AI can help a dental team draft routine communications, organize administrative work, summarize approved material, and explore ideas. It can also create a fast path for patient information, internal records, or confidential business data to leave the systems your practice controls.
The practical answer is not a blanket promise that an AI tool is “HIPAA compliant.” A dental practice needs rules for which tools are approved, what information may be entered, which uses require human review, what vendors are responsible for, and how the practice will document decisions.
Start with one default rule: workforce members should not enter patient information into an AI service unless the practice has approved the specific service, configuration, use case, access controls, and required contract.
Why an AI policy is needed now
AI use often begins informally. A team member may paste an email into a chatbot, upload a spreadsheet for help with a formula, generate a patient-facing message, or ask an assistant to summarize a document. Those actions can create privacy, security, accuracy, intellectual-property, and record-retention questions even when the employee is trying to save time.
A written policy gives the team a safe path to use approved tools while making the boundaries explicit. It should connect to the practice's existing HIPAA policies, risk analysis, acceptable-use rules, vendor-management process, incident-response plan, and workforce training.
1. Classify information before choosing a tool
Define simple data classes that staff can recognize:
- Public: information already approved for public release, such as office hours or published website copy.
- Internal: procedures, templates, pricing, vendor notes, or operating information not intended for the public.
- Confidential: employee information, credentials, financial records, contracts, security details, or sensitive business plans.
- PHI or ePHI: individually identifiable health information created, received, maintained, or transmitted by the practice in a covered context.
The policy should say which classes are allowed in each approved AI tool. A public consumer chatbot may be appropriate for brainstorming with public information but not for patient records, screenshots from practice software, images, insurance details, or appointment exports.
De-identification is not the same as deleting a patient's name. Dates, locations, identifiers, images, free-text notes, and combinations of facts can still identify a person. Do not ask staff to improvise de-identification.
2. Approve the service, account, and configuration
Approval should apply to a specific service and configuration—not merely to a vendor's brand name. Review:
- Whether the service will create, receive, maintain, or transmit ePHI.
- Whether the vendor will sign an appropriate Business Associate Agreement when required.
- How submitted data, prompts, files, outputs, and logs are stored and retained.
- Whether customer content is used to train or improve models, and which controls change that behavior.
- Where administrators can manage accounts, roles, sharing, integrations, and audit logs.
- How the organization can export or delete data and close the service.
- Which subcontractors or connected services may handle information.
- How security incidents are reported and escalated.
HHS explains that a cloud service provider that maintains ePHI on behalf of a covered entity is generally a business associate even if the information is encrypted and the provider does not possess the decryption key. The practice still must understand the service, execute a BAA when required, and include the arrangement in risk analysis and risk management.
3. Approve use cases separately
An approved tool does not make every use appropriate. Maintain a short register of allowed, restricted, and prohibited activities.
Lower-risk uses may include brainstorming public educational content, improving the tone of a message that contains no patient or confidential information, or summarizing public vendor documentation.
Higher-risk uses may include drafting patient-specific communications, interpreting clinical information, generating documentation that enters the patient record, making employment decisions, analyzing security logs, or processing claims and financial data. These require a defined purpose, minimum necessary data, suitable contractual and technical controls, and accountable human review.
Prohibit uses that the practice is not prepared to govern. Examples may include autonomous diagnosis or treatment decisions, uploading credentials, bypassing approved record systems, impersonating a patient or workforce member, or using unapproved AI browser extensions that can read page content.
4. Require meaningful human review
AI output can be incomplete, inaccurate, outdated, biased, or confidently wrong. “A person looked at it” is not enough. Assign a reviewer who has the knowledge and authority to verify the result.
For patient-facing or clinical material, the reviewer should confirm factual accuracy, appropriateness for the patient and context, consistency with the official record, and whether the output belongs in the designated record system. For compliance or legal material, use qualified professional review rather than treating generated language as authoritative.
The person approving the final work remains accountable for it. The policy should prevent staff from representing AI output as independently verified when it is not.
5. Control identities, access, and integrations
Use organization-managed accounts instead of shared or personal logins. Apply multifactor authentication, role-based access, least privilege, and documented onboarding and offboarding. Restrict who can enable plugins, connectors, agents, file sources, external sharing, or automated actions.
An AI assistant connected to email, cloud storage, calendars, or practice systems can reach far more information than a standalone chat. Review the permissions of every integration, test with limited scope, log administrative changes, and remove access when the use case ends.
6. Define records and evidence
Decide when prompts, outputs, approvals, or decision notes must be retained. Do not let an AI conversation become the only copy of an important operating decision or patient-related record. Move approved information into the practice's official system and follow applicable retention rules.
Keep an AI register containing:
- Tool, owner, business purpose, and approved users.
- Approved data classes and use cases.
- Vendor review, contract, and BAA status.
- Key configuration decisions and review dates.
- Training completion and policy acknowledgments.
- Known limitations, incidents, and corrective actions.
This evidence helps the practice show that adoption was deliberate rather than accidental.
7. Prepare for mistakes and incidents
Staff should know how to report an accidental upload, incorrect patient communication, unauthorized integration, exposed credential, or suspicious AI output immediately. The reporting path should not punish good-faith early reporting; delay can make containment harder.
The response team should be prepared to preserve relevant evidence, stop further disclosure or automation, revoke sessions or integrations, contact the vendor, assess affected information and individuals, and route privacy or breach analysis to the appropriate leaders and advisers.
A practical AI policy outline
- Purpose and scope.
- Defined information classes.
- Approved tools and account requirements.
- Allowed, restricted, and prohibited uses.
- PHI, BAA, and minimum-necessary rules.
- Human-review and documentation requirements.
- Access, integrations, sharing, and retention.
- Vendor assessment and change review.
- Incident reporting and response.
- Training, enforcement, exceptions, and review cycle.
Use governance to make AI safer—not invisible
The biggest policy failure is assuming that staff are not using AI because no approved program exists. Give the team useful, approved options; train with realistic examples; and review the policy when services, integrations, laws, or clinical workflows change.
NIST's voluntary AI Risk Management Framework organizes risk work around four functions: govern, map, measure, and manage. That structure translates well to a dental practice: assign responsibility, understand each use case, evaluate risk and performance, and maintain controls throughout the service lifecycle.
Authoritative references
- HHS: Guidance on HIPAA and Cloud Computing
- HHS: Business Associate Contracts
- NIST: Artificial Intelligence Risk Management Framework
- NIST: Generative Artificial Intelligence Profile
This guide is educational and does not provide legal, clinical, or compliance advice. AI services and their terms change frequently. Confirm current requirements and evaluate each service, configuration, contract, and use case for your organization.

