Security & compliance

HIPAA Statement

Dental practices trust DentAI with sensitive patient information, so protecting it is central to how we build. This statement describes how DentAI approaches the Health Insurance Portability and Accountability Act (HIPAA) and the safeguards we apply when handling protected health information (PHI) on behalf of the practices we serve. Please confirm each practice below reflects your current deployment before publishing.

Our role under HIPAA

When a dental practice (a HIPAA Covered Entity) uses DentAI to answer calls, schedule appointments, verify patients, or handle related workflows, DentAI acts as a Business Associate. We process PHI only to provide the services the practice has engaged us for, and only as permitted by our agreement with that practice and by law.

Business Associate Agreements (BAAs)

We make a Business Associate Agreement available to every practice that uses DentAI to process PHI. The BAA governs our permitted uses and disclosures of PHI, our safeguard obligations, breach-notification commitments, and the handling of PHI at the end of the engagement. We also enter into agreements with our own subcontractors that handle PHI, so protections extend down the chain.

Encrypted data transmission

PHI is encrypted in transit using industry-standard protocols. Connections between DentAI, your practice management system, and our infrastructure are secured to protect data as it moves between systems.

Secure access to your practice management system

DentAI connects to your PMS (such as Open Dental, Curve Dental, or CareStack) through secure, scoped access. We request only the access needed to perform the workflows you enable, and access is managed through controlled credentials rather than broad, shared logins.

Role-based access controls

Access to systems and PHI is governed by the principle of least privilege. Team members and system components receive only the access required for their function, and access is reviewed and adjusted as roles change.

Audit logging

Actions taken within the platform are logged so that access to and activity involving PHI can be reviewed. Audit logs support monitoring, investigation, and accountability.

Patient verification

Before sharing sensitive information, DentAI verifies the patient's identity using the method you configure, so PHI is disclosed only to the right person.

Administrative and physical safeguards

Beyond technical controls, we maintain administrative safeguards — such as workforce practices and vendor oversight — and rely on infrastructure providers that maintain physical and environmental protections for the facilities where data is hosted.

Breach notification

If a breach of unsecured PHI affecting a practice's data were to occur, we would notify the affected practice in accordance with our Business Associate Agreement and applicable law, so the practice can meet its own notification obligations.

A note on certifications

HIPAA does not provide an official government certification, and we describe our practices rather than claim credentials we do not hold. Where we obtain formal attestations or certifications, we will state them specifically. We are happy to discuss our security posture in detail during your evaluation.

Contact

To request a Business Associate Agreement or discuss our HIPAA-ready practices, contact us at support@dentaicall.com.

Call us