This site provides independent HIPAA compliance cost estimates for informational purposes only. We are not affiliated with HHS, OCR, or any compliance vendor. This is not legal or regulatory advice. Consult a qualified HIPAA compliance professional for guidance specific to your organization.

Dental Practice HIPAA Compliance Cost in 2026

A dental practice's HIPAA budget splits cleanly in two. The tooling layer has published rate cards, and at 5-operatory scale it is small and knowable: the compliance platform, MFA and endpoint protection all publish per-user or per-device prices you can read today. The other half, the Security Rule risk analysis and the counsel time around your BAAs, is quoted per engagement and published by nobody. This page prices the first half from the vendors' own cards, is explicit about the second rather than filling it with an estimate, and covers the dental-specific BAA portfolio and the OCR enforcement patterns that most often catch dental practices.

Priced from a published card

  • Compliance platform subscription
  • MFA, per user
  • Endpoint protection, per device
  • Workstation encryption (shipped with the OS)
  • Workforce training, inside the platform tier

Quoted per engagement, published by nobody

  • The Security Rule risk analysis
  • Dental-specific policy and procedure work
  • Penetration testing and vulnerability scanning
  • Counsel review of your BAA portfolio
  • The IT managed-services relationship

The right-hand column is usually the larger half of a first-year dental programme, which is uncomfortable for a cost page. The alternative is to print a number no assessor stands behind. What you can do instead is take the published inputs below to your own quotes.

What counts as a dental covered entity

A dental practice is a healthcare provider covered entity under 45 CFR 160.103 when the practice transmits health information electronically in connection with a transaction covered by the rule. Electronic claim submission through Change Healthcare, DentalXChange, Apex EDI, ClaimConnect, eAssist, or any other claim clearinghouse triggers covered-entity status. Electronic eligibility verification or electronic referral transmission triggers it independently. The set of dental practices that legitimately fall outside HIPAA is essentially restricted to small cash-only practices that submit no electronic claims and run no electronic eligibility checks; those practices still benefit from HIPAA-aligned hygiene practices but are not legally bound.

This page covers general dentistry, specialty practices (orthodontics, oral surgery, endodontics, periodontics, pediatric dentistry, prosthodontics), and small dental support organizations (DSOs) at the per-branch level. Larger DSO operations consolidated under enterprise IT (Heartland Dental, Aspen Dental, Pacific Dental Services, Smile Brands, MB2 Dental) are closer to the physician-group or hospital cost profile and are not the primary focus here.

This is an informational cost reference, not legal or compliance advice. Consult a dental healthcare attorney or HIPAA-qualified compliance professional before making program or budget decisions.

The dental-specific vendor stack

The dental software ecosystem is meaningfully different from medical, which has implications for both BAA management and technical safeguards. The five dominant practice-management systems are Dentrix (Henry Schein One), Eaglesoft (Patterson Dental), Open Dental, Curve Dental, and Carestream Dental. Each signs a BAA for the practice-management application; each leaves workstation and network security as the practice's responsibility.

Beyond the PMS, a typical 5-operatory general-dentistry practice maintains BAAs across the following vendor categories. The list below is illustrative; the specific vendor names rotate practice-by-practice.

The dental-record-specific complication is that PMS data exports for lab-Rx purposes (sending a crown order to the lab with patient identification + clinical detail) often include more than the minimum-necessary subset under 45 CFR 164.502(b). Most lab orders need only the patient's identifier, the prescribing dentist, and the clinical Rx; routing the entire patient chart is a minimum-necessary failure.

The tooling layer, as published

Every figure in this table is read off the vendor's own pricing page and carries the date we checked it. Note the units: they are not the same across these products, and comparing a per-user monthly rate to a per-device annual rate is how a dental budget goes wrong before it starts.

LayerProduct and tier, as named by the vendorPublished rateUnit, as the vendor states it
Compliance platformAccountable HQ Basic$199/mo ($169 annually)Flat, includes 15 employees
Compliancy Group Foundationfrom $99/mo + from $8/employee/moPlan fee plus a separate per-employee fee
MFADuo Free$0Per user/month. Card says “Add up to 10 users”
Duo Essentials$3Per user/month. Licences sold in increments of 10 under 100 users
Microsoft Entra ID P1$7.00User/month, paid yearly (annual commitment)
Endpoint protectionCrowdStrike Falcon Go$59.99Per device, billed annually. Capped at 100 devices
CrowdStrike Falcon Pro$99.99Per device, billed annually
SentinelOne Singularity Core$69.99Per endpoint annually
Workstation encryptionBitLocker (Windows Pro), FileVault (macOS)No separate licenceShipped with the operating system you already bought
Endpoint allowlistingThreatLockerNo published priceIts pricing page offers “a price quote built around your environment”

