Dental Practice HIPAA Compliance Cost in 2026
A dental practice's HIPAA budget splits cleanly in two. The tooling layer has published rate cards, and at 5-operatory scale it is small and knowable: the compliance platform, MFA and endpoint protection all publish per-user or per-device prices you can read today. The other half, the Security Rule risk analysis and the counsel time around your BAAs, is quoted per engagement and published by nobody. This page prices the first half from the vendors' own cards, is explicit about the second rather than filling it with an estimate, and covers the dental-specific BAA portfolio and the OCR enforcement patterns that most often catch dental practices.
Priced from a published card
- Compliance platform subscription
- MFA, per user
- Endpoint protection, per device
- Workstation encryption (shipped with the OS)
- Workforce training, inside the platform tier
Quoted per engagement, published by nobody
- The Security Rule risk analysis
- Dental-specific policy and procedure work
- Penetration testing and vulnerability scanning
- Counsel review of your BAA portfolio
- The IT managed-services relationship
The right-hand column is usually the larger half of a first-year dental programme, which is uncomfortable for a cost page. The alternative is to print a number no assessor stands behind. What you can do instead is take the published inputs below to your own quotes.
What counts as a dental covered entity
A dental practice is a healthcare provider covered entity under 45 CFR 160.103 when the practice transmits health information electronically in connection with a transaction covered by the rule. Electronic claim submission through Change Healthcare, DentalXChange, Apex EDI, ClaimConnect, eAssist, or any other claim clearinghouse triggers covered-entity status. Electronic eligibility verification or electronic referral transmission triggers it independently. The set of dental practices that legitimately fall outside HIPAA is essentially restricted to small cash-only practices that submit no electronic claims and run no electronic eligibility checks; those practices still benefit from HIPAA-aligned hygiene practices but are not legally bound.
This page covers general dentistry, specialty practices (orthodontics, oral surgery, endodontics, periodontics, pediatric dentistry, prosthodontics), and small dental support organizations (DSOs) at the per-branch level. Larger DSO operations consolidated under enterprise IT (Heartland Dental, Aspen Dental, Pacific Dental Services, Smile Brands, MB2 Dental) are closer to the physician-group or hospital cost profile and are not the primary focus here.
This is an informational cost reference, not legal or compliance advice. Consult a dental healthcare attorney or HIPAA-qualified compliance professional before making program or budget decisions.
The dental-specific vendor stack
The dental software ecosystem is meaningfully different from medical, which has implications for both BAA management and technical safeguards. The five dominant practice-management systems are Dentrix (Henry Schein One), Eaglesoft (Patterson Dental), Open Dental, Curve Dental, and Carestream Dental. Each signs a BAA for the practice-management application; each leaves workstation and network security as the practice's responsibility.
Beyond the PMS, a typical 5-operatory general-dentistry practice maintains BAAs across the following vendor categories. The list below is illustrative; the specific vendor names rotate practice-by-practice.
- Imaging: intra-oral camera + panoramic + 3D imaging vendors (Sirona, Vatech, Carestream, Planmeca, J Morita).
- Dental lab partners: any lab receiving patient name + Rx data for crowns, bridges, dentures, aligners (Glidewell, Modern Dental Group, regional labs).
- Claim clearinghouse: Change Healthcare, DentalXChange, Apex EDI, ClaimConnect, eAssist.
- Patient communication: Weave, Solutionreach, Lighthouse 360, Demandforce, RevenueWell.
- Online review platforms: any platform that pulls patient name and visit data for review solicitation.
- Teledentistry vendors: Toothpic, MouthWatch TeleDent, Denteractive (if telehealth services are offered).
- Backup + cloud storage: on-premise backup vendor, cloud-backup provider, off-site disaster-recovery vendor.
- IT managed-services provider (MSP): the IT support partner with access to practice systems.
- Document shredding service: ProShred, Shred-it, or local equivalent for paper records.
- Insurance verification service: if the practice uses a third-party verification specialist who logs into payer portals.
- Billing or RCM service: if outsourced.
- Aligner / ortho-software vendor: Invisalign / SmileDirectClub provider portals, ortho-tracking systems.
The dental-record-specific complication is that PMS data exports for lab-Rx purposes (sending a crown order to the lab with patient identification + clinical detail) often include more than the minimum-necessary subset under 45 CFR 164.502(b). Most lab orders need only the patient's identifier, the prescribing dentist, and the clinical Rx; routing the entire patient chart is a minimum-necessary failure.
