Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA compliance for dental practices in Colorado

Colorado keeps obligations of its own alongside HIPAA, with different recipients and triggers from the federal rules. Beyond that, Colorado has 2 recorded rules that apply to dental practices differently from other businesses in the state — set out below with their conditions and sources.

Colorado jurisdiction record verified against primary state authority August 2026. General reference, not legal advice.

Does this reach your practice?

Two questions have to be settled before any state rule matters: whether HIPAA reaches a practice like yours, and whether Colorado's own law reaches a practice that HIPAA already covers.

Federal — is this practice a covered entity

Dental practices that electronically submit claims, check eligibility, request authorization, or have a billing service conduct those standard transactions on their behalf are HIPAA covered entities. Most modern dental practices meet that definition. Once covered, the duties below are required.

State — how Colorado law interacts with HIPAA

Colorado substitutes federal notice for part of its scheme but keeps a residual state duty of its own. Dental practices operating here should expect both a federal and a state obligation, with different recipients and triggers.

Colorado Attorney General guidance under § 6-1-716 provides that an entity regulated under HIPAA or another applicable state or federal regime may generally comply with § 6-1-716 by following its primary regulator's notification procedures, subject to two express exceptions: (a) Colorado AG notice under § 6-1-716 is still required when the breach affects 500 or more Colorado residents, and (b) where federal and state notice periods differ, the shorter period applies. The Colorado AG has specifically noted that HIPAA's potential 60-day individual-notice window does not override Colorado's 30-day outer bound — a HIPAA-regulated entity must therefore notify Colorado residents within 30 days even if HIPAA alone would allow up to 60. Colorado also maintains the Colorado Privacy Act (CPA, C.R.S. §§ 6-1-1301 et seq.) which imposes independent obligations on controllers of personal data.

What Colorado adds for dental practices specifically

Rules that exist because of the combination — not federal HIPAA, which applies the same way everywhere, and not Colorado's general breach law, which applies the same way to every business in the state.

How long records must be kept

How long the record must be kept

Records for ADULT patients shall be kept for a MINIMUM OF SEVEN YEARS AFTER THE LAST DATE OF DENTAL TREATMENT OR EXAMINATION, WHICHEVER OCCURS AT THE LATEST DATE. Records for MINORS shall be kept for a MINIMUM OF SEVEN YEARS AFTER THE PATIENT REACHES THE AGE OF MAJORITY (AGE EIGHTEEN). This Rule DOES NOT APPLY to records kept by EDUCATIONAL, NOT-FOR-PROFIT AND/OR PUBLIC HEALTH PROGRAMS, which are subject to Colo. Rev. Stat. § 25-1-802.

Provider class
Colorado dental licensees

What this means operationally

Seven years, but note the clock is the LATER of treatment or examination — a recall exam with no treatment restarts it, so a hygiene-only patient does not age out on the date of their last filling. The minor rule is a straight age-25 endpoint rather than a whichever-is-longer test, which makes it simpler than most states and, for a patient last seen at seventeen, longer than the adult rule would give. The carve-out is worth checking before applying this in a community setting: educational, not-for-profit and public health dental programs fall out of the board rule entirely and back onto the general statute, which has no retention period at all.

Applies when

  • A Colorado dental licensee holds a patient record

Exceptions

  • Does not apply to records kept by educational, not-for-profit or public health programs, which are subject to Colo. Rev. Stat. § 25-1-802
State regulation3 Colo. Code Regs. 709-1, Patient Records Retention ¶¶ 1-3Patients of the practice, adult and minorVerified 2026-08-30

Destruction and disposition

Destruction or disposition requirement

When the DESTRUCTION CYCLE IS IMMINENT, WRITTEN NOTICE to the patient's last known EMAIL ADDRESS, MAILING ADDRESS, OR NOTICE BY PUBLICATION must be made SIXTY DAYS PRIOR TO DESTRUCTION. DESTRUCTION CANNOT TAKE PLACE UNTIL A THIRTY DAY PERIOD HAS ELAPSED wherein the patient may claim the records. NOTICE BY PUBLICATION may be accomplished by publishing or posting online in A MAJOR NEWSPAPER AND A NEWSPAPER BROADLY CIRCULATED IN THE LOCAL COMMUNITY ONE DAY PER WEEK FOR FOUR CONSECUTIVE WEEKS. When the destruction cycle is imminent, records will be provided to the patient, patient representative or legal guardian AT NO CHARGE; however, reasonable postage and handling costs are permitted, or actual costs associated with the electronic medium. DESTRUCTION SHALL BE ACCOMPLISHED BY A MEANS WHICH RENDERS THE RECORDS UNABLE TO BE IDENTIFIED OR READ — for paper, by incinerating or shredding; for electronic records, by clearing, using software or hardware products to overwrite media.

