HeyDental
All posts Join waiting list

Blog · Architecture

Why practices must switch to HeyDental to use AI — and why Open Dental and Dentrix cannot bolt it on

· HeyDental team

An agent that books a chair, checks eligibility, and texts a patient is not a plugin. It is an operating system. Legacy practice-management software was built for humans clicking forms on a local database. You cannot paste AI on top of that without copying the practice’s most sensitive data into a second, weaker system.

Human staff with peach HeyDental helper robots handling charts, schedules, and follow-ups.

Every dental vendor now says they “have AI.” Most of those products are a chat box beside the same schedule, the same ledger, and the same insurance screen staff already hate. That is not how you take full advantage of agents. Agents need live tools, event streams, and systems of record that already know how to hold money, payroll, and claims. HeyDental was built that way from the first commit. Open Dental and Dentrix were not, and they cannot become that platform by buying a sidecar.

We’re not pasting a chatbot on Dentrix. We’re raising a robot team that calls Stripe, Gusto, Stedi, Twilio, and Resend — and never keeps a souvenir copy of your life.

What an agent actually needs

A language model with no tools is a parlour trick. A useful dental agent has to do work: read remaining deductible, hold a chair, take a card authorization, clock a hygienist, send an SMS, start a voice call, file or status a claim. That requires:

  • Typed APIs — “check eligibility for this subscriber” — not pixel coordinates on a Windows form.
  • Write-back — the booking, payment, or message has to land in the real system, not in a sticky note the front desk retypes.
  • Events — cancelled appointment, denied claim, no-show — so the next agent can react without polling a report.
  • Least privilege — the insurance agent should not see payroll; the payroll agent should not see charts.
  • An audit trail — who (or which robot) did what, with which vendor, for which office.

None of that is a feature you sprinkle onto a 1990s client-server app. It is the runtime. If the practice OS cannot call Stripe, Gusto, Stedi, Twilio, and Resend as first-class peers, the “AI” is stuck describing screens to a human.

Why Open Dental and Dentrix cannot bolt this on

Open Dental is a Windows practice-management client over a practice-owned MySQL (or MariaDB) database. Automation is a second thought: a REST layer over the same tables, bridges, and a universe of reports designed for staff. Dentrix is older still — a local SQL product with decades of COM interop, reseller custom reports, and “AI” that, in practice, means a vendor watching the same human UI.

That architecture assumes a person is looking at a form. The schema is a dumping ground: charts, family balances, insurance plans, notes, and often HR-adjacent staff records in one blast radius. There is no clean tool boundary. There is no specialist vault for cards. There is no native way for an agent to place a phone call, run payroll, or exchange X12 without standing up yet another box that copies the data out.

So the bolt-on playbook is always the same, and it always fails as an AI platform:

  • RPA / screen scrape. A robot clicks Dentrix. A Windows update, a dialog, or a slow printer job breaks the flow. You now have an unattended client with the same privileges as the office manager.
  • Nightly extract. CSV or HL7 into an “AI cloud.” The model is working on yesterday’s chart, and you have created a second copy of PHI the PMS vendor never designed to protect.
  • COM / bridge sidecar. A local service that mirrors the database so a chatbot can answer “who is on the schedule.” The chatbot still cannot pay a lab, run Gusto, or talk to a payer without more copies.
  • Chat widget on the existing UI. Staff still click. The model still cannot hold a payment method or a payroll file, because the PMS is not Stripe and not Gusto.

Those products can add a summarize-this-note button. They cannot become an agentic operating system without throwing away the thing that made them successful: a human GUI on a local, all-in-one database. Rewriting that in place would mean becoming a payments company, a payroll company, an EDI company, and a CPaaS company — which they will not do, and should not do. Specialists already exist.

HeyDental insurance agent illustration.
Insurance, phones, and payroll are jobs for specialists — not another table inside last decade’s PMS.

Bolt-on AI is a security problem, not a feature gap

The worst part of the sidecar is not that it is clumsy. It is that it multiplies copies of you, your staff, and your patients. Card numbers that used to live in a swiper now sit in a PMS table and an AI vendor. Call recordings land on a third disk. Eligibility responses get pasted into a fourth database so the chatbot has “context.”

