HIPAA Compliance Guides for Dental Practices — 2026
Every guide is specific to your dental specialty and state. Find your combination below to see exact violation risks, average fines, and the ADA-recommended compliance tools for 2026.
General Dentistry
35 state guides available
Dallas, Texas
Avg fine: $35,000
Outdated NPP · Missing BAA with billing vendor
high urgencyMiami, Florida
Avg fine: $42,000
Outdated NPP · Verbal PHI disclosure
high urgencyPhoenix, Arizona
Avg fine: $28,000
Missing Risk Assessment · Outdated NPP
medium urgencyChicago, Illinois
Avg fine: $31,000
Missing BAA with IT vendor · No sanction policy
high urgencyLos Angeles, California
Avg fine: $47,000
CMIA violations · Missing NPP translation
critical urgencyScottsdale, Arizona
Avg fine: $28,000
Missing BAA with cosmetic imaging vendor · Outdated NPP for concierge services
high urgencyCape Coral, Florida
Avg fine: $42,000
Billing errors on high-value procedures · Missing BAA with dental finance company
high urgencyRaleigh, North Carolina
Avg fine: $32,000
Outdated NPP at newly opened locations · Missing BAA with practice management software
high urgencyHouston, Texas
Avg fine: $35,000
Insurance pre-authorization PHI leaks · Missing BAA with insurance clearinghouse
high urgencyOrlando, Florida
Avg fine: $42,000
Missing multilingual NPP · No translated patient authorization forms
high urgencyAustin, Texas
Avg fine: $35,000
Missing BAA with DSO management platform · No multi-location sanction policy
high urgencyTampa, Florida
Avg fine: $42,000
Missing disaster recovery plan for ePHI · No encrypted offsite backup
high urgencySan Diego, California
Avg fine: $47,000
Missing BAA for TRICARE PHI sharing · CMIA violations from military-adjacent billing
critical urgencyCharlotte, North Carolina
Avg fine: $32,000
Missing BAA with corporate HR dental plan administrator · No HIPAA policy for employer-sponsored plan PHI
high urgencyTucson, Arizona
Avg fine: $28,000
Missing NPP in Spanish for Spanish-speaking patient majority · No bilingual workforce HIPAA training
medium urgencySan Antonio, Texas
Avg fine: $35,000
Missing BAA with Medicaid managed care billing agent · No bilingual NPP for Spanish-speaking majority
high urgencyFort Worth, Texas
Avg fine: $35,000
Missing BAA with DSO regional management platform · No MFA on practice management software
high urgencyJacksonville, Florida
Avg fine: $42,000
Missing BAA with military insurance billing agent · No ePHI disaster recovery plan
high urgencyFort Lauderdale, Florida
Avg fine: $42,000
Missing BAA with dental tourism facilitator · No cross-border PHI protocol for international patients
high urgencySan Francisco, California
Avg fine: $52,000
CCPA health data requests mishandled · Missing BAA with AI diagnostic tool vendor
critical urgencySan Jose, California
Avg fine: $47,000
Missing BAA with employer health portal integration · CCPA employee dependent data rights
critical urgencySacramento, California
Avg fine: $47,000
Missing BAA with state government employee dental plan administrator · CMIA violations from Covered California exchange data
critical urgencyNew York, New York
Avg fine: $52,000
Missing SHIELD Act written security program · No MFA on all ePHI systems
critical urgencyAtlanta, Georgia
Avg fine: $29,000
Missing BAA with insurance clearinghouse · No MFA on cloud-based practice management software
high urgencyColumbus, Ohio
Avg fine: $27,000
Missing BAA with OSU student health plan administrator · No MFA on insurance verification tools
medium urgencyPhiladelphia, Pennsylvania
Avg fine: $34,000
Missing BAA with Penn Medicine or Jefferson Health referral system · No MFA on billing software
high urgencySeattle, Washington
Avg fine: $38,000
Missing MHMD Act consumer health data privacy notice · No geofencing prohibition policy
high urgencyDenver, Colorado
Avg fine: $26,000
Missing Colorado Privacy Act consumer rights procedures · No MFA on cloud practice management software
medium urgencyLas Vegas, Nevada
Avg fine: $33,000
Missing BAA with dental tourism facilitator · No transient patient PHI protocol
high urgencyNashville, Tennessee
