Blog · Security & HIPAA
HIPAA, PII security, and why traditional dental IT cannot keep up
HeyDental is a fully digital, AI-first, AI-native practice platform. Protecting personally identifiable information (PII) and protected health information (PHI) is a core tenet of the architecture — not a bolt-on policy PDF. This note is how we answer owners and counsel who ask whether we are ready, and why a stack of random systems usually is not.
The careful short answer
Are we “HIPAA compliant”? Compliance is not a sticker you buy. When HeyDental creates, receives, maintains, or transmits PHI for a dental practice, we are a business associate under HIPAA. That triggers BAAs with the practice and with every subprocessor that can see PHI, a documented risk analysis, administrative / physical / technical safeguards mapped to the Security Rule, append-only audit logs, and a breach-notification path. Until real patient data is live, production BA duties are not yet triggered — but the platform is built so we do not have to rebuild security later.
Are we secure? Security is continuous evidence, not a slogan: encryption in transit and at rest, MFA and role boundaries, tenant isolation, least-privilege agents, PHI kept off uncovered models and analytics, workforce training in our HIPAA Center, and a platform red-team robot that keeps looking for weak points without ever modifying or deleting office data.
PII and PHI security is a core tenet of HeyDental — the same way chairs and schedules are. If a feature cannot meet the boundary, it does not ship with real patients.
Why traditional setups fail the muster
Most practices did not choose insecurity. They inherited a pile: a on-prem or “server in the closet” practice-management database, a separate imaging PC, a recall vendor, a website last touched by a webmaster who left in 2019, a shared front-desk Windows login, USB sticks for “the biller’s reports,” personal Gmail forwards, and a chatbot trial that quietly copied yesterday’s schedule into someone else’s cloud.
That pattern makes continuous HIPAA-grade safeguards structurally impractical to demonstrate:
- Random systems, no single map. You cannot complete a serious risk analysis or accounting of where PHI lives when every vendor holds a partial copy and nobody owns the inventory.
- The webmaster who is not around. Public pages, forms, and plugins rot. Old contact forms still POST patient details to forgotten mailboxes. TLS certificates expire. Admin URLs stay on the open internet.
- Unencrypted customer data everywhere. Flat files on desktops, unencrypted backups on USB, exports in Dropbox-class folders, screenshots in group chats — each is a disclosure waiting for a laptop theft or a phishing click.
- Shared logins and no audit trail. “Front desk” as a user means you cannot answer who opened which chart. HIPAA access controls and audit controls expect unique identities and logged access.
- Bolt-on “AI.” Screen scrapers and nightly CSV extracts multiply PHI into new systems that often lack BAAs, retention limits, or least privilege. You did not gain an agentic OS — you gained another data lake.
- No workforce program you can prove. A PDF in a drawer is not training. When an OCR or payer asks who was trained, when, and on which runbook version, scattered offices shrug.
We are not saying every legacy office is “illegal.” We are saying that with that architecture, practices have no realistic path to show counsel, a regulator, or a partner that safeguards are designed, implemented, trained, audited, and continuously tested. Hope is not a control.
AI-native means security is the product
HeyDental is fully digital and AI-first / AI-native: specialized agents operate the practice through typed tools, not through a human GUI we scrape. That only works if identity, encryption, audit, and minimum-necessary context are first-class — otherwise agents become a faster way to leak.
Design rules we hold ourselves to:
- One graph, specialist payloads. We orchestrate Stripe for money, Gusto-class payroll, Stedi for EDI, Twilio for voice/SMS, Resend for mail, and Cloudflare for public edge. We refuse to become a second warehouse of PANs, payroll files, or claim bodies.
- Chart / PHI on a covered path. Office facts that identify patients in a care or payment context stay in BAA-backed storage. Public marketing sites stay non-PHI.
- Agents with least privilege. Insurance robots do not see payroll. Finance robots do not roam charts. Tools are allowlisted; models do not “discover” arbitrary URLs.
- No uncovered-model failover for PHI. Charts, intake, and briefs do not spill into consumer chat or uncovered routers “because the primary model was busy.”
- Human gates for irreversible acts. Money movement, rule publishes, and legal filings wait on a person.
