Dental HIPAA HubGet Compliant →

HIPAA Compliance Guides for Dental Practices — 2026

Every guide is specific to your dental specialty and state. Find your combination below to see exact violation risks, average fines, and the ADA-recommended compliance tools for 2026.

General Dentistry

35 state guides available

Dallas, Texas

Avg fine: $35,000

Outdated NPP · Missing BAA with billing vendor

high urgency

Miami, Florida

Avg fine: $42,000

Outdated NPP · Verbal PHI disclosure

high urgency

Phoenix, Arizona

Avg fine: $28,000

Missing Risk Assessment · Outdated NPP

medium urgency

Chicago, Illinois

Avg fine: $31,000

Missing BAA with IT vendor · No sanction policy

high urgency

Los Angeles, California

Avg fine: $47,000

CMIA violations · Missing NPP translation

critical urgency

Scottsdale, Arizona

Avg fine: $28,000

Missing BAA with cosmetic imaging vendor · Outdated NPP for concierge services

high urgency

Cape Coral, Florida

Avg fine: $42,000

Billing errors on high-value procedures · Missing BAA with dental finance company

high urgency

Raleigh, North Carolina

Avg fine: $32,000

Outdated NPP at newly opened locations · Missing BAA with practice management software

high urgency

Houston, Texas

Avg fine: $35,000

Insurance pre-authorization PHI leaks · Missing BAA with insurance clearinghouse

high urgency

Orlando, Florida

Avg fine: $42,000

Missing multilingual NPP · No translated patient authorization forms

high urgency

Austin, Texas

Avg fine: $35,000

Missing BAA with DSO management platform · No multi-location sanction policy

high urgency

Tampa, Florida

Avg fine: $42,000

Missing disaster recovery plan for ePHI · No encrypted offsite backup

high urgency

San Diego, California

Avg fine: $47,000

Missing BAA for TRICARE PHI sharing · CMIA violations from military-adjacent billing

critical urgency

Charlotte, North Carolina

Avg fine: $32,000

Missing BAA with corporate HR dental plan administrator · No HIPAA policy for employer-sponsored plan PHI

high urgency

Tucson, Arizona

Avg fine: $28,000

Missing NPP in Spanish for Spanish-speaking patient majority · No bilingual workforce HIPAA training

medium urgency

San Antonio, Texas

Avg fine: $35,000

Missing BAA with Medicaid managed care billing agent · No bilingual NPP for Spanish-speaking majority

high urgency

Fort Worth, Texas

Avg fine: $35,000

Missing BAA with DSO regional management platform · No MFA on practice management software

high urgency

Jacksonville, Florida

Avg fine: $42,000

Missing BAA with military insurance billing agent · No ePHI disaster recovery plan

high urgency

Fort Lauderdale, Florida

Avg fine: $42,000

Missing BAA with dental tourism facilitator · No cross-border PHI protocol for international patients

high urgency

San Francisco, California

Avg fine: $52,000

CCPA health data requests mishandled · Missing BAA with AI diagnostic tool vendor

critical urgency

San Jose, California

Avg fine: $47,000

Missing BAA with employer health portal integration · CCPA employee dependent data rights

critical urgency

Sacramento, California

Avg fine: $47,000

Missing BAA with state government employee dental plan administrator · CMIA violations from Covered California exchange data

critical urgency

New York, New York

Avg fine: $52,000

Missing SHIELD Act written security program · No MFA on all ePHI systems

critical urgency

Atlanta, Georgia

Avg fine: $29,000

Missing BAA with insurance clearinghouse · No MFA on cloud-based practice management software

high urgency

Columbus, Ohio

Avg fine: $27,000

Missing BAA with OSU student health plan administrator · No MFA on insurance verification tools

medium urgency

Philadelphia, Pennsylvania

Avg fine: $34,000

Missing BAA with Penn Medicine or Jefferson Health referral system · No MFA on billing software

high urgency

Seattle, Washington

Avg fine: $38,000

Missing MHMD Act consumer health data privacy notice · No geofencing prohibition policy

high urgency

Denver, Colorado

Avg fine: $26,000

Missing Colorado Privacy Act consumer rights procedures · No MFA on cloud practice management software

medium urgency

Las Vegas, Nevada

Avg fine: $33,000

Missing BAA with dental tourism facilitator · No transient patient PHI protocol

high urgency

Nashville, Tennessee

Avg fine: $24,000

Missing BAA with healthcare industry employer dental plan · No MFA on cloud-based billing software

medium urgency

Boston, Massachusetts

Avg fine: $48,000

Missing Written Information Security Plan (WISP) · No Massachusetts 201 CMR 17.00 compliance documentation

critical urgency

Minneapolis, Minnesota

Avg fine: $30,000

Missing BAA with Mayo Clinic Health System referral network · No MFA on practice management software

medium urgency

Portland, Oregon

Avg fine: $29,000

Missing Oregon Consumer Privacy Act compliance procedures · No MFA on cloud EHR

medium urgency

Baltimore, Maryland

Avg fine: $36,000

Missing BAA with Johns Hopkins Health System referral network · No MFA on cloud billing software

high urgency

Detroit, Michigan

Avg fine: $25,000

Missing BAA with auto industry employer dental plan administrator · No MFA on insurance clearinghouse connections

medium urgency

Pediatric Dentistry

35 state guides available

Dallas, Texas

Avg fine: $35,000

Minor patient authorization gaps · Missing parental consent documentation

high urgency

Miami, Florida

Avg fine: $42,000

Parental record request mishandling · Missing BAA with school health systems

high urgency

Phoenix, Arizona

Avg fine: $28,000

Missing minor consent forms · No policy for divorced parent access

medium urgency

Chicago, Illinois

Avg fine: $31,000

Emancipated minor record confusion · Missing BAA with Medicaid billing agent

high urgency

Los Angeles, California

Avg fine: $47,000

CMIA minor provisions · Missing multilingual NPP

critical urgency

Scottsdale, Arizona

Avg fine: $28,000

Missing parental portal BAA · No custody access policy

medium urgency

Cape Coral, Florida

Avg fine: $42,000

Missing parental consent for high-value procedures · No billing BAA with insurance coordinator

high urgency

Raleigh, North Carolina

Avg fine: $32,000

Missing parental consent updates after staff turnover · No HIPAA training for newly hired pediatric staff

high urgency

Houston, Texas

Avg fine: $35,000

Medicaid pre-authorization PHI exposure · Missing BAA with state Medicaid billing agent

high urgency

Orlando, Florida

Avg fine: $42,000

No translated parental consent forms · Missing NPP in Spanish and Portuguese

high urgency

Austin, Texas

Avg fine: $35,000

PHI sharing with Austin ISD school programs · Missing BAA with school health data platform

high urgency

Tampa, Florida

Avg fine: $42,000

Missing ePHI backup policy for pediatric records · No hurricane contingency plan for patient data

high urgency

San Diego, California

Avg fine: $47,000

CMIA minor provisions for military dependent children · Missing bilingual NPP for Spanish-speaking military families

critical urgency

Charlotte, North Carolina

Avg fine: $32,000

Missing BAA with employer-sponsored pediatric benefit administrator · No policy for separated corporate parent record access

high urgency

Tucson, Arizona

Avg fine: $28,000

Missing parental consent in Spanish · No bilingual authorization forms for pediatric procedures

medium urgency

San Antonio, Texas

Avg fine: $35,000

Missing bilingual parental consent forms · No BAA with CHIP billing administrator

high urgency

Fort Worth, Texas

Avg fine: $35,000

PHI access gaps after DSO staff turnover · Missing parental consent updates during ownership transition

high urgency

Jacksonville, Florida

Avg fine: $42,000

Missing BAA with military dependent child health system · No disaster recovery plan for pediatric records

high urgency

Fort Lauderdale, Florida

Avg fine: $42,000

Missing multilingual parental consent for international families · No cross-border record transfer protocol

high urgency

San Francisco, California

Avg fine: $52,000

CCPA minor data rights requests · Missing CMIA consent for wellness apps used by pediatric patients

critical urgency

San Jose, California

Avg fine: $47,000

Missing BAA with employer dependent benefit platform · CCPA requests for children's dental records from tech employer HR systems

critical urgency

Sacramento, California

Avg fine: $47,000

Missing BAA with Medi-Cal billing intermediary · CMIA minor provisions for Medi-Cal patients