Avg fine: $24,000
Missing BAA with healthcare industry employer dental plan · No MFA on cloud-based billing software
medium urgencyBoston, Massachusetts
Avg fine: $48,000
Missing Written Information Security Plan (WISP) · No Massachusetts 201 CMR 17.00 compliance documentation
critical urgencyMinneapolis, Minnesota
Avg fine: $30,000
Missing BAA with Mayo Clinic Health System referral network · No MFA on practice management software
medium urgencyPortland, Oregon
Avg fine: $29,000
Missing Oregon Consumer Privacy Act compliance procedures · No MFA on cloud EHR
medium urgencyBaltimore, Maryland
Avg fine: $36,000
Missing BAA with Johns Hopkins Health System referral network · No MFA on cloud billing software
high urgencyDetroit, Michigan
Avg fine: $25,000
Missing BAA with auto industry employer dental plan administrator · No MFA on insurance clearinghouse connections
medium urgencyPediatric Dentistry
35 state guides available
Dallas, Texas
Avg fine: $35,000
Minor patient authorization gaps · Missing parental consent documentation
high urgencyMiami, Florida
Avg fine: $42,000
Parental record request mishandling · Missing BAA with school health systems
high urgencyPhoenix, Arizona
Avg fine: $28,000
Missing minor consent forms · No policy for divorced parent access
medium urgencyChicago, Illinois
Avg fine: $31,000
Emancipated minor record confusion · Missing BAA with Medicaid billing agent
high urgencyLos Angeles, California
Avg fine: $47,000
CMIA minor provisions · Missing multilingual NPP
critical urgencyScottsdale, Arizona
Avg fine: $28,000
Missing parental portal BAA · No custody access policy
medium urgencyCape Coral, Florida
Avg fine: $42,000
Missing parental consent for high-value procedures · No billing BAA with insurance coordinator
high urgencyRaleigh, North Carolina
Avg fine: $32,000
Missing parental consent updates after staff turnover · No HIPAA training for newly hired pediatric staff
high urgencyHouston, Texas
Avg fine: $35,000
Medicaid pre-authorization PHI exposure · Missing BAA with state Medicaid billing agent
high urgencyOrlando, Florida
Avg fine: $42,000
No translated parental consent forms · Missing NPP in Spanish and Portuguese
high urgencyAustin, Texas
Avg fine: $35,000
PHI sharing with Austin ISD school programs · Missing BAA with school health data platform
high urgencyTampa, Florida
Avg fine: $42,000
Missing ePHI backup policy for pediatric records · No hurricane contingency plan for patient data
high urgencySan Diego, California
Avg fine: $47,000
CMIA minor provisions for military dependent children · Missing bilingual NPP for Spanish-speaking military families
critical urgencyCharlotte, North Carolina
Avg fine: $32,000
Missing BAA with employer-sponsored pediatric benefit administrator · No policy for separated corporate parent record access
high urgencyTucson, Arizona
Avg fine: $28,000
Missing parental consent in Spanish · No bilingual authorization forms for pediatric procedures
medium urgencySan Antonio, Texas
Avg fine: $35,000
Missing bilingual parental consent forms · No BAA with CHIP billing administrator
high urgencyFort Worth, Texas
Avg fine: $35,000
PHI access gaps after DSO staff turnover · Missing parental consent updates during ownership transition
high urgencyJacksonville, Florida
Avg fine: $42,000
Missing BAA with military dependent child health system · No disaster recovery plan for pediatric records
high urgencyFort Lauderdale, Florida
Avg fine: $42,000
Missing multilingual parental consent for international families · No cross-border record transfer protocol
high urgencySan Francisco, California
Avg fine: $52,000
CCPA minor data rights requests · Missing CMIA consent for wellness apps used by pediatric patients
critical urgencySan Jose, California
Avg fine: $47,000
Missing BAA with employer dependent benefit platform · CCPA requests for children's dental records from tech employer HR systems
critical urgencySacramento, California
Avg fine: $47,000
Missing BAA with Medi-Cal billing intermediary · CMIA minor provisions for Medi-Cal patients
critical urgencyNew York, New York
Avg fine: $52,000
Missing SHIELD Act security program covering minor records · No emancipated minor policy under New York law
critical urgencyAtlanta, Georgia
Avg fine: $29,000
Missing BAA with Atlanta Public Schools health program · No policy for minor patient Medicaid billing compliance
high urgencyColumbus, Ohio
Avg fine: $27,000
Missing BAA with Nationwide Children's Hospital referral system · No Medicaid billing BAA for pediatric patients
medium urgencyPhiladelphia, Pennsylvania
Avg fine: $34,000
Missing BAA with CHOP referral system · No Medicaid billing BAA for pediatric patients
high urgencySeattle, Washington
Avg fine: $38,000
Missing MHMD Act minor consumer health data rights policy · No geofencing near pediatric dental offices
high urgencyDenver, Colorado
Avg fine: $26,000
Missing Colorado Privacy Act minor rights procedures · No MFA for pediatric EHR access
medium urgencyLas Vegas, Nevada
Avg fine: $33,000
Missing BAA with casino resort employee pediatric benefit plan · No protocol for emergency minor patient treatment without parental presence
high urgencyNashville, Tennessee
Avg fine: $24,000
Missing BAA with HCA or Ascension pediatric referral system · No Medicaid TennCare billing BAA
medium urgencyBoston, Massachusetts
Avg fine: $48,000
Missing WISP covering pediatric patient data · No Massachusetts 201 CMR 17.00 third-party vendor due diligence
critical urgencyMinneapolis, Minnesota
Avg fine: $30,000
Missing bilingual parental consent for immigrant families · No BAA with Minneapolis Public Schools health program
medium urgencyPortland, Oregon
Avg fine: $29,000
Missing Oregon Consumer Privacy Act minor rights procedures · No MFA for pediatric EHR access
medium urgencyBaltimore, Maryland
Avg fine: $36,000
Missing BAA with Kennedy Krieger Institute referral system · No MPIPA-compliant breach notification timeline policy
high urgencyDetroit, Michigan
Avg fine: $25,000
Missing BAA with Medicaid managed care billing agent · No MCPA breach notification timeline policy
medium urgencyOrthodontics
35 state guides available
Dallas, Texas
Avg fine: $35,000
Before/after photo sharing without consent · Missing BAA with imaging lab
high urgencyMiami, Florida
Avg fine: $42,000
Instagram patient photos · Missing imaging lab BAA
high urgencyPhoenix, Arizona
Avg fine: $28,000
Digital scan sharing without BAA · Missing retention record policy
medium urgencyChicago, Illinois
Avg fine: $31,000
Multi-location record access gaps · Missing BAA with remote monitoring platform
high urgencyLos Angeles, California
Avg fine: $47,000
CMIA image provisions · Influencer partnership PHI exposure
critical urgencyScottsdale, Arizona
Avg fine: $28,000
3D scan sharing with premium aligner labs · Missing BAA with virtual monitoring platform
high urgencyCape Coral, Florida
Avg fine: $42,000
Missing BAA with premium aligner brand · Outdated NPP for financing patients
high urgencyRaleigh, North Carolina
Avg fine: $32,000
Missing BAA with remote monitoring platform · Outdated NPP after software migration
high urgencyHouston, Texas
Avg fine: $35,000
Missing BAA with insurance verification service · Before/after photo sharing without consent
high urgencyOrlando, Florida
Avg fine: $42,000
Patient photo social media posts without multilingual consent · Missing BAA with international aligner lab
high urgencyAustin, Texas
Avg fine: $35,000
Missing BAA with virtual monitoring app · Before/after photos shared via Slack or Teams
high urgencyTampa, Florida
Avg fine: $42,000
No hurricane contingency plan for patient imaging data · Missing BAA with cloud backup provider
high urgencySan Diego, California
Avg fine: $47,000
CMIA image provisions for TRICARE patient photos · Missing BAA with military-adjacent imaging lab
critical urgencyCharlotte, North Carolina
Avg fine: $32,000
Missing BAA with corporate flex spending account administrator · Before/after photos shared internally via email
high urgencyTucson, Arizona
Avg fine: $28,000
Missing BAA with university research program using patient data · No Spanish-language before/after photo authorization
medium urgencySan Antonio, Texas
Avg fine: $35,000
