Dental Compliance: HIPAA, OSHA, And State Rules For Practices
Dental compliance is the set of rules a practice follows to protect patients, staff, and data. Those rules come from federal agencies, state dental boards, and professional...
Written by Rachel Thompson
Read time: 7 min read
Dental compliance is the set of rules a practice follows to protect patients, staff, and data. Those rules come from federal agencies, state dental boards, and professional guidelines. Most of the daily work falls into four areas, HIPAA, OSHA, infection control, and licensing. This guide explains each area and closes with two checklists a practice can use today.
TL;DR
Run a documented HIPAA security risk analysis every year and after major system changes.
Keep a written exposure control plan and train clinical staff at hire and annually.
Follow CDC infection control guidance, since many state boards enforce it as law.
Treat the 2025 HIPAA Security Rule proposal as a roadmap, since it is not final yet.
What Is Dental Compliance?
Dentistry compliance means meeting every legal and regulatory duty that applies to a dental practice. Those duties cover patient data, staff safety, instrument processing, billing, and licensing. Each duty has its own enforcer, its own records, and its own inspection style.
Dental compliance also has a practical side. Inspectors judge what the office can prove on paper, so records weigh as much as habits. A spotless operatory with no sterilizer log still fails an inspection.
Area | Main rule | Enforcer | Key record to keep |
|---|---|---|---|
Patient privacy | HIPAA Privacy, Security, and Breach Notification Rules | HHS Office for Civil Rights | Security risk analysis |
Workplace safety | OSHA bloodborne pathogens and hazard communication standards | Federal OSHA or a state plan | Exposure control plan |
Infection control | CDC dental guidelines, adopted by many states | State dental board | Sterilizer spore test log |
Licensing | State dental practice act | State dental board | Licenses and CE records |
Billing integrity | False Claims Act and Anti-Kickback Statute | HHS OIG, CMS, state Medicaid | Coding and audit records |
Two more rules sit at the edges. The EPA regulates amalgam wastewater, and federal civil rights laws cover accessibility and language help.
Who Enforces Dentistry Requirements In The US?
Federal and state dentistry requirements come from several agencies, and each one inspects in its own way. Knowing who enforces what helps a practice keep the right records ready.
The HHS Office for Civil Rights enforces HIPAA. Most of its investigations start with a patient complaint or a reported breach. OSHA covers workplace safety, either directly or through an approved state plan such as Cal/OSHA. An OSHA visit usually follows an employee complaint or a serious injury.
State dental boards license dentists, hygienists, and assistants. Many boards write CDC infection control guidance into their rules, which turns a recommendation into law. The CDC itself issues guidance and never inspects offices.
Billing falls to the HHS Office of Inspector General, CMS, and state Medicaid agencies. Local wastewater authorities oversee amalgam separators, and the DEA regulates controlled substances.
What Does Dental Office HIPAA Compliance Require?
Dental office HIPAA compliance applies to nearly every US practice. A practice becomes a covered entity once it sends claims or eligibility checks electronically. From there, three HIPAA rules shape daily work: privacy, security, and breach notification.
What Does The Privacy Rule Require?
The Privacy Rule controls how the office uses and shares protected health information. It also gives patients rights over their own records.
Post and hand out a current notice of privacy practices
Answer patient record requests within 30 days
Share only the minimum information needed for each task
Get written authorization before any marketing use
Train every workforce member, including front desk and temporary staff
Record requests trip up more offices than most privacy duties. OCR runs a dedicated enforcement effort on slow access. Dental groups have paid settlements under it. A simple request log with dates closes that risk.
Why Does The Security Risk Analysis Matter So Much?
The security risk analysis is one of the first documents OCR requests in any investigation. It maps where electronic patient data lives and what could expose it.
A useful analysis lists every system that touches patient data. That includes practice management software, imaging, intraoral scanners, email, phones, and backups. It then rates each threat and records the fix. HHS offers a free Security Risk Assessment Tool built for small practices. A yearly update, plus one after major changes such as a new server, keeps it current.
What Happens After A Data Breach?
The Breach Notification Rule sets firm deadlines once patient data is exposed. The clock starts on the day the office discovers the breach.