HeyDental’s design rule is the opposite: we do not warehouse a shadow copy of the sensitive systems of record. Agents orchestrate. Specialists hold the payload. We keep the graph — which office, which job, which permission — not a second vault of PANs, Social Security numbers, EDI bodies, or call recordings. There is no “HIPAA certified” badge in this industry (the U.S. Department of Health and Human Services does not issue one). What exists are BAAs, attested controls, and a refusal to become an accidental data lake.

Built on specialists, not a private data lake

We built the practice OS on major service providers that already run that domain at internet scale, with their own audits, encryption, and customer contracts. Your agents call them. We do not re-implement a worse version in our database.

Payments

Stripe

Stripe is the payments infrastructure used by millions of businesses to accept and move money. Card data is captured in Stripe Checkout / Elements — not typed into HeyDental.

Why it is safe: Stripe is a PCI DSS Level 1 service provider, the most stringent level in the industry, assessed annually by a Qualified Security Assessor. We store customer and payment-method tokens, never PAN or CVC. Charge metadata stays non-clinical. Read Stripe’s security documentation.

Payroll / HR

Gusto

Gusto runs payroll, benefits, and HR for small businesses. Staff tax identifiers, direct-deposit accounts, and benefit elections stay in Gusto — we do not keep a parallel HR file.

Why it is safe: Gusto publishes annually updated SOC 1 and SOC 2 reports, encrypts customer data, and follows HIPAA guidelines for benefits PHI with BAAs where that path applies. Read Security at Gusto.

Insurance

Stedi

Stedi is a healthcare EDI platform: X12 eligibility, claims, claim status, and coordination of benefits with payers. HeyDental’s insurance desk enables locked rules; Stedi is the pipe, not a spreadsheet we host.

Why it is safe: Stedi is SOC 2 Type II attested and HIPAA-eligible, with a Trust Center for policies, access control, and certifications, plus a BAA for PHI accounts. Read the Stedi Trust Center.

Voice and SMS

Twilio

Twilio is the communications platform behind programmable voice and SMS. Calls and texts are placed through Twilio, not through a PBX we operate or recordings we stockpile as a product database.

Why it is safe: Twilio publishes SOC 2 Type II across services, ISO 27001/27017/27018, and HIPAA-eligible products under a Business Associate Addendum. PHI-bearing workflows stay on those eligible products. Read the Twilio Trust Center.

Email

Resend

Resend is a transactional email API for the messages your agents send: waiting-list, booking confirmations, “you’re all set” notes. It is the mail pipe, not a clinical inbox we mine.

Why it is safe: Resend is SOC 2 Type II compliant, encrypts data at rest (AES-256) and in transit (TLS 1.3+), and runs annual third-party penetration tests. We keep clinical detail out of email bodies — status plus a portal link, not charts in the clear. Read Resend security.

Text and voice agents

Latest appropriate AI

Agents use current-generation models suited to the job: short booking turns, insurance language, and voice at the front desk. We pick the model for the task. We do not publish a model brand on the product, and we do not dump your charts into a training set to “make the chatbot smarter.”

Why it is safe: models are callers, not a new system of record. They receive the minimum tool context for that step, act through Stripe / Gusto / Stedi / Twilio / Resend, and leave the payload with the specialist. No bolt-on copy of the practice, no mystery fine-tune on your patients.

Overall platform

Cloudflare

Cloudflare is the edge and application platform: DNS, TLS, Workers, access control, DDoS, and the public site. HeyDental.app runs on Cloudflare rather than a clinic closet server — the failure mode of a lot of on-prem PMS deployments.

Why it is safe: Cloudflare’s Trust Hub covers SOC 2 Type II (security, confidentiality, availability) and an independently audited HIPAA/HITECH Attestation of Compliance for in-scope services, with BAAs where PHI transits the network. Read the Cloudflare Trust Hub.

Orchestration is the product

Put the pieces together and the difference is architectural, not cosmetic:

  • Legacy PMS — one local database, human screens, optional AI that must clone data to see anything.
  • HeyDental — an agent runtime. Stripe is money. Gusto is people. Stedi is payers. Twilio is the phone. Resend is mail. Cloudflare is the platform. Agents use the latest appropriate text and voice models to call those tools.

