Does HIPAA Apply to Dentists?

HIPAA applies to dentists that qualify as – or who are employed by – HIPAA covered entities and to dentists that provide services to or on behalf of a HIPAA covered entity as a business associate. However, what standards of HIPAA apply to dentists can vary depending on a dentist’s HIPAA status and whether a dental practice is part of an affiliated entity or a Dental Service Organization (DSO) under third party control.

Most dental practices qualify as HIPAA covered entities because they meet the definition of a healthcare provider in §160.103 of the HIPAA General Administrative Requirements and conduct – or subcontract – electronic healthcare transactions for which the Secretary for Health and Human Services has adopted standards in Part 162 of the HIPAA Administrative Simplification Regulations.

Dentists who own – or who are employed by – a HIPAA covered dental practice are required to comply with all applicable requirements, standards, and implementation specifications of the HIPAA Administrative Simplification Regulations. The same can apply to dentists who do not qualify as HIPAA covered entities in their own right, but who provide services for or on behalf of a dental practice as a HIPAA business associate.

However, what requirements, standards, and implementation specifications of HIPAA apply to dentists can vary depending on a dentist’s “HIPAA status” and on what HIPAA-covered activities are subcontracted out. For example, a sole proprietor dentist will have more HIPAA compliance obligations than a dentist who is a member of a dental practice’s workforce, but may subcontract claims and billing operations to a Third Party Administrator.

How Does HIPAA Apply to Dentists Who Are Sole Proprietors?

The best way to explain what standards of HIPAA apply to dentists with different HIPAA statuses is to start by explaining how does HIPAA apply to dentists who are sole proprietors. This is because a sole proprietor who does not subcontract operations to a third party is responsible for complying with all applicable requirements, standards, and implementation specifications of the HIPAA Administrative Simplification Regulations.

This means the sole proprietor dentist is responsible for implementing safeguards to protect the privacy of Protected Health Information (PHI) and the security of electronic PHI, developing and distributing Notices of Privacy Practices, responding to patients who exercise their HIPAA rights, and entering into Business Associate Agreements with business partners who have access to PHI created, received, stored, or transmitted by the dentist.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

If the sole proprietor dentist employs receptionists or other non-medical members of the workforce, they must provide HIPAA training on policies and procedures applicable to the workforce members’ functions and a security awareness training program. If a non-medical member of the workforce is responsible for dealing with insurance claims and billing, they must also be trained on the standards for HIPAA covered transactions.

Finally, as the sole proprietor dentist is both the HIPAA Privacy Office and the HIPAA Security Officer for the dental practice, they are responsible for documenting policies and procedures, conducting risk assessments, and notifying patients and HHS’ Office for Civil Rights of a data breach or other impermissible disclosure of PHI – participating in compliance reviews and investigations when necessary.

The HIPAA Rules for Dentists who are Workforce Members

The HIPAA rules for dentists who are workforce members are mostly determined by the dental practice’s HIPAA Privacy Officer. Under §164.530(i) of the HIPAA Privacy Rule, the HIPAA Privacy Officer must develop and implement policies and procedures that are designed to safeguard PHI from any intentional or unintentional uses or disclosures that violate the HIPAA Privacy Rule, and train workforce members on the policies and procedures.

However, under §164.530(e) of the HIPAA Privacy Rule, covered entities are required to impose sanctions on workforce members “who fail to comply with the privacy policies and procedures of the covered entity or the requirements of this subpart [the HIPAA Privacy Rule] or subpart D of this part [the HIPAA Breach Notification Rule]”. This means that all privacy standards in HIPAA apply to dentists regardless of the content of HIPAA training.

Dentists who are workforce members are also required to participate in the dental practice’s security awareness training program – even if they have no access to electronic PHI. This is because workforce members could, in theory, connect an infected personal device to the practice’s network and introduce malware that could permit a cyber attacker to create a backdoor into the network and access databases containing PHI.

With regards to the HIPAA rules for dentists who are workforce members, it is important to note the term “workforce members” not only applies to employees of the dental practice. A dentist who volunteers, studies, or temps at a dental practice is considered a workforce member and subject to the practice’s HIPAA rules for dentists when their conduct is under the control of the dental practice, whether or not they are paid by the dental practice.

Hybrid Entities and Dentist Business Associates

In the context of does HIPAA apply to dentists, some dentists do not qualify as HIPAA covered entities because they work in an environment in which HIPAA does not apply. For example, in public schools, students’ medical records are protected by the Family Education Rights and Privacy Act (FERPA) rather than HIPAA. In such circumstances, no standards of HIPAA apply to dentists who work exclusively in public schools.

However, if a dentist divides their time between working in a school and working in a sole proprietor private practice, their HIPAA status would be that of a hybrid entity if their work in private practice meets the criteria to qualify as a HIPAA covered entity. In this circumstance, the dentist must comply with all applicable standards of FERPA while working in the school, and all applicable standards of HIPAA while working in private practice.

However, if instead of working in private practice, the school dentist divided their time between working in a school and working in a dental practice as an autonomous dentist, their HIPAA status would be that of a business associate. As a business associate, the school dentist would have to enter into a Business Associate Agreement with the dental practice to safeguard the privacy and security of the practice’s PHI when treating the practice’s patients.

A dentist Business Associate Agreement should be more comprehensive than a typical Business Associate Agreement inasmuch as it should include clauses similar to the HIPAA rules for dentists who are workforce members. However, under this type of Agreement, the dental practice has no authority to impose sanctions on the dentist business associate in the event of a HIPAA violation. They can only terminate the Business Associate Agreement.

Affiliated Entities and Dental Service Organizations (DSOs)

What standards of HIPAA apply to dentists can also be influenced by whether a dentist is part of an affiliated entity or Dental Service Organization under third party control. In these cases, some areas of compliance with HIPAA can either be shared (affiliated entities) or subcontracted (Dental Service Organizations) in order to reduce the compliance burden on sole practitioner dentists and small dental practices.

For example, when a group of legally separate dentists designate themselves as an affiliated entity, the legally separate dentists share the same Notice of Privacy Practices. There will likely be one HIPAA Privacy Officer responsible for developing and implementing privacy policies and procedures, providing HIPAA training, and responding to patients exercising their HIPAA rights, and one team dealing with insurance claims and billing.

With regards to Dental Service Organizations, the nature of the services provided by the Organizations will determine what areas of compliance can be subcontracted to them. For example, some Dental Service Organizations can provide IT services, HR services, and billing services. Others may offer a more comprehensive package that includes marketing, training, and compliance with all applicable licensing and regulatory standards.

Due to the growing number of dentists that choose affiliation and Dental Service Organizations, it is becoming harder to determine what standards of HIPAA apply to dentists when a dentist or dental practice qualifies as a HIPAA covered entity, workforce member, or business associate. Dentists who require further information about their HIPAA compliance obligations are advised to speak with an independent compliance professional.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/