HIPAA compliant AI for dental practices

The phrase gets used as though it describes a product you can buy. It does not. Here is what it actually takes, and where the tools fit.

If you search for HIPAA compliant AI you will find a lot of vendors claiming to be exactly that. The claim is doing something slippery, and it is worth taking thirty seconds to see what.

HIPAA does not certify software. There is no government body that inspects an app and stamps it compliant. Compliance is a property of how your practice operates: your safeguards, your agreements, your training, your access controls, your breach procedures.

A vendor can honestly say their product can be used as part of a compliant setup. They can sign a business associate agreement. They can hold real security certifications. Those are meaningful things. What none of them do is make your practice compliant, because most of compliance happens on your side of the wire.

So the useful question is not "is this AI HIPAA compliant". It is what has to be true before patient information goes anywhere near this tool.

What has to be true

Whatever tool you pick, the same short list applies:

That list is unglamorous, and it is most of the work. Any conversation about AI in a dental practice that skips it is selling you the fun part and leaving you the liability.

Where this guide stops

We build AI systems, we are not a compliance consultancy, and this is not legal advice about your practice's obligations. Treat it as a description of how the technology behaves and the questions worth asking.

Before PHI goes into any tool, run the decision past whoever handles your HIPAA compliance. If a vendor tells you their product makes you compliant, that sentence is a reason to be more careful, not less.

Two setups that work

Cloud tool with the paperwork done

A business-tier AI service that will sign a BAA, configured so your data is not used for training, with per-person accounts and a written policy around it. This is the lighter option, it is cheap, and it is entirely legitimate.

What you are accepting is that PHI sits on infrastructure you do not control, and that your exposure widens each time someone adds another tool to the stack. That is a manageable risk, but it is a real one and it needs an owner.

A model that runs inside the practice

The other approach is to keep the data in the building. A single machine in your server closet runs an open-weight model with no internet connection. It reads the records you point it at and answers questions about them, and nothing is transmitted anywhere, because there is nowhere for it to go.

There is no BAA to negotiate for the model itself, because there is no business associate. That does not eliminate your obligations, your access controls and audit logging and training all still apply, but it removes an entire category of third-party risk from the picture.

Our install runs $2,500 one time, managed service is $3,500 to $5,000 a month, and the electricity is about $9. There is no per-seat licence, so the cost does not climb as the team uses it more.

What practices actually use it for

The honest answer is that the highest-value uses are usually the least exciting ones:

None of that replaces clinical judgment, and every output still gets read by the person whose name goes on the record. Language models state wrong things confidently. That is true of every model, local or hosted, and it is the reason a human stays in the loop.

The reasonable place to start

Start with the work that involves no PHI at all. Patient education material, recall messaging templates, internal process documents, your website copy. There is nothing to protect, so there is nothing to get wrong, and your team learns the tools on low stakes.

Then look at what is left. If the remaining work is mostly administrative and you are comfortable with a properly papered cloud vendor, take that route. If it is clinical records and you would rather the question never arise, put the machine in the closet.

Work out which half your practice is in

The free AI Audit maps where your practice loses time, how much of that involves patient information, and what the honest options are. The 30-day plan is yours whether or not you hire us.

See what the audit covers