Regulatory Notice
The following information does not constitute legal advice, and you should check with your state or your legal team before implementing anything based on information read on this site. Regulations change, interpretations vary, and your laboratory is responsible for confirming the current requirements that apply to its own work.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) establishes national standards for protecting the privacy and security of patient health information. While HIPAA is often associated with dental and medical offices, it also affects the day-to-day operations of dental laboratories.
Every crown, bridge, denture, orthodontic appliance, implant restoration, and custom prosthesis is fabricated using information supplied by the prescribing dentist. That information frequently includes Protected Health Information (PHI), making it essential for dental laboratories to understand their responsibilities under HIPAA.
One of the most common misconceptions in dentistry is that dental laboratories must sign Business Associate Agreements (BAAs). They do not.
Yes.
Dental laboratories routinely receive Protected Health Information (PHI) from dentists as part of the patient treatment process. HIPAA specifically permits healthcare providers to exchange PHI when it is necessary for treatment.
Examples of information commonly provided to a laboratory include:
Dentists should disclose only the information necessary for the laboratory to fabricate the prescribed restoration.
Information becomes Protected Health Information (PHI) when it meets two requirements:
The key issue is not whether the information contains a name somewhere. The key issue is whether the information can reasonably be connected to a specific person.
For example, a common name by itself may not be enough to reliably identify one patient. However, a name combined with a date of birth, dentist name, address, phone number, chart number, case number, photograph, radiograph, or other unique information may identify a specific individual.
In a dental laboratory, PHI usually exists because patient identifiers are combined with treatment information, such as a prescription, digital scan, shade record, photograph, implant record, or appliance design.
A de-identified case number, tooth number, shade, and STL file may not be PHI if the laboratory has no reasonable way to determine the patient’s identity from that information alone.
No.
Dental laboratories do not need to sign a Business Associate Agreement (BAA) when receiving Protected Health Information from a dentist for the purpose of manufacturing a prescribed dental restoration.
This is not simply an industry opinion—it is how the HIPAA Privacy Rule is written.
Under HIPAA, dentists and dental laboratories are both healthcare providers participating in the treatment of the patient. HIPAA specifically allows one healthcare provider to disclose Protected Health Information to another healthcare provider for treatment purposes without a Business Associate Agreement.
A dental laboratory is not performing administrative work on behalf of the dental practice. Instead, the laboratory is manufacturing a custom medical device that has been prescribed as part of the patient's treatment plan.
Because of this treatment relationship:
The American Dental Association (ADA), the National Association of Dental Laboratories (NADL), and guidance from the U.S. Department of Health and Human Services all recognize this treatment exception.
HIPAA permits disclosure of Protected Health Information necessary to complete treatment.
Common information sent to laboratories includes:
| Information | Purpose |
|---|---|
| Patient name | Case identification |
| Tooth number | Restoration location |
| Shade | Esthetics |
| Digital scans | Restoration design |
| Impressions | Device fabrication |
| Clinical photographs | Characterization |
| Bite registrations | Occlusion |
| Implant information | Component selection |
| Relevant medical alerts | Safe fabrication |
Information unrelated to treatment should not be transmitted.
Although dental laboratories are not Business Associates, they still have a professional responsibility to protect confidential patient information.
Patient information should only be accessed by employees who require it to perform their job duties.
Laboratories should implement reasonable administrative, physical, and technical safeguards to reduce the risk of unauthorized disclosure.
Digital case transmission has become the standard in modern dentistry.
Whenever possible, laboratories should use secure methods to exchange patient information, including:
Whenever possible, avoid:
Patient information should also be protected within the laboratory.
Good practices include:
Every laboratory should maintain basic cybersecurity practices.
These include:
Modern dental laboratories routinely receive digital patient records, including:
These files often contain Protected Health Information and should be handled with the same care as traditional paper prescriptions.
Whenever practical, patient information should be limited to what is necessary for treatment.
Many laboratories use internal case numbers to reduce unnecessary exposure of patient identifiers.
For example:
Instead of displaying:
John Smith
A laboratory may internally use:
Case #24-10381
However, sufficient information must remain available to correctly identify, fabricate, document, and return the prescribed restoration.
Every laboratory employee should understand basic patient privacy principles.
Employees should:
Protecting patient confidentiality is everyone's responsibility.
Examples of preventable privacy violations include:
Most privacy incidents result from poor procedures rather than malicious intent.
HIPAA protects patient health information.
PCI DSS (Payment Card Industry Data Security Standard) protects payment card information.
Many dental laboratories must comply with both.
Laboratories should ensure that:
Although HIPAA and PCI DSS regulate different information, both are essential components of a secure laboratory.
Every dental laboratory should:
No. Dental laboratories manufacturing prescribed dental restorations do not need a Business Associate Agreement with the prescribing dentist. HIPAA specifically permits healthcare providers to exchange Protected Health Information for treatment purposes without a Business Associate Agreement.
Yes. HIPAA expressly permits dentists to disclose Protected Health Information to a dental laboratory when that information is necessary to fabricate a prescribed dental restoration.
Yes. Laboratories commonly retain prescriptions, digital design files, production records, and remake history as part of quality assurance, regulatory compliance, and business operations. These records should be protected appropriately.
Yes. Digital scans, photographs, radiographs, and other clinical records may be transmitted when necessary for treatment. Laboratories should use secure methods whenever possible.
DentalTechnology.org is dedicated to preserving, teaching, and advancing the craft of dental technology.
This resource is made possible by Russellville Dental Lab, a full-service dental laboratory in Russellville, Kentucky, serving clinicians across the USA for more than 70 years.