Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Dentists

The HIPAA compliance and security operating system for dental offices. Your ePHI does not sit in one place — it moves through Dentrix or Eaglesoft, the CBCT and intraoral units, the operatory workstations, the clearinghouse, the lab, and the front desk's phone. Patient Protect runs the risk analysis, policies, training, vendor agreements, and evidence across all of it, and works to stop a breach rather than document one.

Dental practices that electronically submit claims, check eligibility, request authorization, or have a billing service conduct those standard transactions on their behalf are HIPAA covered entities. Most modern dental practices meet that definition. Once covered, the duties below are required.

HIPAA compliance is not optional for a covered dental practice.

If your practice is a HIPAA covered entity, it is required to maintain an active, documented compliance program — and if it performs covered functions as a Business Associate, it must implement the Security Rule and every other duty attaching to that role. The responsibility does not transfer to your EHR, IT company, consultant, insurance carrier, or software provider. Those partners can support the work; your practice remains responsible for completing it.

Watching one training video is not a compliance program. Downloading a policy template is not a compliance program. Signing one BAA is not a compliance program. HIPAA requires your practice to implement, maintain, and document the complete operating system behind each of those activities.

Your practice is required to do all of the following

  1. 01Conduct and document a Security Risk Analysis

    Identify every place electronic protected health information enters, moves through, or leaves the practice. Assess the systems, devices, people, vendors, locations, workflows, threats, and vulnerabilities that could compromise that information.

    45 CFR §164.308(a)(1)(ii)(A)

  2. 02Manage the risks the analysis uncovers

    Turn identified risks into a documented remediation plan. Assign responsibility, prioritize the work, implement safeguards, and preserve evidence showing how the practice responded.

    45 CFR §164.308(a)(1)(ii)(B)

  3. 03Designate Privacy and Security Officials

    Assign and document who is responsible for developing, maintaining, and enforcing the practice's privacy and security program. In a small practice, one person may perform both roles — but the responsibilities must still be assigned and documented.

    45 CFR §164.530(a) · §164.308(a)(2)

  4. 04Maintain written policies and procedures

    Document how the practice protects patient information, controls access, handles permitted disclosures, responds to incidents, enforces workforce accountability, and maintains required privacy and security safeguards.

    45 CFR §164.316(a) · §164.530(i)

  5. 05Train the entire workforce

    Train workforce members on the privacy policies relevant to their roles and maintain an ongoing security-awareness program. Preserve records showing who was trained, what the training covered, and when it was completed.

    45 CFR §164.530(b) · §164.308(a)(5)

  6. 06Identify and govern every Business Associate

    Determine which vendors and service providers create, receive, maintain, or transmit protected health information on the practice's behalf. Execute the required Business Associate Agreement before protected information flows and maintain the agreement as part of the practice's compliance record.

    45 CFR §164.502(e) · §164.308(b) · §164.504(e)

  7. 07Implement administrative, physical, and technical safeguards

    Control who can access patient information, secure the systems and locations where it is maintained, review activity, authenticate users, protect data integrity, and safeguard electronic transmission.

    45 CFR §164.308 · §164.310 · §164.312

  8. 08Protect patient privacy rights

    Maintain the required notices, authorization processes, complaint procedures, and workflows for responding to patient requests involving access, amendments, confidential communications, restrictions, and applicable disclosure accounting.

    45 CFR §164.520 · §164.524 · §164.526 · §164.522 · §164.528

  9. 09Prepare for incidents, outages, and breaches

    Maintain security-incident procedures, data backup, disaster recovery, emergency operations, mitigation, and breach-notification processes before an event occurs.

    45 CFR §164.308(a)(6) · §164.308(a)(7) · Subpart D

  10. 10Preserve proof that the work was completed

    Retain the assessments, risk decisions, policies, training records, official designations, BAAs, acknowledgments, incident records, and other documentation needed to demonstrate what the practice actually did.

    45 CFR §164.316(b) · §164.530(j)

The Security Risk Analysis is where the work begins.

The Security Rule requires an accurate, thorough assessment of the risks and vulnerabilities affecting every form of electronic protected health information your practice creates, receives, maintains, or transmits. This is commonly called a Security Risk Analysis, or SRA.

