HIPPA Security Rule Compliance for Dental Practices: Protecting Your Patients' Data - And Yourself.

Dave Argentar • September 17, 2019

The care that dentists need to provide their patients doesn’t end when they get up from the chair. Dental offices, and the computers, networks, servers, and files maintained within (and outside of) their walls contain patient information that must be kept secure and protected from data breaches and unauthorized disclosure. If your practice doesn’t have the systems, protocols, and policies in place to comply with HIPAA’s multitude of patient privacy and security requirements, even inadvertent and seemingly “harmless” violations can lead to significant financial and legal headaches.


HIPAA security compliance simply cannot be an afterthought for dental practices, nor is it a matter of “set it and forget it.” It requires constant vigilance, proactive planning, and regular audits and updates. This is particularly true when it comes to ensuring the security of electronic health records. Dentists need to commit people, time, and resources to the protection of patient information and should regularly consult with attorneys who can assist them in making their HIPAA compliance efforts robust and effective.


HIPAA Application to Dental Practices


After HIPAA became law in 1996, the U.S. Department of Health and Human Services (HHS) issued a set of national standards governing the use and disclosure of patients’ protected health information (PHI). Commonly known as the Privacy Rule , the Standards for Privacy of Individually Identifiable Health Information apply to “covered entities” as defined in HHS regulations.


The odds that your dental practice is a “covered entity” under HIPAA sit pretty close to 100%. If you send claims, eligibility inquiries and requests, pre-determinations, claim status inquiries, or treatment authorization requests to third parties through electronic means, you must comply with HIPAA.


HIPAA obligations don’t end at the Privacy Rule, which limits how and to whom PHI can be disclosed. Dental practices must also comply with the Security Rule ( Security Standards for the Protection of Electronic Protected Health Information ) as well as the Breach Notification Rule.


The HIPAA Security Rule


While the Privacy Rule addresses who may have access to PHI, the Security Rule sets the standards for ensuring that only those authorized individuals can access that information. One important distinction between the Privacy Rule and Security Rule is that while the former applies to PHI in whatever form – paper, oral, electronic - the Security Rule only covers electronic health records (ePHI). Since dental practices increasingly rely on electronic means to create, store, and transmit records, ensuring that your practice satisfies the Security Rule’s mandates is the centerpiece of any HIPAA compliance program.


The safeguards required under the Security Rule are divided into three categories:


· Administrative – As defined in the rules, these are policies and procedures designed “to manage the selection, development, implementation, and maintenance of security measures to protect electronically protected health information and to manage the conduct of the covered entity’s workforce in relation to the protection of that information.”


Practices must sufficiently implement and monitor their “performance of security management process, assignment or delegation of security responsibility, training requirements, and evaluation and documentation of all decisions.”


The essence of administrative compliance is people: people who are in charge of security, people who are trained about security, and people who are responsible for administering, monitoring, and auditing security compliance.


· Physical Access Controls – This involves safeguards established to control physical access to data and information and the systems which store them. This includes such essential elements as:


o Facility Access Controls – policies and procedures that limit physical access to all areas and devices where ePHI is stored, such as locked doors, restricted areas, surveillance systems, security guards, etc.

o Workstation Access and Security – policies and procedures that specify the proper functions to be performed on workstations, how employees should perform those functions, and physical workstation security.

o Device and Media Controls – thumb drives, laptops, phones, tablets, and other devices represent a significant vulnerability for unauthorized access to or distribution of ePHI. Dental practices need to establish policies and procedures that govern how hardware and electronic media containing ePHI can enter or exit dental offices. These controls must include disposal, media reuse, accountability, and data backup and storage.


· Technical controls – this involves “the technology and the policy and procedures for its use that protect electronic protected health information and control access to it.” Firewalls, encryption, data security measures, and other systems put in place to prevent data breaches, cyberattacks, and unauthorized access to ePHI fall into this category.

