Building a HIPAA Compliance Program as a Dental Office Manager

A Dental Office Manager builds a HIPAA compliance program by identifying the specific forms protected health information takes in a dental setting, completing a current HIPAA Security Risk Analysis that accounts for imaging systems and open treatment areas, securing Business Associate Agreements with dental laboratories and referral specialists, and training staff who frequently perform more than one role at once. Dental practices operate under the same HIPAA rules for dentists that apply to medical practices generally, but the operational structure of a dental office introduces compliance considerations that a general medical program does not fully address.

Identifying Protected Health Information Specific to Dental Practice

Protected health information in a dental practice includes treatment records, billing details, and medical history intake forms, but it also includes categories of data that carry a distinct handling requirement in dental settings. Radiographic images, periodontal charting, and treatment plans shared with labs or specialists all qualify as protected health information and need the same safeguards applied to any other patient record.

Medical History and Intake Forms

Dental intake forms typically collect medical history details relevant to treatment, including current medications, allergies, and existing health conditions that affect dental procedures. A Dental Office Manager confirming these forms are stored securely, whether on paper in a locked file or digitally within an access-controlled system, addresses a category of protected health information that patients complete themselves and that staff may handle more casually than a formal medical record, despite carrying the same regulatory protection.

Digital Radiography and Imaging Systems

Digital X-ray systems store patient images on a server or workstation that requires the same access controls, audit logging, and encryption as the practice management software. A Dental Office Manager confirming that the imaging system falls within the scope of the practice’s technical safeguards avoids a common gap where imaging equipment, purchased and installed by a separate vendor, gets treated as a standalone clinical tool rather than a system holding protected health information.

The HIPAA Security Risk Analysis for a Dental Office

A dental practice’s HIPAA Security Risk Analysis needs to account for the practice’s physical layout and equipment inventory in addition to its administrative systems. A Dental Office Manager overseeing this analysis includes imaging workstations, chairside computers, and any tablets used for treatment planning or patient education, since each represents a point where protected health information is created, accessed, or displayed.

Multi-Chair and Open-Bay Treatment Areas

Many dental practices operate with treatment chairs positioned within sight or earshot of one another, a layout that creates disclosure risk not typically present in a medical practice with individual exam rooms. A Dental Office Manager reviewing this layout during the risk analysis identifies where patient names, treatment discussions, or financial conversations at one chair are audible or visible from an adjacent chair, and works with clinical staff to reduce these incidental disclosures where operationally feasible.

Business Associate Relationships Unique to Dental Practices

Dental practices work with vendors that a general medical practice typically does not, and each of these relationships needs evaluation against the same Business Associate standard applied to any other vendor handling patient data.

Dental Laboratories and Referral Specialists

A dental laboratory fabricating a crown, denture, or orthodontic appliance receives patient identifiers, treatment details, and often digital scans or impressions tied to a specific patient, which typically qualifies the lab as a Business Associate requiring a signed Business Associate Agreement. A Dental Office Manager reviewing vendor relationships confirms that every lab, oral surgeon, orthodontist, or other specialist receiving patient information through a referral has an agreement on file, since these relationships are sometimes treated as informal professional courtesies rather than formal data-sharing arrangements requiring documentation.

Insurance Clearinghouses and Dental Support Organizations

A practice submitting claims through a third-party clearinghouse, or operating under a Dental Support Organization that provides administrative or billing services, extends its Business Associate relationships beyond the clinical vendors already discussed. A Dental Office Manager mapping these relationships confirms that agreements cover data flowing through claims processing and administrative support functions, not only the clinical referral and laboratory relationships that are more visible in daily operations.

Policies and the Notice of Privacy Practices

A dental practice’s HIPAA Privacy Rule obligations include providing a Notice of Privacy Practices to every new patient and maintaining written policies covering how the practice uses and discloses protected health information. A Dental Office Manager confirms this notice addresses dental-specific disclosure scenarios, such as sharing images or treatment plans with a referred specialist or a dental laboratory.

Responding to Online Reviews Without Disclosing PHI

Dental practices frequently receive patient reviews on public platforms, and a response that references a specific patient’s treatment, appointment history, or account details to rebut a negative review constitutes an impermissible disclosure regardless of the practice’s intent to clarify the situation. A Dental Office Manager establishing a policy that limits public responses to general statements, without confirming or denying that a reviewer is even a patient, avoids the type of disclosure that has resulted in enforcement action against dental practices in the past.

Photography and Before-and-After Marketing Images

Dental practices commonly photograph patients’ teeth for clinical documentation and, in some cases, for marketing use showing treatment results. A Dental Office Manager confirming that marketing use of these images requires a separate signed authorization, distinct from the general consent obtained for treatment, closes a gap that arises when a clinically useful photograph gets repurposed for a website or social media post without the patient’s specific agreement to that additional use.

Compliance Elements a Dental Office Manager Should Maintain

  • A current HIPAA Security Risk Analysis covering imaging systems and treatment areas
  • Signed Business Associate Agreements with labs and referral specialists
  • A Notice of Privacy Practices addressing dental-specific disclosure scenarios
  • A written social media and online review response policy
  • Role-based training records reflecting staff members who perform multiple functions

Staff Training in a Multi-Role Dental Office

Dental practices commonly staff positions where one employee performs front desk duties, processes payments, and assists chairside during a single shift, a staffing pattern less common in larger medical practices with more defined role separation.

Addressing Overlapping Job Duties in Training Content

Generic HIPAA training for dental offices built around a single job function may not address the full range of situations a multi-role employee encounters during a shift. A Dental Office Manager reviewing training content confirms it covers the intersection of front desk, clinical support, and billing responsibilities a single staff member may hold, rather than assigning training modules based strictly on job title when actual duties extend beyond that title.

Front Desk and Scheduling Privacy Practices

The front desk in a dental practice manages check-in, scheduling, payment collection, and often insurance verification, creating multiple points where protected health information changes hands in view of other patients in the waiting area.

Sign-In Sheets and Treatment Boards

A sign-in sheet that lists patient names alongside appointment times or reasons for visit creates a disclosure visible to every subsequent patient who signs in afterward. A Dental Office Manager reviewing front desk procedures replaces or modifies sign-in practices that expose more information than necessary, and applies the same review to any treatment board, whiteboard, or scheduling display visible from patient-accessible areas that lists patient names alongside clinical information.

Discussing Treatment Costs at an Open Counter

Payment collection and treatment cost discussions often occur at an open front desk counter, within hearing range of other patients waiting nearby. A Dental Office Manager training front desk staff to lower their voice, use a private area for detailed financial discussions, or turn a computer screen away from public view during checkout reduces incidental disclosure of treatment details tied to cost, which patients often consider as sensitive as the clinical information itself.

Keeping the Program Current

A dental practice’s compliance program requires the same ongoing maintenance any HIPAA-covered practice needs, including periodic review of the risk analysis, updated Business Associate Agreements as vendor relationships change, and training refreshed as staff turn over or take on new responsibilities. Software built specifically for HIPAA compliance management gives a Dental Office Manager a structured way to track these recurring requirements across a practice where staff frequently juggle clinical, administrative, and financial duties simultaneously, reducing the likelihood that a compliance task gets overlooked during a busy patient schedule.

Learning from Enforcement Patterns in Dental Practices

A review of HIPAA compliance for dentists shows that enforcement actions against dental practices frequently involve a missing Notice of Privacy Practices, an absent Privacy Officer designation, or a delayed response to a patient’s records request, gaps that a structured, actively maintained program addresses directly. A Dental Office Manager aware of these recurring patterns can prioritize the specific documentation areas most likely to surface during a complaint or investigation involving a dental practice. Patient requests for copies of dental x-rays represent a recurring source of complaints specifically, since these files are sometimes stored in proprietary imaging software that front desk staff are not trained to export, creating a delay that a well-documented, tested export procedure would prevent.

The post Building a HIPAA Compliance Program as a Dental Office Manager appeared first on The HIPAA Journal.

Greater Rochester Independent Practice Association Settles MOVEit Data Breach Litigation

A settlement has been agreed to resolve claims against Greater Rochester Independent Practice Association (GRIPA) arising from the May 2023 data breach involving Progress Software’s MOVEit file transfer solution.

In May 2023, the Russian-speaking hacking group CL0p mass exploited a zero-day vulnerability in Progress Software’s MOVEit Transfer file transfer solution. Cl0p exploited the vulnerability to attack an estimated 2,700 companies that used the software, exfiltrated sensitive data, and then demanded payment to prevent the publication of the stolen data. Globally, almost 96 million individuals were affected. Cl0p proceeded to leak large amounts of data on the dark web when its ransom demands were not met.

In the United States, well over 100 class action lawsuits were filed against Progress Software and more than 100 client organizations over the attack and data breach. The plaintiffs alleged that the data breach could have been prevented by implementing industry-standard cybersecurity measures and protocols, such as software to detect suspicious activity, auditing the platform and Progress Software’s cybersecurity practices, and restricting the IP addresses that could access the platform and limiting the file types that could be uploaded.

The lawsuits had overlapping claims and were consolidated into a single multidistrict litigation, which was centralized in the U.S. District Court for the District of Massachusetts – In re: MOVEit Customer Data Security Breach Litigation. Progress Software made multiple bids to have the lawsuit dismissed, and in July 2025, the court largely denied the motions; however, it failed to dismiss the negligence claims under state law in California, Indiana, Michigan, and Ohio.

