The HIPAA Security Risk Assessment: What Every Dental Practice Needs to Know
It is required, it is the first thing investigators ask for, and most practices are overdue. Here is what a useful risk assessment actually covers.
· 6 min read

If your practice creates, receives, or stores electronic protected health information (ePHI) — and every modern dental office does — the HIPAA Security Rule requires an accurate and thorough assessment of the risks to that information. It is not optional, and it is not a one-time event.
Yet many practices are working from a template filled out years ago, before the new imaging system, the cloud fax service, or the second location. Here is what a practical risk assessment should cover.
1. Find every place ePHI lives
Start with an inventory. Patient data does not only live in your practice management software. It lives in imaging workstations, the scanner at the front desk, email inboxes, backup drives, lab case portals, and the phone of the doctor who texts a colleague about a case.
2. Identify threats and vulnerabilities
For each location, ask what could go wrong. Common findings in dental offices include:
- Shared logins on operatory computers
- Windows machines that have not received security updates
- Backups stored on a drive sitting next to the server
- Guest Wi-Fi on the same network as clinical systems
- Former employees who still have email or software access
3. Rate the risk and make a plan
Not every finding is urgent. A good assessment weighs likelihood against impact so you fix the riskiest gaps first — often multi-factor authentication, encrypted off-site backups, and patching — then schedules the rest.
4. Document and repeat
Documentation is what turns good intentions into evidence. Keep the assessment, your remediation plan, and proof of completed work. Review it at least annually and any time something significant changes in your office.
California adds its own layer through the Confidentiality of Medical Information Act, so your safeguards should be built with both federal and state requirements in mind. This article is general information, not legal advice — talk to your compliance advisor about your specific obligations.
This article is general information about IT and security practices, not legal advice.