Provider class
Colorado dental licensees

What this means operationally

Colorado dentistry does not permit quiet destruction, and this is the most prescriptive destruction regime in the corpus. Three obligations attach before anything is destroyed: sixty days' advance notice, a thirty-day claim window that must actually elapse, and free provision of the records to anyone who claims them, with only postage or media cost recoverable. The publication route exists for patients who cannot be reached, but it is expensive and specific — two newspapers, weekly, for four consecutive weeks — so keeping current contact details is materially cheaper than the alternative. The method requirement rules out ordinary deletion of electronic records: overwriting is named, and a file simply marked deleted in an EHR has not been cleared.

Applies when

  • A Colorado dental licensee proposes to destroy patient records at the end of the retention period

Exceptions

  • Reasonable postage and handling, or actual costs of the electronic medium, may still be charged
State regulation3 Colo. Code Regs. 709-1, Patient Records Retention ¶¶ 4-7Patients of the practice, adult and minorVerified 2026-08-30

Each rule above was read against the cited source on the date shown. General reference for compliance planning, not legal advice — confirm current text before relying on it.

Colorado breach obligations

These apply to businesses generally rather than to dental practices in particular, and they are shown after applicability because whether they reach you depends on the answer above.

Coloradobreach data →

Individual notice deadline

In the most expedient time possible, without unreasonable delay, and within 30 days after the date of determination that a security breach has occurred, subject to the specified law-enforcement delay.

The outer bound of 30 days is materially shorter than HIPAA's 60-day individual-notice window. Federal and state duties apply independently.

State regulator notice

Required at 500+ residents

If a security breach is reasonably believed to have affected 500 or more Colorado residents, the covered entity must provide notice to the Colorado Attorney General using the Data Breach Reporting Form.

Source: Colo. Rev. Stat. § 6-1-716 (material 30-day breach regime enacted by HB18-1128, effective September 1, 2018; further amended by HB26-1426, effective August 12, 2026 — see notes for currency detail)

Statewide rules that also reach dental practices

Minor may consent

A minor eighteen years of age or older, or a minor fifteen years of age or older who is living separate and apart from a parent or legal guardian — with or without their consent — and is managing their own financial affairs regardless of the source of income, or any minor who has contracted a lawful marriage, may consent to organ or tissue donation or to the furnishing of hospital, medical, dental, emergency health and surgical care to themselves. The consent is not subject to disaffirmance because of minority, and the minor has the same rights, powers and obligations as if they had attained majority. Parental consent is not necessary, and no hospital, physician, surgeon, dentist, trained emergency health-care provider or their agent or employee who in good faith relies on such a minor's consent is liable for civil damages for failure to secure the parent's consent.

What this means operationally

The Colorado route that reaches beyond behavioral health — it names dental and surgical care expressly and is not tied to a service list. Fifteen is a lower age floor than the equivalent status routes in Texas, Virginia and Washington, all of which use sixteen. The good-faith reliance protection names dentists and trained emergency health-care providers among those covered, so it is not confined to physicians.

Applies when

  • The minor is 15 or older, living separate and apart from a parent, and managing their own financial affairs
  • Or the minor has contracted a lawful marriage

Exceptions

  • Except as otherwise provided in §§ 15-19-204, 18-1.3-407(4.5) and 25-4-409
StatewideColo. Rev. Stat. § 13-22-103(1), (2)Minors 15 and older living apart and self-supporting, and married minorsVerified 2026-08-29

Payment liability

The parent, parents or legal guardian of a minor described in § 13-22-103(1) shall not be liable to pay the charges for care provided to the minor on that minor's consent, unless the parent, parents or legal guardian agrees to be so liable.

What this means operationally

Colorado uses an AGREEMENT test rather than California's or Maryland's participation test, which puts it alongside Massachusetts at the stricter end: a parent who drives the minor to the appointment, or who is the insurance subscriber, has not agreed to pay. The agreement has to be obtained, which makes it a front-desk step and not an inference from the demographic record.

Applies when

  • Care was provided on the consent of a minor described in § 13-22-103(1)

Exceptions

  • A parent or guardian who agrees to be liable is liable
StatewideColo. Rev. Stat. § 13-22-103(2), payment clauseMinors who consented under § 13-22-103(1)Verified 2026-08-29

Duty to keep an accurate record

For the purposes of § 25-1-802, MEDICAL INFORMATION TRANSMITTED DURING THE DELIVERY OF HEALTH CARE VIA TELEMEDICINE, as defined in § 12-240-104(10), IS PART OF THE PATIENT'S MEDICAL RECORD maintained by a health-care provider.

