This is general information, not legal advice — HIPAA obligations depend on your practice's specific setup, and a compliance attorney or your practice's designated privacy officer is the right source for anything you need to rely on formally. What follows is the practical version most dental teams actually need day to day: how HIPAA shows up in the notes you write and the systems you write them in.
Minimum necessary information
HIPAA's "minimum necessary" standard means a note should contain what's clinically relevant, not everything a patient happens to mention. A patient's comment about an unrelated personal matter doesn't belong in a dental chart just because it came up during the visit. This isn't about writing thinner notes — it's about keeping notes focused on the clinical picture they exist to document.
Secure storage and access controls
Wherever notes live — your PMS, a cloud charting tool, a scanned paper record — access should be limited to people who need it for their role, and the system should log who accessed what and when. A shared login used by the whole front desk, or a chart left open on a screen visible to the waiting room, undermines this even if the underlying software is compliant.
Keep PHI out of insecure channels
This is where most accidental exposure actually happens, not in the charting system itself. A few habits worth checking against:
- Texting a patient's name alongside clinical details on an unencrypted personal phone
- Sending chart notes or radiographs over regular, unencrypted email
- Screenshots of a chart shared in a group chat or saved to a personal device
- Discussing a specific patient's findings somewhere they could be overheard
None of these require malicious intent to become a problem — they're almost always a shortcut taken under time pressure.
Who should have access within the practice
Not everyone on staff needs access to every chart. Clinical documentation should be visible to the people involved in a patient's care and the administrative staff who need it for scheduling, billing, or insurance — role-based access, not blanket access, is the standard to aim for.
Patient right to access their own records
Patients have a right to a copy of their own records, generally within 30 days of requesting it. Notes that are legible, complete, and reasonably organized make this an easy request to fulfill; notes that are shorthand-heavy or scattered across formats make it a project.
AI and voice-recording tools add a few specific questions
If you're using an ambient scribe or any tool that records audio during a visit, a few additional things are worth understanding before you adopt it:
- Consent to record. Patients should know a visit is being recorded for note generation, consistent with your state's recording consent laws.
- Where processing happens. Know whether audio is processed by a business associate under a signed BAA, and where that data is stored.
- Retention of raw audio. A tool that deletes raw recordings once the note is generated, rather than holding onto them indefinitely, reduces the amount of sensitive data sitting around with no ongoing clinical purpose.
None of this should discourage using AI-assisted documentation — it should just be part of what you ask a vendor before you sign up, the same way you'd ask about any other system that touches patient data.
Write notes in the time it takes to do the visit
ProphyNotes listens during the appointment and turns it into a structured note — formatted for your chart, ready before the next patient sits down.
See how it works