Controls we design for (and can point at)
HIPAA’s Security Rule is risk-based. Our engineering program maps to it in language counsel can check:
- Administrative — named security ownership; living risk analysis; access / acceptable-use / incident policies; vendor + BAA register; workforce training via HIPAA Center; sanctions path.
- Physical / workstation — guidance for shared front-desk machines; screen lock; no local PHI exports as a product feature; media handling for anyone who can download records.
- Technical — unique user IDs; RBAC; MFA for PHI reach; TLS; encryption at rest with managed keys; encrypted backups with restore drills; append-only audit logs; idle timeouts; integrity of sessions.
- Privacy / minimum necessary — role-scoped briefs; non-clinical reminder bodies + portal links where possible; patient access / amendment support for records we hold.
SOC 2 may become a later process signal. It is not a HIPAA substitute, and we will not market it as one.
HIPAA Center — workforce training that sticks
Administrative safeguards require a workforce that understands the rules. Our HIPAA Center is built for that — not as a government stamp, and not as legal advice, but as an onboarding and renewal program every employee can finish and every owner can prove.
How it works in product (fictional BrightSmile roster in the mock):
- Owner assigns during onboarding — select members (or select all) and Send. That queues an in-app bell and a robot-lawyer email explaining why the practice trains. Robot lawyers stay in the email chrome; training slides stay people.
- Animated slides cover minimum necessary, no snooping, no clinical SMS, no USB rosters, BAAs, passwords / MFA, and patient rights — then a 10-question test at 100%. Misses recycle; staff do not restart from zero for one miss.
- Certificate of completion with renewal term the owner sets (90 / 180 / 365 days). New hires get it as part of onboarding. Enabling deeper HIPAA pack features waits until certificates are green.
That gives you evidence: who was trained, on which runbook version, when they renew. A PDF in a drawer does not.
The red-team robot that only reports
Training and BAAs are not enough if nobody keeps testing the locks. We are standing up a platform red-team robot (not an office-floor agent patients see in the nursery) whose sole job is to find weak points and file them.
- Always looking — unauthenticated routes, broken tenant walls, missing challenges, config that leaves doors ajar on surfaces we operate.
- Never modify or delete office, patient, billing, or chart data. Dedicated identity, GET/HEAD/SELECT-only tools, mechanical denylist for writes. Prompt text is backup; credentials are the control.
- Only report structured findings to engineering robots — class, surface, severity, redacted evidence. No exploit recipes, no proof-of-concept payloads.
- Re-check after a fix that the safe behavior holds. High / critical / PHI-adjacent items page a human before merge.
Staging and fictional tenants first. This loop complements an external security assessment; it does not replace one.
Gates before real patients
We do not load real PHI because a landing page looks ready. Hard stops include:
- Signed BAAs with each live practice and every PHI-capable subprocessor.
- Documented risk analysis with Security Rule controls enforced in production — not slides alone.
- PHI boundary enforced for AI, analytics, and logs.
- Incident / breach runbook tested; security ownership named.
- Consent, messaging, and payments paths reviewed; patient access / amendment supported for records we hold.
- External assessment (pen-test or equivalent) with high-severity findings fixed before broader real-patient use.
- Workforce certificates current in HIPAA Center for the offices going live.
Until those gates are green, we stay on fictional and staging data. That protects practices that have not signed yet — and it protects us from shipping hope.
What we will and will not claim
We will not claim
- That HeyDental is “HIPAA certified,” or that any certificate from our HIPAA Center is an HHS certification.
- That this blog (or any vendor blog) is a substitute for counsel, your risk analysis, or your BAAs.
- That continuous red-team probes replace an independent assessment.
- That office-floor agents should also attack the platform.
We will claim — when true and reviewable
- HeyDental is built as a fully digital, AI-native platform where PII/PHI security is a core tenet.
- We sign BAAs before real PHI; access is logged; agents run with least privilege; uncovered models stay off the PHI path.
- Workforce training runs through HIPAA Center with assign → train → 100% quiz → certificate → renew.
- A read-only red-team robot reports attack vectors to engineering robots for repair — and never modifies patient data.
If that is the bar you want for an agentic practice, join the waiting list. We open the gates when the controls — not the slogans — are ready.