Category: HIPAA & Dental Practices

  • Does HIPAA Apply to Dental Practices? What You Must Know

    A dangerous misconception persists within the oral healthcare community: many dental practices believe they are flying beneath the regulatory radar of federal investigators. Because dental offices rarely handle large-scale, inpatient medical care, practitioners frequently assume that HIPAA compliance is a burden reserved exclusively for large hospitals and medical groups.

    This assumption is entirely false.

    The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) actively regulates and enforces HIPAA compliance across all dental specialtiesโ€”including general dentistry, orthodontics, periodontics, and oral surgery. If your practice transmits even one standard transaction electronically, such as submitting a digital dental insurance claim or checking patient eligibility online, you are legally classified as a Covered Entity.

    Treating HIPAA compliance as an afterthought doesnโ€™t keep you under the radarโ€”it makes your practice a prime target for severe financial penalties.

    High-Risk Vulnerabilities Unique to Dental Offices

    While dental practices share many general compliance burdens with standard medical practices, certain operational habits place dental offices at an elevated risk for data breaches and OCR scrutiny.

    1. Unencrypted Communication with Specialists

    Dental practitioners frequently collaborate with external oral surgeons, labs, and endodontists. Sending patient X-rays, treatment plans, or clinical notes via standard, unencrypted email or text messages (like iMessage or WhatsApp) is an immediate HIPAA Security Rule violation. All peer-to-peer digital sharing must utilize a secure, encrypted portal or encrypted email solution.

    2. Exposed Operatory Screens

    The physical layout of a modern dental operatory often places computer monitors right next to the patient chair. If a monitor displays a previous patientโ€™s digital charting, panoramic X-rays, or scheduling data while another patient is walking in or sitting in the chair, it constitutes an unauthorized disclosure of Protected Health Information (PHI).

    3. Missing Business Associate Agreements (BAAs)

    Dental practices rely heavily on specialized third-party vendors, including dental practice management software (e.g., Dentrix, Eaglesoft), IT support providers, and digital imaging cloud services. If these vendors touch, store, or transmit your patient data and you do not have a signed Business Associate Agreement (BAA) on file, your practice is operating in direct non-compliance.

    Actionable Safeguards for a Defensible Dental Practice

    To transition your office from vulnerable to audit-ready, you must implement three foundational physical, administrative, and technical controls immediately:

    • Install Monitor Privacy Filters: Equip all operatory and front-desk computer screens with physical privacy filters. This ensures that data is only visible to the staff member standing directly in front of the screen, eliminating accidental visual disclosure to patients in adjacent spaces.
    • Execute Comprehensive Risk Analyses: HIPAA mandates that every covered entity perform a formal, documented Security Risk Analysis (SRA). You cannot protect your network if you have not actively mapped out where your patient data is stored, backed up, and transmitted.
    • Train Dental Staff Annually: From dental hygienists to front-office schedulers, your entire workforce must undergo documented HIPAA training. A significant percentage of dental data breaches result from simple employee mistakes, such as clicking a phishing link or releasing records to the wrong family member.

    Defend Your Practice

    Operating a busy dental practice requires balancing patient care with strict administrative oversight. Ignoring regulatory obligations because you run a smaller clinic is no longer a viable operational strategy. The OCR does not grant exemptions based on practice size.

    Are your digital charting workflows, employee training logs, and IT vendor contracts fully audit-ready? Colington Consulting provides tailored, evidence-based compliance programs specifically designed to protect dental offices from operational liability and costly federal penalties.

    Schedule a 30-Minute HIPAA Risk Review and protect your dental practice.

    • Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: U.S. Department of Health and Human Services (HHS) Enforcement Data; HIPAA Security Rule (45 CFR Part 160 and Part 164, Subparts A and C).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Indiana Dentist Fined by State for HIPAA Violations

    by Jay Hodes, President – Colington Consulting

    According to an article published in the Kokomo (Indiana) Tribune, a former Kokomo dentist, Joseph Beck, โ€œagreed to pay the state $12,000 for disposing of patient files in an Indianapolis dumpster, the Attorney Generalโ€™s Office (recently) reported. The Attorney Generalโ€™s Office sued Beck for failing to protect personal information and for improperly disposing of records containing personal information of Indiana residents, which violates state privacy laws as well as the federal Health Insurance Portability and Accountability Act (HIPAA).โ€

    What is significant is, โ€œThis is the first time Indiana has sued for a violation of HIPAA.โ€ The article went on to say, โ€œMore than 60 boxes of patient records from Beckโ€™s former Comfort Dental clinic in Kokomo were found discarded in an Indianapolis dumpster in March of 2013. The files contained records from 2002-2007.โ€ Not only are the Feds involved with compliance oversight, but now the states have an active interest, especially when civil monetary penalties can be imposed. States may view this as a way to step up their game when it comes to conducting audits, investigations and prosecutions for HIPAA compliance. With more and more data breaches occurring, it makes perfect sense for this course of action.

    The Office for Civil Rights (OCR), which enforces Federal regulations and compliance for HIPAA, has been conducting training for State Attorneys General (AGs). OCR developed HIPAA enforcement training to state AGs and their staff on how to use this authority to enforce the HIPAA Privacy and Security Rules. The training course provides assistance on how to investigate HIPAA violations. But more importantly, the training shows AGs how to seek civil damages for HIPAA violations that affect residents of their respective states.

    With this recent case in Indiana, the dentist โ€œhired a private company, Just the Connection, Inc. to retrieve and dispose of his patient records, which included names, medical records, phone numbers, birth dates, Social Security numbers, insurance cards, insurance information and state ID numbers.โ€ It is unclear if Beck had a Business Associate Agreement (BAA) in place with the private company to properly dispose of the records. The BAA would have been required in this case.

    As a covered entity, this story reinforces the need not only to have a BAA in place with any vendor who is accessing your protected health information, but also make sure your own HIPAA policies and procedures cover proper record disposal. Any BAA must require that a business implement the proper safeguards to prevent unauthorized use or disclosure of protected health information (PHI) not only for electronic records, but also for any paper records or charts. This is especially critical for the document destruction process for PHI.

    Although smaller state civil settlements are not on par with the millions OCR seeks during a resolution agreement, it does allow the states to become more engaged in investigating these types of breaches. Just more one reason to be HIPAA compliant.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.