HIPAA for dental offices, in plain English
Covered entity, ePHI, Security Rule still in force. The 2026 NPP deadline was real. The Security Rule rewrite is not in effect.
Journal · Legal, Plain English · F·01 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida
Short answer: Most dental practices are HIPAA covered entities. HIPAA has three core rules: Privacy (how PHI is used and disclosed), Security (how ePHI is protected) and Breach Notification. Practices must designate responsible people, conduct a risk analysis, train staff, sign BAAs, give patients a Notice of Privacy Practices and document it all. As of late 2026, the proposed Security Rule rewrite is not in effect.
At a glance
| Who is covered | Dental practices that conduct standard electronic transactions (for example, electronic insurance claims) |
| Three core rules | Privacy, Security, Breach Notification |
| Core duties | Risk analysis, policies, training, BAAs, NPP, patient rights, incident response |
| Documentation | Generally retained for six years |
| 2026 status | NPP update deadline of Feb 16, 2026 passed; Security Rule overhaul still proposed |
General information, not legal advice. Consult qualified counsel about your specific obligations.
Is my dental practice covered by HIPAA?
Most are. HIPAA applies to covered entities: health care providers who transmit health information electronically in connection with standard transactions (such as submitting insurance claims electronically), plus health plans and clearinghouses. A dental practice that bills insurance electronically is a covered entity. Vendors that handle PHI on a practice's behalf are business associates, which is where your MSP, backup provider and cloud PMS come in. See Business associate agreements for dental practices.
What are the three rules that matter most?
- The Privacy Rule governs how PHI may be used and disclosed, patients' rights (including access to their records, generally within 30 days), the minimum-necessary standard and the Notice of Privacy Practices (NPP).
- The Security Rule requires administrative, physical and technical safeguards for electronic PHI: risk analysis, access controls, audit controls, transmission security, contingency planning and more. This is where IT lives.
- The Breach Notification Rule requires notifying affected individuals, HHS and sometimes the media after a breach of unsecured PHI, within set timeframes. See Florida data-breach notification for dental practices.
What must a dental practice actually do?
- Designate a Privacy Officer and a Security Officer.
- Conduct a risk analysis and act on it. See Risk analysis vs risk management.
- Write and follow policies for access, devices, email, disposal, incident response and contingency planning.
- Train the workforce on hire and periodically.
- Sign BAAs with vendors who can access PHI.
- Provide an NPP and honor patient rights.
- Use technical safeguards: unique user IDs, MFA, encryption, audit logs, backups, endpoint security. See MFA for dental practices and Cloud backup that is actually HIPAA-shaped.
- Document everything, generally retaining required documentation for six years.
What is flexible and what is not?
The Security Rule is scalable: "addressable" implementation specifications must be implemented if reasonable and appropriate, or an equivalent measure documented. "Addressable" does not mean optional. And the practice's size changes the controls, not the duty.
What are dental-specific HIPAA pitfalls?
- X-rays and records sent by regular email or text.
- Sign-in sheets and chart visibility at the front desk.
- Responding to online reviews in a way that discloses patient information.
- Shared logins and passwords on sticky notes.
- No BAA with the IT provider, backup vendor or answering service.
- A risk analysis from years ago, or none at all.
What changed in 2026?
Two things get conflated and should not be. The Notice of Privacy Practices update tied to the 2024 rule aligning HIPAA with 42 CFR Part 2 had a February 16, 2026 compliance date, which has passed. The HIPAA Security Rule rewrite, proposed in January 2025, is not final; HHS's agenda points to July 2027 for final action, and the current Security Rule remains in force and enforced. See NPP 2026 vs the Security Rule NPRM.
What are the penalties?
Civil penalties are tiered by culpability and adjusted annually for inflation, and state attorneys general can also act. See HIPAA penalties in plain English.
Frequently asked questions
Does HIPAA apply to my small dental practice?
Yes, if you transmit health information electronically in connection with standard transactions such as electronic insurance claims. Size does not exempt a practice.
What is the HIPAA Security Rule?
A federal rule requiring administrative, physical and technical safeguards to protect electronic PHI, including risk analysis, access controls, audit controls, transmission security and contingency planning.
Is the new HIPAA Security Rule in effect?
No. The Security Rule update proposed in January 2025 is not final as of late 2026. The current Security Rule remains in effect and is enforced.
How long must HIPAA documentation be kept?
Generally six years from creation or last effective date, whichever is later. Confirm specific retention rules, including state requirements, with counsel.
Sources and further reading
Related in the Journal
- NPP 2026 vs the Security Rule NPRM — two different clocks
- Business associate agreements for dental practices
- Risk analysis vs risk management for dental IT
- HIPAA penalties in plain English — tiers, caps, and caution
About CyberDental
CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.
- HelpDesk: (954) 639-7049
- Email: support@cyberdental.co
- Address: 480 W 84th Street, Suite B106, Hialeah, FL 33014
- Website: cyberdentalgroup.com