Compliance · United States

Using Dentalreel in line with HIPAA

A compliance reference for US dental practices using the Dentalreel smile simulation widget. For US practices, patient photos and enquiries are Protected Health Information (PHI), and HIPAA governs how they are handled.


Summary

When a US dental practice uses Dentalreel, the practice is a HIPAA Covered Entity and Dentalreel is its Business Associate. We sign a Business Associate Agreement (BAA) directly with each practice before any patient data is processed. Marketing agencies that resell Dentalreel are deliberately kept out of the patient-data chain and are not business associates.

The headline points:


Covered Entity, Business Associate and the BAA

Under 45 CFR 160.103, a Business Associate is a party that creates, receives, maintains, or transmits PHI on behalf of a Covered Entity. Because Dentalreel processes patient photos and captures patient enquiries for your practice, it is your Business Associate and signs a BAA with you directly.

When a US practice is added, the authorised practice contact receives the BAA by email to review and accept. Acceptance is recorded (name, email, timestamp, IP). The widget will not process real patient photos for a US practice until that BAA has been accepted — it stays in a non-live state until then.

What counts as PHI

For the widget, PHI is: the patient's uploaded photograph, the AI-generated smile preview, and the patient's contact details and enquiry (name, email, phone, treatment interest). Your agency, if you use one, only ever sees de-identified aggregate counts — never this PHI.

Safeguards

Subprocessors and the BAA chain

Dentalreel uses subprocessors that touch PHI only under downstream BAAs:

We remain responsible to you for our subprocessors' handling of PHI. A current list is available on request.

Breach notification

In the event of a breach of unsecured PHI, we will notify your practice without unreasonable delay and consistent with 45 CFR 164.410, providing the information you need to meet your own notification obligations. Notifications run from Dentalreel to your practice directly — never through your agency.

Advertising (US)

Widget outputs are clearly labelled as AI-generated aesthetic simulations, never treatment-outcome guarantees, with a permanent on-screen disclaimer the practice cannot remove and explicit patient consent on every use. This is designed to align with FTC truth-in-advertising principles and your state dental board's advertising rules. You remain responsible for your own advertising claims.

What we provide to support your compliance

What we expect from you

Disclaimer. This page describes how Dentalreel is designed to support your HIPAA obligations as of 2026. It is not legal advice. HIPAA compliance is a shared responsibility; consult your own privacy officer or healthcare counsel for your practice's specific position. Questions: compliance@dentalreel.com.