Contain the incident and preserve system logs
Run a four-factor risk assessment to decide if it counts as a breach
Notify affected patients within 60 days of discovery
Report breaches of 500 or more people to HHS and local media within 60 days
Log smaller breaches and report them to HHS within 60 days after year-end
Ransomware counts as a presumed breach unless the practice can show a low probability of compromise. That makes tested, offline backups the best defense a small office has.
What Changed For Dental HIPAA Compliance In 2026?
Two separate updates matter this year, and only one of them is final. Mixing them up leads to wasted effort or missed deadlines.
The final change concerns substance use disorder records under 42 CFR Part 2. Covered practices had to update their notice of privacy practices by February 16, 2026. The new language explains how those records may be used and disclosed. The safest course is for every covered dental practice to post the updated notice.
The second change is still a proposal. HHS published a proposed Security Rule overhaul in January 2025. It would make encryption and multifactor authentication mandatory. It would also require an asset inventory, a network map, yearly audits, and 72-hour restoration plans. As of September 2026, the rule is not final. HHS lists July 2027 as its target. The current Security Rule stays in force until then. Adopting multifactor authentication and encryption now protects patient data either way.
Which Vendors Need A Business Associate Agreement?
Any vendor that handles patient data for the practice needs a signed business associate agreement. The agreement makes the vendor share responsibility for that data.
Cloud practice management and imaging software
IT support and managed security providers
Claims clearinghouses and billing services
Answering services and patient messaging tools
AI scribes, chatbots, and other tools that read patient records
AI tools are the newest weak spot. Staff sometimes paste clinical notes into consumer chatbots with no agreement in place. Our guide to AI governance in dentistry covers how to set rules for those tools. A dental answering service also needs an agreement before it takes its first call.
What Belongs On A HIPAA Compliance Checklist For Dental Offices?
A HIPAA checklist keeps privacy and security duties from slipping between busy clinic days. Review it once a year alongside the risk analysis.
Item | What "done" looks like | Record and where to keep it |
|---|---|---|
Privacy and security officers | Both roles named in writing, and one person can hold both | Designation memo in the HIPAA folder |
Security risk analysis | All systems with patient data reviewed and risks rated | Dated analysis in the HIPAA folder |
Risk fixes | High risks fixed or scheduled with a named owner | Risk management plan in the HIPAA folder |
Notice of privacy practices | Current notice, with the 2026 Part 2 update, posted in the office and online | Copy posted in the waiting room and linked on the website |
Patient acknowledgments | Signed acknowledgment collected at the first visit | Signed form in each patient chart |
Business associate agreements | Signed agreement with every vendor that handles patient data | Signed agreements in the HIPAA folder |
Workforce training | Every staff member trained at hire and yearly | Sign-in sheets and training content in the HIPAA folder |
Access controls | Unique logins, automatic screen locks, and multifactor authentication | Settings record in the IT folder |
Encryption | Laptops, phones, backups, and email with patient data encrypted | Device inventory in the IT folder |
Record requests | Patient requests answered within 30 days | Request log in the HIPAA folder |
Breach response | Written plan and a log of every incident | Breach plan and log in the HIPAA folder |
Documentation retention | Policies and HIPAA records kept for six years | Retention schedule in the HIPAA folder |
What Are The OSHA Requirements For Dental Offices?
OSHA rules protect the dental team from injury and infection. Two standards draw most dental citations: bloodborne pathogens and hazard communication. Both depend on written programs, training records, and daily habits that match the paperwork.
What Does The Bloodborne Pathogens Standard Require?
The bloodborne pathogens standard covers every employee who could contact blood or saliva. In a dental office, that means nearly the whole clinical team.
A written exposure control plan, reviewed and updated every year
Training at hire and at least once a year, during paid hours
Hepatitis B vaccine offered free within 10 working days of assignment
Signed declination forms for staff who refuse the vaccine
Post-exposure evaluation and follow-up at no cost to the employee
A yearly review of safer sharps devices, with input from frontline staff
The sharps injury log surprises many offices. Dental offices are a partially exempt industry under OSHA recordkeeping rules. As a result, federal OSHA does not require them to keep a sharps log. State plans can differ, and California requires one. Every exposure incident still needs documented follow-up, whatever the log rules say.