Sources, each read off the vendor's own pricing page and checked July 2026: duo.com/pricing, Microsoft Entra pricing, crowdstrike.com/pricing, sentinelone.com/platform-packages, threatlocker.com/pricing, plus Accountable HQ and Compliancy Group. Two things worth knowing before you compare these. Cisco states a monthly per-user figure but no billing term on its pricing page, so whether $3 is an annual commitment expressed monthly is not something the card answers. CrowdStrike publishes its monthly and annual rates independently, and the annual one is not the monthly one times twelve: Falcon Go is $7.99 per device billed monthly against $59.99 billed annually, so deriving one from the other gets you a number CrowdStrike does not charge.

What those rates work out to at 5-operatory scale

Our arithmetic, not a vendor price

Every input below is a published figure from the table above. The multiplication is ours: no vendor publishes an annual total for a dental practice, and the Compliancy Group figures are worded as starting prices, so anything built on them is a floor. This is a worked example of how the published units behave at a stated headcount, not a quote, and it covers the tooling layer only. The risk analysis, the policy work and any counsel time are not in it, because nobody publishes a rate for them.

A 5-operatory practice: 10 workforce members, 8 workstations

MFA at 10 users lands on a threshold rather than a price. Duo publishes a free tier for up to 10 users, so a practice at exactly 10 pays $0 and a practice at 11 does not. On Duo Essentials the arithmetic is $3 × 10 users × 12 = $360 per year, though Cisco sells licences in increments of 10 below 100 users, so 11 users buys 20 licences. If the practice already runs Microsoft 365, Entra ID Free includes multifactor authentication at no additional cost, and Entra ID P1 at $7 per user per month paid yearly is $840 per year for the conditional-access policies rather than for the MFA itself.

Endpoint protection across 8 workstations

CrowdStrike Falcon Go at $59.99 per device billed annually is $59.99 × 8 = $479.92 per year, and a dental practice sits comfortably inside its 100-device cap. SentinelOne Singularity Core at $69.99 per endpoint annually is $69.99 × 8 = $559.92. Falcon Pro at $99.99 per device is $799.92. The spread across the whole endpoint layer at this scale is a few hundred dollars a year, which is worth knowing mainly because it is so much smaller than the unpublished half of the budget that it is rarely where a dental practice should spend its attention.

The platform, where the two cards diverge

Accountable HQ Basic at $169 per month billed annually is $2,028 per year, and its card states the tier includes 15 employees, which covers a 5-operatory practice outright. Compliancy Group Foundation is a plan fee plus a per-employee fee, so at 10 workforce members our arithmetic is $99 + (10 × $8) = $179 per month, which is $2,148 per year. Both are floors. The reason they land close here and diverge at 15 operatories is the per-employee axis: count workforce rather than operatories, because your hygienists, assistants and front office are all workforce members and they are what the per-employee line meters.

What this arithmetic does not cover is the entire right-hand column further up. A practice that buys every product in the table above has bought tooling, not a HIPAA programme: the risk analysis is the artifact OCR asks for first, no platform performs it for you, and nobody publishes what it costs.

OCR enforcement patterns affecting dental practices

Three recurring patterns drive almost all OCR enforcement against dental practices. Each is preventable at modest cost, and each is a process failure rather than a spending failure, which is why more tooling does not fix them. On the amounts, OCR publishes each resolution agreement it concludes and this page quotes them individually rather than averaging them into a per-pattern range: the published settlements cover scopes too different to average, and a range across them would describe no case that actually happened. The full published record is on the penalties page.

Pattern 1: Online-review responses that disclose PHI. A patient leaves a negative review on Google, Yelp, or Healthgrades. The dentist or front-desk staff responds with clinical detail to defend the practice ("Mrs. Smith's claim is unsupported; she presented for treatment X on date Y and we recommended Z which she declined"). The response is a public disclosure of PHI without authorization, which violates the Privacy Rule. OCR has resolved cases on precisely this fact pattern against dental practices, each with a corrective action plan attached to the settlement amount. The fix costs nothing: a written social-media-and-review policy with workforce training that explicitly prohibits clinical detail in public responses. This is the cheapest control on this page and the one most likely to be missing.

