HIPAA-Safe AI for Small Dental Practices: A Governance Checklist
BAAs, PHI minimization, vendor due diligence, and an operating model that lets a 3-op practice ship AI without putting the license at risk.
- PUBLISHED
- May 13, 2026
- READ TIME
- 8 MIN
- AUTHOR
- ONE FREQUENCY
- Topic
- HIPAA AI dental, dental AI compliance, dental BAA
- Industry
- dentists
- Published
- May 13, 2026
- Read time
- 8 min
- Word count
- 1,432
Most dental owners we meet describe HIPAA the way they describe flossing: yes, important, and yes, mostly avoided. That posture worked when the only AI in the practice was the radiograph software. It does not work in 2026, when the office manager has a Claude tab open, the front desk uses Modento for recall, and a voice agent is on track to handle 40% of inbound calls. AI in a dental practice is a HIPAA, state dental board, TCPA, and call-recording problem all at once.
The good news: the governance work that protects a 1-to-4-doctor practice fits on a single page. The bad news: most practices have done none of it. This article is that single page, plus the operating cadence that keeps it current. Workflow context is in the dental AI operator playbook; the front-desk copilot scoping detail is in the front-desk copilot guide.
The five-pillar checklist
1. BAA on every vendor that touches PHI
If a vendor sees patient name, DOB, MRN, account number, diagnosis, treatment, or any combination that could identify a person, that vendor signs a Business Associate Agreement before any data moves. No exceptions, no "we'll get to it next month."
Vendors that execute BAAs on the appropriate tier in 2026:
- Anthropic Claude (enterprise)
- Microsoft 365 Copilot and Azure OpenAI (commercial)
- OpenAI ChatGPT Enterprise
- Hyro, Numa, Modento, Weave, Solutionreach (healthcare or enterprise tier)
- Dentrix Ascend, Open Dental cloud, Eaglesoft cloud, Curve
- Vyne Dental, DentalXChange, Onederful
- Otter, Fireflies, and the major transcription vendors (enterprise tier)
Consumer free tiers do not offer BAAs. ChatGPT free, Claude.ai consumer, Microsoft Copilot consumer, Otter free — all off-limits.
2. PHI minimization
Even with a BAA in place, send only the minimum necessary PHI. A treatment-plan-narration prompt does not need the patient's SSN. A recall message draft does not need the patient's full diagnosis history. The rule: if removing a field does not change the output quality, the field should not be in the prompt.
Practices that institutionalize this with a one-page "what goes in a prompt" reference inside the team handbook see PHI-disclosure incidents drop to near zero.
3. State dental board language
Several state boards (California, Florida, Texas, New York, Washington) have specific treatment-plan disclosure, advertising, and patient-communication requirements. AI-generated content — patient-facing narratives, marketing copy, review replies — must comply with those rules.
The practical operating model: maintain a library of pre-approved AI prompts and templates that have been reviewed against the current state board guidance. Refresh the library annually or whenever the board issues a new bulletin.
4. TCPA and consent
AI-driven outbound SMS and voice for recall, review requests, and confirmation must honor:
- Express written consent for marketing-class messages
- 8 a.m.–9 p.m. local-time quiet hours
- Easy opt-out (STOP keyword for SMS, immediate hang-up tolerance for voice)
- Recordkeeping for the consent trail (audit log, 4-year retention minimum)
Most communication vendors handle this by default — but the practice owns the configuration. Verify on day one.
5. Call recording and two-party consent
Eleven U.S. states require two-party consent for call recording: California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington. Hawaii is one-party but requires disclosure if the recorder is not on the call.
The practical fix: the voice receptionist greeting includes the consent disclosure ("this call may be recorded for quality and training purposes"). Verify retention matches state law. Verify the prompt is on every inbound, not just new patients.
The 1-page governance artifact
The single document every practice should have signed by the owner, the office manager, and every team member with system access:
- List of approved AI vendors and the BAA on file
- List of prohibited AI tools (consumer free tiers)
- PHI handling rules (what goes in a prompt, what does not)
- TCPA and call-recording rules in the operating jurisdiction
- Incident escalation path (who to call if PHI ends up where it should not be)
- Annual review date
That is it. One page. Reviewed annually. Updated when a new vendor lands or a state rule changes.
The vendor due-diligence flow
Before signing any new AI vendor:
- Request the BAA and standard security questionnaire. If the vendor cannot produce both inside 5 business days, walk.
- Confirm the data residency. Healthcare-tier deployments should be in US data centers.
