01/16/2024

8 Common HIPAA Violations in Dental Practices (With Examples)

~ 7 minutes to read

Dental HIPAA violations often begin with routine mistakes. A new employee gets record access before training. A vendor handles patient information without the right agreement. A team member sends a radiograph through an unapproved process.

This guide explains eight common violation areas, gives dental-office examples and shows what to review. HIPAA enforcement depends on the facts. Outcomes may include technical assistance, corrective action, a resolution agreement or civil penalties.

Compliance note: This article is for education and doesn’t replace legal advice. Source review date: August 24, 2026. The rules and HHS guidance can change.

Rule status: HHS still identifies its December 2024 HIPAA Security Rule changes as a proposed rule. The current Security Rule remains in effect. This article describes current requirements unless a passage says “proposed.”

8 Common HIPAA Violations in Dental Offices

  1. Failing to train employees on the practice’s HIPAA policies
  2. Missing or outdated privacy and security policies
  3. Missing business associate agreements with covered vendors
  4. Failing to provide or post the Notice of Privacy Practices
  5. Failing to perform and update a security risk analysis
  6. Leaving known security risks unresolved
  7. Allowing unauthorized access to patient records
  8. Sending patient information without reasonable email safeguards

Dental HIPAA Violation Examples

Violation area Dental-office example First prevention step
Training A new employee receives patient-record access before learning the practice’s privacy and security procedures. Connect access approval to role-based training.
Written policies The office can’t produce the current procedure for responding to a patient-record request. Keep one controlled policy set with review dates.
Business associate agreements A cloud or billing vendor maintains PHI without the required agreement. Review the relationship before the vendor receives PHI.
Notice of Privacy Practices The current notice isn’t provided by first service or posted in the office. Check distribution, posting and acknowledgment procedures.
Risk analysis The practice adds a cloud system without assessing risks to electronic PHI. Update the documented analysis when systems or risks change.
Risk management A shared-password problem stays open without an owner or correction date. Give every risk a response, owner and due date.
Unauthorized access An employee opens a patient chart without a job-related reason. Use individual accounts and review access.
Email safeguards A radiograph is sent outside the approved process without checking the recipient or security controls. Set one approved process for messages containing PHI.

Official Sources Used for This Guide

Topic Primary source Last checked
Privacy policies and workforce training HHS Privacy Rule guidance August 24, 2026
Electronic PHI safeguards HHS Security Rule August 24, 2026
Security risk analysis HHS Risk Analysis Guidance August 24, 2026
Vendor agreements HHS Business Associate Guidance August 24, 2026
Privacy notice HHS Notice of Privacy Practices FAQs August 24, 2026
Possible breaches HHS Breach Notification Rule August 24, 2026

Violation #1: Incomplete HIPAA Employee Training

The Privacy Rule requires a covered entity to train workforce members on its privacy policies and procedures. The training must fit each person’s job. New workforce members need training within a reasonable period after joining. Workers affected by a material policy change need training on that change.

The Security Rule also requires a security awareness and training program for the workforce. HHS doesn’t set one universal annual deadline for every type of HIPAA training. Many practices still use annual refreshers as a management choice.

Dental-office example: A front-desk employee can open charts and send records before learning identity checks, minimum-necessary rules or the incident-reporting process.

How to prevent it: Match training to each role. Record the date, topics, trainer and attendees. Retrain affected staff after a material policy, job or system change.

Violation #2: Missing Privacy and Security Policies

Covered dental practices need written policies and procedures that support the HIPAA rules. The documents should match the office’s actual systems and workflows. A copied manual that describes tools the practice doesn’t use is weak evidence of a working program.

HHS provides privacy guidance at hhs.gov/hipaa/for-professionals/privacy/guidance. The American Dental Association also sells a resource at engage.ada.org/p/pb/the-ada-complete-hipaa-compliance-kit-1394.

Dental-office example: A patient requests a copy of a record, but staff members follow different identity-check and delivery procedures.

How to prevent it: Keep one approved policy set. Include privacy, security, access, sanctions, incident response and breach review. Record the owner, effective date and latest review.

Violation #3: Missing Business Associate Agreements

A business associate is usually a person or company that creates, receives, maintains or transmits PHI for a covered entity. Common dental examples can include billing services, cloud storage providers, IT support and software vendors.

A BAA describes permitted uses and disclosures, required safeguards and reporting duties. HHS provides hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions.

A BAA isn’t required for every outside company. For example, HHS says a janitorial service whose access to PHI is only incidental may fall outside the business associate definition when reasonable safeguards are in place. Treatment disclosures and some conduit services also have exceptions.

Dental-office example: An outside backup provider stores the practice’s patient database, but the practice has no signed BAA on file.

How to prevent it: Review the service and data flow before granting access. Record why a BAA is required or why an exception applies. Store signed agreements and renewal dates.

Violation #4: Notice of Privacy Practices Problems

A covered dental provider with a direct treatment relationship must give its Notice of Privacy Practices by the date of first service. It must make a good-faith effort to obtain written acknowledgment of receipt. If the patient won’t sign, document the effort and reason.

The entire current notice must be posted clearly at the physical care site. A provider that maintains a website describing services or benefits must also post the notice there. HHS offers models at hhs.gov/hipaa/for-professionals/privacy/guidance/model-notices-privacy-practices.

Dental-office example: The office’s wall notice names a former privacy contact, while the website has an older version.

How to prevent it: Compare the printed, digital and handout versions. Check the contact information and effective date. Keep the acknowledgment process separate from treatment authorization or consent.

Violation #5: Failing to Perform and Update a Security Risk Analysis

The Security Rule requires an accurate and thorough assessment of risks and vulnerabilities to electronic PHI. The analysis should cover every place the practice creates, receives, maintains or transmits that information.

The rule sets no fixed annual schedule. HHS describes risk analysis as an ongoing process. Update it when systems, threats, ownership, key staff or business operations change. The HHS guidance is available at hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis.

Dental-office example: The practice connects a new imaging platform to patient records without documenting where ePHI moves or who can access it.

How to prevent it: Map every system and device that handles ePHI. Record threats, vulnerabilities, current safeguards, likelihood and possible impact. Revisit the analysis after meaningful changes.

Violation #6: Leaving Known Security Risks Unresolved

A risk analysis identifies problems. Risk management assigns a response. The practice should reduce identified risks to a reasonable and appropriate level, then document what it did.

Dental-office example: The analysis flags shared accounts for the practice-management system. The same issue appears months later with no assigned owner or correction date.

How to prevent it: Create a risk register. Record the problem, priority, planned response, owner, due date and completion evidence. Document the reason when the practice chooses an alternate safeguard.

Violation #7: Unauthorized Access to Patient Records

Access to PHI should match each person’s job. Paper charts, computer screens, exported files and portable devices all need reasonable safeguards. Individual accounts also help the practice identify who viewed or changed a record.

HIPAA doesn’t set a universal password length or a 60-day change rule. The practice should choose access controls based on its risk analysis, systems and current security guidance.

Dental-office example: An employee opens a neighbor’s chart out of curiosity. In another example, staff share one login, so the practice can’t identify who accessed a record.

How to prevent it: Use unique accounts, role-based permissions and automatic screen locks. Secure paper records. Remove access promptly after a worker leaves or changes roles. Review access logs based on risk.

Violation #8: Sending Patient Information Without Email Safeguards

Email isn’t automatically a HIPAA violation. HHS says covered providers may use email with reasonable safeguards. Those safeguards can include checking the address, limiting the information and following the Security Rule for electronic PHI.

An email service also isn’t compliant or noncompliant based only on its brand. Review how the service is configured, which safeguards are active and whether a BAA is required. Follow the practice’s approved process for referrals, records, radiographs and patient messages.

Dental-office example: A team member attaches the wrong patient’s radiograph after relying on autofill. The office has no second check for recipient and patient identity.

How to prevent it: Set one approved communication process. Check the recipient and attachment before sending. Limit the PHI to what the task needs. Train staff on patient-requested email and alternate communication procedures.

What to Do After a Possible HIPAA Incident

Don’t decide alone that an event is harmless or reportable. Preserve the facts, stop further access when possible and notify the practice’s privacy or security lead. Follow the written incident process.

  1. Record what happened, when it happened and how it was found.
  2. Identify the PHI involved and who may have received or viewed it.
  3. Limit further access or disclosure without destroying evidence.
  4. Notify the person responsible for the practice’s incident process.
  5. Document the assessment and any steps taken to reduce risk.
  6. Use the HHS Breach Notification Rule and legal guidance to decide whether notice is required.

An impermissible use or disclosure is presumed to be a breach unless the covered entity or business associate documents a low probability that PHI was compromised. The assessment reviews the information involved, the unauthorized person, whether the information was acquired or viewed and how much the risk was reduced.

Frequently Asked Questions About Dental HIPAA Violations

What are examples of HIPAA violations in dental offices?

Examples include accessing a chart without a work reason, disclosing PHI to the wrong person, missing a required BAA, failing to provide the privacy notice and leaving known electronic security risks unresolved.

Are all dentists and dental offices covered by HIPAA?

HIPAA applies to a dentist or dental practice that meets the covered-entity definition. HHS includes dentists who transmit health information electronically for a transaction covered by an HHS standard. An entity outside the covered-entity or business-associate definitions doesn’t have to follow HIPAA, though other privacy laws may apply.

How can you violate HIPAA in dentistry?

A dental practice can violate HIPAA through an impermissible use or disclosure, missing safeguards, incomplete policies, weak access control or failure to follow required notice and response procedures. The exact rule depends on the facts.

What happens if a dental office violates HIPAA?

OCR may close a matter after intake, provide technical help, require corrective action or pursue a settlement or civil money penalty. Some cases can be referred for criminal investigation. The outcome depends on the conduct, harm, knowledge, response and other facts.

Do dental offices need business associate agreements?

A covered dental practice needs a BAA when a vendor or contractor meets the business associate definition. The agreement usually must be in place before the business associate receives PHI. HHS lists exceptions, so review the service instead of assuming every vendor needs one.

Does HIPAA require encrypted email for every patient message?

HHS doesn’t ban unencrypted email for every patient communication. The provider must apply reasonable safeguards and meet the Security Rule when transmitting ePHI. A patient may also request a reasonable alternate communication method.

Review These Eight Areas in Your Practice

Check the practice’s training records, policy set, vendor files, privacy notice, risk analysis, corrective-action list, access controls and email process. Assign each gap to a person and record a due date.

Related reading:

Join 1400+ dental professionals, shop from your favorite
suppliers, compare prices instantly, and save over $17,000/year

Try our platform free for 14 days.

Get the latest ZenOne updates and product launches in your inbox

Don't miss the latest news!

Receive exclusive offers and news straight to your inbox!



    Let's discover how we can help you

    Tiger Safarov

    Hi, I'm Tiger, the CEO at ZenOne, and I'm happy to personally ensure your success with ZenOne. Send me your latest invoice or a statement for a Free Savings Analysis.

    Ask me a question: