A dental practice that submits claims or checks eligibility electronically is a HIPAA covered entity โ and the office manager usually runs the compliance program that follows.
HHS's own summaries lay out what's required: a business associate agreement with the billing service and PMS vendor, a privacy official, workforce training, a notice of privacy practices, minimum-necessary habits at the front desk, patient rights requests, and a 60-day breach clock. (OSHA is separate, not covered here.)
Why a dental practice is a HIPAA covered entity
HHS's Privacy Rule summary states it directly: "Every health care provider, regardless of size, who electronically transmits health information in connection with certain transactions, is a covered entity." Those transactions "include claims, benefit eligibility inquiries, referral authorization requests, or other transactions for which HHS has established standards under the HIPAA Transactions Rule" โ which covers the everyday work of submitting a claim or checking what a plan will pay.
Size doesn't matter, and neither does who presses send: "The Privacy Rule covers a health care provider whether it electronically transmits these transactions directly or uses a billing service or other third party to do so on its behalf." One thing that doesn't automatically trigger coverage: "Using electronic technology, such as email, does not mean a health care provider is a covered entity; the transmission must be in connection with a standard transaction." A one-dentist practice that files claims electronically is covered on the same terms as a large group.
Being covered draws a line most people don't expect: almost everything a covered entity discloses is discretionary, not mandatory.
HHS's summary is specific that "A covered entity must disclose protected health information in only two situations: (a) to individuals (or their personal representatives) specifically when they request access to, or an accounting of disclosures of, their protected health information; and (b) to HHS when it is undertaking a compliance investigation or review or enforcement action." Everything else โ sharing for treatment, payment, or health care operations โ is permitted, not required, and governed by the minimum-necessary standard covered below.
OSHA isn't in this article
Business associate agreements: the billing service, PMS vendor, and IT provider
A business associate is, in HHS's words, "a person or organization, other than a member of a covered entity's workforce, that performs certain functions or activities on behalf of, or provides certain services to, a covered entity that involve the use or disclosure of individually identifiable health information." Claims processing and billing are the named example.
A practice's outside billing service, its practice-management software vendor, and its IT support provider are typically business associates when their work touches PHI โ "typically," because HHS's examples are general, not written for dentistry specifically.
The Security Rule requires a written agreement before that access begins: "Before permitting a business associate to create, receive, maintain, or transmit ePHI, a regulated entity must have in place a contract or other written arrangement." That agreement has to do real work โ it must "Provide that the business associate will comply with the Security Rule," "Commit the business associate to ensuring that any subcontractors that create, receive, maintain, or transmit ePHI on behalf of the business associate agree to comply with the Security Rule by entering into a business associate agreement with the subcontractor," and "Obligate the business associate to report to the covered entity any security incident of which it becomes aware, including breaches of unsecured PHI as required by the Breach Notification Rule." For where PHI actually moves through the billing side of that relationship, see how dental insurance verification works.
The privacy official, and training the workforce
Two administrative duties sit at the center of the Privacy Rule: "A covered entity must designate a privacy official responsible for developing and implementing its privacy policies and procedures, and a contact person or contact office responsible for receiving complaints and providing individuals with information on the covered entity's privacy practices." In most dental practices, that's the office manager, whether or not the title says so.
Everyone who touches patient information has to be trained on the practice's privacy policies โ "A covered entity must train all workforce members on its privacy policies and procedures, as necessary and appropriate for them to carry out their functions." "Workforce" is broader than just paid staff: it "include[s] employees, volunteers, trainees, and may also include other persons whose conduct is under the direct control of the entity (whether or not they are paid by the entity)." Training without teeth isn't enough โ the rule also requires that "A covered entity must have and apply appropriate sanctions against workforce members who violate its privacy policies and procedures or the Privacy Rule." HHS's summary says to train workforce members; it does not set a frequency, and this article doesn't invent one.
The paperwork behind all of this has its own shelf life โ separate from the six-year lookback patients can request on an accounting of disclosures, covered below under patient rights.
HHS's administrative requirements state that "A covered entity must maintain, until six years after the later of the date of their creation or last effective date, its privacy policies and procedures, its privacy practices notices, disposition of complaints, and other actions, activities, and designations that the Privacy Rule requires to be documented." That's the policies themselves, the notices handed to patients, and the complaint file โ not the record of who saw what.
The notice of privacy practices and the acknowledgement
The document patients sign at their first visit exists because the rule requires it: "Each covered entity, with certain exceptions, must provide a notice of its privacy practices," describing how the practice uses and discloses PHI, the practice's duties, and patients' rights โ including the right to complain to HHS.
Getting a signature on file isn't optional busywork, either: "A covered health care provider with a direct treatment relationship with individuals must make a good faith effort to obtain written acknowledgement from patients of receipt of the privacy practices notice," and "The provider must document the reason for any failure to obtain the patient's written acknowledgement."
There's one carve-out worth knowing: "The provider is relieved of the need to request acknowledgement in an emergency treatment situation." Outside of an emergency, a missing acknowledgement means a documented reason, not a shrug.