Missing BAA with military base dental referral network · No bilingual photo authorization forms
high urgencyFort Worth, Texas
Avg fine: $35,000
Missing BAA with DSO central imaging platform · No MFA for shared orthodontic software across locations
high urgencyJacksonville, Florida
Avg fine: $42,000
Missing BAA with remote monitoring platform for mobile patients · No protocol for treatment continuation PHI transfers
high urgencyFort Lauderdale, Florida
Avg fine: $42,000
Missing BAA with international aligner lab · No multilingual photo authorization form
high urgencySan Francisco, California
Avg fine: $52,000
CCPA data access requests for treatment photos · CMIA commercial use restrictions on patient imagery
critical urgencySan Jose, California
Avg fine: $47,000
Missing BAA with digital treatment tracking app · CCPA deletion requests for treatment timeline data
critical urgencySacramento, California
Avg fine: $47,000
Missing BAA with state legislative employee benefit plan · CMIA photo provisions for state government patient imagery
critical urgencyNew York, New York
Avg fine: $52,000
Missing SHIELD Act vendor oversight documentation · Before/after photos on social media without NY-compliant authorization
critical urgencyAtlanta, Georgia
Avg fine: $29,000
Missing BAA with remote monitoring platform · Before/after photos shared on Instagram without authorization
high urgencyColumbus, Ohio
Avg fine: $27,000
Missing BAA with OSU Athletics dental program · No MFA for cloud treatment tracking
medium urgencyPhiladelphia, Pennsylvania
Avg fine: $34,000
Missing BAA with dental school clinic partner · Before/after photos shared without explicit consent
high urgencySeattle, Washington
Avg fine: $38,000
Missing MHMD Act consent for remote monitoring data · No consumer health data privacy notice on website
high urgencyDenver, Colorado
Avg fine: $26,000
Missing Colorado Privacy Act data rights request procedures · Before/after photos on social media without authorization
medium urgencyLas Vegas, Nevada
Avg fine: $33,000
Missing BAA with casino resort employee wellness benefit platform · No protocol for transient adult orthodontic patients
high urgencyNashville, Tennessee
Avg fine: $24,000
Missing BAA with remote monitoring platform · Before/after photos used in country music industry marketing
medium urgencyBoston, Massachusetts
Avg fine: $48,000
Missing WISP covering orthodontic imaging data · No 201 CMR 17.00 portable device encryption documentation
critical urgencyMinneapolis, Minnesota
Avg fine: $30,000
Missing BAA with remote monitoring platform · Before/after photos on social media without authorization
medium urgencyPortland, Oregon
Avg fine: $29,000
Missing Oregon Consumer Privacy Act data subject rights procedures · Before/after photos on social media without HIPAA authorization
medium urgencyBaltimore, Maryland
Avg fine: $36,000
Missing BAA with dental school partner at UMD or UB · Before/after photos used without authorization
high urgencyDetroit, Michigan
Avg fine: $25,000
Missing BAA with remote monitoring platform · Before/after photos on social media without authorization
medium urgencyOral Surgery
35 state guides available
Dallas, Texas
Avg fine: $35,000
Missing BAA with anesthesia provider · Prescription record gaps
critical urgencyMiami, Florida
Avg fine: $42,000
Surgical consent documentation gaps · Missing anesthesia BAA
critical urgencyPhoenix, Arizona
Avg fine: $28,000
Missing pathology lab BAA · Outdated NPP
high urgencyChicago, Illinois
Avg fine: $31,000
Hospital privilege PHI gaps · Missing BAA with surgical center
high urgencyLos Angeles, California
Avg fine: $47,000
CMIA surgical record provisions · Missing IV sedation consent documentation
critical urgencyScottsdale, Arizona
Avg fine: $28,000
Missing BAA with premium anesthesia group · No implant lab data sharing protocol
high urgencyCape Coral, Florida
Avg fine: $42,000
Missing BAA with implant manufacturer portal · No high-value case PHI retention policy
critical urgencyRaleigh, North Carolina
Avg fine: $32,000
Missing BAA with CBCT imaging service · No post-surgical PHI retention schedule
high urgencyHouston, Texas