Several of the affected client organizations have already entered into settlements, including Bank of America, Nuance Communications, and Arietis Health. Now a settlement has been agreed to resolve claims against GRIPA related to the data breach, although the claims against Progress Software have not been resolved and will continue.

GRIPA faced four class action lawsuits over the data breach, the first of which was Clarke, et al. v. Progress Software Corp., et al, which were transferred to and coordinated with In re: MOVEit Customer Data Security Breach Litigation. GRIPA patients had their names, dates of birth, Social Security numbers, health & treatment information, health insurance information, pharmacy prescription information, and prescriber information compromised in the incident, and the publication of that data, according to the lawsuit, resulted in cognizable injuries. GRIPA faced claims for negligence, negligence per se, breach of third-party beneficiary contract, breach of implied contract, unjust enrichment, and declaratory and injunctive relief. GRIPA filed a motion to dismiss, which was denied in part and granted in part by the court on December 12, 2024.

GRIPA denies any wrongdoing and disagrees with the claims and contentions in the lawsuit. After considering the cost, expense, and length of proceedings, and the uncertainty of a trial and related appeals, the parties began settlement discussions. Mediation on June 10, 2025, was successful, with the material terms of a settlement agreed upon by all parties.

Under the terms of the settlement, GRIPA has agreed to establish a $2,150,000 settlement fund to pay claims made by the settlement class members. Claims will be paid after attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives have been deducted. Class members may submit a claim for reimbursement of up to $2,500 in ordinary losses, and up to $10,000 in extraordinary losses. Alternatively, if a claim for reimbursement of losses is not filed, class members may claim a one-time cash payment, estimated to be $100 per class member. The cash payments will be subject to a pro rata increase or decrease, depending on the number of valid claims received. In addition, all class members are entitled to file a claim for two years of complimentary credit monitoring and identity theft protection services.

The settlement has received preliminary approval from the court. The deadline for filing a claim is September 3, 2026. The final fairness hearing will be held on the same date. Individuals wishing to exclude themselves from the settlement or object to it must do so by August 4, 2026. Further information on the settlement can be found on the settlement website: https://www.moveitsettlementgripa.com/index.htm

The post Greater Rochester Independent Practice Association Settles MOVEit Data Breach Litigation appeared first on The HIPAA Journal.

Serviceaide Pays $1.8 Million to Settle Data Breach Litigation

Serviceaide, Inc., a provider of AI-powered solutions to boost productivity and enhance service delivery, has agreed to pay $1.8 million to settle a lawsuit stemming from a 2024 data breach that exposed the protected health information of patients of its client, Catholic Health.

Catholic Health is a Buffalo, NY-based non-profit healthcare system serving patients in Western New York through its hospitals, nursing homes, home care agencies, and physician practices. Catholic Health contracted with Serviceaide, and the provision of the contracted services required access to patient data. On or around November 15, 2024, Serviceaide identified unauthorized access to its systems. The forensic investigation confirmed that an unauthorized third party had access to its network from September 19, 2024, to November 5, 2024.

Servieaide determined that a database containing the records of approximately 483,000 Catholic Health patients was potentially accessed or obtained. The database contained names, dates of birth, Social Security numbers, medical/health information, treatment information, health insurance information, and email/usernames and accompanying passwords. The affected individuals were notified about the data breach on May 9, 2025.

Eleven class action lawsuits were filed in response to the data breach, which were consolidated – Nancy Balzer, et al., v. Serviceaide, Inc. – in the Supreme Court of the State of New York, County of Nassau. The consolidated lawsuit alleges that the data breach should have been prevented and was the result of negligence on the part of the defendant. The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, invasion of privacy, violations of California’s Unfair Competition Law, Cal. Bus. & Prof. Code §§ 17200, et seq., and declaratory judgment.

Serviceaide denies all wrongdoing, and disagrees with all claims and contentions in the lawsuit. The defendant filed a motion to dismiss, and the plaintiffs filed their opposition to the motion. To conserve resources for the benefit of the class members, the parties explored a potential settlement. As a result of hard-fought negotiations, the terms of a settlement were agreed, and the settlement has now been finalized.

Under the terms of the settlement, Serviceaide has agreed to establish a $1,800,000 settlement fund, from which attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the 15 class representatives will be deducted. The remainder of the fund will be used to pay valid claims from the class members.

Class members may claim one of two cash payments. They may submit a claim for reimbursement of documented, unreimbursed losses due to fraud or identity theft as a result of the incident, and other losses up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a cash payment, estimated to be approximately $50 per claim. The cash payments will be paid pro rata after the claims for losses have been paid. The deadline for submitting a claim is September 1, 2026. The final fairness hearing has been scheduled for September 16, 2026. The deadline for objection and opting out is August 17, 2026.

The post Serviceaide Pays $1.8 Million to Settle Data Breach Litigation appeared first on The HIPAA Journal.