Skip to main content
CoreFolioHIPAA
Proposed rule updates

What the proposed HIPAA Security Rule update means for a solo dental practice

Small dental practices face specific HIPAA challenges: legacy imaging software, shared workstations, and minimal IT support. What the proposed Security Rule update would change.

By CoreFolio

6-minute read

Dental practices are covered entities under HIPAA. If your practice submits insurance claims electronically — which virtually every practice does — you fall under the Security Rule and its requirements for protecting electronic protected health information (ePHI).

The U.S. Department of Health and Human Services (HHS) has proposed an update to the HIPAA Security Rule — a Notice of Proposed Rulemaking, or NPRM (90 Fed. Reg. 898). It is still a proposal, not yet law, and is not expected before 2027. But it would change several things that hit dental practices particularly hard. This article covers the specific impact on a solo or small dental practice — not the theoretical hospital version.

What a solo dental practice's ePHI landscape actually looks like

Before getting to the rule changes, it helps to map what many small dental practices actually have:

  • electronic health record (EHR)/practice management software — Dentrix, Eaglesoft, Carestream, Curve Dental, or similar. Often installed locally on Windows computers.
  • Digital imaging — intraoral cameras, digital X-rays, cone beam CT. These are often on separate workstations or a dedicated imaging server.
  • Billing — either in-house via the practice management software or outsourced to a dental billing company.
  • Email — usually a general consumer or small-business email account (Gmail, Outlook) not configured for HIPAA-compliant transmission.
  • Remote access — the dentist often checks schedules or messages after hours via a personal phone or home computer.

Each of these touches ePHI. Each is in scope for the Security Rule. And several of them have specific challenges under the proposed rule.

The six most impactful proposed changes for dental practices

The changes below are drawn from the proposed rule. The NPRM restructures and renumbers large parts of the Security Rule, so the descriptions here track what the proposal would require rather than pinpointing not-yet-final subsection numbers.1

1. Annual risk analysis, mandatory

The existing rule requires risk analysis but does not specify a frequency. The NPRM proposes to make it explicitly annual.

Many dental practices have never done a formal risk analysis, or did one when they opened and never updated it. The proposed change formalizes what the Office for Civil Rights (OCR) already expects.

Your action: Complete a current-year risk analysis covering all the systems above — not just the EHR. Dental imaging systems are in scope. Remote access is in scope.

2. MFA on every system that touches ePHI

This is the most operationally significant change for dental practices.

Your practice management software — Dentrix, Eaglesoft, or any locally installed system — may not support multi-factor authentication (MFA), or may support it only in newer versions. Your imaging software almost certainly does not.

The proposed rule would require MFA on every system that creates, receives, maintains, or transmits ePHI. That means:

  • Your practice management software login
  • Your imaging workstation login
  • Your email if you use it for patient communication
  • Any remote access method (VPN, remote desktop, cloud portal)
  • Your billing software if it is separate

The proposal allows only a few narrow exceptions to the MFA requirement — chiefly certain legacy systems and older FDA-authorized medical devices, and even then only with a written plan to migrate the ePHI onto supported technology. Some older dental imaging systems may be exactly the kind of legacy technology that exception is written for — but the exception is narrow and time-limited, not a permanent pass.1

Your action: Contact your practice management software vendor and ask whether MFA is available and how to enable it. If not, this is a gap that will need a plan before the rule finalizes.

3. Encryption at rest and in transit

Digital X-rays, cone beam CT images, and patient records contain ePHI. The proposed rule would require this data to be encrypted when stored and when transmitted.

Cloud-based dental software (Curve Dental, Carestream Cloud) typically encrypts by default. Locally installed systems like Dentrix and Eaglesoft store data on your local server or workstations — encryption of that storage is a configuration choice that many practices have never made.

Your action: Ask your software vendor and your IT provider whether your local storage is encrypted. If you are on local servers, this is likely a gap.

Under the current rule, encryption is an addressable specification (45 CFR § 164.312(a)(2)(iv) for stored data and § 164.312(e)(2)(ii) for data in transit); the proposal would make encryption a standalone requirement rather than an option you document your way around.21

4. Technology asset inventory

The proposed rule would require a documented inventory of all hardware and software that touches ePHI, reviewed annually.

For a dental practice, this means: every computer, every imaging workstation, every mobile device used by staff, every server, every cloud service, and every external vendor system. The imaging server that runs your cone beam CT is in scope.

Your action: Walk through your office and list every device and system that touches patient data. This is also the starting point for your risk analysis.

5. BAA annual verification

The proposed rule would require covered entities to verify annually that their business associates have implemented required safeguards.

For a dental practice, your business associates include: your practice management software vendor (if they host your data), your dental billing company, your IT managed service provider, and any cloud services that store patient data.

Your action: Make sure you have a current business associate agreement (BAA) with each of these vendors. File a copy in your compliance records. Note the date of each agreement.

6. 72-hour restoration requirement

A ransomware attack on a dental practice is not hypothetical — dental practice management systems are a known ransomware target because they often run on outdated Windows versions with no off-site backup.

The proposed rule would require covered entities to restore critical systems within 72 hours of a security incident.

Your action: Confirm you have an off-site backup of your practice management data and imaging data. Test that you can restore from it. Know who to call if your systems go down.

What has not changed

The existing 2013 Security Rule is still in effect and still requires:

  • A risk analysis (the annual requirement is proposed, not final, but the requirement to keep it current is existing law)
  • A risk management plan to respond to identified risks
  • Workforce training
  • BAAs with business associates
  • Policies for workstation security and device disposal

The NPRM proposes to strengthen these requirements. It does not replace them.

The practical priority list for a solo dental practice right now

Given the current state of enforcement (the 2013 rule is actively enforced; the proposed rule is not yet final):

  1. Do a current risk analysis covering all systems above
  2. Verify your BAAs with your major vendors
  3. Enable MFA on any system where it is available
  4. Confirm off-site backup of practice management and imaging data
  5. Ask your software vendors about encryption status

That is the floor. The proposed changes, if finalized, would raise it — but starting from the floor now means the incremental lift later is manageable.

Sources

Footnotes

  1. HHS, HIPAA Security Rule Notice of Proposed Rulemaking (90 Fed. Reg. 898, published January 6, 2025). Source for the proposed annual risk analysis, technology asset inventory, mandatory MFA and its exceptions, standalone encryption requirement, business associate verification, and 72-hour restoration. A proposal, not final law. https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html 2 3

  2. 45 CFR § 164.312 (technical safeguards) — encryption is currently an addressable specification at § 164.312(a)(2)(iv) (at rest) and § 164.312(e)(2)(ii) (in transit). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312