Pattern 2: Unencrypted backup drives or stolen laptops. The Dentrix or Eaglesoft data file is backed up to an external USB drive that is taken off-site or lost. The drive is unencrypted. The drive contains patient charts. OCR investigation typically arrives via the breach-notification rule (the practice was required to notify under 45 CFR 164.404 for breaches affecting 500+ individuals to HHS plus media; under 500, annually). The fix is BitLocker or equivalent disk encryption on every workstation and backup target, which the table above shows costs no separate licence: it ships with the Windows you already bought. That is the whole economics of this pattern. The control is free, the breach is not, and encryption is what moves a lost drive from a reportable breach to a non-event under the Breach Notification Rule.

Pattern 3: Missing BAAs for long-tail vendors. The OCR investigation requests the practice's BAA portfolio. The PMS BAA and the clearinghouse BAA are present. The imaging vendor BAA is missing. The patient-communication platform BAA is missing. The MSP BAA is missing or outdated. Each missing BAA is a potential Tier 2 (reasonable cause) violation at $1,461 to $73,011 per missing BAA (2026 inflation-adjusted amounts). The fix is a centralized BAA tracker (usually a feature of the compliance platform) with annual re-verification of every active vendor.

The Lifespan Health $1.04 million settlement in 2020, while technically a medical not dental case, established the pattern that small healthcare entities are not exempt from significant penalties for the unencrypted-laptop fact pattern. Dental practices that assume small-entity size protects them are reading the enforcement archive incorrectly.

The dental-specific compliance gotchas

Family-account PMS structures. Most dental PMS systems are organized around the patient account ("Smith family") rather than the individual patient record. Front-desk staff routinely view the family account to schedule a child's cleaning; the family account exposes the spouse's and other children's charts. Minimum-necessary access policy under 45 CFR 164.502(b) is technically violated in the standard PMS workflow at every dental practice; OCR has tolerated this in practice but the underlying tension exists.

Photo and video before-and-after marketing. Cosmetic dentistry and orthodontic marketing often features identifiable patient before-and-after photos. Patient authorization under 45 CFR 164.508 is required for marketing use of PHI, and the authorization must be specific (which photos, for which media, for how long, with right to revoke). A blanket "we may use your image" form at intake is not a compliant marketing authorization.

Lab-Rx routing as a minimum-necessary issue. Sending a full patient chart to the lab when only the Rx is needed is a minimum-necessary violation in technical reading of the rule. PMS vendors increasingly support per-lab data-export templates that limit the routing scope; using these templates is the cost-free fix.

Teledentistry plus emergency-discretion wind-down. The HHS OCR teledentistry / telehealth enforcement-discretion announcement issued in March 2020 was wound down on 11 August 2023. Practices that adopted consumer-grade videoconferencing during the pandemic (FaceTime, Skype consumer) and never migrated to a BAA-eligible platform are now in violation of the Security Rule for the videoconferencing channel. The fix is to migrate to a HIPAA-compliant teledentistry platform or a BAA-eligible general videoconferencing platform.