Avg fine: $35,000
Pre-authorization PHI sent via unsecured fax · Missing BAA with hospital system
critical urgencyOrlando, Florida
Avg fine: $42,000
Missing translated surgical consent forms · No multilingual post-op PHI protocol
critical urgencyAustin, Texas
Avg fine: $35,000
Missing BAA with DSO anesthesia management company · No PHI policy for multi-site surgical records
critical urgencyTampa, Florida
Avg fine: $42,000
No ePHI disaster recovery plan covering surgical imaging · Missing BAA with CBCT cloud storage vendor
critical urgencySan Diego, California
Avg fine: $47,000
Missing BAA for TRICARE surgical billing · CMIA surgical record provisions
critical urgencyCharlotte, North Carolina
Avg fine: $32,000
Missing BAA with corporate anesthesia billing group · No PHI policy for executive patient records
high urgencyTucson, Arizona
Avg fine: $28,000
Missing BAA with UA Medical Center referral network · No bilingual surgical consent in Spanish
high urgencySan Antonio, Texas
Avg fine: $35,000
Missing BAA with military hospital surgical referral system · No bilingual surgical consent in Spanish
critical urgencyFort Worth, Texas
Avg fine: $35,000
Missing BAA with DSO anesthesia management company · No per-location surgical record access controls
critical urgencyJacksonville, Florida
Avg fine: $42,000
Missing BAA with naval hospital referral system · No encrypted hurricane backup for surgical records
critical urgencyFort Lauderdale, Florida
Avg fine: $42,000
Missing cross-border surgical record transfer protocol · No multilingual surgical consent
critical urgencySan Francisco, California
Avg fine: $52,000
Missing BAA with robotic surgery system vendor · CCPA deletion requests conflicting with surgical record retention
critical urgencySan Jose, California
Avg fine: $47,000
Missing BAA with employer-provided surgical benefit platform · CCPA requests for surgical records from HR systems
critical urgencySacramento, California
Avg fine: $47,000
Missing BAA with UC Davis Medical Center referral system · CMIA surgical record provisions for academic health system patients
critical urgencyNew York, New York
Avg fine: $52,000
Missing SHIELD Act written security program covering surgical records · NYDFS cybersecurity regulation for practices with financing
critical urgencyAtlanta, Georgia
Avg fine: $29,000
Missing BAA with Emory or Grady Hospital referral systems · No MFA on surgical EHR
high urgencyColumbus, Ohio
Avg fine: $27,000
Missing BAA with OhioHealth or OSU Wexner Medical Center · No MFA on surgical EHR system
medium urgencyPhiladelphia, Pennsylvania
Avg fine: $34,000
Missing BAA with Penn or Jefferson hospital surgical credentialing system · No MFA on surgical EHR
high urgencySeattle, Washington
Avg fine: $38,000
Missing MHMD Act compliance for surgical data apps · No Washington consumer health data privacy notice
high urgencyDenver, Colorado
Avg fine: $26,000
Missing Colorado Privacy Act data processing records for surgical data · No MFA on surgical EHR
medium urgencyLas Vegas, Nevada
Avg fine: $33,000
Missing BAA with emergency trauma center referral system · No protocol for unidentified or uncommunicative surgical patients
critical urgencyNashville, Tennessee
Avg fine: $24,000
Missing BAA with Vanderbilt Medical Center referral system · No MFA on surgical EHR
medium urgencyBoston, Massachusetts
Avg fine: $48,000
Missing WISP covering surgical records · No 201 CMR 17.00 compliance for Mass General or BWH referral systems
critical urgencyMinneapolis, Minnesota
Avg fine: $30,000
Missing BAA with University of Minnesota Medical Center referral system · No MFA on surgical EHR
medium urgencyPortland, Oregon
Avg fine: $29,000
Missing Oregon Consumer Privacy Act data processing records for surgical data · No MFA on surgical EHR
medium urgencyBaltimore, Maryland
Avg fine: $36,000
Missing BAA with Johns Hopkins or University of Maryland Medical System · No MPIPA-compliant breach response plan
critical urgencyDetroit, Michigan
Avg fine: $25,000
Missing BAA with Henry Ford Health or DMC referral system · No MCPA breach notification plan for surgical data
medium urgency