1.Is my practice covered by HIPAA?
Dental practices are HIPAA covered entities if they transmit health information electronically in connection with a covered transaction — most commonly, submitting insurance claims electronically. In practice, this covers the overwhelming majority of US dental offices, from solo practitioners to multi-location groups. The obligations do not scale down for smaller practices: a three-operatory office and a large group practice face the same underlying rules, even though the risk surface and available resources differ.
2.The three HIPAA rules
HIPAA compliance for a covered entity breaks down into three rules:
- The Privacy Rule governs how protected health information (PHI) can be used and disclosed, requires a Notice of Privacy Practices for patients, and sets the "minimum necessary" standard — staff should only access the PHI required for their specific role.
- The Security Rule governs how electronic PHI (ePHI) must be technically protected, covering administrative, physical, and technical safeguards such as access controls, encryption, and audit logging.
- The Breach Notification Rule sets requirements for notifying affected patients, HHS, and in some cases the media, if unsecured PHI is breached.
3.Business Associate Agreements
Any vendor that creates, receives, maintains, or transmits PHI on your practice's behalf is a "business associate" under HIPAA, and needs a signed Business Associate Agreement (BAA) before they touch that data. For a typical dental practice, this list usually includes:
- Your practice management / clinical software provider
- Cloud hosting or database providers
- Billing and insurance clearinghouse services
- IT support and managed service providers
- Any AI-based diagnostic or imaging tool that touches patient data
Missing or outdated BAAs are one of the most common gaps OCR identifies during breach investigations, and an out-of-date BAA can trigger penalties even when the underlying vendor relationship is otherwise appropriate.
4.Technical safeguards checklist
At a practical level, the Security Rule's technical safeguards translate into a short list of controls every practice should have in place:
- Encryption of ePHI both in transit (e.g. TLS) and at rest (e.g. AES-256)
- Role-based access control, so staff only see the records relevant to their job
- An audit trail logging who accessed or changed which records, and when
- Multi-factor authentication for any system holding ePHI
- Regular, tested backups — ideally immutable, so they can't be altered or deleted by an attacker
- A documented, current Security Risk Analysis covering your practice management system, imaging, email, and every vendor with access to PHI
5.What's changing in 2025–2026
In January 2025, HHS issued a Notice of Proposed Rulemaking for a significant update to the HIPAA Security Rule. The proposed changes would remove the old distinction between "required" and "addressable" safeguards, making controls like multi-factor authentication, encryption, and annual penetration testing mandatory rather than optional for every covered entity, including dental practices.
Industry reporting on the exact finalization status of this update has been inconsistent through mid-2026, with some sources describing elements as finalized and others describing the rule as still pending. Rather than track the exact regulatory timeline here, the practical takeaway is straightforward: the direction of travel is clear, and practices that already have MFA, encryption, and a current Security Risk Analysis in place will be in a strong position regardless of the rule's exact final form. Confirm the current status directly with HHS.gov or a healthcare compliance professional before making compliance decisions based on the proposed rule.
6.Patient rights under HIPAA
Patients have several rights that your practice needs documented procedures for:
- The right to access their own records, generally within 30 days of a request
- The right to request amendments to their records
- The right to request restrictions on certain disclosures
- The right to receive an accounting of certain disclosures
7.Enforcement and penalties
HIPAA penalties follow a tiered structure based on the covered entity's level of culpability, ranging from unknowing violations to willful neglect, with per-violation penalties and annual caps that are periodically adjusted for inflation. OCR does not distinguish between a solo dentist and a large health system when it comes to obligations or enforcement — both are audited under the same framework. Because penalty amounts change periodically, check HHS.gov for the current fine schedule rather than relying on a fixed number.
8.How SmileCare supports compliance
SmileCare is built with HIPAA-aware security practices at every layer: data is encrypted in transit (TLS 1.3) and at rest (AES-256), access is controlled through role-based permission levels, and every action is written to a full audit trail. SmileCare is self-hosted on your own Supabase instance, so patient data never passes through a third-party server you don't control. See the US Compliance & Readiness page for the full breakdown of what's delivered out of the box.
Software alone doesn't make a practice compliant. HIPAA compliance also depends on your policies, staff training, signed BAAs with every vendor, and a current risk analysis — areas that are your practice's responsibility regardless of which software you use.
9.Practical starting checklist
- Confirm you have a current, documented Security Risk Analysis
- Verify every vendor touching PHI has a signed, up-to-date BAA
- Enable multi-factor authentication everywhere ePHI is accessible
- Confirm encryption is enabled both in transit and at rest
- Review your Notice of Privacy Practices for currency
- Confirm your backup strategy is tested and, ideally, immutable
- Schedule recurring staff training on PHI handling and security awareness
Not legal advice. This guide is for general informational purposes and reflects publicly available guidance as of September 2026. It is not a substitute for advice from a qualified healthcare compliance attorney or consultant familiar with your practice's specific circumstances.