Your Practice Could Be Held Responsible for Any HIPAA Violations by a “Business Associate”


Many if not most practices contract at least some of their billing, claims management, and other back-office responsibilities to third-party vendors. If a practice fails to obtain “satisfactory assurances” from a “business associate” that it is HIPAA-compliant before retaining their services, and a PHI breach subsequently occurs, the practice entity may be considered liable for any damages that result


That is why every dental practice that shares PHI with outside contractors enter into a written HIPAA-Compliant Business Associate Agreement with such vendors. These agreements should specify:


·the types of PHI that the practice will provide to the business associate;

·the permissible uses and disclosures of PHI by the business associate;

·the measures that the business associate must implement to protect PHI;

·the actions that the business associate will take in the event of a data breach.


HIPAA Compliance Questions? Call Grogan, Hesse & Uditsky Today


At Grogan, Hesse & Uditsky, P.C., we focus a substantial part of our practice on providing exceptional legal services for dentists and dental practices, as well as orthodontists, periodontists, endodontists, pediatric dentists, and oral surgeons. We bring unique insights and deep commitment to protecting the interests of dental professionals and their practices and welcome the opportunity to work with you.


If you have questions or concerns about your practice’s compliance with HIPAA, please call us at (630) 833-5533 or contact us online to arrange for your free initial consultation.


Jordan Uditsky, an accomplished businessman and seasoned attorney, combines his experience as a legal counselor and successful entrepreneur to advise dentists and other business owners in the Chicago area. Jordan grew up in a dental family, with his father, grandfather, and sister each owning their own dental practices, and this blend of legal, business, and personal experience provides Jordan with unique insight into his clients’ needs, concerns, and goals.

Speak to an Attorney

Related Posts
By Jordan Uditsky July 9, 2025
Recent amendments to the Illinois Dental Practice Act (the “Act”), which Gov. JB Pritzker is expected to soon sign into law, will make it easier for newly minted dental professionals to begin practicing while their license applications are pending. The amendments, which would take effect on January 1, 2026, establish the following criteria under which license-pending dentists and dental hygienists can practice under the delegation of a licensed general dentist: The Applicant has completed and passed the IDFPR-approved licensure exam and presented their employer with an official written notification indicating such; The Applicant has completed and submitted the application for licensure; and The Applicant has submitted the required licensure fee. Once obtained, authorization for dentists and dental hygienists to practice under these provisions can be terminated upon the occurrence of any of the following: The Applicant receives their full-practice license; IDFPR provides notification that the Applicant’s application has been denied; IDFPR requests that the Applicant stop practicing as a license-pending dentist/dental hygienist until the Department makes an official decision to grant or deny a license to practice; or Six months have passed since the official date of the Applicant’s passage of the licensure exam (i.e., the date on the formal written notification of such from the Department). IDFPR has yet to post anything on its website regarding these amendments, but we will provide an update if and when it does. If you have any questions about these new provisions regarding the employment of license-pending dentists and hygienists, please contact Grogan Hesse & Uditsky today at (630) 833-5533 or contact us online to arrange for your free initial consultation. We focus a substantial part of our practice on providing exceptional legal services for dentists and dental practices, as well as orthodontists, periodontists, endodontists, pediatric dentists, and oral surgeons. We bring unique insights and deep commitment to protecting the interests of dental professionals and their practices and welcome the opportunity to work with you. Jordan Uditsky, an accomplished businessman and seasoned attorney, combines his experience as a legal counselor and successful entrepreneur to advise dentists and other business owners in the Chicago area. Jordan grew up in a dental family, with his father, grandfather, and sister each owning their own dental practices, and this blend of legal, business, and personal experience provides Jordan with unique insight into his clients’ needs, concerns, and goals.
By Robert Haney June 25, 2025
As all dental practice owners know, insurance companies frequently make adjustments to their reimbursement amounts, leading to the common circumstance that a patient who paid a certain amount at the time of treatment may be entitled to a credit from the practice. That credit, usually kept on the practice’s books so that the patient can apply it to future services, has two distinct qualities that have significant legal and financial implications when a practice is about to be purchased or sold. Failure to account for and address such outstanding patient credits early in a transaction can lead to unwanted surprises as well as potentially costly penalties. That is because a patient credit is not only a liability on the books of the practice, it is also the as-yet unclaimed personal property of the patient. That latter characteristic comes with legal obligations under state unclaimed property laws. If you are buying or selling a dental practice, here is what you need to know about handling patient credits during and after the transaction. Accounting For Credits in the Purchase Price More often than not, unused patient credits remain just that – unused. If a practice purchaser knew for an absolute certainty that the patient would never return and ask for the credit to be applied to new services, it would not impact the underlying practice valuation or sale price. Of course, nothing is certain, and if a practice has thousands, tens of thousands, or hundreds of thousands of credits on the books, even a fraction of those credits, if redeemed, could have a significant impact on the practice’s profitability. That is why any patient credits should be disclosed, identified, and addressed as early in the transaction as possible so that neither the buyer nor seller find themselves in the uncomfortable position of renegotiating the purchase price or providing the buyer with a credit. Reporting and Accounting Obligations Under Unclaimed Property Laws Any business holding goods or funds that belong to a customer, client, or other company or individual cannot simply pocket that property or money because its owner may have forgotten about it or is unaware of its existence. If a business holding such property, which includes patient credits, loses contact with the owner for a certain period set by law (called the “dormancy period”), the company effectively becomes the trustee of that property, holding it for the benefit of the owner until they make a claim for its return. In Illinois, that claim may come after the owner searches the Illinois State Treasurer’s unclaimed property database . The information in that database comes from businesses that must provide the Treasurer’s Office with detailed and frequent reports about any unclaimed property they hold pursuant to the requirements of Illinois’ Revised Uniform Unclaimed Property Act (the “Act”). Most U.S. states have adopted this model act, so the following discussion of Illinois’ version is representative of unclaimed property laws generally. When Does Property Become “Unclaimed”? As noted, property is considered unclaimed and abandoned if it has not had any activity within a designated “dormancy period” and the holder is unable to locate the property owner. Under Sec. 15-201 of the Act, the dormancy period is three years for most types of property, though others have longer or shorter periods. For example, there is a 15-year period for traveler's checks, a five-year period for money orders, and a one-year period for payroll checks. Patient credits would fall under the three-year period. Reporting and Notice Obligations For Holders of Unclaimed Property Any for-profit and not-for-profit business entities that conduct business in Illinois are required to electronically report unclaimed property to the Treasurer’s Office on an annual basis. Even businesses not holding any unclaimed property must file a negative report advising as such if they meet any of the following criteria: Annual sales of more than $1,000,000; Securities that are publicly traded; A net worth of more than $10,000,000; or More than 100 employees. The deadline for Illinois dental practices to file unclaimed property reports for unused patient credits is May 1 of each year. The report should reflect one year of account activity three years prior to the last calendar year. Example: If your report is due May 1, 2018, your report will cover activity from January 1, 2014, through December 31, 2014. The detailed requirements as to what must be included in the report are set forth in Section 760.410 of the Illinois Administrative Code . At the same time the report is filed, unclaimed property must be remitted to the Treasurer’s Office. Holders of unclaimed property also must make efforts to reach out to the owner before filing their report and remitting the property. Specifically, the holder of property presumed abandoned shall send a due diligence notice to the apparent owner by first-class U.S. Mail between 60 days and one year before reporting the property. The required contents of the due diligence notice are set forth in Section 760.460 of the Illinois Administrative Code . Consequences of Non-Compliance Holders of unclaimed property face significant penalties for failing to comply with the reporting, notice, and remittance requirements of the Act. Interest and penalties may be imposed on the failure to file, pay, or deliver property by the required due date. Specifically, the state can charge interest at 1% per month on the value of the unreported/unpaid property and impose a penalty of $200 per day up to a maximum of $5,000 until the date a report is filed or the unclaimed property is paid or delivered. For businesses that may have neglected their obligations under the Act, Illinois (and most other states that have adopted the uniform act) offers a Voluntary Disclosure Agreement (VDA) program for unclaimed property holders. In exchange for voluntary compliance through an executed VDA, the Treasurer's Office will agree to forgo the right to assess penalties and interest outlined in the Act. How To Address Unclaimed Property Obligations in a Practice Sale As part of transactional due diligence, a practice purchaser should ensure that the seller has satisfied all of its reporting obligations under applicable law. If it has not, the purchaser should require the seller to complete a Voluntary Disclosure Agreement prior to closing and also include a robust indemnification clause in the purchase agreement should the practice later face penalties for noncompliance. Because of the financial complexities and legal risks involved relating to unclaimed patient credits, practice buyers and sellers alike should consult with experienced counsel to help them navigate this significant and oft-neglected aspect of the practice’s finances and operations. If you are a dental professional considering a sale, acquisition, or merger, please contact us at ddslawyers.com at (630) 833-5533 or contact us online to arrange for your complimentary initial consultation. We focus a substantial part of our practice on providing exceptional legal services for dentists and dental practices, as well as orthodontists, periodontists, endodontists, pediatric dentists, and oral surgeons. We bring unique insights and deep commitment to protecting the interests of dental professionals and their practices and welcome the opportunity to work with you. Jordan Uditsky, an accomplished businessman and seasoned attorney, combines his experience as a legal counselor and successful entrepreneur to advise dentists and other business owners in the Chicago area. Jordan grew up in a dental family, with his father, grandfather, and sister each owning their own dental practices, and this blend of legal, business, and personal experience provides Jordan with unique insight into his clients’ needs, concerns, and goals.
By Jordan Uditsky March 12, 2025
Once again, mandatory Beneficial Ownership Information (BOI) reporting deadlines under the Corporate Transparency Act (CTA) have been put on hold. Not only have all deadlines been scrapped but domestic reporting companies may soon be permanently relieved of any CTA obligations whatsoever. Just days after stating it would enforce new March 21, 2025 deadlines, FinCEN issued a February 27, 2025, alert announcing that “ it will not issue any fines or penalties or take any other enforcement actions against any companies based on any failure to file or update” BOI reports by the current deadlines “until a forthcoming interim final rule becomes effective and new relevant due dates in the interim final rule have passed. FinCEN said that no later than March 21, 2025, it “intends to issue an interim final rule that extends BOI reporting deadlines, recognizing the need to provide new guidance and clarity as quickly as possible, while ensuring that BOI that is highly useful to important national security, intelligence, and law enforcement activities is reported.” Just two days after FinCEN’s announcement suspending existing deadlines, the Department of the Treasury went even further. In a March 2, 2025 release , the department said that “not only will it not enforce any penalties or fines associated with the beneficial ownership information reporting rule under the existing regulatory deadlines, but it will further not enforce any penalties or fines against U.S. citizens or domestic reporting companies or their beneficial owners after the forthcoming rule changes take effect either.” That is because “the Treasury Department will further be issuing a proposed rulemaking that will narrow the scope of the rule to foreign reporting companies only.” The bottom line is that it appears the new administration has decided to kill the CTA altogether as to domestic reporting companies. We will, of course, provide updates as warranted. If you have questions about this latest development or the CTA generally, please contact Jordan Uditsky at Grogan Hesse & Uditsky, P.C.
Show More
By Jordan Uditsky July 9, 2025
Recent amendments to the Illinois Dental Practice Act (the “Act”), which Gov. JB Pritzker is expected to soon sign into law, will make it easier for newly minted dental professionals to begin practicing while their license applications are pending. The amendments, which would take effect on January 1, 2026, establish the following criteria under which license-pending dentists and dental hygienists can practice under the delegation of a licensed general dentist: The Applicant has completed and passed the IDFPR-approved licensure exam and presented their employer with an official written notification indicating such; The Applicant has completed and submitted the application for licensure; and The Applicant has submitted the required licensure fee. Once obtained, authorization for dentists and dental hygienists to practice under these provisions can be terminated upon the occurrence of any of the following: The Applicant receives their full-practice license; IDFPR provides notification that the Applicant’s application has been denied; IDFPR requests that the Applicant stop practicing as a license-pending dentist/dental hygienist until the Department makes an official decision to grant or deny a license to practice; or Six months have passed since the official date of the Applicant’s passage of the licensure exam (i.e., the date on the formal written notification of such from the Department). IDFPR has yet to post anything on its website regarding these amendments, but we will provide an update if and when it does. If you have any questions about these new provisions regarding the employment of license-pending dentists and hygienists, please contact Grogan Hesse & Uditsky today at (630) 833-5533 or contact us online to arrange for your free initial consultation. We focus a substantial part of our practice on providing exceptional legal services for dentists and dental practices, as well as orthodontists, periodontists, endodontists, pediatric dentists, and oral surgeons. We bring unique insights and deep commitment to protecting the interests of dental professionals and their practices and welcome the opportunity to work with you. Jordan Uditsky, an accomplished businessman and seasoned attorney, combines his experience as a legal counselor and successful entrepreneur to advise dentists and other business owners in the Chicago area. Jordan grew up in a dental family, with his father, grandfather, and sister each owning their own dental practices, and this blend of legal, business, and personal experience provides Jordan with unique insight into his clients’ needs, concerns, and goals.
By Robert Haney June 25, 2025
As all dental practice owners know, insurance companies frequently make adjustments to their reimbursement amounts, leading to the common circumstance that a patient who paid a certain amount at the time of treatment may be entitled to a credit from the practice. That credit, usually kept on the practice’s books so that the patient can apply it to future services, has two distinct qualities that have significant legal and financial implications when a practice is about to be purchased or sold. Failure to account for and address such outstanding patient credits early in a transaction can lead to unwanted surprises as well as potentially costly penalties. That is because a patient credit is not only a liability on the books of the practice, it is also the as-yet unclaimed personal property of the patient. That latter characteristic comes with legal obligations under state unclaimed property laws. If you are buying or selling a dental practice, here is what you need to know about handling patient credits during and after the transaction. Accounting For Credits in the Purchase Price More often than not, unused patient credits remain just that – unused. If a practice purchaser knew for an absolute certainty that the patient would never return and ask for the credit to be applied to new services, it would not impact the underlying practice valuation or sale price. Of course, nothing is certain, and if a practice has thousands, tens of thousands, or hundreds of thousands of credits on the books, even a fraction of those credits, if redeemed, could have a significant impact on the practice’s profitability. That is why any patient credits should be disclosed, identified, and addressed as early in the transaction as possible so that neither the buyer nor seller find themselves in the uncomfortable position of renegotiating the purchase price or providing the buyer with a credit. Reporting and Accounting Obligations Under Unclaimed Property Laws Any business holding goods or funds that belong to a customer, client, or other company or individual cannot simply pocket that property or money because its owner may have forgotten about it or is unaware of its existence. If a business holding such property, which includes patient credits, loses contact with the owner for a certain period set by law (called the “dormancy period”), the company effectively becomes the trustee of that property, holding it for the benefit of the owner until they make a claim for its return. In Illinois, that claim may come after the owner searches the Illinois State Treasurer’s unclaimed property database . The information in that database comes from businesses that must provide the Treasurer’s Office with detailed and frequent reports about any unclaimed property they hold pursuant to the requirements of Illinois’ Revised Uniform Unclaimed Property Act (the “Act”). Most U.S. states have adopted this model act, so the following discussion of Illinois’ version is representative of unclaimed property laws generally. When Does Property Become “Unclaimed”? As noted, property is considered unclaimed and abandoned if it has not had any activity within a designated “dormancy period” and the holder is unable to locate the property owner. Under Sec. 15-201 of the Act, the dormancy period is three years for most types of property, though others have longer or shorter periods. For example, there is a 15-year period for traveler's checks, a five-year period for money orders, and a one-year period for payroll checks. Patient credits would fall under the three-year period. Reporting and Notice Obligations For Holders of Unclaimed Property Any for-profit and not-for-profit business entities that conduct business in Illinois are required to electronically report unclaimed property to the Treasurer’s Office on an annual basis. Even businesses not holding any unclaimed property must file a negative report advising as such if they meet any of the following criteria: Annual sales of more than $1,000,000; Securities that are publicly traded; A net worth of more than $10,000,000; or More than 100 employees. The deadline for Illinois dental practices to file unclaimed property reports for unused patient credits is May 1 of each year. The report should reflect one year of account activity three years prior to the last calendar year. Example: If your report is due May 1, 2018, your report will cover activity from January 1, 2014, through December 31, 2014. The detailed requirements as to what must be included in the report are set forth in Section 760.410 of the Illinois Administrative Code . At the same time the report is filed, unclaimed property must be remitted to the Treasurer’s Office. Holders of unclaimed property also must make efforts to reach out to the owner before filing their report and remitting the property. Specifically, the holder of property presumed abandoned shall send a due diligence notice to the apparent owner by first-class U.S. Mail between 60 days and one year before reporting the property. The required contents of the due diligence notice are set forth in Section 760.460 of the Illinois Administrative Code . Consequences of Non-Compliance Holders of unclaimed property face significant penalties for failing to comply with the reporting, notice, and remittance requirements of the Act. Interest and penalties may be imposed on the failure to file, pay, or deliver property by the required due date. Specifically, the state can charge interest at 1% per month on the value of the unreported/unpaid property and impose a penalty of $200 per day up to a maximum of $5,000 until the date a report is filed or the unclaimed property is paid or delivered. For businesses that may have neglected their obligations under the Act, Illinois (and most other states that have adopted the uniform act) offers a Voluntary Disclosure Agreement (VDA) program for unclaimed property holders. In exchange for voluntary compliance through an executed VDA, the Treasurer's Office will agree to forgo the right to assess penalties and interest outlined in the Act. How To Address Unclaimed Property Obligations in a Practice Sale As part of transactional due diligence, a practice purchaser should ensure that the seller has satisfied all of its reporting obligations under applicable law. If it has not, the purchaser should require the seller to complete a Voluntary Disclosure Agreement prior to closing and also include a robust indemnification clause in the purchase agreement should the practice later face penalties for noncompliance. Because of the financial complexities and legal risks involved relating to unclaimed patient credits, practice buyers and sellers alike should consult with experienced counsel to help them navigate this significant and oft-neglected aspect of the practice’s finances and operations. If you are a dental professional considering a sale, acquisition, or merger, please contact us at ddslawyers.com at (630) 833-5533 or contact us online to arrange for your complimentary initial consultation. We focus a substantial part of our practice on providing exceptional legal services for dentists and dental practices, as well as orthodontists, periodontists, endodontists, pediatric dentists, and oral surgeons. We bring unique insights and deep commitment to protecting the interests of dental professionals and their practices and welcome the opportunity to work with you. Jordan Uditsky, an accomplished businessman and seasoned attorney, combines his experience as a legal counselor and successful entrepreneur to advise dentists and other business owners in the Chicago area. Jordan grew up in a dental family, with his father, grandfather, and sister each owning their own dental practices, and this blend of legal, business, and personal experience provides Jordan with unique insight into his clients’ needs, concerns, and goals.
By Jordan Uditsky March 12, 2025
Once again, mandatory Beneficial Ownership Information (BOI) reporting deadlines under the Corporate Transparency Act (CTA) have been put on hold. Not only have all deadlines been scrapped but domestic reporting companies may soon be permanently relieved of any CTA obligations whatsoever. Just days after stating it would enforce new March 21, 2025 deadlines, FinCEN issued a February 27, 2025, alert announcing that “ it will not issue any fines or penalties or take any other enforcement actions against any companies based on any failure to file or update” BOI reports by the current deadlines “until a forthcoming interim final rule becomes effective and new relevant due dates in the interim final rule have passed. FinCEN said that no later than March 21, 2025, it “intends to issue an interim final rule that extends BOI reporting deadlines, recognizing the need to provide new guidance and clarity as quickly as possible, while ensuring that BOI that is highly useful to important national security, intelligence, and law enforcement activities is reported.” Just two days after FinCEN’s announcement suspending existing deadlines, the Department of the Treasury went even further. In a March 2, 2025 release , the department said that “not only will it not enforce any penalties or fines associated with the beneficial ownership information reporting rule under the existing regulatory deadlines, but it will further not enforce any penalties or fines against U.S. citizens or domestic reporting companies or their beneficial owners after the forthcoming rule changes take effect either.” That is because “the Treasury Department will further be issuing a proposed rulemaking that will narrow the scope of the rule to foreign reporting companies only.” The bottom line is that it appears the new administration has decided to kill the CTA altogether as to domestic reporting companies. We will, of course, provide updates as warranted. If you have questions about this latest development or the CTA generally, please contact Jordan Uditsky at Grogan Hesse & Uditsky, P.C.
Show More