Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA compliance for dental practices in Ohio

Ohio's general breach-notification statute excludes HIPAA covered entities outright, so for covered dental practices the federal rules govern and the state statute adds no separate notification duty. Patient Protect has not recorded any Ohio rule that applies to dental practices differently from other providers in the state — the statewide rules below are the ones that reach you.

Ohio jurisdiction record verified against primary state authority August 2026. General reference, not legal advice.

Does this reach your practice?

Two questions have to be settled before any state rule matters: whether HIPAA reaches a practice like yours, and whether Ohio's own law reaches a practice that HIPAA already covers.

Federal — is this practice a covered entity

Dental practices that electronically submit claims, check eligibility, request authorization, or have a billing service conduct those standard transactions on their behalf are HIPAA covered entities. Most modern dental practices meet that definition. Once covered, the duties below are required.

State — how Ohio law interacts with HIPAA

Ohio's general breach-notification statute expressly excludes HIPAA covered entities from its scope. For dental practices that qualify as covered entities under 45 CFR §160.103, the federal rules govern and the state statute below adds no separate notification duty.

Covered-entity exclusion. Ohio Rev. Code § 1349.19(F)(2) provides that '[t]his section does not apply to any person or entity that is a covered entity as defined in 45 C.F.R. 160.103.' HIPAA covered entities operating in Ohio are excluded from § 1349.19 — no residual state-law breach-notification obligation runs alongside HIPAA for CEs. Business associates are NOT expressly included in the (F)(2) exclusion and require separate analysis — a BA should independently evaluate whether it qualifies as a covered entity under 45 C.F.R. 160.103 (which enumerates health plans, healthcare clearinghouses, and qualifying healthcare providers as covered entities and separately defines business associate) or whether some other Ohio provision applies to it. Financial institutions, trust companies, and credit unions subject to and complying with their functional federal regulator's requirements are also excluded from § 1349.19 under (F)(1).

What Ohio adds for dental practices specifically

Rules that exist because of the combination — not federal HIPAA, which applies the same way everywhere, and not Ohio's general breach law, which applies the same way to every business in the state.

No verified intersection rules recorded

Patient Protect has not recorded any Ohio rule that applies to dental practices differently from any other practice in the state. Where that is the case, the federal obligations and the Ohio rules below are the whole picture, and the dentists guidance that applies nationally is the better starting point.

HIPAA compliance for dental practices

Ohio breach obligations

These apply to businesses generally rather than to dental practices in particular, and they are shown after applicability because whether they reach you depends on the answer above.

Ohiobreach data →

Individual notice deadline

In the most expedient time possible but not later than forty-five days following discovery or notification of the breach, subject to law-enforcement delay and any measures reasonably necessary to determine the scope of the breach, ascertain the identity of affected residents, and restore the reasonable integrity of the data system.

The statute sets a 45-day outer bound. It is shown for context: a HIPAA covered entity is outside this section, so HIPAA's own 60-day individual-notice window is the operative deadline.

State regulator notice

Not required

None for HIPAA-covered entities (they are excluded from the section entirely — see the HIPAA-interaction note below). For entities subject to § 1349.19, the section does not impose an Attorney General notice obligation.

Source: Ohio Rev. Code § 1349.19(B)(2)

Statewide rules that also reach dental practices

Parental right of access

A patient, a patient's personal representative, or an authorized person who wishes to examine or obtain a copy of part or all of a medical record SHALL SUBMIT TO THE HEALTH CARE PROVIDER A WRITTEN REQUEST SIGNED by the requester and DATED NOT MORE THAN ONE YEAR BEFORE THE DATE ON WHICH IT IS SUBMITTED. The request SHALL INDICATE WHETHER THE COPY IS TO BE SENT to the requester, sent to a physician, advanced practice registered nurse or chiropractor, or HELD FOR THE REQUESTER at the office of the health care provider. WITHIN A REASONABLE TIME after receiving a request that meets those requirements and includes sufficient information to identify the record, a health care provider that has the patient's medical records SHALL PERMIT THE PATIENT TO EXAMINE THE RECORD DURING REGULAR BUSINESS HOURS WITHOUT CHARGE or, on request, shall provide a copy in accordance with § 3701.741. If a health care provider FAILS TO FURNISH a medical record as required, the requester MAY BRING A CIVIL ACTION to enforce the patient's right of access.

What this means operationally

Two conditions sit on the REQUEST rather than the practice, and both are enforceable gatekeeping. The request must be signed, and it must be DATED NOT MORE THAN ONE YEAR before submission — a staleness rule that lets a practice decline an old authorization without inventing a policy. It must also state the destination, which is why a bare 'send me my records' note is incomplete under Ohio law. On the practice's side, in-person EXAMINATION is free and must be available in regular business hours; only copying attracts a fee. Note what Ohio does not give: no day count. The standard is a reasonable time, and the sanction is a private civil action rather than board discipline.

Applies when

  • A patient, personal representative or authorized person submits a signed written request dated within the past year, identifying the record and stating where the copy should go

Exceptions

  • Does not apply to records covered by Ohio Rev. Code §§ 173.20 or 3721.13, chapters 1347, 5119 or 5122, 42 C.F.R. part 2 (alcohol and drug abuse patient records), or 42 C.F.R. § 483.10
  • Does not supersede the peer-review confidentiality provisions at §§ 2305.24, 2305.25, 2305.251 and 2305.252
StatewideOhio Rev. Code § 3701.74(B), (C), (D)Patients, personal representatives and authorized personsVerified 2026-08-30

Limit on copy fees, format or delivery

Where the request is made by the PATIENT, the patient's personal representative, or an individual authorized through a valid power of attorney, TOTAL COSTS for copies and all related services SHALL BE REASONABLE, COST-BASED AMOUNTS PERMITTED TO BE CHARGED TO THE PATIENT UNDER FEDERAL LAWS AND REGULATIONS, and any per-page charges SHALL NOT EXCEED the sums authorized for third-party requests. If the request by such a person is for ACCESS TO DIGITAL RECORDS OR ELECTRONICALLY TRANSMITTED RECORDS, the TOTAL COST for that access or transmission, AND ALL RELATED SERVICES, SHALL NOT EXCEED FIFTY DOLLARS.

What this means operationally

The fifty-dollar cap is the number to build the workflow around: it is a TOTAL, covering access, transmission and every related service, and it applies regardless of how large the record is. For any substantial chart electronic delivery is therefore dramatically cheaper for the requester than paper, and a practice that defaults to printing is charging more than it needs to defend. For non-digital patient requests Ohio does not write its own figure at all — it adopts the federal cost-based limit by reference and then caps per-page charges at the third-party schedule, so the federal rules are the operative constraint and the state schedule is only a ceiling.

Applies when

  • A patient, personal representative or power-of-attorney holder requests copies of a medical record
StatewideOhio Rev. Code § 3701.741(B)(1)Patients, personal representatives and authorized personsVerified 2026-08-30

Limit on copy fees, format or delivery

Where the request is made by ANYONE OTHER THAN the patient, personal representative or power-of-attorney holder, total costs for copies and all related services SHALL NOT EXCEED the sum of: AN INITIAL FEE OF SIXTEEN DOLLARS AND EIGHTY-FOUR CENTS, adjusted in accordance with § 3701.742, WHICH SHALL COMPENSATE FOR THE RECORDS SEARCH; for data recorded on paper or electronically, ONE DOLLAR AND ELEVEN CENTS PER PAGE FOR THE FIRST TEN PAGES, FIFTY-SEVEN CENTS PER PAGE FOR PAGES ELEVEN THROUGH FIFTY, and TWENTY-THREE CENTS PER PAGE FOR PAGES FIFTY-ONE AND HIGHER, each adjusted under § 3701.742; for data resulting from an X-RAY, MRI OR CAT SCAN recorded on paper or film, ONE DOLLAR AND EIGHTY-SEVEN CENTS PER PAGE; and THE ACTUAL COST OF ANY RELATED POSTAGE. Every charge in this schedule applies to MEDICAL RECORDS COMPANIES as well as to health care providers.

What this means operationally

Ohio is unusual in letting the practice recover a SEARCH fee at all — most cost-based regimes exclude retrieval time — and it is a flat initial charge rather than an hourly one. The per-page rate is steeply degressive, so the marginal cost of a long record is low and the fixed component dominates a short one. Two structural points matter more than the figures. All of them are INFLATION-ADJUSTED under § 3701.742, so any quoted amount needs a date beside it. And the schedule expressly binds MEDICAL RECORDS COMPANIES, the third-party firms practices outsource copying to, which prevents a practice from routing around the cap through a vendor.

Applies when

  • A third party such as an attorney or insurer requests copies of a medical record from a provider or a medical records company

Exceptions

  • One free copy, and one copy of subsequently created records, must be provided without charge to the Bureau of Workers’ Compensation and the other recipients § 3701.741(C) names
StatewideOhio Rev. Code § 3701.741(A), (B)(2)Patients, personal representatives and authorized personsVerified 2026-08-30

What applies to dental practices everywhere

Dental ePHI does not live in one system. It moves through the practice management system, digital imaging equipment, operatories, front-desk workstations, insurance transactions, laboratories, referral workflows, mobile devices, cloud backups, patient communication, and third-party support systems.

The practice management system and every user with administrative, clinical, scheduling, or billing access
Panoramic, CBCT, intraoral, and other imaging systems — including how images move between devices, workstations, laboratories, specialists, and storage
Electronic claims, eligibility verification, payment, and clearinghouse workflows
Patient portals, digital forms, e-fax, email, text messaging, appointment reminders, and referral tools
Office servers, workstations, laptops, tablets, phones, removable media, network equipment, and cloud backups
Every vendor that stores, maintains, transmits, or can remotely access the practice's ePHI
Full dentistscompliance guide →

Federal obligations still have to be evidenced for dental practices in Ohio.

The risk assessment asks what your practice actually does — which systems hold records, who reaches them, which vendors touch them — and reports against the obligations that apply to you, including the Ohio rules on this page.

Start the risk assessment