HIPAA and AI Tools in the Dental Practice: What to Review First
AI tools have arrived in dentistry faster than most practices’ compliance habits have. A new tool gets adopted because the front desk likes it, or because a team member starts pasting things into a chatbot to save time, and the question of what happens to patient information inside that tool gets asked later, if at all.
The good news is that HIPAA does not require you to become a technologist. The rules that applied to your practice management system and your email provider apply to AI vendors in the same way. What changes is the set of questions worth asking. This article walks through those questions: business associate status, the BAA, where data actually goes, whether models learn from your patients, and what your team does day to day. None of this is legal advice. Treat everything here as a checklist to bring to your compliance advisor, not a substitute for one. For the broader landscape, see the guide to AI in the dental practice.
Why an AI vendor handling patient data is a business associate
HIPAA draws a simple line. If a vendor creates, receives, maintains, or transmits protected health information on your behalf, that vendor is a business associate. The technology does not matter. A billing service is a business associate, a cloud storage provider is a business associate, and an AI tool that reads your schedule, drafts messages to patients, or transcribes conversations that mention patients is a business associate for the same reason: patient information passes through its hands so that work gets done for your practice.
The practical implication is that “AI” does not create a new compliance category you have to learn from scratch. It creates a new vendor type that belongs in the same review process you already use, or should already use, for any system that touches patient data. If a tool never touches patient information at all, the analysis is different. But be honest about that boundary: a tool marketed for something generic often ends up receiving patient names and appointment details the moment your team starts using it for real work.
The BAA is table stakes, not a differentiator
A business associate agreement is the contract that obligates the vendor to safeguard patient information and defines what happens if something goes wrong. Under HIPAA, working with a business associate without one is a problem all by itself, before any breach ever occurs.
So treat the BAA as the entry ticket. A vendor that will not sign one is telling you the product is not built for your data, whatever the marketing says. A vendor that signs one readily has cleared the minimum bar, not the whole bar. The questions that separate vendors come after the signature: what the agreement actually permits the vendor to do with the data, whether subcontractors are covered, and how incidents are reported to you. Read the document, or have your advisor read it, rather than filing it. This sits alongside the other diligence in how to evaluate dental AI vendors.
Ask where the data is processed and stored
Modern AI tools are rarely one company. The product you see is often built on infrastructure and models operated by other companies, and your patients’ information may travel through several of them to produce a single drafted message or transcript.
You do not need a network diagram. You need clear answers to plain questions: Where is our data stored, and for how long? Which other companies process it along the way, and do those relationships carry the same obligations downstream? Can we have data deleted, and what does deletion actually mean in their systems? What happens to our data if we cancel? A vendor that can answer these questions crisply has thought about them. A vendor that answers with reassurance instead of specifics has given you your answer too.
Ask whether models train on your patients’ data
This question deserves its own conversation because it is where AI genuinely differs from earlier software. Some AI systems improve by training on the data that flows through them. If your patients’ information is used that way, fragments of it may influence a model that serves other customers, which is a very different arrangement than data sitting in a database.
Ask directly: Is our data used to train or improve models, either yours or a third party’s? Is that setting on by default, and can it be turned off contractually rather than by a toggle someone could flip back? Get the answer in writing, ideally in the BAA or an addendum, not in a sales call. There are legitimate arrangements on both sides of this question; what matters is that you know which one you are in and that your advisor has reviewed it.
Staff habits: which data goes into which tool
The most common HIPAA exposure with AI is not a vendor failure. It is a team member pasting a patient’s details into a free consumer chatbot to draft a letter, because the tool is convenient and nobody said not to. No BAA covers that tool, and no vendor review ever saw it.
The fix is a simple, written rule everyone knows: which tools are approved for patient information, which tools are for everything else, and the habit of leaving names and identifying details out when a general-purpose tool is good enough for the task. Revisit the rule when new tools show up, because they will. The human side of this is the same lesson as elsewhere in AI adoption: the tool is only half the system, as covered in what AI can’t do.
Bring it to your compliance advisor
Nothing above replaces professional review. What it does is make that review efficient. Arrive with the list of AI tools actually in use (including the unofficial ones), the BAAs you have, the vendors’ written answers on data location and model training, and your internal rule for staff usage. Your advisor can then evaluate a real picture instead of a guess, and update your risk analysis and policies accordingly. The practices that handle this well are not the ones that avoid AI; they are the ones that adopted the same tools deliberately, on paper, with eyes open. That deliberateness pays off across every AI use case, from AI patient communication onward.
Where CaseLift fits
CaseLift signs a business associate agreement with every practice and treats the questions in this article as ones every vendor, CaseLift included, should answer in writing before a practice commits.