Dentrix HIPAA Compliance: Essential Updates Every Dental Team Should Know

LINDA HARVEY, RDH, MS, Risk Manager
Linda is a veteran risk manager and strategic advisor to dental practices, group practices, and DSO's who want to anticipate risk, navigate emerging threats, and elevate their compliance expertise.
HIPAA compliance isn't usually the topic that gets dental teams excited, but after recording a recent podcast with compliance expert Linda Harvey, I was reminded just how important these conversations really are.
Listen on Apple Podcasts:
Listen on Soundcloud:
Technology has changed dramatically over the past decade. We communicate with patients differently, collect information electronically, and rely on our practice management software more than ever before. But while technology continues to evolve, many HIPAA requirements remain the same.
That means it's up to us to make sure our systems, policies, and Dentrix workflows evolve alongside today's compliance expectations.
Here are some of my biggest takeaways from our conversation.
HIPAA Compliance Is More Than Just Paperwork
When HIPAA first became a requirement, many dental teams viewed it as another stack of paperwork for patients to sign.
Today, HIPAA is much more than that.
It's about protecting patient privacy while creating consistent systems that help your team respond appropriately in everyday situations.
Whether you're using Dentrix or another practice management system, your office should have documented processes for:
- Patient privacy acknowledgements
- Release of information requests
- HIPAA training
- Security documentation
- Notice of Privacy Practices updates
Strong compliance starts with consistent office systems. If you're building standardized workflows for your team, you'll also find my article on Building Rock-Solid Dentrix Workflows: Daily, Weekly, and Monthly Systems That Actually Work helpful. Creating repeatable systems makes compliance much easier because everyone follows the same process instead of relying on memory.
One important reminder Linda shared is that HIPAA documentation should be retained for six years, even if other record retention requirements differ in your state.
If you're updating your Notice of Privacy Practices, don't overwrite your previous version. Instead, save each revision so you maintain a historical record of your compliance documents.
Be Prepared for Sensitive Patient Privacy Situations
One of the stories we discussed involved a married couple.
The wife specifically requested that no information, including appointments or treatment, be shared with her husband.
Situations like this are uncommon, but they do happen.
If a patient requests additional privacy protections, your team needs a system to document those requests clearly within Dentrix so everyone on the team understands the restrictions.
Consistency is everything.
Without proper documentation, it's easy for an innocent conversation to become a HIPAA violation.
Watch it on YouTube:
Don't Forget About Patients Turning 18
This was one of my favorite practical tips from the interview.
When a patient turns 18, they're legally an adult.
That means it's time to review your HIPAA documentation.
I recommend adding a quick reminder to your morning huddle to identify patients who recently turned 18. That gives your team an opportunity to:
- Have the patient sign their own HIPAA acknowledgement.
- Update consent forms.
- Confirm who the practice is authorized to communicate with.
- Document parents or guardians who may still discuss financial matters or appointments.
It's a simple step that can prevent a lot of confusion later.
Add HIPAA to Your Morning Huddle
One suggestion Linda shared immediately made it onto my own morning huddle checklist.
Include a brief Safety and Compliance discussion during your team meetings.
It doesn't need to take long.
Spend just a few minutes reviewing items such as:
- HIPAA reminders
- Compliance updates
- Water testing
- Sterilization documentation
- Security procedures
- Upcoming policy changes
If you're looking for more ideas to structure your daily routines, I recommend reading Best Practices for Your Daily Reports and Workflow. Daily systems create consistency, reduce mistakes, and help your entire team stay accountable
These small conversations help build a culture of compliance instead of treating HIPAA as something you only think about once a year.
Make Your Notice of Privacy Practices Easy to Find
Another excellent takeaway involved your practice website.
Many offices bury their HIPAA Notice of Privacy Practices in the website footer under "Privacy Policy."
Those are actually two different documents.
Linda recommends placing your Notice of Privacy Practices in an easy-to-find location, such as your New Patient section alongside your patient forms.
Your website's Privacy Policy, which addresses website cookies and visitor data, can remain in the footer.
Making these documents easy to locate improves both patient experience and compliance.
Small Compliance Habits Make a Big Difference
One thing I appreciate about Linda's approach is that she focuses on practical, everyday habits rather than creating fear around HIPAA.
Compliance doesn't have to feel overwhelming.
It starts with simple systems:
- Save previous HIPAA documents instead of replacing them.
- Review new compliance updates regularly.
- Update patient forms when regulations change.
- Train your team consistently.
- Build compliance reminders into your existing workflows.
These small habits reduce risk and create confidence across your entire dental team.
Another way to strengthen compliance is by reducing paper-based processes. My article Stop Printing Reports in Dentrix: Smarter Workflows for a More Efficient Dental Practice explains how using Dentrix's live reports and electronic workflows helps improve documentation, accuracy, and overall efficiency.
If you're using Dentrix, combining strong compliance systems with organized documentation helps your practice run more efficiently while protecting both your patients and your team.
Take the Next Step
HIPAA compliance isn't just about avoiding penalties. It's about protecting your patients, building trust, and creating consistent systems your team can follow every day.
If you'd like help optimizing your Dentrix workflows, implementing electronic forms, or building stronger office systems that support both efficiency and compliance, I'd love to help.
Schedule a discovery call, and together we'll identify opportunities to streamline your practice while making the most of your Dentrix software.
Frequently Asked Questions
What HIPAA changes should dental practices know about?
Dental practices should stay current with HIPAA updates, including revisions to the Notice of Privacy Practices, documentation requirements, and patient privacy protections. Regular policy reviews help maintain compliance.
Should patients sign a new HIPAA form when they turn 18?
Yes. Once a patient turns 18, they become legally responsible for their own healthcare decisions. Practices should have them complete updated HIPAA authorization forms and document who may receive information about their care.
How long should HIPAA documents be retained?
HIPAA-related documents—including policies, training records, Notices of Privacy Practices, and acknowledgements—should generally be retained for six years.
Where should a Notice of Privacy Practices appear on a dental website?
It should be easy for patients to locate, ideally within the New Patient section or alongside patient forms—not hidden in the website footer.
How can Dentrix help support HIPAA compliance?
Dentrix supports HIPAA compliance by helping practices securely document patient information, manage electronic forms, organize patient communication, and maintain consistent workflows that protect patient privacy.
Stay connected with news and updates!
Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.
We hate SPAM. We will never sell your information, for any reason.