You Bought the Practice. Now You Have Two of Everything.

George
By George
21 August 2026
IT systems merging after acquisition

The deal closes on a Friday. On Monday the new office is still running its own practice management system, its own email domain, its own phone system, its own backup arrangement that nobody has verified, and its own IT vendor who still has administrator access to everything. Meanwhile the front desk expects to book patients across both locations by the end of the week.

This is the part of an acquisition that nobody budgets and everybody underestimates. Practice acquisition IT work is not a technology project bolted on after the close; it is the thing that decides whether the two businesses actually operate as one within a quarter or fight each other for a year.

Decide the Target State Before You Touch Anything

There are only three destinations, and choosing consciously prevents most of the pain. You can absorb the acquired office into your systems, keep the two environments separate and connect only what must be shared, or build something new and move both onto it.

Absorption is usually cheapest to operate and hardest on the acquired staff, since everything familiar changes at once. Separation is gentle at first and expensive forever, because you pay for two of everything and reconcile data by hand. Building new is right occasionally, mostly when both environments are genuinely poor, and it is the option most often chosen for emotional reasons rather than good ones.

Pick a Date, Not a Direction

Separation gets chosen by default whenever no one makes a decision, which is how most groups end up there. Six months later the group has two of everything, two vendor relationships, two security postures, and a reporting problem, and the migration that would have been straightforward in month one now has a year of new data sitting on both sides.

Write down the target state and a date, even a rough one. Whichever direction you choose becomes far cheaper when it is a decision rather than a drift.

Day One: The Things That Cannot Wait

Whatever the long-term plan is, a short list has to happen in the first days after the close. Most of it concerns access rather than convenience, which is why it gets deferred and why deferring it is the wrong call.

  • Revoke the seller's access, including the previous owner's accounts, their family members who had logins, and the outgoing IT vendor's administrative credentials.
  • Take ownership of the domain and the tenant, since a business whose domain registrar account is still controlled by the seller does not really own its email.
  • Confirm the backups are running and restorable, because you now own the consequences of an arrangement you did not build.
  • Change shared passwords, which in a small practice usually means the front desk login, the imaging workstation, and the Wi-Fi that half the neighborhood knows.
  • Inventory what you actually bought: devices, servers, software licenses, cloud subscriptions, and which of them transfer with the business.
  • Establish who to call, so staff at the acquired office are not calling a vendor you have not contracted with.

The access items matter most and are the easiest to defer. A departing owner who keeps mailbox access for months is a common arrangement in small acquisitions and a really poor one, and the discipline for handling it is the same as for any departure, described in our guide to employee offboarding.

Securing acquired IT environment access

The Identity Merge Is the Hard Part

Two businesses mean two Microsoft 365 tenants, and merging them is the single largest piece of work in most integrations. It is also the one that determines whether staff experience one company or two.

The options are to migrate the acquired tenant into yours, to keep both and connect them with guest access and shared calendars, or to leave them entirely separate. Migration gives you one directory, one set of security policies, one place to manage access, and it costs real project effort. Connecting is faster and leaves you administering two of everything, which is tolerable for a year and painful for five.

Identity systems merging securely

What Usually Gets Underestimated

Three details consume more time than expected. Email addresses and the acquired domain need a decision, since patients and clients will use the old address for years and it usually has to keep working long after the brand changes.

Shared mailboxes, distribution lists, and the automated messages sent by clinical or case systems all have to be recreated rather than moved. And the acquired staff have years of files in personal storage that belong to the business, which no one discovers until an account is deactivated. If the plan involves moving systems or storage in the process, the sequencing described in our guide to the cloud migration process applies to this move as much as to any other.

The Records Question, and Who Owns It

For a medical, dental, or legal acquisition, patient and client records are the asset, and they come with obligations rather than just files. Two questions need answers early, ideally with counsel involved.

Who is the custodian of the records created before the close, and for how long must they be retained. And can the records be read at the end of that period, which is a technical question rather than a legal one. If the acquired office ran different software from yours, migrating current patients is normal and migrating a decade of history frequently is not, which leaves the old system alive as an archive with a support and security cost attached.

The Old System Rarely Dies on Schedule

Plan for the legacy system to outlive the integration, because it usually does. Either export the historical data into a form that will be readable without the original software, or keep a restorable copy of the old environment and budget for it deliberately rather than discovering the line item next year.

Set a retention driven end date rather than a hopeful one, and record the decision alongside the rest of your data retention policy. An archive with no owner and no end date is how businesses end up paying to protect data they were entitled to delete years ago.

What You Inherited, Security Wise

Due diligence in a small acquisition covers the financials thoroughly and the technology rarely. That means the buyer routinely inherits unpatched servers, shared administrator passwords, accounts belonging to people who left in 2021, no multi-factor authentication, a backup no one has restored, and occasionally an incident the seller never disclosed because they never noticed it.

Assume none of it is clean and check rather than trust. The first ninety days should include a real assessment of the acquired environment, because the moment you connect the two networks you have merged their risk, and a compromise on their side becomes an incident on yours.