What this means operationally

This closes the gap a practice would otherwise argue: material generated in a telehealth encounter is not ancillary correspondence, it is the medical record, and every access, copying, format, timing and inspection-logging duty in the section reaches it. The practical consequence is about systems rather than policy — where a telemedicine platform holds session data outside the EHR, that data is still the record and must be retrievable and producible on the same clocks. A practice that cannot export from its telehealth vendor has a records problem, not a vendor problem.

Applies when

  • Health care is delivered via telemedicine as defined in § 12-240-104(10)
StatewideColo. Rev. Stat. § 25-1-802(5)Patients, personal representatives and authorized third-party requestersVerified 2026-08-30

Parental right of access

Every patient record in the custody of an enumerated licensed provider, EXCEPT records withheld in accordance with 45 C.F.R. 164.524(a), MUST BE AVAILABLE to the patient or the patient's personal representative UPON SUBMISSION OF A VALID AUTHORIZATION FOR INSPECTION OF RECORDS, DATED AND SIGNED BY THE PATIENT, at reasonable times and upon reasonable notice. A SUMMARY of records pertaining to a patient's MENTAL HEALTH PROBLEMS may, upon written request accompanied by a signed and dated authorization, be made available to the patient or personal representative FOLLOWING TERMINATION OF THE TREATMENT PROGRAM.

What this means operationally

Colorado requires a signed, dated authorization even for the patient inspecting their OWN record, which is unusual and is a real workflow difference from states where a patient's own request needs no form. Practices should hold a compliant inspection-authorization form rather than treating a verbal or emailed ask as sufficient. The mental-health limb is narrower than it looks twice over: what is available is a SUMMARY rather than the record, and it is available only AFTER the treatment program has terminated, so a patient in active treatment has no route to it under this section.

Applies when

  • A patient or personal representative submits a signed, dated authorization to inspect records held by an enumerated provider

Exceptions

  • Records withheld in accordance with 45 C.F.R. § 164.524(a)
  • Mental health records yield only a summary, and only after the treatment program terminates
StatewideColo. Rev. Stat. § 25-1-802(1)(a)Patients and patients' personal representativesVerified 2026-08-30

Duty to keep an accurate record

ALL REQUESTS by a patient or the patient's personal representative for inspection of their medical records SHALL BE NOTED WITH THE TIME AND DATE OF THE REQUEST AND THE TIME AND DATE OF INSPECTION by the health-care provider or the provider's designated representative. The patient or personal representative SHALL ACKNOWLEDGE THE INSPECTION BY DATING AND SIGNING THE RECORD FILE. A health-care provider SHALL NOT CHARGE A FEE FOR THE INSPECTION of medical records.

What this means operationally

This creates a record ABOUT the record, and it is the duty Colorado practices most often have no system for. Four data points must be captured — request time, request date, inspection time, inspection date — and the patient must physically sign the file to acknowledge having seen it. An electronic portal that logs a view but collects no signature does not satisfy the acknowledgment limb. Note the fee rule: inspection is free, which is distinct from copying, so a practice that charges a records-handling fee merely to let someone look at their chart is charging for something the statute forbids.

Applies when

  • A patient or personal representative requests inspection of their medical records
StatewideColo. Rev. Stat. § 25-1-802(4)Patients and patients' personal representativesVerified 2026-08-30

Parental right of access

A COPY of the records, INCLUDING RADIOGRAPHIC STUDIES, must be made available to the patient or personal representative upon request and payment of the fee A COVERED ENTITY MAY IMPOSE IN ACCORDANCE WITH HIPAA, or to a THIRD PERSON who requests the records upon submission of a HIPAA-compliant authorization, a valid subpoena, or a court order, and payment of reasonable fees. FOR A REQUEST NOT EXCEEDING SIX HUNDRED SIXTY-FOUR PAGES, the fees charged to a third person SHALL NOT EXCEED THE REASONABLE FEES.

What this means operationally

Colorado does not write its own per-page schedule for patient requests — it adopts the HIPAA covered-entity fee by reference, so the federal cost-based limit is the operative constraint and a practice tracking only state law will look in the wrong place. The six-hundred-and-sixty-four-page threshold is the hinge for third-party requests: at or below it, reasonable fees; above it, the separate attorney cap applies. That specific number is worth building into the billing workflow, because it is where the rule changes character.

