Do I need HIPAA forms for my dental office?
Almost certainly yes. Your dental office needs HIPAA forms if it is a covered entity, and it becomes one the moment any claim, eligibility check, or claim attachment is transmitted electronically, by you or by a billing service acting for you (45 CFR 160.103). Nearly every dental office meets that test.
Not sure your office meets it? Walk the covered-entity test, profession by profession, then come back for the checklist below.
Researched and written by Larry Osakwe · Last verified July 15, 2026
Checked against the current 45 CFR text. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
The eight documents your dental office needs
This is the HIPAA compliance checklist for a dental office: the same document set every covered practice must be able to produce, flavored with the vendors and records a dental office actually has. Each item cites the rule that requires it, so you can verify any of it against the regulation.
Notice of Privacy Practices
The notice you give every patient, post in a clear and prominent place in your office, and publish on your website, describing how the practice uses and discloses patient information.
45 CFR § 164.520
NPP acknowledgment of receipt
The form documenting your good-faith effort to obtain each patient's written acknowledgment that they received the notice; the front desk files it at the first visit.
45 CFR § 164.520(c)(2)
Patient authorization + rights request forms
The written-permission form for uses HIPAA does not already permit, plus request forms for access, amendment, restrictions, and an accounting of disclosures.
45 CFR § 164.508; §§ 164.522–164.528
Business Associate Agreements + vendor register
A signed BAA with every vendor that touches patient data, tracked in a register. For a dental office that typically means your practice-management and imaging software (Dentrix, Eaglesoft, Open Dental), your clearinghouse or billing service, cloud backup, email, and IT support.
45 CFR § 164.502(e); § 164.504(e)
Security Risk Analysis
The documented, accurate and thorough assessment of risks to your electronic patient data, imaging servers and X-ray systems included: the most-cited deficiency in OCR enforcement.
45 CFR § 164.308(a)(1)(ii)(A)
Privacy & security policies with a training log
Your written rulebook for access, minimum-necessary use, and safeguards, plus documented workforce training and a sanctions policy, covering everyone from hygienists to the front desk.
45 CFR § 164.530(b); § 164.308(a)(5); § 164.316
Breach notification procedure + breach log
What to do when something goes wrong: notification without unreasonable delay and no later than 60 calendar days after discovery, plus your state's breach statute answered specifically.
45 CFR §§ 164.400–414
Privacy Official & Security Official designation
Names, in writing, the person responsible for your privacy policies and the person responsible for security; in a small dental office both are usually the owner-dentist.
45 CFR § 164.530(a); § 164.308(a)(2)
The full annotated table of contents, with what each document does and an honest binder-vs-software comparison, is on the HIPAA binder template page.
Is a dental practice a HIPAA covered entity?
Almost always. A dental practice becomes a covered entity the moment it transmits any covered transaction electronically (45 CFR 160.103), and nearly every office files electronic claims, checks eligibility electronically, or sends claim attachments such as X-rays to payers. Even an all-paper office is covered when its billing service or clearinghouse converts its claims to electronic form. The rare exception is a purely paper practice where no covered transaction ever moves electronically, by it or for it.
The covered-entity test, profession by professionDo patients have to sign the NPP acknowledgment?
No. Patients are never required to sign, and you cannot refuse treatment over a refusal. What 45 CFR 164.520(c)(2) requires of you is a good-faith effort to obtain each patient's written acknowledgment of receipt, and, when you cannot get it, documentation of the effort and the reason. A signed form or a documented refusal both satisfy the rule; a blank chart satisfies nothing, which is why the acknowledgment form belongs in your intake packet.
What is the difference between HIPAA and OSHA for a dental office?
They are separate laws from separate agencies with separate paperwork. HIPAA (HHS) protects patient information: the notice, authorizations, BAAs, and security documentation above. OSHA (Department of Labor) protects your team: the bloodborne pathogens standard (29 CFR 1910.1030) requires a written exposure control plan and training, and hazard communication (29 CFR 1910.1200) covers the chemicals in your operatories. A HIPAA binder satisfies none of your OSHA obligations, and vice versa; a dental office needs both document sets.
Does Dentrix, Eaglesoft, or Open Dental make my office HIPAA compliant?
No. Your practice-management software is a business associate: it should sign a BAA and secure the data it holds, but it does not supply your Notice of Privacy Practices, your written policies, your Security Risk Analysis, your training log, or your breach procedure. The software secures data inside its walls; the compliance documentation for the whole practice is yours to produce and maintain.
Do I need a BAA with my dental lab?
It depends on the relationship, and it is worth getting right. Disclosing patient information to a lab so it can fabricate a crown can qualify as a treatment disclosure rather than a business-associate relationship, while a lab or portal performing services on your behalf beyond treatment generally does need a BAA. Evaluate each lab, imaging partner, and specialist relationship on its facts, and when in doubt, paper it correctly: a signed BAA you did not strictly need costs nothing, the missing one is what shows up in enforcement.
Don’t skip the training log
Two rules make training a documentation requirement, not a nice-to-have. The Privacy Rule (45 CFR 164.530(b)) requires you to train all members of your workforce on your privacy policies: new hires within a reasonable period after they join, and everyone affected within a reasonable period after a material policy change, with the training documented. The Security Rule (45 CFR 164.308(a)(5)) separately requires a security awareness and training program for the entire workforce, management included, with periodic security updates.
Neither rule names a fixed interval, so an annual all-hands pass, logged with names and dates, is how small practices evidence both: it catches new hires, refreshes everyone else, and pairs naturally with the annual review of your Security Risk Analysis. In a dental office the log must cover everyone who touches patient information, which means associates, hygienists, assistants, and the front desk, not just the owner.
Get the documents done
The dental binder
Every document above, built to order for your office, state, and software stack.
See the full template
The annotated binder table of contents, document by document.
Generate your NPP
Build your Notice of Privacy Practices now and see it before you pay.
See a sample first
Real excerpts from a delivered binder, citations included.
Opening a dental office? The HIPAA + OSHA Binder Bundle covers both document sets in one order for $299 ($328 separately): the full HIPAA binder above plus the OSHA binder, exposure control plan and training documentation included.
Sources
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- www.ecfr.gov/current/title-29/subtitle-B/chapter-XVII/part-1910/subpart-Z/section-1910.1030
- www.ecfr.gov/current/title-29/subtitle-B/chapter-XVII/part-1910/subpart-Z/section-1910.1200
Last verified July 15, 2026. Educational self-help information, not legal advice and not a covered-entity determination for any specific practice. Whether HIPAA applies to your office turns on its actual billing arrangements; confirm with the sources above and, where appropriate, a qualified attorney. State law may add stronger requirements.
Every HIPAA document your dental office needs, done for you
The complete binder, built to order for your office and state, with every policy citing the rule that requires it.
See the dental binder and pricing