Skip to content
Kythro

Compliance

Compliance checklist for a US dental practice: what's actually required

By Kythro Team, Product team · · 7 min read

A locked filing cabinet beside a laptop on a clinic desk

Dental practices get a lot of advice about compliance. Most of it is correct in isolation and overwhelming in aggregate. A practice owner trying to figure out what they actually need to do before opening, or what they need to fix in an existing operation, ends up either ignoring the topic or paying a consultant to restate the obvious.

This is the short version. It is not legal advice, rules vary by state, and your state dental board and a healthcare attorney are the final word. It is the operational list we see working clinics actually run on.

The 8 things that are actually required

1. State dental board licensure

Every dentist and hygienist needs an active license in the state where they practice, and most states also require the practice itself to be registered or permitted. Renewal cycles, continuing education hours, and sedation permits are all state specific. Put the renewal dates in the same calendar as your lease.

2. NPI and DEA numbers

An NPI for each provider and for the practice if you ever bill a third party. A DEA registration for any dentist who prescribes controlled substances, plus your state's controlled substance registration where one exists. Check your state's prescription drug monitoring program requirements before the first prescription, not after.

3. HIPAA Privacy Rule

You are a covered entity. That means a Notice of Privacy Practices given to every patient, a designated privacy officer (it can be you), documented staff training, and a written policy for how records are accessed, shared, and released. Patients can request their records and you have 30 days to respond.

4. HIPAA Security Rule

The part most practices skip. A written risk analysis of where electronic patient data lives and how it could leak, then reasonable safeguards: unique logins per staff member, encryption for anything that leaves the building, access that ends when employment does, and a plan for a breach. A software vendor that holds your data is a business associate and must sign a Business Associate Agreement. No BAA, no data.

5. OSHA

Two standards do most of the work. The Bloodborne Pathogens standard requires a written exposure control plan, hepatitis B vaccination offered to exposed staff, sharps handling, and annual training. The Hazard Communication standard requires labelled chemicals and safety data sheets on hand. Both need training records you can produce on request.

6. Radiation safety and x-ray registration

X-ray equipment is registered with the state radiation control program, inspected on a schedule, and operated by people with the training your state requires. Keep the registration, the last inspection report, and operator certificates in one folder.

7. Infection control

Most state boards adopt the CDC guidelines for infection prevention in dental settings, and inspect against them. Sterilizer monitoring with a biological indicator at least weekly, a log of the results, and a written protocol for instrument processing are the items inspectors ask for first.

8. Informed consent and record retention

Documented consent for treatment, with the material risks and alternatives explained. Retention periods are set by state law and typically run 5 to 10 years for adults and longer for minors, counted from the last visit. Digital records make retention easy; make sure export is possible before you commit to a vendor.

The 4 things you should do

9. Professional liability insurance

Malpractice coverage for each dentist. Occurrence or claims-made, with tail coverage if you ever change carriers. The cost of one uninsured dispute will dwarf a decade of premiums.

10. General liability and cyber liability

General liability covers slips, falls, and property claims. Cyber liability covers the breach response, notification, and credit monitoring costs that HIPAA makes yours. Both are inexpensive relative to what they cover.

11. Written breach response plan

HIPAA requires notification of affected patients within 60 days of discovering a breach, and of the Department of Health and Human Services on a schedule that depends on the size. Decide now who makes the call, who writes the letters, and who talks to the press if it comes to that.

12. A signed BAA with every vendor that touches patient data

Practice management software, cloud storage, email, imaging, billing services, the IT company. Keep the signed copies together. An auditor will ask for them in the first ten minutes.

The 5 things you can skip until someone specifically asks

13. Accreditation programs

AAAHC and similar accreditations matter for surgical centers and some payor contracts. A general or specialty practice rarely needs them.

14. Association membership

ADA, AAO, and state association membership is valuable for advocacy, education, and networking. It is not a compliance requirement.

15. A dedicated compliance officer

A practice with fewer than twenty staff does not need a separate role. It needs one named person, a calendar, and a folder.

16. Formal SOC 2 or ISO reports of your own

You should ask your vendors for these. Your practice does not need to produce them.

17. Accessibility certifications

ADA accessibility obligations are real, but they are met by the building and your policies, not by a certificate.

The compliance audit you should run yourself

Once a year, on a slow Friday afternoon, walk the building with this list and a folder.

  1. Every license and registration current, with renewal dates in the calendar.
  2. Notice of Privacy Practices posted and given to new patients.
  3. Risk analysis dated within the last twelve months.
  4. Training records for HIPAA and OSHA, signed and dated.
  5. Sterilizer log complete with weekly biological indicator results.
  6. Signed BAAs on file for every vendor.
  7. Every staff member has their own login to every system, and the departed ones are gone.

If the walk takes more than an hour, something is missing.

What this looks like in software

Practice management software does not make you compliant, but it makes the boring parts cheap. Unique logins with roles, an audit trail on clinical notes, encrypted storage with a BAA from the vendor, exportable records for retention, and consent captured on the treatment plan rather than in a drawer. Kythro covers those five, and will sign a BAA on request.

The honest summary

Eight things are required. Four more are wise. Everything else can wait until a payor, a buyer, or an inspector asks for it by name. Spend your compliance energy on the eight, run the annual walk, and keep the folder current.

Run your clinic on Kythro.

Start a free 30 day trial. No credit card required.