Dental Office Policies and Procedures Manual: What Goes in It
The written programs the law requires, the clinical and front-office protocols worth documenting, and who keeps each chapter current.
A dental office policies and procedures manual is the practice's operating document: OSHA's written programs (the exposure control plan and the hazard communication program), HIPAA privacy and security policies, infection control protocols, radiation-safety paperwork, emergency and exposure-incident procedures, and the front-office workflows your team follows.
Parts of it are legally required to exist in writing; the rest is simply how your office runs.
Here is what belongs in it, who maintains each part, and how to keep it current.
Rules vary by state and change
This guide explains federal rules and the state rules it names, as of the date above.
Employment law and dental-practice rules differ by state and are revised often, so confirm current requirements with your state dental board, labor agency or employment counsel before you act on them.
It is general information, not legal advice.
Employee handbook vs. procedures manual: what each document covers
The employee handbook and the procedures manual are different documents with different jobs.
The handbook is the HR document: paydays, time off, conduct, discipline, benefits and the complaint route.
The procedures manual is the operations and clinical document: how instruments get processed, what happens after an exposure incident, who checks the sterilizer, how a records release goes out the door.
A practice needs both, and each should point to the other instead of repeating it.
The HR side is covered in our employee handbook guide; this page is the manual that sits next to it.
Keep the boundary clean by giving each document a cross-reference line.
The handbook says clinical and safety procedures live in the procedures manual; the manual's front-office chapter says pay and leave questions are answered in the handbook.
Writing a policy twice is how version drift starts: you update one copy, forget the other, and the documents disagree in front of an employee or an inspector.
What goes in the manual is part compliance, part operations.
Some chapters are written programs regulators actually require you to have, and those come first; the rest are protocols no one demands but your Tuesday-morning coverage absolutely does.
The chapters below run in that order.
The required written programs: the exposure control plan and HazCom
Start with the written programs OSHA's rules require, because these are the chapters the rules themselves name.
There is no OSHA standard written specifically for dentistry; OSHA says so itself, and dental offices are covered instead by its general industry standards, principally the Bloodborne Pathogens standard and the Hazard Communication (HazCom) standard.
Which OSHA rules that means for you also depends on where you practice: OSHA lists 22 State Plans, 21 of them states plus Puerto Rico, that cover private-sector as well as state and local government workplaces, and those State Plans must be at least as effective as federal OSHA's and may be more stringent.
A manual copied from a template in another State Plan state can miss requirements your state adds.
The Exposure Control Plan.
Every employer with an employee who has occupational exposure must establish a written Exposure Control Plan designed to eliminate or minimize that exposure.
Three parts give it its structure: the exposure determination, the schedule and method for implementing the standard's requirements, and the procedure for evaluating exposure incidents.
The exposure determination lists the job classifications in which all employees have occupational exposure and those in which some do, naming the tasks involved, and it is made without regard to personal protective equipment.
A copy must be accessible to employees, so keep it where staff can actually reach it during a shift rather than filed away.
It is a living document: review and update it at least annually and whenever new or modified tasks, procedures or positions affect occupational exposure.
The annual review is more than a re-read, because you must document your consideration and implementation of safer medical devices and document that you solicited input from the non-managerial employees who handle direct patient care.
In California, Cal/OSHA's version of the plan must also be reviewed and updated at least annually with a look back at exposure incidents since the previous update.
The written hazard communication program.
Every workplace covered by HazCom must maintain a written program describing how it will meet the labels, safety data sheets and training requirements, including a list of the hazardous chemicals known to be present.
Employees must be told where the written program, the chemical list and the safety data sheets are kept, so state the location in the manual rather than assuming everyone knows.
The standard has one limit worth writing down too: it does not reach consumer products used in the workplace for their intended purpose when the duration and frequency of exposure are no greater than a consumer's.
For the compliance program built on top of these documents β training calendars, who oversees what β our career guide to OSHA in the dental office picks that up, and our OSHA training guide covers when each new hire has to be trained and for how long records are kept.
