If you search for HIPAA compliant AI you will find a lot of vendors claiming to be exactly that. The claim is doing something slippery, and it is worth taking thirty seconds to see what.
HIPAA does not certify software. There is no government body that inspects an app and stamps it compliant. Compliance is a property of how your practice operates: your safeguards, your agreements, your training, your access controls, your breach procedures.
A vendor can honestly say their product can be used as part of a compliant setup. They can sign a business associate agreement. They can hold real security certifications. Those are meaningful things. What none of them do is make your practice compliant, because most of compliance happens on your side of the wire.
So the useful question is not "is this AI HIPAA compliant". It is what has to be true before patient information goes anywhere near this tool.
What has to be true
Whatever tool you pick, the same short list applies:
- A signed business associate agreement with any vendor that will touch protected health information. No BAA means no PHI, and consumer AI accounts do not come with one.
- Access controls that match roles. The front desk and the hygienist do not need the same access, and shared logins defeat the whole exercise.
- An audit trail. You should be able to answer who looked at what, and when.
- A written policy your team has actually read, saying plainly what may and may not be entered into which tool.
- Minimum necessary. If the task can be done with the patient's name stripped out, strip it out.
That list is unglamorous, and it is most of the work. Any conversation about AI in a dental practice that skips it is selling you the fun part and leaving you the liability.
We build AI systems, we are not a compliance consultancy, and this is not legal advice about your practice's obligations. Treat it as a description of how the technology behaves and the questions worth asking.
Before PHI goes into any tool, run the decision past whoever handles your HIPAA compliance. If a vendor tells you their product makes you compliant, that sentence is a reason to be more careful, not less.
Two setups that work
Cloud tool with the paperwork done
A business-tier AI service that will sign a BAA, configured so your data is not used for training, with per-person accounts and a written policy around it. This is the lighter option, it is cheap, and it is entirely legitimate.
What you are accepting is that PHI sits on infrastructure you do not control, and that your exposure widens each time someone adds another tool to the stack. That is a manageable risk, but it is a real one and it needs an owner.
A model that runs inside the practice
The other approach is to keep the data in the building. A single machine in your server closet runs an open-weight model with no internet connection. It reads the records you point it at and answers questions about them, and nothing is transmitted anywhere, because there is nowhere for it to go.
There is no BAA to negotiate for the model itself, because there is no business associate. That does not eliminate your obligations, your access controls and audit logging and training all still apply, but it removes an entire category of third-party risk from the picture.
Our install runs $2,500 one time, managed service is $3,500 to $5,000 a month, and the electricity is about $9. There is no per-seat licence, so the cost does not climb as the team uses it more.
What practices actually use it for
The honest answer is that the highest-value uses are usually the least exciting ones:
- Turning a clinician's rough notes into a clean chart entry in the practice's own format
- Drafting pre-treatment explanations patients can actually understand
- Answering "what did we do for this patient in 2023" without opening six screens
- Writing the insurance narrative that supports a claim
- Summarizing a new patient's history before they sit in the chair
None of that replaces clinical judgment, and every output still gets read by the person whose name goes on the record. Language models state wrong things confidently. That is true of every model, local or hosted, and it is the reason a human stays in the loop.
The reasonable place to start
Start with the work that involves no PHI at all. Patient education material, recall messaging templates, internal process documents, your website copy. There is nothing to protect, so there is nothing to get wrong, and your team learns the tools on low stakes.
Then look at what is left. If the remaining work is mostly administrative and you are comfortable with a properly papered cloud vendor, take that route. If it is clinical records and you would rather the question never arise, put the machine in the closet.
Work out which half your practice is in
The free AI Audit maps where your practice loses time, how much of that involves patient information, and what the honest options are. The 30-day plan is yours whether or not you hire us.
See what the audit covers