Applies when

  • A patient, personal representative or authorized third person requests copies of records

Exceptions

  • Nothing requires disclosure of information privileged, confidential or protected from discovery or admission under state or federal law, including under §§ 12-30-204 and 25-3-109 or 42 U.S.C. § 1320c
StatewideColo. Rev. Stat. § 25-1-802(1)(b)(I)(A), (1)(e)Patients and patients' personal representativesVerified 2026-08-30

Deadline to respond to an access request

An INVOICE for all records provided in response to a request for medical records MUST BE PROVIDED TO THE REQUESTOR WITHIN THIRTY DAYS of receiving a valid request, and the records must be provided UPON PAYMENT of the invoice. If a health-care provider is UNABLE to provide access within thirty days, the provider MAY EXTEND the time frame by AN ADDITIONAL THIRTY DAYS, and MUST NOTIFY THE REQUESTOR IN WRITING of the extension WITHIN THE INITIAL THIRTY-DAY PERIOD. A RECORD NOT PROVIDED WITHIN THIRTY DAYS, OR WITHOUT WRITTEN NOTIFICATION OF A THIRTY-DAY EXTENSION, MUST BE PROVIDED TO THE REQUESTOR AT NO COST, absent an independent intervening FORCE MAJEURE that renders the requested records inaccessible, irretrievable or undeliverable within the required time frame. Where a force majeure event prevents compliance, the provider shall give WRITTEN NOTICE as soon as reasonably practicable but NOT LATER THAN FIVE BUSINESS DAYS after becoming aware of the event; the thirty-day period recommences upon RESOLUTION of the event; the provider shall notify the requestor within five business days after resolution; and all notices must be DELIVERED IN THE SAME FORMAT IN WHICH THE REQUEST WAS RECEIVED. Force majeure means a factor outside the parties' control that makes performance impossible or impracticable as a result of an event the parties could not have anticipated or controlled.

What this means operationally

The sanction is the point: miss thirty days without a written extension notice and the records become FREE. That converts a records backlog from an administrative annoyance into direct revenue loss, and it is self-executing rather than requiring a complaint. Two traps follow. The extension notice must go out INSIDE the first thirty days — a notice on day thirty-one preserves nothing — and it must be written. The force majeure route is real but tightly policed: notice within five business days of becoming aware, a fresh thirty days only from RESOLUTION, a second notice within five business days of resolution, and every notice delivered in the same format the request arrived in, so an emailed request cannot be answered by post.

Applies when

  • A valid request for medical records is received

Exceptions

  • An independent intervening force majeure event, with written notice within five business days of the provider becoming aware of it
StatewideColo. Rev. Stat. § 25-1-802(1)(d)(II), (III), (IV)Patients, personal representatives and authorized third-party requestersVerified 2026-08-30

Parental right of access

As used in § 25-1-802, PATIENT RECORD DOES NOT INCLUDE A DOCTOR'S OFFICE NOTES.

What this means operationally

A single sentence that removes a whole class of material from every access, copying, format and timing duty in the section. It is narrower than the federal psychotherapy-notes exclusion and differently drawn — it turns on the material being office notes rather than on a separately maintained psychotherapy record — and Colorado does not define the term further, so the boundary between a clinical entry and an office note is left to the practice. That ambiguity cuts both ways and should not be leaned on: a practice that classifies substantive clinical content as office notes to avoid disclosure is making a judgement no authority in this section supports.

Applies when

  • A request under § 25-1-802 would otherwise reach a doctor’s office notes
StatewideColo. Rev. Stat. § 25-1-802(3)Patients, personal representatives and authorized third-party requestersVerified 2026-08-30

Limit on copy fees, format or delivery

The health-care provider MUST provide the medical records IN ELECTRONIC FORMAT if the person requests electronic format, the ORIGINAL medical records ARE STORED IN ELECTRONIC FORMAT, and the medical records ARE READILY PRODUCIBLE in electronic format. The provider SHALL DELIVER the medical records in electronic format, upon request and payment of the fees, where those three conditions are met.

What this means operationally

Three conditions, all of which must hold, and the middle one is the one practices misread: the ORIGINAL must be stored electronically. A paper chart later scanned to satisfy a request is not an original stored in electronic format, so a practice with paper originals owes paper. Conversely a fully electronic practice cannot insist on printing. Readily producible refers to the system's actual capability, so a format the EHR genuinely cannot export is outside the duty — but inconvenience is not incapability.

