HIPAA compliance for dental offices: what auditors actually check
Dental offices handle full health records, imaging, and payment data, usually on a handful of computers looked after by whoever is best with technology. That works day to day. It does not hold up when someone asks for your documents.
Free preview before you pay. Editable Word files. 14 day refund.
The five things auditors ask for first
- A written security risk analysis. Required by the HIPAA Security Rule. Not having one is itself a finding, before any breach happens.
- Written policies and procedures. Passwords, access, what happens when an employee leaves, how devices and x ray images are handled.
- Business associate agreements. Your practice management software, imaging vendor, IT person, cloud backup, reminder texting service, and billing service each need one.
- Workforce training records. Staff must be trained on handling patient information, and you must be able to prove it with dates and signatures.
- A current Notice of Privacy Practices. Posted in the office and on your website, given to every patient, with signed acknowledgments.
The gaps we see most in small dental offices
None of these are exotic problems. Every one can be found in an afternoon and fixed within a month, and the fix starts with written policies that describe what the office actually does.
- One shared login on the front desk computer.
- Imaging and sensor PCs running old operating systems because the vendor software needs them.
- Backups that have never been test restored.
- Treatment plans and x rays emailed without encryption.
- Appointment reminder and review request services with no signed BAA.
- A privacy notice last updated years ago.
Where to start
Start with the risk analysis and the policies, because every other document refers back to them. The kit generates a full set written for a dental practice: the treatment examples in your privacy notice mention referrals to oral surgeons and specialists, and the risk worksheet lists imaging PCs and reminder services as assets to review.
Questions
Does HIPAA apply to a small dental office?
If the practice bills insurance electronically, it is a covered entity under HIPAA, regardless of size. Most dental offices do.
Do dental offices need a BAA with their software vendor?
Yes. Any vendor that creates, receives, stores, or transmits patient information for the practice is a business associate and needs a signed agreement.
Full HIPAA Policy Kit, $129
- Notice of Privacy Practices, updated for the 2026 rules, plus the acknowledgment form
- 22 Privacy policies and procedures
- 19 Security policies mapped to the Security Rule
- Breach Notification policy with a risk assessment form and log
- Business Associate Agreement for your vendors
- Workforce confidentiality agreement, training log, and access checklist
- Security Risk Analysis worksheet, pre filled from your answers
- Patient request forms, plus a California addendum for California practices
More guides
- HIPAA compliance checklist for small medical practices in California
- The HIPAA security risk assessment, explained for small practices
- Notice of Privacy Practices template, updated for 2026
- HIPAA policies for chiropractic offices
- HIPAA policies for physical therapy practices
- HIPAA policies for mental health and behavioral health practices
- HIPAA policies for optometry practices
- HIPAA for med spas and aesthetics practices
- HIPAA policies and procedures for small medical practices
Templates, not legal advice. Eaglizer IT is not a law firm and does not certify HIPAA compliance. Using templates does not by itself make a practice compliant; follow the policies, train your staff, and keep records.