The federal government publishes its own Security Risk Assessment Tool for small and medium-sized practices. You are not required to use that particular tool. You are required to perform and document the underlying analysis.

Patient Protect provides its own guided SRA. It walks the practice through the assessment in plain language, identifies what is missing, and carries those findings into risk management, remediation, policies, tasks, and documentation — so the assessment ends with the problem assigned and resolved, not merely named.

A five-minute readiness quiz is not an SRA. Reviewing only your EHR is not an SRA. Reusing an old checklist that no longer reflects your systems, vendors, workforce, or workflows is not an SRA.

That includes our own free tool. The Patient Protect Score is a free exposure scan and a starting point. It is not your completed Security Risk Analysis, and we will not tell you it is.

What a dental practice’s Security Risk Analysis must cover

Dental ePHI does not live in one system. It moves through the practice management system, digital imaging equipment, operatories, front-desk workstations, insurance transactions, laboratories, referral workflows, mobile devices, cloud backups, patient communication, and third-party support systems.

  • The practice management system and every user with administrative, clinical, scheduling, or billing access
  • Panoramic, CBCT, intraoral, and other imaging systems — including how images move between devices, workstations, laboratories, specialists, and storage
  • Electronic claims, eligibility verification, payment, and clearinghouse workflows
  • Patient portals, digital forms, e-fax, email, text messaging, appointment reminders, and referral tools
  • Office servers, workstations, laptops, tablets, phones, removable media, network equipment, and cloud backups
  • Every vendor that stores, maintains, transmits, or can remotely access the practice's ePHI
  • Employee onboarding, role changes, shared-workstation use, and the immediate removal of access when someone leaves

What the dental compliance program must also address

  • Unique workforce access instead of shared front-desk or operatory credentials
  • Written photo, imaging, referral, and patient-communication procedures
  • Business Associate identification and BAA management across the technology and service stack
  • HIPAA training for dentists, hygienists, assistants, front-desk personnel, billing staff, and temporary workers
  • State dental-board requirements governing clinical and imaging-record retention

Dental practices do not carry a smaller HIPAA obligation because the office is small. They carry the same responsibility to assess risk, implement safeguards, train the workforce, govern Business Associates, and document the work.

What HIPAA actually looks like for dental practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Dental practices operate under HIPAA as covered entities through standard electronic transactions — most commonly the 837D dental claim submitted to clearinghouses for insurance reimbursement, eligibility verification (270/271), and prior authorization (278). Electronic prescribing under NCPDP SCRIPT is a standard the practice may use, but it is not itself an adopted covered transaction and does not establish coverage on its own. State dental practice acts apply on top: HIPAA's six-year rule governs compliance documentation, while state law governs clinical-record retention, typically seven to ten years post-last-encounter and longer for minors. The ADA's HIPAA-compliance guidance is widely referenced but not regulatorily binding; the controlling frameworks remain HIPAA, state dental board rules, and the dental practice acts of operating jurisdictions.

OCR enforcement patterns

OCR's enforcement record against dental practices includes resolution agreements citing lost or stolen unencrypted laptops containing patient records, unauthorized access to patient information by terminated employees whose credentials were not promptly revoked, ransomware incidents on dental practice management systems where the practice had inadequate backup or risk-analysis documentation, and improper disposal of patient records and imaging media. The common thread: small practices with limited IT oversight failing to implement administrative safeguards under §164.308 — risk analysis, workforce training, sanction policies — that scale to the size of the operation.

Standards beyond HIPAA

Beyond HIPAA itself, dental practices intersect with the DICOM standard for imaging (panoramic, CBCT, intraoral), NCPDP SCRIPT for any electronic prescribing, ADA-CDT procedure coding embedded in claims, state dental board licensure rules governing record-keeping, and state pharmacy board e-prescribing requirements. A dental laboratory fabricating to the practice's prescription is generally a business associate under §160.103, while one acting as another treating provider is not — the relationship has to be classified rather than assumed. Imaging-software vendors are typically business associates whether or not the practice realizes it.

