Legal

HIPAA Readiness

How we handle patient intake for the practices we build for.

Last updated: June 2026

Dental practices are covered entities under HIPAA. When we build patient intake for your practice, we treat it accordingly. This page describes our approach in plain terms. It is informational and is not legal advice; your practice remains responsible for its own HIPAA compliance program.

HIPAA-ready intake

The patient intake we build is designed with privacy in mind from the start, not bolted on afterward:

  • Encryption. Patient submissions are encrypted in transit and at rest.
  • Access control. Access to patient data is restricted to authorized people on a need-to-know basis.
  • Audit logging. Access to and changes in patient data are logged so activity can be reviewed.

A BAA when we touch PHI

Where we act as a business associate — meaning our systems create, receive, store or transmit protected health information on your behalf — we will enter into a Business Associate Agreement with your practice. See our BAA page for details and to request one.

What we keep off our forms

The forms on this marketing website are for business enquiries only. We ask you not to submit any patient health information through them. Patient information should only ever flow through the purpose-built, HIPAA-ready intake we set up for your practice.

Roadmap, stated honestly

Some capabilities (such as voice and additional channels for the AI front desk) are on our roadmap rather than live today. Where a feature is not yet available, we label it as coming — and we will not route protected health information through any channel until it meets the same readiness bar described above.

Contact

Questions about our HIPAA approach? Email info@onesuitedental.com.