HIPAA policies and procedures
The Privacy Rule requires a HIPAA covered entity to implement privacy policies and procedures designed to comply with its standards, to change them as needed to comply with changes in the law, and to keep them in written or electronic form.
The rules contemplate practices of different sizes: the policies should be reasonably designed considering the entity's size and activities.
The size-and-activities test means a single-location office's policies are scaled to its own operations rather than copied from a hospital's β but they do need to be genuinely yours, written around how your team touches patient information.
Four contents are easy to miss when the policies get drafted.
First, sanctions: the Privacy Rule requires appropriate sanctions against workforce members who fail to comply with privacy policies, applied and documented, and the Security Rule separately requires a sanction policy for failures to comply with security policies.
Second, a named security official responsible for developing and implementing the security policies.
Third, a risk analysis of potential risks and vulnerabilities to electronic protected health information, which is a required specification, not an optional extra.
Fourth, retention: privacy documentation is kept 6 years from creation or the date last in effect, whichever is later, and Security Rule documentation carries the same 6-year retention, must be made available to the people who implement it, and must be reviewed periodically and updated as needed.
One timing note: HHS published a proposed overhaul of the Security Rule on January 6, 2025, and as of October 7, 2026 it still appeared in the Federal Register as a proposed rule, with no final rule found.
Build your policies to the rule in force; do not treat the proposals as current law.
For the privacy and security program as a whole β training, access changes when staff leave, breach response β our career guide to HIPAA in the dental office covers running it, and our HIPAA training guide covers bringing each new hire inside it.
Clinical protocols: infection control, radiation and emergencies
Infection control.
CDC's Guidelines for Infection Control in Dental Health-Care Settingsβ2003 are archived but still serve as the standard of practice for clinical dentistry, alongside the later CDC recommendations collected in the Summary of Infection Prevention Practices in Dental Settings.
CDC recommends that at least one individual trained in infection prevention β the infection prevention coordinator β be responsible for developing written infection prevention policies and procedures, and that those policies be reassessed on a regular basis, for example annually, or according to state or federal requirements.
These are CDC recommendations rather than federal legal requirements, but they are the skeleton of the clinical chapter: someone owns it, the policies are written, and they get revisited on a schedule.
States can add written-protocol requirements of their own, and the verified example in this guide's research is California: the Dental Board's infection control rule (16 CCR 1005) requires a written protocol for proper instrument processing, operatory cleanliness and management of injuries, made available to all dental health care personnel, plus a copy of the regulation conspicuously posted in each dental office.
The same rule requires at least weekly biological-indicator (spore) testing of every sterilizer, with results documented and kept 12 months, and California employers must keep evidence, for the length of the dental assistant's employment at the facility, that the assistant met and maintained all certification requirements.
If you practice in California, those are manual chapters; if you practice elsewhere, ask your own state dental board what it requires in writing and posted.
Radiation safety.
State radiation-safety written-program requirements were outside this guide's research, so this page cannot tell you what your state demands.
Ask your state's radiation-control program what it requires in writing β machine registration, quality-assurance records and posting are the questions to ask β and file the answers as a manual chapter with the certificates and test records behind it.
Emergencies.
The federal rules put one emergency procedure in writing themselves: the Exposure Control Plan must include the procedure for evaluating exposure incidents, so the needlestick and splash protocol belongs in this manual, not just in someone's head.
For medical emergencies, what each state dental board expects a practice to document was outside this guide's research.
Document what you can defend regardless β who calls 911, who retrieves the emergency kit, where the drugs are, which hospital you direct people to β and ask your state dental board whether it requires emergency-preparedness documentation on top of that.
Front-office procedures worth writing down
Our research turned up no written-program mandate for front-office workflows the way the exposure control plan has one, but the front office is where unwritten policy gets expensive, because it decides what gets billed, collected and rebooked.
Write down the decisions you are already making by habit:
- Scheduling and confirmations. How appointments are confirmed, when a broken appointment is flagged, and what happens after repeated no-shows.
- Payment and collections. When payment is due, what you accept, how a payment plan gets approved, and who signs off on a write-down.
- Insurance workflows. Who verifies benefits, who submits claims, how rejections get worked, and what you tell a patient when coverage differs from the estimate.
