Industry

HIPAA compliance for dental practices

Imaging systems, third-party billing, and practice management software that all touch ePHI — usually with shared logins.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Imaging systems, third-party billing, and practice management software that all touch ePHI — usually with shared logins.

What usually goes wrong

  • Shared operatory logins with no individual accountability
  • Imaging and CAD/CAM systems outside IT’s inventory
  • Outsourced billing companies without current BAAs
  • Patient communication over unsecured SMS

What SuperHIPAA does about it

  • Unique-user access control rollout with practical operatory workflows
  • Imaging and PMS asset inventory templates
  • BAA cleanup for billing, labs, and IT vendors
  • Patient communication policy that staff will actually follow

Your obligations in one paragraph

As a covered entity, you must conduct an accurate and thorough risk analysis, implement the required Security Rule specifications (and either implement or document a rationale for each addressable one), maintain policies and procedures, train your workforce, execute business associate agreements with everyone who touches ePHI on your behalf, and be able to detect, assess, and report breaches. All of it must be evidenced. None of it is a one-time project.

Where most dental practices actually stand

The pattern we see in this vertical: policies exist, training happens sporadically, BAAs are partially in place, and the risk analysis is either missing or several years stale. That last one is the finding that turns an incident into a penalty, because it is the first document OCR requests.

Getting started

  1. Free readiness assessment — scored report, no call required
  2. Gap assessment — if the score shows real exposure
  3. Implementation — we fix it with you, or hand your team the plan
  4. Platform — keeps it true after we leave

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Are dental practices covered entities or business associates?

Typically **Covered Entity**. It matters because it changes which obligations are yours directly and which flow through a BAA. The readiness assessment determines your scope in the first three questions.

How long does it take to get compliant?

For an organisation starting from near zero, 8–12 weeks to a defensible position: risk analysis complete, required safeguards implemented, policies live, workforce trained. Anyone promising two weeks is selling you a certificate.

What does it cost?

Platform starts at a published monthly price — see pricing. Services are fixed-fee. There is no 'contact us for a quote' wall on this site.

Do you replace our IT provider?

No. We tell your IT provider exactly what to configure and then verify they did it.

Are X-rays and intraoral photos PHI?

Yes — panoramics, CBCT scans, and clinical photos are all PHI. Sending them to specialists, labs, or insurers requires encrypted transmission or another protected channel, not a plain email attachment.

Which of our vendors actually need a BAA?

Your practice management software, offsite backup, billing service, IT provider, and shredding vendor do. A case sent to a dental lab fabricating a crown is generally a treatment disclosure, so the exposure is usually in the software and service vendors, not the lab bench.

Is conversation overheard at the front desk a violation?

Incidental disclosures are permitted if reasonable safeguards exist — lowered voices, positioned monitors, spacing at check-in. Document those safeguards and an overheard name is defensible rather than reportable.

We still keep paper charts. Does HIPAA apply to those?

Yes. Paper PHI falls under the §164.310 physical safeguards — locked storage, chart tracking, and destruction that renders records unreadable. Hybrid paper-and-digital practices need both sides covered in the risk analysis.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo