Using Dentalreel in line with HIPAA
A compliance reference for US dental practices using the Dentalreel smile simulation widget. For US practices, patient photos and enquiries are Protected Health Information (PHI), and HIPAA governs how they are handled.
Summary
When a US dental practice uses Dentalreel, the practice is a HIPAA Covered Entity and Dentalreel is its Business Associate. We sign a Business Associate Agreement (BAA) directly with each practice before any patient data is processed. Marketing agencies that resell Dentalreel are deliberately kept out of the patient-data chain and are not business associates.
The headline points:
- Your practice is the Covered Entity; Dentalreel is your Business Associate under a signed BAA
- Patient photos and enquiries are treated as PHI
- The BAA is accepted (one click, by an authorised person) before the widget processes any patient photos
- PHI is encrypted in transit (TLS 1.2+) and at rest; patient images auto-delete within about an hour and lead data within 30 days (excluding encrypted backups, which expire on rotation within 35 days); consent + access audit logs are retained for 6 years
- We never sell PHI and never use patient photos to train AI models
Covered Entity, Business Associate and the BAA
Under 45 CFR 160.103, a Business Associate is a party that creates, receives, maintains, or transmits PHI on behalf of a Covered Entity. Because Dentalreel processes patient photos and captures patient enquiries for your practice, it is your Business Associate and signs a BAA with you directly.
When a US practice is added, the authorised practice contact receives the BAA by email to review and accept. Acceptance is recorded (name, email, timestamp, IP). The widget will not process real patient photos for a US practice until that BAA has been accepted — it stays in a non-live state until then.
What counts as PHI
For the widget, PHI is: the patient's uploaded photograph, the AI-generated smile preview, and the patient's contact details and enquiry (name, email, phone, treatment interest). Your agency, if you use one, only ever sees de-identified aggregate counts — never this PHI.
Safeguards
- Encryption in transit (TLS 1.2+) and at rest
- Patient images auto-deleted within approximately one hour of processing; lead data within 30 days (encrypted backups expire on rotation within 35 days)
- Explicit patient consent captured before any processing, with an audit record
- Access controls and least-privilege on systems that touch PHI
- We never sell PHI and never use patient photos to train AI models
Subprocessors and the BAA chain
Dentalreel uses subprocessors that touch PHI only under downstream BAAs:
- Amazon Web Services — storage and patient-enquiry email, under an executed HIPAA BAA.
- Google Cloud (Vertex AI) — AI image/video generation, under a HIPAA Business Associate Agreement. Generation is pinned to generally-available (GA) models only, as Google's HIPAA coverage excludes pre-GA offerings.
We remain responsible to you for our subprocessors' handling of PHI. A current list is available on request.
Breach notification
In the event of a breach of unsecured PHI, we will notify your practice without unreasonable delay and consistent with 45 CFR 164.410, providing the information you need to meet your own notification obligations. Notifications run from Dentalreel to your practice directly — never through your agency.
Advertising (US)
Widget outputs are clearly labelled as AI-generated aesthetic simulations, never treatment-outcome guarantees, with a permanent on-screen disclaimer the practice cannot remove and explicit patient consent on every use. This is designed to align with FTC truth-in-advertising principles and your state dental board's advertising rules. You remain responsible for your own advertising claims.
What we provide to support your compliance
- A HIPAA Business Associate Agreement, signed directly with your practice
- The technical safeguards above, and our subprocessor list on request
- Consent and access audit records
- Breach notification support
What we expect from you
- Ensure the person who accepts the BAA is authorised to bind your practice
- Present the widget's disclaimer and consent to patients as delivered
- Handle the leads you receive in line with your own HIPAA obligations
Disclaimer. This page describes how Dentalreel is designed to support your HIPAA obligations as of 2026. It is not legal advice. HIPAA compliance is a shared responsibility; consult your own privacy officer or healthcare counsel for your practice's specific position. Questions: compliance@dentalreel.com.