- Records requests. Who releases records, what gets copied, and how the authorization is checked β this is the front-desk end of the HIPAA chapter above.
- New patients and recalls. Intake, how charts get created, and the recall system that decides who gets called when.
- Phones and opening/closing. How calls are answered and routed, what the opening checklist covers, and who locks up.
Little of this comes from a regulator.
Its value shows up when someone is out: a documented front office survives a resignation week, an undocumented one re-learns everything by trial and error.
It is also the chapter new front-desk hires train against.
When you are hiring for those seats, the dental hiring hub collects the rest of our employer guides.
Keeping the manual current
A manual is only as good as its review calendar, and the review obligations differ by chapter:
- Exposure Control Plan: at least annually, plus on change. Review and update it at least annually and whenever new or modified tasks, procedures or positions affect occupational exposure. The annual review must document consideration and implementation of commercially available safer medical devices, and you must solicit and document input from non-managerial employees responsible for direct patient care on engineering and work-practice controls. Cal/OSHA's California version adds a look back at exposure incidents since the previous update.
- HIPAA: periodic, and on operational change. Security Rule documentation is reviewed periodically and updated in response to environmental or operational changes; privacy policies change as the law changes.
- Infection control: regularly, for example annually. CDC recommends that dental infection prevention policies be reassessed on a regular basis (for example, annually) or according to state or federal requirements, and the coordinator responsible for the written policies is the natural owner of that review.
Give every chapter a named owner so each review date has a person attached: the infection prevention coordinator for the clinical protocols, the security official for HIPAA, the office manager for the front-office chapter, and the dentist-owner signing off on the whole.
Record each review β date, who, what changed β because a review nobody documented is hard to distinguish from a review that never happened.
Keep superseded versions.
HIPAA documentation is retained 6 years from creation or the date last in effect, whichever is later, so last year's policy may still need to exist.
The records behind the manual run on their own clocks:
| Record | How long it is kept |
|---|---|
| Bloodborne pathogens training records | 3 years from the date of the training |
| Bloodborne pathogens medical records | At least the duration of employment plus 30 years |
| HIPAA privacy and security documentation | 6 years from creation or the date last in effect, whichever is later |
| Sterilizer spore-test results (California) | 12 months |
| Sharps injury log (California, covered employers) | 5 years from the date of the exposure incident |
| Sharps injury log (federal, where required) | 5 years following the end of the calendar year the records cover |
Two footnotes on the sharps injury log rows.
Under federal OSHA, the sharps injury log requirement applies only to employers required to keep OSHA injury and illness logs, and Offices of Dentists (NAICS 6212) are listed as a partially exempt industry for that recordkeeping, so dental offices generally need not keep the logs regardless of size unless the government asks.
California is the verified state difference: every employer covered by its bloodborne pathogens standard must keep a Sharps Injury Log, with each exposure incident involving a sharp recorded within 14 working days of the report.
Build the manual in this order
- Start with the required written programs: the Exposure Control Plan, the written hazard communication program, and HIPAA privacy and security policies.
- Do the exposure determination by job classification β all exposed, and some exposed with the tasks named β decided without regard to PPE.
- Name the owners: infection prevention coordinator, HIPAA security official, office manager for the front-office chapter.
- State where the manual, the HazCom program, the chemical list and the safety data sheets live, so employees can actually reach them.
- Write the front-office workflows you already follow: scheduling, payments, insurance, records releases, recalls, opening and closing.
- Put every review date on one calendar: the exposure control plan annually and on change, infection policies regularly, HIPAA documentation periodically and on operational change.
- Keep superseded versions β HIPAA documentation runs 6 years from creation or the date last in effect, whichever is later.
Questions employers ask
Does a dental practice legally need a policies and procedures manual?
Our research found no rule that requires a single document called a manual.
What exist are requirements for specific written programs where they apply: an employer with occupationally exposed employees must establish a written Exposure Control Plan, a covered workplace must maintain a written hazard communication program, and a HIPAA covered entity must implement written privacy policies and maintain security policies.
