect patient data. Most practices don't have one — and that's the first thing auditors look for. We build yours from scratch: a complete library of policies, procedures, and compliance documentation.

Our security plans are built on NIST SP 800-66r2 and 45 CFR Part 164, and are written so your practice can actually implement them — not just file them in a drawer.

What's included

HIPAA Security Risk Assessment (required by law)
Written security plan: administrative, physical, technical safeguards
Full HIPAA policy library (workforce, device, breach notification, etc.)
Business Associate Agreement review and log
Staff training outline and implementation checklist
Annual maintenance retainer available

Pricing Tiers

Essential
Risk assessment + security plan
$4,000 – $7,000
Complete
Full policy suite + BAA review
$7,000 – $12,000
Annual Retainer
Ongoing updates + quarterly check-ins
$3,500 – $5,000/yr
Get a Quote ›

Not sure where to start?

Our free 30-minute HIPAA Health Check call will tell you exactly which service your practice needs most — and in what order.

Book Free Health Check ›

Transparent Pricing

Flat-rate. No surprises. No hourly billing.

Every engagement is scoped and priced upfront. You know exactly what you're getting before you sign anything.

Vulnerability Assessment

Find your weak spots before attackers do

Vulnerability Assessment
Starter
For practices that have never had a security scan and want a fast, affordable first look at their exposure.
$1,500 – $3,000
Automated external network scan
Internet-facing system review
One-page findings summary
Top 5 priority fixes
Get a Quote
Vulnerability Assessment
Quarterly Program
Year-round coverage with quarterly scans and an annual compliance summary for auditors.
$4,000 – $8,000/yr
4 scans per year
Trend analysis over time
Annual compliance summary report
1 free re-scan after remediation
Get a Quote

Penetration Testing

Test your defenses before attackers do

Penetration Testing
External
Test everything visible from the internet — firewall, remote access, email security, and patient-facing systems.
$3,500 – $6,000
External network pen test
Firewall and remote access testing
Written findings report
Remediation guidance
Get a Quote
Penetration Testing
HIPAA+
Maximum coverage including staff phishing simulation and a signed attestation letter for OCR audits.
$10,000 – $18,000
Everything in Full Test
Staff phishing simulation
Social engineering test
Signed attestation letter
OCR audit-ready documentation
Get a Quote

Security Plan Development

The documentation HIPAA actually requires

Security Plan
Essential
The two documents every HIPAA-covered dental practice must have: a risk assessment and a security plan.
$4,000 – $7,000
HIPAA Security Risk Assessment
Written Security Plan
Risk register and remediation roadmap
Audit-ready documentation
Get a Quote
Security Plan
Annual Retainer
Keep your security plan current year after year — with regulatory updates, policy revisions, and quarterly check-ins.
$3,500 – $5,000/yr
Annual policy updates
Regulatory change alerts
Quarterly compliance check-in calls
New BAA reviews as needed
Get a Quote

Complete Protection Bundle

Everything your practice needs. One engagement.

Vulnerability Assessment + Penetration Test + Full Security Plan — all three services combined into a single Year 1 engagement. Get fully audit-ready from day one, then transition to an affordable annual retainer.

Talk to Us About the Bundle ›
$14,000
– $20,000 · Year 1 all-inclusive
Then $6,000 – $10,000/yr
for the ongoing retainer program

All prices are flat-rate and scoped upfront. Final pricing depends on practice size, number of devices, and scope of services. We offer a 10–15% bundle discount for Year 1 all-in engagements. Contact us for a custom quote.

About Us

Federal-grade security for your dental practice.

PentestDC, LLC was built specifically to serve small healthcare providers in the DC metro area who deserve the same level of security expertise as the federal agencies we've spent years protecting.

Our Story

From federal IT to protecting patient data.

PentestDC, LLC grew out of years of delivering IT consulting and infrastructure to DC government agencies — environments where security isn't optional and compliance isn't a checkbox. We know what it looks like when security is done right, because we've built it for organizations that can't afford to get it wrong.

When we looked at the small dental practice market, we saw a gap: practices full of sensitive patient data, subject to strict federal regulations, but without access to the kind of credentialed, experienced security expertise that larger healthcare organizations take for granted.

We built PentestDC, LLC to close that gap. Every service we offer is designed specifically for small dental practices — flat-rate, plain-English, and grounded in the same NIST-based frameworks we've applied to federal systems for years.

We're CISSP and CEH certified, we know HIPAA deeply, and we're based in the DC metro area serving practices across DC, Maryland, and Virginia.

CISSP
Certified Information Systems Security Professional
CEH
Certified Ethical Hacker
HIPAA
45 CFR Part 164 Specialist
NIST
800-53 / 800-66r2 Aligned

Our Values

How we work with every client.

01

Plain language, always

Every report, every recommendation, every conversation is written for practice owners — not IT professionals. If you can't act on it, it's not useful to you.

02

No fear-based selling

Cybersecurity has a bad habit of using scare tactics to close deals. We'll tell you exactly where your risks are — and we'll be honest when something isn't urgent.

03

Flat rates, full scope

You'll know the price before we start. No surprise invoices, no hourly billing creep. We scope every engagement and stick to it.

04

Long-term relationships

HIPAA compliance is an ongoing commitment, not a one-time project. We're building a practice of clients who trust us year after year — not a transaction pipeline.

05

Small practice focus

We don't try to serve everyone. Our frameworks, pricing, and deliverables are built around the reality of a 2–5 dentist practice. That specificity is what makes us effective.

Our Roadmap

Where we're headed.

PentestDC, LLC is building a long-term healthcare security practice — starting with dental, expanding across the DMV.

2025–26
Small Dental Practices — DC / MD / VA. Building the playbook, establishing the brand, landing the first clients.
2026–27
Specialty Health Clinics — Expanding HIPAA security services to other small healthcare providers: therapy practices, chiropractic, urgent care.
2027–28
Rural Hospitals — Bringing credentialed security services to underserved rural health systems that lack dedicated IT security staff.
2028–30
Health IT & Web Applications — Penetration testing for DC Health Link and similar government-adjacent health portals.
2030+
Full Regional Healthcare Security Firm — A recognized name in DMV healthcare cybersecurity with a team, certifications, and a track record.

Ready to work with us?

Schedule your free HIPAA Health Check and find out where your practice stands.

Book Free Consultation ›

Get In Touch

Start with a free HIPAA Health Check.

A 30-minute call where we walk through your biggest risks and tell you exactly what your practice needs — no obligation, no sales pressure.

Contact Information

📞
Phone
202-498-4299
✉️
Email
dwalker@pentestdc.com
📍
Service Area
Washington DC · Maryland · Virginia
🕐
Response Time
Within 1 business day

✅ What happens on your free HIPAA Health Check call

We ask 10 quick questions about your current setup
We tell you where your biggest HIPAA gaps are
We recommend the right service(s) for your situation
You get a written summary emailed after the call
No obligation to purchase anything

Send Us a Message

Message received!

We'll be in touch within one business day to schedule your free HIPAA Health Check call.