Common compliance gaps

OCR audits and breach investigations of dental practices routinely surface missing or expired BAAs with practice management vendors (Dentrix, Eaglesoft, Open Dental are the common dental PMS vendors), unsigned BAAs with dental laboratories, untrained staff using personal phones for patient communication, shared workstation logins without role-based access controls, undocumented or inconsistent risk analyses, no Privacy Official designation in writing, and inadequate breach response protocols. Most of these gaps trace to administrative-safeguard implementation rather than technical weakness.

Compliance documentation, then state record law.

HIPAA requires retention of policy and procedure documentation for six years (§164.530(j)). State dental practice acts typically require seven to ten years of patient record retention post-last-encounter, with extended timelines for minors (often until age of majority plus statute-of-limitations period). Dental imaging records are sometimes subject to separate retention rules under state radiation-safety regulations. Malpractice insurance carriers may require longer retention than either HIPAA or state law as a condition of coverage. The practical retention floor is whichever is longest among these frameworks for any given record type.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to dental practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

HIPAA training for dental practices.

A 19-module HIPAA Foundations series with the workforce roles, PHI workflows, disclosure scenarios, and vendor risks that actually apply to dental practices— not a generic healthcare course.

Where dental practices are most exposed.

Digital imaging systems transmit ePHI without encryption

Panoramic X-rays, intraoral scans, and CBCT files move between operatories, labs, and specialists. If your imaging software sends unencrypted data over the network, every transmission is a potential breach — and you may not know it's happening.

Your practice management vendor may not have a current BAA

Dentrix, Eaglesoft, Open Dental — every PMS vendor needs a signed, current BAA. Most dental offices have unsigned templates or expired agreements on file. One vendor breach exposes you to joint liability under HIPAA.

Front desk staff text patients from personal phones

Appointment reminders, insurance questions, treatment updates — when staff use iMessage or SMS from personal phones, patient data leaves the practice's control and its records. HIPAA does not ban texting outright. It requires reasonable safeguards, documented patient communication preferences, and a channel the practice can actually govern and produce evidence for.

No IT department means no one monitors for threats

Most dental offices don't have dedicated IT staff. Attacks on independent providers have risen sixfold since 2021, and small practices are targeted precisely because nobody is watching. Without continuous monitoring, you won't know you've been breached until it's too late.

Built for dental practices, not hospital systems.

Guided SRA wizard

Walk through every required assessment step in plain language. No consultants, no spreadsheets. Satisfies §164.308(a)(1) for dental-specific workflows.

BAA lifecycle management

Track agreements with Dentrix, labs, clearinghouses, and every other vendor. Get alerts before agreements expire. E-sign and store in one place.

Secure messaging

Replace personal texts and unencrypted email with BAA-gated messaging. Patient data stays inside your compliance perimeter — automatically.

Real-time compliance scoring

See your practice's compliance standing update in real time as you close gaps. Know exactly where you stand before an audit, not after.

DICOM and dental-imaging compliance built into the SRA

Panoramic X-rays, intraoral scans, and CBCT files transmitted between operatories, labs, and specialists are part of the audit surface. The risk analysis module covers DICOM transmission paths, imaging-software vendor BAAs, and the workstation-side controls that keep imaging data ePHI-compliant under §164.312.

Patient communication that fits dental practice workflows

Appointment reminders, treatment plans, post-op instructions, and insurance updates routed through HIPAA-compliant channels. Replaces the front-desk-personal-phone pattern that creates §164.530 exposure on every message — without sacrificing the responsiveness patients expect from a dental office.

HIPAA already requires the work. Patient Protect starts at $39 a month.

For a covered practice, HIPAA does not ask whether the organization has the budget, internal expertise, or spare time to build a compliance program. The obligation already exists. The only real question is whether you run it through spreadsheets, generic templates, disconnected training and scattered agreements — or keep the whole program in one place.

  • Guided Security Risk Analysis
  • Risk-management and remediation workflows
  • 48 customizable policies and procedures
  • HIPAA Foundations workforce training
  • Completion tracking and verifiable training certificates
  • Workforce and vendor management
  • Business Associate Agreement tracking and documentation
  • Compliance scoring and centralized audit evidence
Start your 14-day free trial

$39 per office per month · Up to 25 personnel · No long-term contract

State-specific HIPAA rules for dental practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for dental practices.

Do dental offices really need HIPAA compliance software?