The exemption has limits. Every employer must report a work-related death to OSHA within 8 hours. Hospitalizations, amputations, and eye losses must be reported within 24 hours.
What Does Hazard Communication Cover?
Hazard communication, often called the right-to-know standard, covers every chemical in the office. Disinfectants, sterilants, bonding agents, and amalgam all count.
Keep a written hazard communication program
Maintain a chemical inventory that matches the shelves
Keep a safety data sheet for every hazardous product
Label secondary containers, such as spray bottles, with GHS elements
Train staff at hire and whenever a new hazard arrives
The secondary container label is a frequent miss. A disinfectant poured into an unlabeled spray bottle is an easy citation.
Which Other OSHA Rules Apply?
Several general industry standards round out OSHA compliance in a dental office. They are simple to meet and easy to forget.
Personal protective equipment, backed by a written hazard assessment
An emergency action plan and a fire prevention plan
Clear exit routes and working fire extinguishers
Eyewash stations where staff handle corrosive chemicals
The OSHA job safety poster in a common area
What Belongs On A Dental OSHA Compliance Checklist?
A dental OSHA compliance checklist turns the standards above into tasks. Review it at least once a year and after any exposure incident.
Item | Requirement | Record and where to keep it | How long to keep it |
|---|---|---|---|
Exposure control plan | Written, updated yearly, lists exposed job roles | Dated plan in the compliance binder, open to all staff | Current version on site |
Bloodborne pathogens training | At hire and yearly, during paid hours | Date, content, trainer, and attendees in the compliance binder | 3 years |
Hepatitis B vaccination | Offered free within 10 working days of assignment | Vaccine record or declination in the confidential medical file | Employment plus 30 years |
Exposure incidents | Evaluation and follow-up at no cost to the employee | Confidential medical file, locked and separate from personnel files | Employment plus 30 years |
Safer sharps review | Yearly review with frontline staff input | Notes inside the exposure control plan | Kept with the plan |
Hazard communication program | Written program, chemical inventory, and GHS labels | Program and SDS index in the hazard communication binder | Current version on site |
Safety data sheets | One for every hazardous product on site | Binder or digital index every staff member can reach during a shift | Current version on site |
PPE hazard assessment | Written certification of PPE by task | Signed certification in the compliance binder | Current version on site |
Emergency action plan | Written plan for offices with more than 10 employees | Plan or briefing record in the compliance binder | Current version on site |
Fire extinguishers | Monthly visual check and yearly service | Tag on each unit, service record in the binder | 1 year for service records |
Eyewash stations | Weekly activation | Log posted at each station | Office policy |
OSHA poster | Displayed where all staff can see it | Posted in the staff area | Always posted |
OSHA tasks often fall under dental assistant responsibilities, so a senior assistant can own this list. The dentist-owner still holds the legal liability.
How Does Infection Control Fit Into Dental Compliance?
Infection control sits where OSHA, the CDC, and state boards overlap. OSHA rules protect staff, and CDC guidance protects patients.
The CDC's 2003 dental guidelines remain the standard of practice. The 2016 Summary of Infection Prevention Practices in Dental Settings condenses them and adds a checklist. Many state boards cite these documents, so a missed step can put a license at risk.
A written infection prevention program with a trained coordinator
Weekly biological spore testing of every sterilizer, with results logged
Chemical indicators in every package and a printout or readout for every cycle
Dental unit waterlines at or below 500 CFU/mL of heterotrophic bacteria
Single-use items discarded after one patient
Hand hygiene and PPE matched to each procedure
Sterilization failures often trace back to loading and packaging errors. Our guides on spore testing frequency, common sterilization mistakes, and infection control in dentistry go deeper.
What Do State Dental Boards Require?
State boards set the licensing side of dentistry requirements, and the rules vary widely by state. Each practice should reread its own dental practice act at least once a year.
License renewals for dentists, hygienists, and assistants
Continuing education hours, often with required infection control or opioid topics
Radiography certification for staff who take X-rays
Expanded function permits and supervision rules
Sedation and anesthesia permits with facility inspections
X-ray equipment registration and periodic inspection
Patient record retention periods
Controlled substances add a federal layer. Prescribers need a DEA registration for each state where they prescribe. Most states also require a prescription monitoring program check before opioid prescriptions. Staff certification paths, such as dental X-ray certification and EFDA certification, also differ by state.
