|

BLOG
brenden kellwy law NEWS

Insightful Legal Perspectives for Ohio Residents

|

HIPAA Cybersecurity Changes: What Dental Practices Should Be Doing Before There Is a Breach

Brenden Kelley

Dental office computer showing cybersecurity and HIPAA privacy protections for patient information

Dental practices are healthcare businesses, and healthcare businesses are data businesses. Every practice depends on electronic patient records, imaging systems, practice management software, online forms, text reminders, payment systems, and outside vendors. That makes cybersecurity a legal issue, not just an IT issue.

HHS has proposed significant changes to the HIPAA Security Rule intended to strengthen protection for electronic protected health information. While the current Security Rule remains in effect during the rulemaking process, the direction is clear: regulators expect covered entities and business associates to take cybersecurity seriously.

Dental practices should not wait for a breach to discover that their policies, vendor contracts, backups, access controls, and incident response plans are outdated. A ransomware attack, lost laptop, compromised email account, or vendor breach can create patient notification obligations, reputational damage, operational disruption, and regulatory scrutiny.

The first step is understanding where patient data lives. That includes practice management software, imaging platforms, cloud storage, email, text messaging systems, online scheduling tools, website forms, payment processors, billing vendors, IT providers, consultants, and backup systems.

The second step is reviewing business associate relationships. If a vendor creates, receives, maintains, or transmits protected health information on behalf of the practice, the practice should evaluate whether a business associate agreement is needed and whether the agreement is current.

Access controls also matter. Team members should not all have the same level of access. Departing employees should be removed promptly. Multi-factor authentication should be considered for sensitive systems. Password practices, device security, and remote access should be addressed in written policies.

Dental practices should also think about incident response. Who gets called first if the practice discovers a breach? Who contacts IT? Who evaluates whether patient notice is required? Who communicates with vendors? A plan created after a crisis begins is not much of a plan.

The legal takeaway is that HIPAA compliance and cybersecurity cannot be separated. Dental practices should coordinate legal, IT, and operations before something goes wrong.

Brenden Kelley Law helps dental practices evaluate legal risks involving HIPAA, vendor contracts, patient data, and practice operations.

Additional legal and practical context

Dental practices are covered entities when they transmit health information electronically in covered transactions, and they often work with business associates such as IT vendors, imaging vendors, billing companies, cloud software providers, answering services, marketing vendors, and patient communication platforms. A breach can disrupt patient care, billing, scheduling, insurance claims, referrals, and practice reputation.

HHS’s Office for Civil Rights has proposed updates to the HIPAA Security Rule to strengthen cybersecurity protections for electronic protected health information. HHS explains that the proposed rule is intended to address a growing number of cyberattacks and would require covered entities and business associates to strengthen cybersecurity protections. HHS also reported significant increases in large breach reports and individuals affected by breaches from 2018 through 2023. See HHS’s HIPAA Security Rule NPRM page.

Even before any final rule, the current Security Rule remains in effect. That means dental practices should already be conducting risk analyses, implementing reasonable safeguards, managing access, training workforce members, and using business associate agreements where required. The proposed changes are a reminder that “we are a small practice” is not a cybersecurity plan.

Practical steps include reviewing user access, enabling multi-factor authentication where available, documenting backups, testing restoration, patching systems, encrypting laptops and portable devices, training staff on phishing, reviewing remote access, requiring vendors to explain their safeguards, and maintaining an incident response plan. Practices should also know who to call if systems go down or patient information is exposed.

Practical takeaway

Dental cybersecurity should be treated as an operations issue, not just an IT issue. Owners should understand where ePHI is stored, who can access it, which vendors touch it, whether backups work, and what the practice will do during the first 24 hours of a suspected breach.

Sources and further reading

            HHS HIPAA Security Rule NPRM

            HHS Summary of the HIPAA Security Rule

Share this post