Dental IT is HIPAA IT
Imaging systems, practice management software, and patient portals all touch PHI. That makes nearly every system in a dental office in-scope for HIPAA — including the imaging workstation everyone forgets about.
The checklist
- Encrypted backups of imaging and PMS data, with restore tests
- MFA on email and any remote access
- BAAs in place with every vendor that touches PHI (including your imaging cloud)
- Workstation encryption (BitLocker/FileVault) on every device
- Audit logging on systems that store or transmit PHI
- A documented incident response process