critical urgency

New York, New York

Avg fine: $52,000

Missing SHIELD Act security program covering minor records · No emancipated minor policy under New York law

critical urgency

Atlanta, Georgia

Avg fine: $29,000

Missing BAA with Atlanta Public Schools health program · No policy for minor patient Medicaid billing compliance

high urgency

Columbus, Ohio

Avg fine: $27,000

Missing BAA with Nationwide Children's Hospital referral system · No Medicaid billing BAA for pediatric patients

medium urgency

Philadelphia, Pennsylvania

Avg fine: $34,000

Missing BAA with CHOP referral system · No Medicaid billing BAA for pediatric patients

high urgency

Seattle, Washington

Avg fine: $38,000

Missing MHMD Act minor consumer health data rights policy · No geofencing near pediatric dental offices

high urgency

Denver, Colorado

Avg fine: $26,000

Missing Colorado Privacy Act minor rights procedures · No MFA for pediatric EHR access

medium urgency

Las Vegas, Nevada

Avg fine: $33,000

Missing BAA with casino resort employee pediatric benefit plan · No protocol for emergency minor patient treatment without parental presence

high urgency

Nashville, Tennessee

Avg fine: $24,000

Missing BAA with HCA or Ascension pediatric referral system · No Medicaid TennCare billing BAA

medium urgency

Boston, Massachusetts

Avg fine: $48,000

Missing WISP covering pediatric patient data · No Massachusetts 201 CMR 17.00 third-party vendor due diligence

critical urgency

Minneapolis, Minnesota

Avg fine: $30,000

Missing bilingual parental consent for immigrant families · No BAA with Minneapolis Public Schools health program

medium urgency

Portland, Oregon

Avg fine: $29,000

Missing Oregon Consumer Privacy Act minor rights procedures · No MFA for pediatric EHR access

medium urgency

Baltimore, Maryland

Avg fine: $36,000

Missing BAA with Kennedy Krieger Institute referral system · No MPIPA-compliant breach notification timeline policy

high urgency

Detroit, Michigan

Avg fine: $25,000

Missing BAA with Medicaid managed care billing agent · No MCPA breach notification timeline policy

medium urgency

Orthodontics

35 state guides available

Dallas, Texas

Avg fine: $35,000

Before/after photo sharing without consent · Missing BAA with imaging lab

high urgency

Miami, Florida

Avg fine: $42,000

Instagram patient photos · Missing imaging lab BAA

high urgency

Phoenix, Arizona

Avg fine: $28,000

Digital scan sharing without BAA · Missing retention record policy

medium urgency

Chicago, Illinois

Avg fine: $31,000

Multi-location record access gaps · Missing BAA with remote monitoring platform

high urgency

Los Angeles, California

Avg fine: $47,000

CMIA image provisions · Influencer partnership PHI exposure

critical urgency

Scottsdale, Arizona

Avg fine: $28,000

3D scan sharing with premium aligner labs · Missing BAA with virtual monitoring platform

high urgency

Cape Coral, Florida

Avg fine: $42,000

Missing BAA with premium aligner brand · Outdated NPP for financing patients

high urgency

Raleigh, North Carolina

Avg fine: $32,000

Missing BAA with remote monitoring platform · Outdated NPP after software migration

high urgency

Houston, Texas

Avg fine: $35,000

Missing BAA with insurance verification service · Before/after photo sharing without consent

high urgency

Orlando, Florida

Avg fine: $42,000

Patient photo social media posts without multilingual consent · Missing BAA with international aligner lab

high urgency

Austin, Texas

Avg fine: $35,000

Missing BAA with virtual monitoring app · Before/after photos shared via Slack or Teams

high urgency

Tampa, Florida

Avg fine: $42,000

No hurricane contingency plan for patient imaging data · Missing BAA with cloud backup provider

high urgency

San Diego, California

Avg fine: $47,000

CMIA image provisions for TRICARE patient photos · Missing BAA with military-adjacent imaging lab

critical urgency

Charlotte, North Carolina

Avg fine: $32,000

Missing BAA with corporate flex spending account administrator · Before/after photos shared internally via email

high urgency

Tucson, Arizona

Avg fine: $28,000

Missing BAA with university research program using patient data · No Spanish-language before/after photo authorization