The tooling layer, as published
Every figure in this table is read off the vendor's own pricing page and carries the date we checked it. Note the units: they are not the same across these products, and comparing a per-user monthly rate to a per-device annual rate is how a dental budget goes wrong before it starts.
| Layer | Product and tier, as named by the vendor | Published rate | Unit, as the vendor states it |
|---|---|---|---|
| Compliance platform | Accountable HQ Basic | $199/mo ($169 annually) | Flat, includes 15 employees |
| Compliancy Group Foundation | from $99/mo + from $8/employee/mo | Plan fee plus a separate per-employee fee | |
| MFA | Duo Free | $0 | Per user/month. Card says “Add up to 10 users” |
| Duo Essentials | $3 | Per user/month. Licences sold in increments of 10 under 100 users | |
| Microsoft Entra ID P1 | $7.00 | User/month, paid yearly (annual commitment) | |
| Endpoint protection | CrowdStrike Falcon Go | $59.99 | Per device, billed annually. Capped at 100 devices |
| CrowdStrike Falcon Pro | $99.99 | Per device, billed annually | |
| SentinelOne Singularity Core | $69.99 | Per endpoint annually | |
| Workstation encryption | BitLocker (Windows Pro), FileVault (macOS) | No separate licence | Shipped with the operating system you already bought |
| Endpoint allowlisting | ThreatLocker | No published price | Its pricing page offers “a price quote built around your environment” |
Sources, each read off the vendor's own pricing page and checked July 2026: duo.com/pricing, Microsoft Entra pricing, crowdstrike.com/pricing, sentinelone.com/platform-packages, threatlocker.com/pricing, plus Accountable HQ and Compliancy Group. Two things worth knowing before you compare these. Cisco states a monthly per-user figure but no billing term on its pricing page, so whether $3 is an annual commitment expressed monthly is not something the card answers. CrowdStrike publishes its monthly and annual rates independently, and the annual one is not the monthly one times twelve: Falcon Go is $7.99 per device billed monthly against $59.99 billed annually, so deriving one from the other gets you a number CrowdStrike does not charge.
What those rates work out to at 5-operatory scale
Our arithmetic, not a vendor price
Every input below is a published figure from the table above. The multiplication is ours: no vendor publishes an annual total for a dental practice, and the Compliancy Group figures are worded as starting prices, so anything built on them is a floor. This is a worked example of how the published units behave at a stated headcount, not a quote, and it covers the tooling layer only. The risk analysis, the policy work and any counsel time are not in it, because nobody publishes a rate for them.
A 5-operatory practice: 10 workforce members, 8 workstations
MFA at 10 users lands on a threshold rather than a price. Duo publishes a free tier for up to 10 users, so a practice at exactly 10 pays $0 and a practice at 11 does not. On Duo Essentials the arithmetic is $3 × 10 users × 12 = $360 per year, though Cisco sells licences in increments of 10 below 100 users, so 11 users buys 20 licences. If the practice already runs Microsoft 365, Entra ID Free includes multifactor authentication at no additional cost, and Entra ID P1 at $7 per user per month paid yearly is $840 per year for the conditional-access policies rather than for the MFA itself.
Endpoint protection across 8 workstations
CrowdStrike Falcon Go at $59.99 per device billed annually is $59.99 × 8 = $479.92 per year, and a dental practice sits comfortably inside its 100-device cap. SentinelOne Singularity Core at $69.99 per endpoint annually is $69.99 × 8 = $559.92. Falcon Pro at $99.99 per device is $799.92. The spread across the whole endpoint layer at this scale is a few hundred dollars a year, which is worth knowing mainly because it is so much smaller than the unpublished half of the budget that it is rarely where a dental practice should spend its attention.
The platform, where the two cards diverge
Accountable HQ Basic at $169 per month billed annually is $2,028 per year, and its card states the tier includes 15 employees, which covers a 5-operatory practice outright. Compliancy Group Foundation is a plan fee plus a per-employee fee, so at 10 workforce members our arithmetic is $99 + (10 × $8) = $179 per month, which is $2,148 per year. Both are floors. The reason they land close here and diverge at 15 operatories is the per-employee axis: count workforce rather than operatories, because your hygienists, assistants and front office are all workforce members and they are what the per-employee line meters.
What this arithmetic does not cover is the entire right-hand column further up. A practice that buys every product in the table above has bought tooling, not a HIPAA programme: the risk analysis is the artifact OCR asks for first, no platform performs it for you, and nobody publishes what it costs.
OCR enforcement patterns affecting dental practices
Three recurring patterns drive almost all OCR enforcement against dental practices. Each is preventable at modest cost, and each is a process failure rather than a spending failure, which is why more tooling does not fix them. On the amounts, OCR publishes each resolution agreement it concludes and this page quotes them individually rather than averaging them into a per-pattern range: the published settlements cover scopes too different to average, and a range across them would describe no case that actually happened. The full published record is on the penalties page.
