
When a dentist suspects embezzlement, many firms start with the audit trail in the practice-management software, and many stop there too. That review has real value. It is not digital forensics, and treating it as the whole investigation can cost you the truth.
The audit trail is one witness, not the whole story
An audit trail can show deleted payments, altered transactions, unusual write-offs, permission changes, and which user ID did what. That is useful evidence. But it only records what happened inside that one system.
It cannot tell you what happened before a transaction was entered or after it was changed. It cannot tell you whether a password was shared or a workstation was left logged in. It cannot tell you whether records were copied, destroyed, or moved through a different system entirely.
At Hiltz & Associates, the practice-management system is one source of evidence inside a much larger digital environment. Our job is to reconstruct what happened across all of it, preserve the evidence properly, test every reasonable explanation, and report only what the data can reliably prove.
A user ID is not a person
In one practice-sale dispute worth more than $1.2 million, the audit trail showed over 800 patient-record deletions under the seller’s user ID. On the logs alone, the case looked closed.
We matched every deletion timestamp against email, appointment, text-message, and geolocation data. When those deletions happened, the seller was in surgery, away from the practice, or out of town. The buyer withdrew its claim six weeks before trial. See more case results.
The audit trail told us what happened. Only the wider evidence could tell us who.
What digital forensics actually involves
Digital forensics is the disciplined identification, preservation, collection, examination, analysis, and reporting of electronic evidence. In a dental practice, depending on the question, that can include:
- The practice-management database itself, not just its reports: audit trails, deleted records, user activity, and the underlying transaction tables.
- Workstations, laptops, servers, and removable storage, including Windows event logs, file-system metadata, and application history.
- Email: attachments, mailbox rules, deleted messages, and forwarding activity.
- Cloud platforms, shared drives, and backups, including synchronization history.
- The money trail: bank records, deposits, merchant-processing portals, and electronic funds transfers.
- Accounting software, spreadsheets, and exported reports, including hand-kept reconciliation files.
- Browser history, downloads, uploads, remote-access tools, and software that should not be there.
- Text messages, collaboration apps, and mobile devices, where lawfully obtained and properly authorized.
The point is not to collect everything. It is to find the systems that matter, preserve them in a way that holds up, connect the records to each other, and answer the questions that actually decide your case.
Where a software-only review falls short
An audit trail can record a change to a patient ledger. On its own, it usually cannot tell you:
- Whether the user actually did it, or someone else used their credentials.
- Whether a report was exported, altered, or sent outside the practice.
- Whether a deleted transaction is part of a larger scheme involving deposits, merchant refunds, or accounting entries.
- Whether someone reached confidential information through a shared workstation or a remote-access tool.
- Whether a suspicious entry is fraud, a training problem, a system setting, or a legitimate correction.
- Whether the evidence you need is sitting on a workstation, in a cloud account, on a backup, on a phone, or in email.
- Whether the loss estimate actually agrees with bank activity, merchant settlements, payroll, insurance remittances, and the general ledger.
Two rules follow from that. The absence of an entry does not prove nothing happened. And the presence of a suspicious entry does not prove who made it, or why. A reliable conclusion needs corroboration and context.
How we investigate
Every investigation moves from isolated system events to a reconstruction of what happened that we can defend, in a report, to an insurer, or on the stand.
1. Define the question
Suspected employee theft, unauthorized access, a provider-credit dispute, manipulated collections, missing records, a partnership disagreement, a privacy incident. The question decides which systems, date ranges, people, accounts, and devices matter.
2. Map the digital environment
No dental practice runs on one system. Financial, clinical, administrative, and communication records live in separate places: the practice-management platform, accounting, bank and merchant accounts, email, file storage, workstations, servers, backups, and third-party apps. We identify which of them hold evidence and how they need to be reconciled.
3. Preserve the evidence before it changes
Ordinary business activity overwrites, syncs, and deletes digital evidence every day. Preservation can mean securing exports, imaging devices, protecting cloud records, documenting system settings, and freezing user accounts, all while recording the condition of the evidence when it was collected. A screenshot or a printed report is fine for a first look. It is rarely enough to preserve the underlying evidence or prove where it came from.
4. Collect and validate the data
We document the source, scope, format, and handling of everything we collect. Where appropriate, forensic copies, cryptographic hash values, collection notes, and chain-of-custody records show the evidence was not altered during the examination. The goal is analysis that someone else can repeat and that we can explain, not a convenient spreadsheet.
5. Analyze across systems
We compare records that should agree and dig into the ones that do not. Depending on the matter, that means:
- Patient-ledger activity against daily collections and bank deposits.
- Merchant settlements against posted payments and refunds.
- Bank activity against accounting entries and deposit records.
- User logins against schedules, access privileges, devices, and where people actually were.
- Deleted or adjusted transactions against their replacement entries and supporting documents.
- Email, file, and device activity against the timing of financial or system changes.
- Exported reports against the underlying database and what the system actually retained.
That is how you tell a data-entry mistake from a pattern, an authorized correction from concealment, and a system glitch from conduct that actually cost the practice money.
6. Report findings, and their limits
A forensic report should explain the method, the evidence reviewed, the findings, the loss calculation, the assumptions, the limitations, and the alternative explanations we tested. It should also separate three things clearly: what the evidence establishes, what can reasonably be inferred, and what remains unresolved. That separation matters when the report lands in front of an insurer, counsel, law enforcement, a regulator, the other side, or a judge.
Audit-trail review vs. digital forensics
| Audit-trail review | Digital-forensics investigation | |
|---|---|---|
| Scope | Activity recorded inside the practice-management system. | The practice’s wider digital and financial environment. |
| What it finds | Deleted, altered, or adjusted transactions. | How that activity connects to devices, accounts, communications, banking, and accounting. |
| Evidence | Often reports or exports supplied from the software. | Preserved, validated sources, including metadata, system artifacts, and documented handling. |
| Who did it | Points to suspicious transactions and user IDs. | Tests attribution, sequence, intent indicators, and competing explanations. |
| Loss | Estimates a discrepancy within the software data. | Ties the discrepancy to source records and the actual movement of money. |
| Best used for | Initial screening or a first financial review. | A defensible reconstruction of events, with the gaps identified. |
We do audit-trail reviews ourselves, and they are a smart first step. See our Dentrix Audit Trail Expert Review. We just don’t call them digital forensics, and neither should anyone else.
Questions to ask before you hire
- What will you examine beyond the practice-management software?
- Will you review the underlying database, or only the standard reports?
- How will you preserve the evidence before you collect and analyze it?
- Can you examine workstations, servers, email, cloud storage, backups, or phones if we need to?
- How will you test who actually did it if passwords were shared or compromised?
- Will you reconcile bank, merchant, accounting, payroll, and deposit records against the software?
- What documentation will I get on collection methods, evidence handling, and limitations?
- Will your report separate confirmed facts from assumptions and interpretation?
- Can you support my attorney, my insurer, investigators, or a court if it comes to that?
- Does your proposed scope fit my question, or just the easiest data to get?
If every answer circles back to one software platform, you are buying a software review, not a forensic investigation.
Why the label matters
Calling a review “digital forensics” sets expectations about its scope, its reliability, and its value as evidence. A report built only on practice-management logs can still be useful. But it may miss evidence that lives elsewhere, and it cannot tell you whether a person, a device, an account, or a third party was actually responsible.
In an embezzlement matter, an incomplete review can skew the loss estimate, the decision to confront an employee, an insurance claim, a civil suit, or a referral to law enforcement. It can also miss the evidence that clears someone, the evidence that separates deliberate theft from an honest mistake or poor training.
That is why we don’t define digital forensics as reading an audit trail. We use the practice-management data wherever it is relevant, and then we put it where it belongs: inside a documented, cross-system investigation built to find the truth in the data.
If you suspect something today
- Don’t confront anyone yet. Preserve the evidence first.
- Don’t reset, wipe, reinstall, or delete devices or user accounts unless you must to protect the practice.
- Preserve the records: bank, merchant, accounting, payroll, email, cloud, backups, and the practice-management system.
- Write down what you know: dates, users, devices, systems, and anything unusual.
- Get advice on scope and legal authority before anyone collects personal or private information.
- Choose an investigator for the evidence you need, not for their familiarity with one software platform.
Hiltz & Associates provides forensic consulting, digital-evidence analysis, financial-data auditing, and litigation support for dental practices and their advisors. We are not a law firm. When a matter needs legal advice, legal process, or a privileged investigation, we work alongside the practice’s counsel.
The bottom line
Audit trails matter. They are one window into what happened. Digital forensics looks through all of them: systems, devices, accounts, communications, metadata, financial records, and how every one of those connects.
The right question isn’t “What does the software log show?” It’s “What evidence exists across the practice, how do we preserve and connect it, and what does it actually prove?” That is the standard we hold every investigation to.