Applies when

  • A requester asks for electronic format, the originals are stored electronically, and the records are readily producible in that format
StatewideColo. Rev. Stat. § 25-1-802(1)(b)(I)(B), (1)(d)(I)Patients and patients' personal representativesVerified 2026-08-30

Limit on copy fees, format or delivery

If a licensed health-care professional determines that a COPY of a radiographic study, including an X ray, mammogram, CT scan, MRI or other film, IS NOT SUFFICIENT for diagnostic or other treatment purposes, the enumerated practitioner SHALL MAKE THE ORIGINAL of any radiographic study AVAILABLE to the patient, the personal representative, a person authorized by the patient, or another health-care professional or facility as specifically directed, pursuant to a HIPAA-compliant authorization and upon payment of the reasonable fees. If a practitioner releases an original radiographic study, THE PRACTITIONER IS NOT RESPONSIBLE for any loss, damage or other consequences as a result of the release. Any original radiographic study made available MUST BE RETURNED UPON REQUEST TO THE LENDING PRACTITIONER WITHIN THIRTY DAYS.

What this means operationally

The trigger is a clinical judgement by a licensed professional that a copy will not do, which means the practice cannot be compelled to surrender originals on request alone. Two protections follow that are worth relying on: releasing the original carries no liability for loss or damage, and the original is RETURNABLE within thirty days of a request to return it. A practice lending films should log the loan and the return date, because the thirty-day clock is the only lever it has to get a diagnostic original back into a record it must still retain.

Applies when

  • A licensed health-care professional determines a copy of a radiographic study is insufficient for diagnostic or treatment purposes
StatewideColo. Rev. Stat. § 25-1-802(1)(b)(II)Patients and patients' personal representativesVerified 2026-08-30

Limit on copy fees, format or delivery

The TOTAL SUM of fees that a health-care provider may charge and collect for a record request made by AN ATTORNEY WHO REPRESENTS THE PATIENT, or the attorney of the patient's personal representative, pursuant to a HIPAA-compliant authorization, a valid subpoena or a valid court order, IF THE REQUESTED RECORD EXCEEDS SIX HUNDRED SIXTY-FOUR PAGES, MUST NOT EXCEED FOUR HUNDRED DOLLARS. That cap DOES NOT APPLY if a health-care provider is REQUIRED TO SEGREGATE, WITHHOLD OR REDACT protected health information from the requested record to comply with applicable law.

This changes on 2028-01-01

The figure in this proposition changes on 1 January 2028 and biennially after. The four-hundred-dollar amount is a floor as well as the current cap, so the rule never moves downward, but any published guidance quoting four hundred dollars will be stale from that date and the operative number will be the one the Secretary of State publishes rather than one stated in statute.

What this means operationally

A hard dollar ceiling, not a per-page rate, and it bites exactly where large-volume litigation requests do. Two boundaries decide whether it applies at all: the requester must be the patient's own attorney rather than any third party, and the record must exceed 664 pages — at or below that threshold the ordinary reasonable-fee rule governs instead. The redaction carve-out is the practical escape and it is narrower than it reads: it applies where segregation or redaction is REQUIRED by law, not where the practice chooses to review the file, so a routine privilege check does not lift the cap.

Applies when

  • An attorney representing the patient or the personal representative requests a record exceeding 664 pages under a HIPAA authorization, subpoena or court order

Exceptions

  • Does not apply where the provider is required by law to segregate, withhold or redact protected health information from the requested record
  • Does not apply to requests at or below 664 pages, which are governed by the reasonable-fee rule
StatewideColo. Rev. Stat. § 25-1-802(1)(b)(III), (1)(c)Patients, personal representatives and authorized third-party requestersVerified 2026-08-30

What applies to dental practices everywhere

Dental ePHI does not live in one system. It moves through the practice management system, digital imaging equipment, operatories, front-desk workstations, insurance transactions, laboratories, referral workflows, mobile devices, cloud backups, patient communication, and third-party support systems.

The practice management system and every user with administrative, clinical, scheduling, or billing access
Panoramic, CBCT, intraoral, and other imaging systems — including how images move between devices, workstations, laboratories, specialists, and storage
Electronic claims, eligibility verification, payment, and clearinghouse workflows
Patient portals, digital forms, e-fax, email, text messaging, appointment reminders, and referral tools
Office servers, workstations, laptops, tablets, phones, removable media, network equipment, and cloud backups
Every vendor that stores, maintains, transmits, or can remotely access the practice's ePHI
Full dentistscompliance guide →

Knowing the Colorado rule is not the same as meeting it.

The risk assessment asks what your practice actually does — which systems hold records, who reaches them, which vendors touch them — and reports against the obligations that apply to you, including the Colorado rules on this page.

Start the risk assessment