Dental practice HIPAA cost FAQ

Do dental practices need full HIPAA compliance?
Yes, with one narrow exception. A dental practice that does not transmit any health information electronically in connection with a covered transaction (claims, eligibility, referrals, remittance, etc.) is not a covered entity. In practice, nearly every dental practice that submits electronic claims to a payer through any clearinghouse (Change Healthcare, Apex EDI, DentalXChange, ClaimConnect, eAssist) is a covered entity and must comply with the full Privacy, Security, and Breach Notification Rules. The set of practices that legitimately fall outside the rule is essentially restricted to cash-only practices that file no electronic claims, no electronic eligibility checks, and no electronic referrals.
How much does HIPAA cost a typical 5-operatory dental practice?
There is no honest single number and this page does not print one, because a dental HIPAA budget is half published rates and half quotes. The part you can price from a published card today: Accountable HQ publishes Basic at $199 per month, or $169 billed annually, including 15 employees, which covers a 5-operatory practice's whole workforce; Compliancy Group publishes Foundation from $99 per month billed annually plus a separate per-employee fee from $8 per employee per month. Cisco Duo publishes a free tier for up to 10 users and Duo Essentials at $3 per user per month; CrowdStrike publishes Falcon Go at $59.99 per device billed annually. All figures checked July 2026 on the vendors' own pricing pages, and the Compliancy Group ones are worded as starting prices, so they are floors. The part nobody publishes is the part that usually costs more: the Security Rule risk analysis, policy work and any counsel review of your BAAs are quoted per engagement against your scope, and no firm publishes a rate card for them. Any all-in dental figure you are shown, including any in this site's earlier drafts, is somebody's estimate.
What dental-specific HIPAA vendors do I need BAAs with?
Beyond the obvious EHR/PMS BAA (Dentrix, Eaglesoft, Open Dental, Curve Dental, Carestream, or similar), a typical dental practice needs BAAs with imaging vendors (Sirona, Vatech, Carestream, Planmeca for intra-oral and panoramic), dental lab partners (any lab that receives patient name + Rx data for crowns, dentures, aligners), claim clearinghouse (Change Healthcare, DentalXChange, Apex EDI), payment processing if patient PHI flows into the merchant account routing, patient communication platforms (Weave, Solutionreach, Lighthouse 360, Demandforce, RevenueWell), online review platforms that pull patient data, IT support / managed service provider, document shredding service, and any teledentistry vendor. A typical 5-operatory general-dentistry practice maintains 15 to 30 active BAAs.
What is the most common HIPAA failure that triggers OCR investigation of dental practices?
Three patterns dominate. First, unencrypted backup drives or stolen laptops with PMS data on them; the unencrypted-laptop pattern has driven multiple OCR settlements across small practices generally, and dental practices that back up Dentrix or Eaglesoft data to local external drives are exposed. Second, online-review responses where the dentist replies to a negative review with patient-specific clinical detail, which OCR has resolved against dental practices more than once. Third, BAA gaps with the long-tail vendor list (imaging service, lab partner, billing service). On what any of these cost, OCR publishes every resolution agreement it concludes individually, and this page does not average them into a range: the published amounts span scopes that are not comparable, and a range built across them describes no actual case. See the penalties page for the record itself. The dental-record-specific challenge is that PMS data exports for treatment-planning or lab-Rx purposes often include the full patient chart rather than the minimum-necessary subset under 45 CFR 164.502(b).
Can a solo dentist DIY HIPAA compliance without a consultant?
Yes, using a guided compliance platform plus a one-time external risk assessment. The platform half has a published price: Accountable HQ publishes Basic at $169 per month billed annually and Plus at $254, and Compliancy Group publishes Foundation from $99 per month billed annually plus a per-employee fee from $8, each on its own pricing page, checked July 2026. That buys guided risk assessment, policy templates, training modules and BAA tracking. The consultant half does not have a published price: HIPAA consultants quote per engagement against your scope and essentially none publishes a rate card, so this page prints no figure for the formal Security Rule risk assessment. The DIY-with-platform-only approach without any external risk assessment is feasible but trades cost for risk: OCR treats the risk analysis under 45 CFR 164.308(a)(1)(ii)(A) as the foundational compliance artifact, and a platform-generated assessment is sometimes less defensible in an OCR investigation than a consultant-led one.
How does HIPAA training work for a dental practice?
Under 45 CFR 164.530(b)(1) and 164.308(a)(5), the practice must train every workforce member who handles PHI on the policies and procedures relevant to their job function. For dental practices, this typically means an initial onboarding training plus an annual refresher for all workforce members (clinical and admin), plus event-driven training when policies change materially. On price, the useful answer for a dental practice is that training is usually not a separate line at all: the compliance platforms that publish a rate card include the training module in the subscription, so at 5-operatory scale the training cost is already inside the Accountable HQ or Compliancy Group figure rather than sitting next to it. Standalone per-user training is sold by vendors that mostly quote rather than publish, so this page prints no per-user rate.
What 2026 Security Rule NPRM changes most affect a dental practice?
Three of the proposed changes are the most material at dental-practice scale. First, the MFA requirement for all ePHI access means that the historical pattern of shared workstations using a single Dentrix login at the front desk needs to migrate to per-user login with MFA. Second, the asset inventory + network map requirement adds a documentation burden that small dental practices often skip; the GRC platform vendors are likely to add asset-inventory templates to their dental-practice tier. Third, the proposal would mandate an annual penetration test, which is work most practices at this scale have never bought. On what any of it costs, the answer is more pointed for dentistry than for any other segment: HHS did not model dental practices at all. The word "dental" does not appear once in the rule's regulatory impact analysis, and dentistry is not broken out in its entity tables, sitting instead inside a 527,951-establishment category covering offices of physicians, dentists and other health practitioners. What HHS does publish is roughly $9 billion in first-year costs across 1,822,600 regulated entities and a single flat per-entity figure of approximately $1,235 in annualized cost, applied identically to a solo dentist and a reference laboratory. It gave the asset inventory no dollar figure at all. So there is no dental NPRM number to quote, and this page does not manufacture one.

Related cost guides

Updated 2026-07-17