Compliance · United States

Using Dentalreel in line with HIPAA

A compliance reference for US dental practices using the Dentalreel smile simulation widget. For US practices, patient photos and enquiries are Protected Health Information (PHI), and HIPAA governs how they are handled.


Summary

When a US dental practice uses Dentalreel, the practice is a HIPAA Covered Entity and Dentalreel is its Business Associate. We sign a Business Associate Agreement (BAA) directly with each practice before any patient data is processed. Marketing agencies that resell Dentalreel do not receive patients' names, contact details or photos; what an agency can receive is set out under “What counts as PHI” below.

The headline points:


Covered Entity, Business Associate and the BAA

Under 45 CFR 160.103, a Business Associate is a party that creates, receives, maintains, or transmits PHI on behalf of a Covered Entity. Because Dentalreel processes patient photos and captures patient enquiries for your practice, it is your Business Associate and signs a BAA with you directly.

When a US practice is added, the authorized practice contact receives the BAA by email to review and accept. Acceptance is recorded (name, email, timestamp, IP). The widget will not process real patient photos for a US practice until that BAA has been accepted — it stays in a non-live state until then.

What counts as PHI

For the widget, PHI is: the patient's uploaded photograph, the AI-generated smile preview, and the patient's contact details and enquiry (name, email, phone, treatment interest). Your agency, if you use one, sees enquiry counts and activity (time, clinic and status) in its console — never patient names, contact details, photos or, for HIPAA-mode practices, treatment interest. It receives your practice's conversion export only if your practice authorizes it: ad click identifiers, the enquiry time, a conversion value set by the receiving account, a per-location identifier and an enquiry reference — no patient names, contact details or photos.

Safeguards

Subprocessors and the BAA chain

Dentalreel uses subprocessors that may touch PHI. Our commitment is that no subprocessor processes PHI for a US practice until a downstream BAA is in place with that subprocessor:

With those agreements in place, the HIPAA lane is available to any US practice that accepts our BAA. We remain responsible to you for our subprocessors' handling of PHI. Our contractual subprocessor list, with locations, is at /legal/sub-processors.

Breach notification

In the event of a breach of unsecured PHI, we will notify your practice without unreasonable delay and consistent with 45 CFR 164.410, providing the information you need to meet your own notification obligations. Notifications run from Dentalreel to your practice directly — never through your agency.

Advertising (US)

Widget outputs are clearly labeled as AI-generated aesthetic simulations, never treatment-outcome guarantees, with a permanent on-screen disclaimer the practice cannot remove and explicit patient consent on every use. This is designed to align with FTC truth-in-advertising principles and your state dental board's advertising rules. You remain responsible for your own advertising claims.

What we provide to support your compliance

What we expect from you

Disclaimer. This page describes how Dentalreel is designed to support your HIPAA obligations as of 2026. It is not legal advice. HIPAA compliance is a shared responsibility; consult your own privacy officer or healthcare counsel for your practice's specific position. Questions: compliance@dentalreel.com.