medium urgency

San Antonio, Texas

Avg fine: $35,000

Missing BAA with military base dental referral network · No bilingual photo authorization forms

high urgency

Fort Worth, Texas

Avg fine: $35,000

Missing BAA with DSO central imaging platform · No MFA for shared orthodontic software across locations

high urgency

Jacksonville, Florida

Avg fine: $42,000

Missing BAA with remote monitoring platform for mobile patients · No protocol for treatment continuation PHI transfers

high urgency

Fort Lauderdale, Florida

Avg fine: $42,000

Missing BAA with international aligner lab · No multilingual photo authorization form

high urgency

San Francisco, California

Avg fine: $52,000

CCPA data access requests for treatment photos · CMIA commercial use restrictions on patient imagery

critical urgency

San Jose, California

Avg fine: $47,000

Missing BAA with digital treatment tracking app · CCPA deletion requests for treatment timeline data

critical urgency

Sacramento, California

Avg fine: $47,000

Missing BAA with state legislative employee benefit plan · CMIA photo provisions for state government patient imagery

critical urgency

New York, New York

Avg fine: $52,000

Missing SHIELD Act vendor oversight documentation · Before/after photos on social media without NY-compliant authorization

critical urgency

Atlanta, Georgia

Avg fine: $29,000

Missing BAA with remote monitoring platform · Before/after photos shared on Instagram without authorization

high urgency

Columbus, Ohio

Avg fine: $27,000

Missing BAA with OSU Athletics dental program · No MFA for cloud treatment tracking

medium urgency

Philadelphia, Pennsylvania

Avg fine: $34,000

Missing BAA with dental school clinic partner · Before/after photos shared without explicit consent

high urgency

Seattle, Washington

Avg fine: $38,000

Missing MHMD Act consent for remote monitoring data · No consumer health data privacy notice on website

high urgency

Denver, Colorado

Avg fine: $26,000

Missing Colorado Privacy Act data rights request procedures · Before/after photos on social media without authorization

medium urgency

Las Vegas, Nevada

Avg fine: $33,000

Missing BAA with casino resort employee wellness benefit platform · No protocol for transient adult orthodontic patients

high urgency

Nashville, Tennessee

Avg fine: $24,000

Missing BAA with remote monitoring platform · Before/after photos used in country music industry marketing

medium urgency

Boston, Massachusetts

Avg fine: $48,000

Missing WISP covering orthodontic imaging data · No 201 CMR 17.00 portable device encryption documentation

critical urgency

Minneapolis, Minnesota

Avg fine: $30,000

Missing BAA with remote monitoring platform · Before/after photos on social media without authorization

medium urgency

Portland, Oregon

Avg fine: $29,000

Missing Oregon Consumer Privacy Act data subject rights procedures · Before/after photos on social media without HIPAA authorization

medium urgency

Baltimore, Maryland

Avg fine: $36,000

Missing BAA with dental school partner at UMD or UB · Before/after photos used without authorization

high urgency

Detroit, Michigan

Avg fine: $25,000

Missing BAA with remote monitoring platform · Before/after photos on social media without authorization

medium urgency

Oral Surgery

35 state guides available

Dallas, Texas

Avg fine: $35,000

Missing BAA with anesthesia provider · Prescription record gaps

critical urgency

Miami, Florida

Avg fine: $42,000

Surgical consent documentation gaps · Missing anesthesia BAA

critical urgency

Phoenix, Arizona

Avg fine: $28,000

Missing pathology lab BAA · Outdated NPP

high urgency

Chicago, Illinois

Avg fine: $31,000

Hospital privilege PHI gaps · Missing BAA with surgical center

high urgency

Los Angeles, California

Avg fine: $47,000

CMIA surgical record provisions · Missing IV sedation consent documentation

critical urgency

Scottsdale, Arizona

Avg fine: $28,000

Missing BAA with premium anesthesia group · No implant lab data sharing protocol

high urgency

Cape Coral, Florida

Avg fine: $42,000

Missing BAA with implant manufacturer portal · No high-value case PHI retention policy