Pattern 1: Online-review responses that disclose PHI. A patient leaves a negative review on Google, Yelp, or Healthgrades. The dentist or front-desk staff responds with clinical detail to defend the practice ("Mrs. Smith's claim is unsupported; she presented for treatment X on date Y and we recommended Z which she declined"). The response is a public disclosure of PHI without authorization, which violates the Privacy Rule. OCR has resolved cases on precisely this fact pattern against dental practices, each with a corrective action plan attached to the settlement amount. The fix costs nothing: a written social-media-and-review policy with workforce training that explicitly prohibits clinical detail in public responses. This is the cheapest control on this page and the one most likely to be missing.
Pattern 2: Unencrypted backup drives or stolen laptops. The Dentrix or Eaglesoft data file is backed up to an external USB drive that is taken off-site or lost. The drive is unencrypted. The drive contains patient charts. OCR investigation typically arrives via the breach-notification rule (the practice was required to notify under 45 CFR 164.404 for breaches affecting 500+ individuals to HHS plus media; under 500, annually). The fix is BitLocker or equivalent disk encryption on every workstation and backup target, which the table above shows costs no separate licence: it ships with the Windows you already bought. That is the whole economics of this pattern. The control is free, the breach is not, and encryption is what moves a lost drive from a reportable breach to a non-event under the Breach Notification Rule.
Pattern 3: Missing BAAs for long-tail vendors. The OCR investigation requests the practice's BAA portfolio. The PMS BAA and the clearinghouse BAA are present. The imaging vendor BAA is missing. The patient-communication platform BAA is missing. The MSP BAA is missing or outdated. Each missing BAA is a potential Tier 2 (reasonable cause) violation at $1,461 to $73,011 per missing BAA (2026 inflation-adjusted amounts). The fix is a centralized BAA tracker (usually a feature of the compliance platform) with annual re-verification of every active vendor.
The Lifespan Health $1.04 million settlement in 2020, while technically a medical not dental case, established the pattern that small healthcare entities are not exempt from significant penalties for the unencrypted-laptop fact pattern. Dental practices that assume small-entity size protects them are reading the enforcement archive incorrectly.
The dental-specific compliance gotchas
Family-account PMS structures. Most dental PMS systems are organized around the patient account ("Smith family") rather than the individual patient record. Front-desk staff routinely view the family account to schedule a child's cleaning; the family account exposes the spouse's and other children's charts. Minimum-necessary access policy under 45 CFR 164.502(b) is technically violated in the standard PMS workflow at every dental practice; OCR has tolerated this in practice but the underlying tension exists.
Photo and video before-and-after marketing. Cosmetic dentistry and orthodontic marketing often features identifiable patient before-and-after photos. Patient authorization under 45 CFR 164.508 is required for marketing use of PHI, and the authorization must be specific (which photos, for which media, for how long, with right to revoke). A blanket "we may use your image" form at intake is not a compliant marketing authorization.
Lab-Rx routing as a minimum-necessary issue. Sending a full patient chart to the lab when only the Rx is needed is a minimum-necessary violation in technical reading of the rule. PMS vendors increasingly support per-lab data-export templates that limit the routing scope; using these templates is the cost-free fix.
Teledentistry plus emergency-discretion wind-down. The HHS OCR teledentistry / telehealth enforcement-discretion announcement issued in March 2020 was wound down on 11 August 2023. Practices that adopted consumer-grade videoconferencing during the pandemic (FaceTime, Skype consumer) and never migrated to a BAA-eligible platform are now in violation of the Security Rule for the videoconferencing channel. The fix is to migrate to a HIPAA-compliant teledentistry platform or a BAA-eligible general videoconferencing platform.
Dental practice HIPAA cost FAQ
Do dental practices need full HIPAA compliance?
How much does HIPAA cost a typical 5-operatory dental practice?
What dental-specific HIPAA vendors do I need BAAs with?
What is the most common HIPAA failure that triggers OCR investigation of dental practices?
Can a solo dentist DIY HIPAA compliance without a consultant?
How does HIPAA training work for a dental practice?
What 2026 Security Rule NPRM changes most affect a dental practice?
Related cost guides
Small Practice Guide
Solo to 15-staff practices budget read
Accountable HQ Cost
$199/mo solo-practice platform pricing
Compliancy Group Cost
Per-practice-size pricing read
Risk Assessment Cost
Annual 164.308 risk-analysis pricing
Training Cost
Per-user training license pricing
HIPAA Penalties
Four-tier penalty structure and enforcement