- Confirm encryption at rest and in transit. Modern vendors all do this; verify the documentation.
- Confirm the SOC 2 Type II report is available. Reputable vendors share it under NDA.
- Confirm the breach notification timeline aligns with HIPAA (60 days maximum).
- Sign the BAA before any PHI moves. No "we'll backfill" exceptions.
The 9-day rollout
The same finite pilot cadence we apply across every dental AI enablement engagement, scoped specifically to governance.
- Day 1. Inventory every AI tool currently in use across the practice. Include the consumer free tools the team uses informally.
- Day 2. Categorize each as PHI-touching or operational. Pull the BAAs the practice already has.
- Day 3. Identify gaps. Vendor without a BAA, consumer tool with PHI exposure, missing call-recording consent.
- Days 4–5. Close the gaps. Sign the missing BAAs, deprecate the consumer tools, fix the consent prompt.
- Day 6. Write the 1-page governance artifact. Owner signs.
- Day 7. Team training. Two 45-minute sessions: BAA basics and the PHI handling rules.
- Day 8. Live. Every team member has signed the artifact and acknowledged the policy.
- Day 9. Audit. Spot-check 10 random AI interactions across the team for compliance.
What good looks like
- BAA coverage rate. Floor: most practices have 30–50% of in-use AI vendors under BAA; target 100%.
- Consumer tool incidents. Floor: unknown; target 0 PHI-touching uses of non-BAA tools.
- Call recording consent. Floor: spotty; target 100% of inbound voice calls with disclosure prompt.
- Annual review cadence. Floor: never; target documented annual review of the 1-page artifact.
- Incident response time. Floor: undefined; target <24 hours from incident detection to documented response.
Pitfalls to avoid
- Do not assume the existing Microsoft 365 BAA covers consumer Copilot. It covers the Microsoft 365 service tier and properly configured Copilot. Consumer Copilot is separate.
- Do not let the front desk drop a patient's chart into a consumer ChatGPT to "draft a recall message faster." This is the most common single HIPAA violation we see in dental practices.
- Do not skip the call-recording disclosure on the AI receptionist. Vendors default it on; verify it is on for the practice's specific configuration.
- Do not over-collect PHI in prompts because "the AI is smarter that way." Data minimization always wins over output quality marginal improvement.
- Do not treat the 1-page artifact as one-and-done. Annual review is the difference between a governance program and a paperweight.
FAQ
Q: Do I need a HIPAA officer for a 3-op practice? A: HIPAA requires a designated privacy officer. For a 1-to-4-doctor practice, that role typically lives with the office manager or owner-doctor. It does not require an external hire.
Q: What if a vendor refuses to sign a BAA? A: Do not use the vendor for any PHI workflow. Period. There are alternative vendors in every dental AI category that will sign.
Q: What is the penalty if we get this wrong? A: HHS OCR penalties range from $137 per violation (with corrective action) to $2.1M per violation category per year for willful neglect. Most dental practice violations land in the $25,000–$250,000 range, plus mandatory corrective action plans and external monitoring.
Q: Do we need to encrypt patient SMS? A: SMS by definition is not encrypted in transit. HIPAA permits SMS with patient consent and minimum-necessary PHI. The recall message "Mrs. Johnson, you are due for your cleaning — call us to schedule" is acceptable; "Mrs. Johnson, follow-up on your perio diagnosis from 5/8" is not.
Q: What about AI in clinical decision support? A: A growing category — Pearl, VideaHealth, Overjet for radiograph review — operates under BAA and FDA cleared algorithms where applicable. Standard BAA and PHI-minimization rules apply.
Q: How does this interact with state dental board AI rules? A: A handful of state boards (Texas notably) issued AI bulletins in 2024–2025 clarifying that AI cannot make autonomous clinical decisions. Workflow design should keep AI in a drafting and review-assist role, not autonomous diagnosis or treatment planning.
If you want a governance audit scoped against your specific vendor stack — contact us. Engagement on AI for dentists.
Cited and consulted.
- 01ADA — Legal and Regulatory Resourcesada.org · accessed May 8, 2026
- 02Dental Economics — Legal and Compliance Coveragedentaleconomics.com · accessed May 8, 2026
- 03Dentistry IQ — Compliance Operationsdentistryiq.com · accessed May 8, 2026
- 04Inside Dentistry — Legal and Complianceaegisdentalnetwork.com · accessed May 8, 2026
Ready to ship the next outcome?
One Frequency Consulting brings 25+ years of technology leadership and military discipline to every engagement. First call is operator-grade scoping — sixty minutes, no charge.