That is how you get AI that actually runs the floor — eligibility through appeals, booking, follow-up, payroll handoff — without asking the practice to trust a startup with a duplicate of every card, paycheck, and chart. We never set out to store or compromise data about you, your staff, or your patients. The specialists already won those problems. We refuse to re-lose them.

Three stages of the floor — before and after the agents

A typical US general practice does not lose money in one mysterious “leak.” It loses money in three operations stages: leads that never book, chairs that sit empty because of weak scheduling, and front-desk turnover that resets the floor. Separately it pays a pile of subscriptions — phone, SMS, website, online scheduling, reminders — that grew up because the PMS could not cover the job. Satisfaction with that core PMS is merely okay — Capterra has Dentrix at 4.3/5 and Open Dental at 4.6/5; G2 is colder. Staff stay because switching hurts, not because they love the product.

HeyDental is $5,000 / year / office with the agent team included. With the agents on the floor, the office should not need a separate phone/SMS vendor, website stack, or scheduling system — those jobs move into the runtime. The worksheet below asks for today’s outcome and the expected outcome with HeyDental for each stage. Change the numbers. The chart stays simple: before vs after annual drag, and the net gain.

Live worksheet

Before and after the agents

Per office. Edit current and expected outcomes for the three stages, list the tools you drop, and watch the annual drag fall.

Three stages of operations

Current outcome vs expected outcome with HeyDental. Amounts are per office.

Lost leads

Missed and unanswered new-patient calls — production that never reaches the chair.

Poor scheduling

No-shows, gaps, and weak booking that leave chairs empty.

Staff turnover

Hiring, training, and lost continuity when the front desk turns over.

Tools the office no longer needs

With HeyDental, phone/SMS, website, scheduling, and patient messaging move into the agent runtime. Edit or remove anything that does not apply.

Annual drag

  • Operations drag
  • Software you drop
  • HeyDental
Revenue recovered / year $0
Turnover cut / year $0
Software dropped / year $0
HeyDental / year $0
Today’s annual drag $0
With HeyDental $0
Net annual gain $0

Shareable report

Send this calculator exactly as it stands

Each link is unique to your numbers — heydental.app/r/…. No login. Open it later to edit, or post it so others see the same before/after.

Why we think these defaults are solid

The seeds are not vendor fairy tales. Call-tracking studies in dentistry routinely put unanswered or mishandled new-patient calls in the 20–35% band. At a few thousand dollars of first-year production per lost lead — not lifetime value — a few unanswered calls a week already land near our $3,000 / month “today” figure. We do not zero that out with agents; we leave $1,000 / month as residual friction so the model stays honest.

Poor scheduling is the same story at chair time: published practice-ops write-ups cluster no-show and gap losses around the mid five figures per year. Our default $5,000 / month today and $1,500 / month with agents assumes reminders, confirmations, and fill-ins actually run — not that every empty slot vanishes. Turnover is seeded lightly on purpose: $5,000 / year today for one messy front-desk replacement cycle, falling to $500 when the phone and book stop depending on who is at the desk. Replacement-cost surveys often quote much higher; we would rather understate than sell a miracle.

The software list is public list-price territory — phone/SMS, a site, online scheduling, Weave-class reminders — not a Dentrix license. With HeyDental those jobs sit inside the agent runtime, so the subscription pile goes away and the $5,000 / office / year fee is the replacement. Edit every field. This is a worksheet for owners who already feel the empty chairs, not a guarantee and not advice.

Switching is the only way to use the agents

You cannot wait for Open Dental or Dentrix to “add AI” in a meaningful way. Their customers need the GUI they already trained on; their databases need to stay the database; their bridges need to keep billing. An agentic practice will always be a foreign object in that world.

If you want agents that maximize profit, cut waste, and keep patients and staff happy, you move the practice onto an OS that was designed for them. Transparent pricing. No sales people. Everything included — including the robots still in the nursery. Get on the waiting list and we will stand the stack up: specialists, agents, and a platform that does not keep a souvenir copy of your life.