Guides · Practice compliance · 7 min read

The HIPAA Compliance Checklist for Dental Practices

By Dr. Sree Koka · 7 min read

A HIPAA-compliant dental practice can produce, on request: written privacy policies with a named privacy official, Business Associate Agreements for every vendor touching patient data, documented workforce training with signed acknowledgments kept six years, a current security risk analysis using tools like the free HHS assessment, encrypted devices with unique logins, and a written breach response plan naming who acts the same day.

HIPAA problems in dental offices rarely start with hackers. They start with a records request nobody knows how to handle, a laptop that walks away, or an investigator asking for a document nobody can find. This checklist organizes what a dental practice should have current and findable, in the order someone would actually ask. Run it once a year, the same week as your annual training. It is general information, not legal advice.

Paperwork: the documents that must exist

Written HIPAA privacy policies and procedures, adapted to your office rather than a binder from a seminar years ago.

A Notice of Privacy Practices that patients receive and that matches what your office actually does.

A named privacy official and a named security official. In most practices this is one person, and everyone should know who.

Business Associate Agreements with every vendor that touches patient information: your practice management software, cloud backup, billing service, IT company, and shredding vendor. Missing BAAs are among the most common findings in small-practice investigations.

Training: the records that prove it

HIPAA training for every workforce member, including part-time staff and new hires when they start, with retraining when your policies materially change.

Documentation of every session: date, content, attendees, and signed acknowledgments, kept at least six years.

Periodic security reminders through the year. A two-minute phishing warning at a team huddle counts, if you log it.

HIPAA documentation and how long to keep it
DocumentKeep for
Training records and acknowledgmentsAt least 6 years
Policies and procedures (each version)At least 6 years from last effective date
Security risk analysisCurrent, updated when systems change
Business Associate AgreementsAt least 6 years after termination

Safeguards: the Security Rule in a dental office

A written security risk analysis, updated when your systems change. This is the document investigators request most, and HHS publishes a free Security Risk Assessment tool sized for small practices.

Unique logins for every user, automatic screen locks, and encryption on laptops and phones that touch patient data. A lost encrypted laptop is an inconvenience; a lost unencrypted one is a reportable breach.

Access limited by role, ended promptly when someone leaves, and backups that someone has actually tested restoring.

Response: when something goes wrong

A written breach response plan naming who gets told the same day, who investigates, and who handles required notifications within the deadlines.

A simple internal habit: any team member who sees something off says so immediately, without fear. Speed and honesty are the difference between an incident and a disaster.

An annual run-through of this whole checklist, logged with a date. DentalReady's Compliance Pack, launching in September, covers the training rows automatically, with dated certificates and completion records for every team member.

Common questions

What are the most common HIPAA violations in dental offices?

Missing or outdated risk analyses, missing Business Associate Agreements with vendors, undocumented training, and improper disclosures through front desk conversations, texting, or social media.

Does a small dental practice really need a security risk analysis?

Yes. The Security Rule applies regardless of practice size, and the risk analysis is the document investigators request first. HHS offers a free assessment tool built for small practices.

Which vendors need a Business Associate Agreement?

Any vendor that creates, receives, stores, or transmits patient information for you: practice management software, cloud backup, billing services, IT support, and document shredding companies.

How often should we run this checklist?

Once a year, logged with a date, ideally the same week as annual training. Also rerun the risk analysis portion whenever your systems or software change.

The Compliance Pack launches in September. Ask about early access.

Handle the training rows automatically

Sources

Written by Dr. Sree Koka, Founder, DentalReady; Prosthodontist

Keep reading

OSHA Training Requirements for Dental Offices, ExplainedHIPAA Training Requirements for Dental Offices, ExplainedThe Dental Office Compliance Checklist: What to Have Ready Before Anyone Asks