Minimum necessary at the front desk
The rule that governs how much PHI gets shared for any given purpose is minimum necessary: "A covered entity must make reasonable efforts to use, disclose, and request only the minimum amount of protected health information needed to accomplish the intended purpose of the use, disclosure, or request." It cuts against defaulting to the whole chart: "a covered entity may not use, disclose, or request the entire medical record for a particular purpose, unless it can specifically justify the whole record as the amount reasonably needed for the purpose." It doesn't apply to every disclosure, though โ treatment-related requests between providers, disclosures to the patient, and a few other categories are excluded from the standard entirely.
Day to day, this is what a sign-in sheet, a schedule left face-up, or a hallway conversation actually tests.
HHS's own safeguard examples are concrete: "such safeguards might include shredding documents containing protected health information before discarding them, securing medical records with lock and key or pass code, and limiting access to keys or pass codes." A brief, incidental disclosure โ someone in the waiting room overhearing a name โ isn't automatically a violation: "A use or disclosure of this information that occurs as a result of, or as 'incident to,' an otherwise permitted use or disclosure is permitted as long as the covered entity has adopted reasonable safeguards as required by the Privacy Rule, and the information being shared was limited to the 'minimum necessary.'"
Patient rights the front desk fields
Four rights show up as requests at the desk, not as abstractions.
Access: "individuals have the right to review and obtain a copy of their protected health information in a covered entity's designated record set." Amendment: "The Rule gives individuals the right to have covered entities amend their protected health information in a designated record set when that information is inaccurate or incomplete" โ and if the practice denies the request, "covered entities must provide the individual with a written denial and allow the individual to submit a statement of disagreement for inclusion in the record."
Accounting of disclosures: "Individuals have a right to an accounting of the disclosures of their protected health information by a covered entity or the covered entity's business associates," covering up to six years back.
Confidential communications: "Health plans and covered health care providers must permit individuals to request an alternative means or location for receiving communications of protected health information." HHS's own examples are the ones a desk actually handles โ "an individual may request that the provider communicate with the individual through a designated address or phone number," or "that the provider send communications in a closed envelope rather than a post card."
The Security Rule: risk analysis, and device and media controls
The Security Rule covers a narrower slice than the Privacy Rule: "Unlike the Privacy and Breach Notification Rules, the Security Rule does not apply to PHI that is maintained or transmitted on paper or verbally" โ it's about electronic PHI (ePHI) specifically.
Everything in it flows from one starting point: "The Administrative Safeguards provisions in the Security Rule require a regulated entity to perform an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the regulated entity." A practice also has to name someone accountable for it: "A regulated entity must designate a security official responsible for developing and implementing the policies and procedures required by the Security Rule."
Two physical safeguards land squarely on office operations.
Workstations: "A regulated entity must implement policies and procedures to specify proper use of, and physical safeguards for, workstations that can access ePHI." Devices and media: "A regulated entity must have in place policies and procedures that govern the receipt and removal of hardware and electronic media that contain ePHI into and out of a facility," down to final disposition โ and separately, "The regulated entity must also implement procedures for removing ePHI from electronic media before the media are made available for re-use." That covers the old front-desk computer or a returned laptop, not just backup drives.
HHS built in flexibility on how: some implementation specifications are "required" and must be adopted as written, while others are "addressable," meaning the practice determines whether it's reasonable and appropriate and documents that decision either way โ the rule doesn't hand down one specific technology for either category, and this article doesn't invent one.
The breach clock: what counts, and how fast notice has to go out
HHS defines a breach broadly and then presumes the worst: "A breach is, generally, an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information," and "An impermissible use or disclosure of protected health information is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised" through a four-factor risk assessment: the nature and extent of the PHI involved, who received or used it, whether it was actually acquired or viewed, and how far the risk has since been mitigated.
Three narrow exceptions exist โ good-faith, in-scope access by a workforce member; an inadvertent disclosure between two people at the practice who were both already authorized to see the information; and a good-faith belief the recipient couldn't have retained it.
Once something counts as a breach, the clock is specific.
Individual notice goes out "without unreasonable delay and in no case later than 60 days following the discovery of a breach." A breach affecting "more than 500 residents of a State or jurisdiction" also requires media notice on the same 60-day clock.
HHS itself gets notified on two tracks: "If a breach affects 500 or more individuals, covered entities must notify the Secretary without unreasonable delay and in no case later than 60 days following a breach," while "If, however, a breach affects fewer than 500 individuals, the covered entity may notify the Secretary of such breaches on an annual basis." A business associate is on the same clock toward the practice: "A business associate must provide notice to the covered entity without unreasonable delay and no later than 60 days from the discovery of the breach." And the paperwork obligation exists whether or not a breach ever happens: "For example, covered entities must have in place written policies and procedures regarding breach notification, must train employees on these policies and procedures, and must develop and apply appropriate sanctions against workforce members who do not comply with these policies and procedures."
Where this sits in the office manager's job
None of this is a personal credential โ see do you need a license to be a dental office manager for why the role itself isn't licensed.
HIPAA compliance is a practice-level obligation that, in most offices, lands on whoever runs the front office: keeping the business associate agreements current, tracking workforce training and acknowledgements, maintaining the notice of privacy practices, and knowing what the breach clock requires if something goes wrong โ one more piece of the broader dental office manager job.
It sits alongside, but separate from, the OSHA obligations the same role usually owns โ two different federal compliance programs, run by the same person.
And it's a different question from how PHI moves once a claim goes out the door or a treatment plan gets presented; see how to read a dental EOB and presenting treatment plans and financing options for those adjacent workflows.
This is general information, not legal advice