Yes. Dental offices are covered entities under HIPAA and face the same regulatory requirements as hospitals. OCR audits dental practices regularly, and fines for non-compliance range from $145 per violation at Tier 1 up to $2,190,294 per violation at the highest tier (2025 inflation-adjusted per 45 CFR §102.3). The average dental practice handles thousands of patient records containing ePHI — X-rays, treatment plans, insurance data, and clinical notes.

How does Patient Protect work with Dentrix and Eaglesoft?

Patient Protect manages the compliance layer around your practice management software — BAA tracking, access control documentation, risk assessments, and audit trails. It doesn't replace your PMS; it ensures your use of it is HIPAA compliant. BAA templates for major dental PMS vendors are included.

What's the biggest HIPAA risk for dental practices?

Unsecured patient communication. Staff texting patients from personal devices, emailing X-rays without encryption, and sharing treatment information through non-compliant channels. These violations are the most common findings in OCR dental practice audits.

How much does HIPAA compliance cost for a dental office?

Traditional compliance consultants charge $3,000–$8,000 per year for dental practices. Patient Protect starts at $39/month ($468/year) with no contracts and no setup fees — covering risk assessments, policies, BAA management, training, and ongoing monitoring.

Are dental X-rays and CBCT scans considered ePHI?

Yes. Any imaging that includes patient-identifying information is ePHI under HIPAA. DICOM headers contain extensive PHI by design — patient name, date of birth, accession number, study UID. Imaging stored on practice servers, transmitted to specialists, or backed up to cloud storage requires the same encryption, access-control, and BAA discipline as any other ePHI.

Do dental labs need a BAA?

It depends on what the lab actually does. A dental laboratory that fabricates a restoration to the dentist's prescription is generally receiving PHI to perform a service on the practice's behalf, which makes it a business associate under §160.103 and requires a written BAA before PHI flows. A laboratory acting as another treating provider is a different relationship, and HHS does not treat provider-to-provider treatment disclosures as business associate arrangements. Classify each lab by function, then paper the ones that qualify. The 'we just receive impressions' argument fails either way once case files carry patient-identifying metadata.

How long must we retain dental records under HIPAA?

HIPAA requires retention of policy and procedure documentation for six years (§164.530(j)). Patient record retention is governed by state dental practice acts, which typically require seven to ten years post-last-encounter, longer for minors. The practical retention floor is whichever is longest among HIPAA, state law, and the practice's malpractice insurer requirements.

Does a dental practice have to complete a HIPAA Security Risk Analysis?

Yes, and it has to reach further than the practice management system. Every covered practice must conduct and document an accurate, thorough assessment of the risks and vulnerabilities affecting all ePHI it creates, receives, maintains, or transmits. For a dental office that means Dentrix, Eaglesoft, or Open Dental plus the panoramic and CBCT units, intraoral scanners, the operatory and front-desk workstations, the claims clearinghouse, cloud backup, the patient portal, and every vendor with remote access. Practice size does not reduce the requirement. An analysis that covers only the PMS is not a completed SRA.

Which of our dental vendors need Business Associate Agreements?

Any organization that creates, receives, maintains, or transmits PHI on the practice's behalf — which for most dental offices means the practice management vendor, imaging software vendor, claims clearinghouse, cloud backup provider, IT support contractor, appointment-reminder service, and patient-communication platform. Dental laboratories require classification rather than assumption: a lab fabricating a restoration to your prescription is generally performing a service on your behalf and needs a BAA, while a laboratory acting as another treating provider is a different relationship that HHS does not treat as a business associate arrangement. Classify each relationship, then execute agreements before PHI flows.

Our operatory computers are shared — do hygienists really need individual logins?

Yes. The Security Rule requires a unique identifier for each user, and a shared operatory or front-desk login defeats it — not as a technicality, but because it removes the practice's ability to answer the only question that matters after an incident: who accessed this record. With one shared account, the audit log shows the operatory, not the person, and the practice cannot distinguish a hygienist checking a chart from a departed employee still using credentials nobody revoked. The common objection is workflow speed across operatories. The workable answer is individual accounts with fast switching and short auto-lock timeouts, set to a value your risk analysis supports rather than a number copied from another practice.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a dental practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your dental practice deserves active breach prevention.

See your compliance gaps in five minutes. No login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions