Prerequisites
- A designated privacy officer and security officer for each PC (often the same person, often DSO-provided)
- The DSO–PC BAA executed, see Put a BAA in place
- An inventory of every system and vendor that touches PHI, starting with the PMS, imaging software, and attachment vendor
Who is responsible for what
Business associates are directly liable. Since the HITECH Act and the 2013 Omnibus Rule, your DSO has independent regulatory obligations, its own risk analysis, safeguards, training, and breach reporting. It is not merely contractually exposed through the BAA.1
The six components
1
Security risk analysis, do this one first
This is required, and its absence is among the most frequently cited findings in OCR enforcement. It must be an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI.A right-sized version:
- Inventory ePHI across every system, device, and location where it resides. Include the PMS, imaging server, sensor-connected operatory workstations, attachment repository, clearinghouse portal, backups, and analytics warehouse.
- Identify threats and vulnerabilities per asset
- Assess likelihood and impact
- Document current safeguards
- Rank residual risk
- Write a remediation plan with owners and dates
- Update annually and on material change, new PMS, new location, new entity
2
Policies
A minimum set, actually written and actually followed:
- Notice of Privacy Practices (and it must be provided to patients)
- Uses and disclosures; minimum necessary
- Patient rights: access, amendment, accounting of disclosures, restrictions
- Access control and workforce authorization
- Device and media controls, including a policy for intraoral photos and other PHI on personal devices
- Password and authentication standards
- Encryption
- Audit logging and review
- Incident response and breach notification
- Sanctions for workforce violations
- Business associate management
- Retention and destruction
3
Training
Train both entities’ workforces at onboarding and annually. Record completion dates so you can demonstrate who received the training.Include role-specific content: front desk staff face different risks than billers, who face different risks than the clinical team.
4
BAA inventory
Every vendor handling PHI, with execution dates, breach notification windows, and review dates. The dental stack is longer than it looks:
- The PMS vendor, for any cloud-hosted or vendor-accessible system
- The imaging software vendor, radiographs are PHI
- The attachment vendor, whose repository may hold radiographs, periodontal charts, and narratives for payer retrieval under an NEA-number workflow
- The clearinghouse, and the RCM vendor if billing is outsourced
- Patient-communication, recall, and online-scheduling tools
- The membership plan platform, if it holds patient data
- Mailing and e-statement vendors
5
Breach response plan
Written, and tested at least once.Under the Breach Notification Rule, an impermissible use or disclosure of unsecured PHI is presumed to be a breach unless you demonstrate a low probability of compromise through a documented risk assessment considering the specified factors.3
State breach laws apply on top and are frequently stricter and faster. A multi-state group faces the union of them.Confirm the BAA’s notification window is short enough for the PC to meet its own deadline.
6
Security basics
The controls that prevent most incidents:
- Multi-factor authentication wherever available. The 2024 Change Healthcare compromise reportedly involved a remote-access service without MFA. The resulting outage affected dental practices, and the ADA publicized emergency funding for dentists.4
- Encryption in transit and at rest, including laptops and mobile devices
- Role-based access, reviewed quarterly
- Prompt offboarding, terminated employees’ access removed same-day
- Audit logging, with periodic review
- Patching on a defined cadence, including imaging servers and operatory workstations
- Backups, tested by actually restoring
- Email security, phishing is the most common entry point
Where enforcement actually comes from
Most enforcement follows a complaint or a breach report, not a random audit. The recurring patterns:- Missing or inadequate security risk analysis
- No BAA with a vendor handling PHI
- Impermissible disclosures, including responding to an online review with clinical detail
- Failure to provide patients access to their own records, including radiographs requested for a second opinion or transfer to a new dentist
- Insufficient access controls, including former employees retaining access
- Unencrypted lost or stolen devices
DSO-PC-specific items
- A BAA per PC. Each professional entity is a separate covered entity.
- Segregate records across PCs in a shared PMS instance. A dentist in one state generally has no treatment relationship justifying access to another PC’s patients.
- Document who serves as each PC’s privacy officer, especially where the DSO provides the person.
- Never put PHI in bank memo fields. The business-associate exclusion for financial institutions covers payment processing, not the receipt of clinical information.
Verify it worked
- Security risk analysis completed, documented, with a remediation plan
- Policy set written and accessible
- Training delivered and documented, both entities
- BAA inventory complete, including PMS, imaging, attachments, clearinghouse, and analytics infrastructure
- Breach response plan written and tested
- MFA everywhere; encryption in transit and at rest
- Access reviewed quarterly; offboarding same-day
- A BAA per PC
- Privacy officer designated per covered entity
- Annual review calendared
Sources
- HITECH Act, Pub. L. 111-5, div. A, tit. XIII; HIPAA Omnibus Rule, 78 Fed. Reg. 5566 (Jan. 25, 2013). HHS OCR, Business Associates.
- HHS/ONC, Security Risk Assessment Tool.
- 45 C.F.R. §§ 164.400–414. HHS OCR, Breach Notification Rule.
- ADA News, Funding assistance available to dentists impacted by Change Healthcare cyberattack (Apr. 2024).