← Back to Blog

HIPAA Compliance Is More Than Keeping Patient Information Private

August 15, 2026 · Brian Groot

Ask someone in a dental practice what HIPAA compliance means and you will probably hear some familiar answers.

Do not discuss patients where other people can hear you. Keep charts secure. Do not leave patient information sitting on the front desk. Be careful about what gets emailed. Make sure employees understand that patient information is private.

All of those things matter.

But HIPAA compliance includes considerably more than simply being careful with patient information. Some of its requirements are surprisingly specific, and a small practice can easily overlook them because nobody is likely to walk into the office on Tuesday morning asking to see the HIPAA binder.

For example, every covered entity must designate a privacy official responsible for developing and implementing its privacy policies and procedures. The HIPAA Security Rule separately requires an assigned security official responsible for its security policies and procedures. In a small practice, these do not have to be full-time positions. An office manager or another employee can perform these roles along with other duties. The important part is that responsibility has actually been assigned.

That is only one of several requirements that can quietly disappear into the daily operation of a busy practice.

Some of the less obvious HIPAA requirements

One of the most important is a formal security risk analysis.

The HIPAA Security Rule requires organizations that handle electronic protected health information, or ePHI, to conduct an accurate and thorough assessment of potential risks and vulnerabilities to that information. The practice then has to manage the risks it identifies. This is not simply installing antivirus software or asking an IT company whether the computers are secure. The practice itself needs to understand where its patient information exists, how it moves, who can access it, what could reasonably go wrong, and what protections are in place.

That can include information stored in an EHR, imaging systems, laptops, email, cloud services, backups, billing systems and other technology used by the practice.

The government has been emphasizing this requirement in enforcement actions. In July 2026, for example, HHS announced another ransomware settlement and specifically called an accurate and thorough HIPAA risk analysis both a legal requirement and an important part of preventing or limiting cyberattacks.

A few other requirements can be just as easy to overlook:

  • Written policies and procedures. HIPAA requires covered entities to develop and implement privacy policies and reasonable security policies appropriate to their organization.

  • Workforce training. Employees need to be trained on the policies that apply to their jobs. Training new employees matters, but so does training when policies materially change.

  • A complaint process. Patients need a way to complain about privacy practices, and complaints and their disposition must be documented.

  • A sanctions policy. A practice must have appropriate consequences for workforce members who violate its HIPAA policies, and sanctions that are actually applied must be documented.

  • Business associate agreements. Vendors that create, receive, maintain or transmit protected health information on behalf of the practice generally require appropriate written agreements.

  • Security incident procedures and contingency planning. Practices need procedures for responding to security incidents and plans for backing up information, restoring it and maintaining critical operations during an emergency.

  • Documentation. Many HIPAA-required policies, procedures, designations and other compliance records must be retained for six years.

That six-year requirement is another good example of a rule that is easily misunderstood. It applies to HIPAA compliance documentation. HIPAA itself does not establish a universal six-year retention period for every patient's dental or medical record.

Your vendors matter too

Modern dental practices depend on an increasingly large collection of outside services.

There may be an EHR vendor, cloud hosting company, billing service, IT support provider, accountant, consultant or software company with some level of access to patient information.

When a vendor performs services for a practice that involve creating, receiving, maintaining or transmitting protected health information, that vendor may be a HIPAA business associate. The covered entity generally needs a written Business Associate Agreement, commonly called a BAA, establishing how that information can be used and how it must be protected.

Simply buying software does not automatically make the software company a business associate. But if the vendor hosts patient data or can access it while providing support, the relationship can change. HHS specifically identifies software and IT vendors with access to PHI as examples of business associates.

Cloud services are another potential trap. Even a cloud provider storing encrypted ePHI can be a business associate under HIPAA, and an appropriate BAA may be required.

That makes maintaining an accurate vendor list a useful part of the compliance process. The question is not merely, "Who handles our patient records?" It is, "Who outside this practice can create, receive, maintain or transmit PHI while doing work for us?"

Patients have rights that create operational requirements

HIPAA is not only about preventing disclosure. It also gives patients specific rights concerning their information.

Patients generally have a right to inspect or obtain copies of health information in a designated record set. A covered entity normally must act on an access request within 30 calendar days. If more time is legitimately needed, only one additional 30-day extension is allowed, and the patient must be notified in writing during the original 30-day period.

Practices must also provide a Notice of Privacy Practices explaining, among other things, how information can be used, the patient's rights, the practice's responsibilities and how a patient can file a complaint. Practices with applicable websites must prominently post and make the notice available there.

There is also the "minimum necessary" standard. When it applies, employees should have access only to the amount of protected information reasonably necessary to perform their jobs. That makes access control an operational issue, not just an IT issue. A new employee may need access. Someone changing jobs may need different access. Someone leaving the practice should no longer have it.

What happens if information is breached?

HIPAA also requires practices to know what happens after something goes wrong.

A lost device, compromised email account, ransomware attack or inappropriate disclosure does not simply become an IT problem.

A covered entity must evaluate an impermissible use or disclosure to determine whether it constitutes a reportable breach. When notification is required, affected individuals generally must be notified without unreasonable delay and no later than 60 days after discovery.

Breaches involving 500 or more individuals must also be reported to HHS without unreasonable delay and within that same 60-day period. Breaches affecting fewer than 500 individuals must also be reported to HHS, but they can generally be reported annually, no later than 60 days after the end of the calendar year in which they were discovered. Certain larger breaches also require media notification.

This is another reason written procedures matter. Discovering a breach is not a great time for the team to begin asking who is responsible for making decisions, contacting vendors, documenting what happened and determining who needs to be notified.

Is there a HIPAA audit?

There can be.

The HHS Office for Civil Rights, or OCR, administers and enforces the HIPAA Privacy, Security and Breach Notification Rules. Federal law requires HHS to periodically audit covered entities and business associates, and OCR maintains a HIPAA Audit Program for that purpose.

That does not mean every dental practice receives an annual HIPAA inspection.

Enforcement can arise in several ways. OCR can receive a patient complaint. A reported breach can lead to scrutiny. OCR can conduct a compliance review or audit. Regulated entities are required to cooperate with complaint investigations.

The distinction matters because it changes the useful question.

Instead of asking, "Are we likely to be audited?" a better question is, "If someone asked us tomorrow to demonstrate how we comply, what could we actually produce?"

Could the practice identify its privacy official?

Its security official?

Its most recent security risk analysis?

Its training records?

Its Business Associate Agreements?

Its privacy and security policies?

Its incident response procedures?

Its documentation showing that identified risks were actually addressed?

Those are much more concrete questions than simply asking whether everyone in the office "knows HIPAA."

What are the penalties?

HIPAA violations can result in substantial civil penalties.

Civil penalties are tiered based on factors including what the organization knew, whether reasonable diligence would have identified the problem, whether the violation resulted from reasonable cause or willful neglect, and whether the organization corrected the problem.

The federal penalty amounts are adjusted periodically for inflation. Under the current inflation-adjusted regulation, individual HIPAA civil penalties can range from relatively modest amounts for violations an organization could not reasonably have known about to more than $2 million for a single violation involving uncorrected willful neglect, with substantial calendar-year caps for repeated violations of an identical requirement.

Those maximum numbers are frightening, but they can also distract from how enforcement usually works.

OCR says that many investigations are resolved through voluntary compliance, corrective action or resolution agreements rather than the maximum possible penalty. Whether the organization recognized the problem, took compliance seriously and corrected deficiencies can matter considerably.

HIPAA also contains criminal penalties for certain knowing misuse or disclosure of individually identifiable health information. Those can reach $250,000 and up to ten years in prison in the most serious category involving intent to sell, transfer or use the information for commercial advantage, personal gain or malicious harm. Those cases are handled by the Department of Justice.

For the ordinary dental practice, however, the useful lesson probably is not to obsess over the largest possible fine.

It is to avoid becoming the practice that cannot show it ever seriously addressed compliance in the first place.

HIPAA compliance is probably more front-loaded than continuous

There is a reassuring side to all of this.

A great deal of HIPAA compliance is exactly the kind of operational problem that becomes much easier once someone deliberately sits down and organizes it.

Identify who is responsible. Map where protected information lives. Conduct and document the risk analysis. Review vendors. Put the appropriate agreements in place. Create sensible written policies. Establish what happens when an employee joins or leaves. Decide what happens if information is accidentally disclosed. Create a breach response procedure. Train the staff and document the training.

Then make those procedures part of the way the practice operates.

HIPAA does not expect a five-person dental practice to build the compliance department of a hospital system. HHS explicitly recognizes that its requirements are scalable and that smaller organizations can create policies appropriate to their size and circumstances.

What it does expect is that the practice has thought about these issues, assigned responsibility for them, established reasonable policies and followed those policies.

That may be the most useful way to think about HIPAA compliance.

It is less about maintaining a giant binder nobody understands and more about turning a complicated legal requirement into a handful of clear operating practices that everyone in the office knows how to follow.

And like many things in a dental practice, putting the system in place is usually the hard part.

Once the system is clear, maintaining it becomes considerably easier.

Audit Preparation Best Practice Case Study Checklist Compliance Gaps Compliance Officer Credential Tracking Dental Practice Facility Based Clinic General Practitioner How-To Guide Mobile Clinic Multi-Location Compliance Office Manager Practice Manager Practice Owner Regulatory Update State Regulations University