Connect Last, Not First

The instinct is to link the two offices immediately so staff can share files. The safer order is to assess, clean up, and only then connect, since a flat connection between a hardened environment and an unknown one gives you the security posture of the weaker side.

If the business needs shared access before the cleanup is finished, provide it through controlled means such as a shared cloud location rather than by joining the networks. It costs a little friction for a few weeks and prevents the most avoidable category of post acquisition incident.

Secure network connection after assessment

Contracts, Licenses, and the Bills You Did Not Sign

Software and service agreements do not automatically follow the business, and the details vary by vendor in ways that matter financially. Some licenses transfer with the entity, some are tied to the seller personally, and some require the vendor's consent that nobody thought to request.

Build a list of every technology contract at the acquired office with its renewal date, notice period, and whether it was assigned to you, then decide which to keep, renegotiate, or end. Duplicate subscriptions across the two offices are the easiest saving available after an acquisition, and they are also the ones most commonly missed because each office assumes the other cancelled theirs. Vendor security expectations should be reviewed at the same time, using the approach in our guide to third-party risk management.

A Ninety Day Sequence That Works

Order beats speed in every integration. The sequence below keeps both offices operating while the work happens, which matters more than finishing quickly.

  1. Days one to seven: revoke access, take domain and tenant ownership, verify backups, change shared credentials, and tell staff who to call.
  2. Days seven to thirty: assess the acquired environment honestly, inventory contracts and licenses, and choose the target state with a date.
  3. Days thirty to sixty: fix what the assessment found, standardize the security baseline across both offices, and plan the identity merge properly.
  4. Days sixty to ninety: execute the merge or the connection, handle records and legacy access deliberately, and retire the duplicate subscriptions.

Nothing in that list is exotic, and every item is cheaper in the order shown than in any other. Groups that run it in reverse, connecting first and assessing later, spend the next year fixing decisions made in the first week.

Get the Technology Question Into Diligence Next Time

If more acquisitions are planned, the highest return change is asking a few technology questions before the close rather than after. What systems does the target run, what do their support and licensing arrangements look like, who holds administrative access today, when was the last successful restore, and has there been an incident.

None of that requires a formal audit, and the answers often change the integration budget by more than they change the purchase price. Groups buying multiple offices can have that review run as a repeatable step by a provider offering IT services in the San Fernando Valley, so each deal starts with a known picture instead of a Monday morning surprise.

Across the region, IT support in Westlake Village covers the same work, from the first-day access items through the tenant merge. Your second acquisition is always easier than the first, provided somebody wrote down what happened during it.

For dental and medical groups specifically, this work pairs with the standards already in place across your dental practice IT arrangements rather than starting from nothing each time. Consistency across locations is the whole point of buying them.

Frequently Asked Questions

Access work, mostly. Revoke the seller's accounts and any family logins, remove the outgoing IT vendor's administrative credentials, take ownership of the domain registrar and the Microsoft 365 tenant, change shared passwords such as the front desk and imaging logins, confirm the backups are running and restorable, and tell the acquired staff who to call for support. Convenience items such as shared file access can wait a few weeks; access items cannot, because you now own the consequences of arrangements you did not build.
Usually yes, if the goal is one business rather than two under common ownership. A tenant merge gives you one directory, one security policy set, and one place to manage access, at the cost of a real project. Keeping both and connecting them with guest access is faster and leaves you administering everything twice, which is tolerable for a year and expensive over five. Decide deliberately with a date, because defaulting to separation is how groups end up with permanent duplication.
They come with obligations, so settle two questions early and with counsel: who is the custodian of records created before the close, and how long must they be retained. Then treat readability as a technical requirement, since migrating current patients into your system is normal while migrating a decade of history often is not. That usually leaves the old system alive as an archive, which needs an owner, a security arrangement, and a retention driven end date rather than an open ended one.
Riskier than it feels, which is why the order matters. Joining a hardened environment to an unassessed one gives you the security posture of the weaker side, and small practices frequently carry unpatched servers, shared administrator passwords, dormant accounts, and no multi-factor authentication. Assess and clean up first, and if staff need shared access sooner, provide it through a controlled cloud location rather than by linking the networks.
Not automatically, and the answer varies by vendor. Some agreements transfer with the entity, some are tied to the seller personally, and some require the vendor's consent that not one person thought to request. Build a list of every technology contract at the acquired office with renewal dates, notice periods, and assignment status, then decide what to keep, renegotiate, or end. Duplicate subscriptions across the two offices are the easiest post acquisition saving and the one most often missed.
Five questions cover most of the risk: what systems does the target run and under what support arrangements, who holds administrative access today, when was the last successful restore tested, what security controls are in place including multi-factor authentication, and has there been an incident. None of it requires a formal audit, and the answers routinely change the integration budget more than they change the purchase price.

Closing on a practice starts a clock on the access items no one has time for, and GlobeVM will handle the first week of practice acquisition IT work and then plan the merge properly.

Comments

0 Comments