critical urgency

Raleigh, North Carolina

Avg fine: $32,000

Missing BAA with CBCT imaging service · No post-surgical PHI retention schedule

high urgency

Houston, Texas

Avg fine: $35,000

Pre-authorization PHI sent via unsecured fax · Missing BAA with hospital system

critical urgency

Orlando, Florida

Avg fine: $42,000

Missing translated surgical consent forms · No multilingual post-op PHI protocol

critical urgency

Austin, Texas

Avg fine: $35,000

Missing BAA with DSO anesthesia management company · No PHI policy for multi-site surgical records

critical urgency

Tampa, Florida

Avg fine: $42,000

No ePHI disaster recovery plan covering surgical imaging · Missing BAA with CBCT cloud storage vendor

critical urgency

San Diego, California

Avg fine: $47,000

Missing BAA for TRICARE surgical billing · CMIA surgical record provisions

critical urgency

Charlotte, North Carolina

Avg fine: $32,000

Missing BAA with corporate anesthesia billing group · No PHI policy for executive patient records

high urgency

Tucson, Arizona

Avg fine: $28,000

Missing BAA with UA Medical Center referral network · No bilingual surgical consent in Spanish

high urgency

San Antonio, Texas

Avg fine: $35,000

Missing BAA with military hospital surgical referral system · No bilingual surgical consent in Spanish

critical urgency

Fort Worth, Texas

Avg fine: $35,000

Missing BAA with DSO anesthesia management company · No per-location surgical record access controls

critical urgency

Jacksonville, Florida

Avg fine: $42,000

Missing BAA with naval hospital referral system · No encrypted hurricane backup for surgical records

critical urgency

Fort Lauderdale, Florida

Avg fine: $42,000

Missing cross-border surgical record transfer protocol · No multilingual surgical consent

critical urgency

San Francisco, California

Avg fine: $52,000

Missing BAA with robotic surgery system vendor · CCPA deletion requests conflicting with surgical record retention

critical urgency

San Jose, California

Avg fine: $47,000

Missing BAA with employer-provided surgical benefit platform · CCPA requests for surgical records from HR systems

critical urgency

Sacramento, California

Avg fine: $47,000

Missing BAA with UC Davis Medical Center referral system · CMIA surgical record provisions for academic health system patients

critical urgency

New York, New York

Avg fine: $52,000

Missing SHIELD Act written security program covering surgical records · NYDFS cybersecurity regulation for practices with financing

critical urgency

Atlanta, Georgia

Avg fine: $29,000

Missing BAA with Emory or Grady Hospital referral systems · No MFA on surgical EHR

high urgency

Columbus, Ohio

Avg fine: $27,000

Missing BAA with OhioHealth or OSU Wexner Medical Center · No MFA on surgical EHR system

medium urgency

Philadelphia, Pennsylvania

Avg fine: $34,000

Missing BAA with Penn or Jefferson hospital surgical credentialing system · No MFA on surgical EHR

high urgency

Seattle, Washington

Avg fine: $38,000

Missing MHMD Act compliance for surgical data apps · No Washington consumer health data privacy notice

high urgency

Denver, Colorado

Avg fine: $26,000

Missing Colorado Privacy Act data processing records for surgical data · No MFA on surgical EHR

medium urgency

Las Vegas, Nevada

Avg fine: $33,000

Missing BAA with emergency trauma center referral system · No protocol for unidentified or uncommunicative surgical patients

critical urgency

Nashville, Tennessee

Avg fine: $24,000

Missing BAA with Vanderbilt Medical Center referral system · No MFA on surgical EHR

medium urgency

Boston, Massachusetts

Avg fine: $48,000

Missing WISP covering surgical records · No 201 CMR 17.00 compliance for Mass General or BWH referral systems

critical urgency

Minneapolis, Minnesota

Avg fine: $30,000

Missing BAA with University of Minnesota Medical Center referral system · No MFA on surgical EHR

medium urgency

Portland, Oregon

Avg fine: $29,000

Missing Oregon Consumer Privacy Act data processing records for surgical data · No MFA on surgical EHR

medium urgency

Baltimore, Maryland

Avg fine: $36,000

Missing BAA with Johns Hopkins or University of Maryland Medical System · No MPIPA-compliant breach response plan

critical urgency

Detroit, Michigan

Avg fine: $25,000

Missing BAA with Henry Ford Health or DMC referral system · No MCPA breach notification plan for surgical data

medium urgency