Guides · Practice compliance · 11 min
You just got a dental practice. Here is the compliance world, explained.
By Dr. Sree Koka · 11 min
A new dental practice owner faces five compliance systems: OSHA workplace safety, HIPAA privacy and security, state dental board rules, payer program requirements, and environmental rules like the EPA amalgam standard. Each expects specific written plans, dated training records, and logs. Build the Exposure Control Plan and staff training first, because those are the documents inspectors request first.
Nobody hands you a map with the keys. The seller's binder is years stale or missing, every vendor is suddenly selling you compliance something, and you half-remember a lecture about OSHA from dental school. Here is the actual shape of it: five systems, each with a short list of documents and dates. None of it is hard. All of it is specific. Owners get in trouble for missing paperwork far more often than for unsafe care. Still setting up? Start with the opening registration checklist first.
The five systems, and what each one actually wants
OSHA cares about your employees, not your patients. It wants a written Exposure Control Plan reviewed yearly, a Hazard Communication program with safety data sheets, annual bloodborne pathogens training with dated records, hepatitis B vaccination offered within 10 working days of an exposure-risk assignment, and a sharps injury log. Dental offices are rarely inspected at random. Inspections almost always start with a complaint, most often from a current or former employee.
HIPAA cares about patient information. The Office for Civil Rights expects a written Security Risk Analysis, privacy and security policies your team actually trains on, signed Business Associate Agreements with every vendor that touches patient data, and records requests answered within 30 days. That last one matters more than new owners expect: recent enforcement against dental practices has been mostly about mishandled records requests and social media replies, with settlements from $23,000 to $80,000.
Your state dental board cares about licenses and infection control. Sterilizer spore testing on a schedule with a log, waterline testing, staff credentials current, and X-ray equipment registered with the state radiation program. Board investigations are the most common kind a dentist faces, and they start with patient complaints.
Payers care about documentation behind claims. If you participate in Medicare, Medicaid, or CHIP, check what your program and plan contracts require: many state Medicaid programs and most managed care plan contracts call for fraud, waste, and abuse training, a written compliance program, and regular exclusion screening, and all of them expect records that support every claim.
The environment gets one big rule: if you place or remove amalgam, federal law requires an amalgam separator and a one-time compliance report to your local water authority, with maintenance records kept as long as you operate.
Who can actually show up at your door
It helps to know the cast before anyone knocks. Most practices go years without a visit. The point of the table is the last column: every inspection opens with a document request, and the documents are knowable in advance.
| Who | What brings them | What they ask for first |
|---|---|---|
| OSHA | An employee complaint or reported injury | Exposure Control Plan, training records, hepatitis B records |
| HHS Office for Civil Rights | A patient complaint or a reported breach | Security Risk Analysis, policies, training documentation |
| State dental board | A patient complaint; some states inspect routinely | Patient records, spore test logs, staff credentials |
| Payer auditors | Billing patterns that stand out | Charts, dated radiographs, clinical notes that support each claim |
| State radiation program | A scheduled registration cycle | Machine registration, operator credentials |
| Local water authority | Paperwork review | Amalgam separator compliance report and maintenance records |
Your first 90 days, in order
Do not try to do everything the first month. Build in the order inspectors ask.
First month: write or update the Exposure Control Plan and get every team member through bloodborne pathogens and HIPAA training with dated records. If the seller left training certificates, keep them, but do not rely on them. Records follow the person and the date, and you need proof the training happened under your ownership.
Second month: the Hazard Communication program with a chemical list and safety data sheets, your written HIPAA policies, and the Security Risk Analysis. The risk analysis is the one to take seriously: its absence is the most common finding when federal investigators look at a small practice.
Third month: the recurring machinery. Weekly spore tests with a log, waterline testing, monthly emergency equipment checks, Business Associate Agreements signed, and the amalgam separator report confirmed with your water authority if the previous owner never filed it. A change of ownership restarts that clock: new owners have 90 days to file.
After that, compliance stops being a project and becomes a calendar.
The calendar that keeps you covered
Weekly: spore test each sterilizer and log the result. A failed test means the sterilizer stops until it passes.
Monthly: emergency equipment check with initials, and exclusion screening if you bill federal programs.
Annually: every written plan reviewed and re-dated, every team member retrained on bloodborne pathogens as OSHA requires, HIPAA refreshed as good practice and whenever policies materially change, the Security Risk Analysis revisited, and the safer-device evaluation documented with input from the people who actually use the sharps.
At every hire: HIPAA and OSHA training before patient contact, hepatitis B vaccination offered within 10 working days of an exposure-risk assignment, a signed confidentiality agreement, and the state's radiography rules checked before they take an X-ray.
Put the calendar somewhere it nags you. The failure mode of practice compliance is never ignorance. It is a quiet month that becomes a quiet year.
The ten documents that answer almost every knock
Across every inspection type, the same records keep coming up: dated staff training logs, the Exposure Control Plan, the Hazard Communication program, the Security Risk Analysis, written HIPAA policies, spore test logs, waterline logs, hepatitis B vaccination and declination forms, Business Associate Agreements, and complete patient charts with diagnostic radiographs.
Nine of those ten live in one binder you control. Charts live in your practice management system. If you can put your hands on all ten inside five minutes, you are more prepared than most practices ever get, and a surprise inspection becomes an inconvenient afternoon instead of a citation.
Common questions
Does a new practice owner inherit the seller's compliance records?
Keep whatever the seller left, but responsibility restarts with you. Training records must show your team trained under your ownership, plans need review under your name, and the amalgam separator report must be refiled within 90 days of an ownership transfer.
How likely is a small dental practice to be inspected?
Random inspection is rare. Federal OSHA inspected roughly 20 dental offices in a recent year, almost all after employee complaints. Board investigations from patient complaints are the most common. Low odds are not the point: every channel opens with a document request you can prepare for.
What gets dental practices fined most often?
Missing paperwork, not unsafe care. OSHA citations cluster around missing or stale Exposure Control Plans and training records. Federal HIPAA actions against dental practices have mostly involved mishandled patient records requests and social media replies, with settlements from $23,000 to $80,000.
Do I need a compliance consultant for a new practice?
Usually not for the documents themselves, since regulators publish model plans you can adapt. A consultant earns their fee for unusual situations: sedation permits, a pending investigation, or multi-state operations. For a standard practice, discipline beats spend.
How long do compliance records need to be kept?
Training records three years, HIPAA documentation six years, sharps injury logs five years, employee medical records including vaccination status for employment plus 30 years, and patient charts per your state dental board rule, commonly seven years and longer for minors.
Training, written plans, and the inspection binder in one place. The Compliance Pack launches in September. Ask about early access.
See how DentalReady handles thisSources
- OSHA Bloodborne Pathogens Standard, 29 CFR 1910.1030, checked August 18, 2026
- HHS Security Risk Analysis requirement, 45 CFR 164.308, checked August 18, 2026
- HHS HIPAA Resolution Agreements and enforcement actions, checked August 18, 2026
- EPA Dental Effluent Guidelines, 40 CFR Part 441, checked August 18, 2026
- CDC Infection Prevention and Control in Dental Settings, checked August 18, 2026
- OSHA inspection and complaint handling, checked August 18, 2026
Written by Dr. Sree Koka, Founder, DentalReady; Prosthodontist
Keep reading
Opening a dental practice: the registration checklist nobody hands youThe Dental Office Compliance Checklist: What to Have Ready Before Anyone AsksThe HIPAA Compliance Checklist for Dental Practices