Do dental offices really need HIPAA compliance software?
Yes. Dental offices are covered entities under HIPAA and face the same regulatory requirements as hospitals. OCR audits dental practices regularly, and fines for non-compliance range from $145 per violation at Tier 1 up to $2,190,294 per violation at the highest tier (2025 inflation-adjusted per 45 CFR §102.3). The average dental practice handles thousands of patient records containing ePHI — X-rays, treatment plans, insurance data, and clinical notes.
How does Patient Protect work with Dentrix and Eaglesoft?
Patient Protect manages the compliance layer around your practice management software — BAA tracking, access control documentation, risk assessments, and audit trails. It doesn't replace your PMS; it ensures your use of it is HIPAA compliant. BAA templates for major dental PMS vendors are included.
What's the biggest HIPAA risk for dental practices?
Unsecured patient communication. Staff texting patients from personal devices, emailing X-rays without encryption, and sharing treatment information through non-compliant channels. These violations are the most common findings in OCR dental practice audits.
How much does HIPAA compliance cost for a dental office?
Traditional compliance consultants charge $3,000–$8,000 per year for dental practices. Patient Protect starts at $39/month ($468/year) with no contracts and no setup fees — covering risk assessments, policies, BAA management, training, and ongoing monitoring.
Are dental X-rays and CBCT scans considered ePHI?
Yes. Any imaging that includes patient-identifying information is ePHI under HIPAA. DICOM headers contain extensive PHI by design — patient name, date of birth, accession number, study UID. Imaging stored on practice servers, transmitted to specialists, or backed up to cloud storage requires the same encryption, access-control, and BAA discipline as any other ePHI.
Do dental labs need a BAA?
It depends on what the lab actually does. A dental laboratory that fabricates a restoration to the dentist's prescription is generally receiving PHI to perform a service on the practice's behalf, which makes it a business associate under §160.103 and requires a written BAA before PHI flows. A laboratory acting as another treating provider is a different relationship, and HHS does not treat provider-to-provider treatment disclosures as business associate arrangements. Classify each lab by function, then paper the ones that qualify. The 'we just receive impressions' argument fails either way once case files carry patient-identifying metadata.
How long must we retain dental records under HIPAA?
HIPAA requires retention of policy and procedure documentation for six years (§164.530(j)). Patient record retention is governed by state dental practice acts, which typically require seven to ten years post-last-encounter, longer for minors. The practical retention floor is whichever is longest among HIPAA, state law, and the practice's malpractice insurer requirements.
Does a dental practice have to complete a HIPAA Security Risk Analysis?
Yes, and it has to reach further than the practice management system. Every covered practice must conduct and document an accurate, thorough assessment of the risks and vulnerabilities affecting all ePHI it creates, receives, maintains, or transmits. For a dental office that means Dentrix, Eaglesoft, or Open Dental plus the panoramic and CBCT units, intraoral scanners, the operatory and front-desk workstations, the claims clearinghouse, cloud backup, the patient portal, and every vendor with remote access. Practice size does not reduce the requirement. An analysis that covers only the PMS is not a completed SRA.
Which of our dental vendors need Business Associate Agreements?
Any organization that creates, receives, maintains, or transmits PHI on the practice's behalf — which for most dental offices means the practice management vendor, imaging software vendor, claims clearinghouse, cloud backup provider, IT support contractor, appointment-reminder service, and patient-communication platform. Dental laboratories require classification rather than assumption: a lab fabricating a restoration to your prescription is generally performing a service on your behalf and needs a BAA, while a laboratory acting as another treating provider is a different relationship that HHS does not treat as a business associate arrangement. Classify each relationship, then execute agreements before PHI flows.
Our operatory computers are shared — do hygienists really need individual logins?
Yes. The Security Rule requires a unique identifier for each user, and a shared operatory or front-desk login defeats it — not as a technicality, but because it removes the practice's ability to answer the only question that matters after an incident: who accessed this record. With one shared account, the audit log shows the operatory, not the person, and the practice cannot distinguish a hygienist checking a chart from a departed employee still using credentials nobody revoked. The common objection is workflow speed across operatories. The workable answer is individual accounts with fast switching and short auto-lock timeouts, set to a value your risk analysis supports rather than a number copied from another practice.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a dental practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.