States can add their own; California's Dental Board rule, for one, requires a written infection control protocol available to all staff and posted in each office.
Whether each requirement reaches your practice depends on your staff's exposure and your HIPAA status.
Is the exposure control plan a separate document or part of the manual?
Either works; the requirements we checked spell out content and access, and nothing in them dictates a binding style.
What is required is that it be written, that it contain the exposure determination, the schedule and method of implementing the standard's requirements, and the procedure for evaluating exposure incidents, and that a copy be accessible to employees.
It must also be reviewed and updated at least annually and whenever tasks, procedures or positions affecting occupational exposure change.
Wherever it physically lives, make sure staff can reach it during a shift.
Who should maintain the manual in a small practice?
Give each chapter a named owner rather than treating the manual as one person's job.
CDC recommends an infection prevention coordinator be responsible for developing written infection prevention policies, and the HIPAA Security Rule requires an identified security official responsible for developing and implementing security policies.
The office manager is the natural owner of the front-office chapter, and the dentist-owner signs off on the whole.
What matters is that every review date on the calendar has a person attached to it.
How long do we keep old versions of policies and the records behind them?
HIPAA documentation is retained 6 years from creation or the date last in effect, whichever is later, so superseded policy versions stay in the file.
Bloodborne pathogens training records are kept 3 years from the date of the training, and bloodborne pathogens medical records are kept at least the duration of employment plus 30 years.
Where a sharps injury log applies, the federal log is kept 5 years following the end of the calendar year the records cover, and California's log is kept 5 years from the date of the exposure incident.
Can we copy another practice's procedures manual?
A template is scaffolding, not a manual.
Three things make each manual practice-specific.
The exposure determination must reflect your job classifications and the tasks that carry exposure, decided without regard to PPE.
State OSHA plans must be at least as effective as federal OSHA's and may be more stringent, so written-program requirements differ by state.
And state dental boards can add written-protocol rules of their own; California's infection control rule is the verified example in this guide's research.
Start from a template, then rebuild those chapters against your state's requirements and your own workflow.
Sources
- OSHA β Dentistry (no dental-specific standards) (retrieved October 7, 2026)
- OSHA β State Plans (retrieved October 7, 2026)
- OSHA β Dentistry, Standards (State Plans at least as effective) (retrieved October 7, 2026)
- eCFR β 29 CFR 1910.1030, Bloodborne Pathogens (Exposure Control Plan; records) (retrieved October 7, 2026)
- eCFR β 29 CFR 1910.1200, Hazard Communication (written program) (retrieved October 7, 2026)
- eCFR β 29 CFR 1904.33 (record retention, 5 years) (retrieved October 7, 2026)
- eCFR β 29 CFR 1904.2 (partially exempt industries, Offices of Dentists) (retrieved October 7, 2026)
- Cal/OSHA β 8 CCR 5193, Bloodborne Pathogens (exposure control plan; Sharps Injury Log) (retrieved October 7, 2026)
- eCFR β 45 CFR 164.530, HIPAA Privacy (policies, sanctions, retention) (retrieved October 7, 2026)
- eCFR β 45 CFR 164.308, HIPAA Security (security official, risk analysis, sanctions) (retrieved October 7, 2026)
- eCFR β 45 CFR 164.316, HIPAA Security documentation (retention, review) (retrieved October 7, 2026)
- Federal Register β HIPAA Security Rule proposed rule (published Jan. 6, 2025) (retrieved October 7, 2026)
- CDC β Summary of Infection Prevention Practices in Dental Settings (2003 Guidelines as standard of practice) (retrieved October 7, 2026)
- CDC β Safe Care in Dental Settings (infection prevention coordinator; policy reassessment) (retrieved October 7, 2026)
- California Business and Professions Code 1750 (dental assistant certification evidence) (retrieved October 7, 2026)
- California 16 CCR 1005 β Dental Board infection control regulation (retrieved October 7, 2026)
More hiring resources
Hiring against your new procedures?
Once the manual says how each seat runs, hire for it.
Post your associate, hygienist, assistant and front-office roles on DentistryHires.