What Other Federal Rules Apply To Dental Practices?
A few federal rules sit outside HIPAA and OSHA, and they tend to catch offices by surprise. Each one carries its own paperwork.
The EPA dental effluent rule requires offices that place or remove amalgam to run an amalgam separator. They must also follow two best management practices and file a one-time compliance report. A new owner must file a fresh report within 90 days of buying a practice. That detail belongs in any dental practice valuation or acquisition review.
Billing integrity falls under the False Claims Act and the Anti-Kickback Statute. The HHS Office of Inspector General publishes compliance program guidance that small practices can scale down. Accurate CDT and CPT codes and routine chart audits are the core defenses. Offices that treat Medicaid patients face the closest review.
Civil rights rules round out the list. The Americans with Disabilities Act covers physical access and effective communication. Practices that take federal funds, including Medicaid, must also offer language help under Section 1557.
What Should A Dental Office Compliance Checklist Include?
A dental office compliance checklist works best when tasks are grouped by how often they happen. Each table below shows the task, what "done" looks like, the record and where to keep it, and the rule behind it. Inspectors ask by regulation, and teams work by calendar, so this layout serves both.
Every record in the tables has a home. A simple system uses five storage points, each with one purpose.
Compliance binder or software for OSHA programs, training records, and logs
Hazard communication binder with the chemical inventory and safety data sheets
Sterilization binder kept beside the sterilizer
Confidential employee medical files, locked and separate from personnel files
HIPAA and IT folders in secure, backed-up storage for privacy and security records
Digital storage works for all five, as long as access is limited and backups run. OSHA requires employee medical records to stay confidential, so they stay out of personnel files.
What Should A Dental Office Check Every Day?
Daily tasks protect patients at the chair and keep the sterilization record unbroken. Most take minutes when they are built into opening and closing routines.
Task | What "done" looks like | Record and where to keep it | Rule behind it |
|---|---|---|---|
Operatory disinfection | Barriers changed and surfaces wiped between patients, with the full product contact time | Disinfectant instructions in the compliance binder | CDC 2003 guidelines |
Waterline flushing and treatment | Lines flushed 20 to 30 seconds between patients, treatment product used as labeled | Treatment log posted in each operatory, filed monthly in the compliance binder | CDC 2003 guidelines |
Sterilizer cycle monitoring | Time, temperature, and pressure checked every cycle, chemical indicator in every package | Cycle log or sterilizer printout in the sterilization binder | CDC 2016 Summary |
Sharps and regulated waste | Containers upright, labeled, and replaced before they overfill | Waste hauler manifests in the compliance binder | OSHA 1910.1030, state waste rules |
PPE and hand hygiene | Gloves, masks, eyewear, and gowns worn for every exposure-prone task | None, checked visually | OSHA 1910.1030, CDC guidelines |
Workstation privacy | Screens locked when unattended, no patient papers left in view | None, checked visually | HIPAA Privacy and Security Rules |
What Should A Dental Office Check Every Week?
Weekly tasks confirm that the equipment behind daily care still works. Spore testing is the one inspectors check first.
Task | What "done" looks like | Record and where to keep it | Rule behind it |
|---|---|---|---|
Spore testing | Biological indicator run in each sterilizer with a control, and in every load with an implant | Spore test log and lab reports in the sterilization binder | CDC 2003 guidelines |
Eyewash stations | Plumbed units activated and flushed until clear water runs | Eyewash log posted at the station | OSHA 1910.151(c), ANSI Z358.1 |
Sterilizer cleaning | Chamber, gasket, and trays cleaned per the manufacturer | Maintenance log in the sterilization binder | Manufacturer instructions |
Backup check | Scheduled backups confirmed complete with no errors | Backup report saved in the IT folder | HIPAA Security Rule |
What Should A Dental Office Check Every Month?
Monthly tasks cover emergency readiness and new products. They are easy to skip, so a named owner helps.
Task | What "done" looks like | Record and where to keep it | Rule behind it |
|---|---|---|---|
Fire extinguishers | Visual check of pin, seal, gauge, and body | Initialed and dated tag on each extinguisher | OSHA 1910.157 |
Emergency kit and oxygen | Drugs in date, oxygen tank full, AED battery and pads ready | Emergency equipment log stored with the kit | State dental board rules |
Safety data sheets | Every chemical on the shelf has a current SDS, staff trained before first use | SDS index in the hazard communication binder, open to all staff | OSHA 1910.1200 |
Amalgam separator | Canister checked and replaced on the manufacturer's schedule | Inspection and disposal records in the compliance binder, kept for 3 years | EPA 40 CFR Part 441 |
What Should A Dental Office Check Every Quarter?
Quarterly tasks catch slow drift in security and documentation. They also give early warning before the annual review.
Task | What "done" looks like | Record and where to keep it | Rule behind it |
|---|---|---|---|
Waterline testing | Each operatory tested on the state or manufacturer schedule, result at or below 500 CFU/mL | Test reports by operatory in the compliance binder | CDC guidelines, state rules |
Access review | Former staff accounts removed, user roles match current jobs | Access review record in the HIPAA folder | HIPAA Security Rule |
Backup restore test | A full restore completed and timed | Restore test log in the IT folder | HIPAA Security Rule |
Chart audit | A sample of charts checked for codes, consent, and signatures | Audit notes with fixes in a locked compliance file | OIG compliance guidance |
Self-inspection walk | A 15-minute walkthrough of this checklist, with an owner for each finding | Dated walkthrough notes in the compliance binder | Best practice |
What Should A Dental Office Review Every Year?
Annual tasks hold the program together, and they are where offices most often fall behind. Scheduling them in the same month each year keeps them from slipping.
Task | What "done" looks like | Record and where to keep it | Rule behind it |
|---|---|---|---|
Security risk analysis | Every system with patient data reviewed, risks rated, fixes recorded | Dated analysis in the HIPAA folder, kept 6 years | HIPAA Security Rule |
Exposure control plan | Plan reviewed, safer sharps evaluated with frontline staff input | Signed plan in the compliance binder, open to all staff | OSHA 1910.1030 |
Bloodborne pathogens training | Every exposed employee trained within a year of the last session | Training records in the compliance binder, kept for 3 years | OSHA 1910.1030 |
HIPAA training | All workforce members trained on privacy and security | Sign-in sheets in the HIPAA folder, kept 6 years | HIPAA Privacy Rule |
Hazard communication | Written program current, labels checked, training refreshed | Written program in the hazard communication binder | OSHA 1910.1200 |
PPE hazard assessment | Written assessment of which tasks need which PPE | Signed certification in the compliance binder | OSHA 1910.132 |
Emergency action plan | Exits, alarms, and roles confirmed, written plan for offices over 10 staff | Plan in the compliance binder, exit map posted | OSHA 1910.38 |
Fire extinguisher service | Annual maintenance by a qualified service | Service tag on the unit and record in the binder, kept for 1 year | OSHA 1910.157 |
Business associate agreements | Every vendor with patient data has a current signed agreement | Signed agreements in the HIPAA folder | HIPAA Privacy and Security Rules |
Licenses and registrations | Licenses, DEA, X-ray registration, and CPR cards current, CE hours met | Copies in each personnel file, originals displayed where state law requires | State dental board, DEA |
What Tasks Follow Staff Changes Or Incidents?
Some tasks start with an event instead of a date. Staff changes, exposures, failed tests, and breaches each start their own clock.
Trigger | What "done" looks like | Record and where to keep it | Rule behind it |
|---|---|---|---|
New hire with exposure risk | Bloodborne pathogens and hazard communication training before patient contact | Training records in the compliance binder | OSHA 1910.1030, 1910.1200 |
New hire in any role | HIPAA training and a signed confidentiality agreement | Training record and signed agreement in the personnel file | HIPAA Privacy Rule |
Hepatitis B vaccination | Vaccine offered free within 10 working days of assignment | Vaccine record or declination in the confidential medical file, kept for employment plus 30 years | OSHA 1910.1030 |
Credentials | License and certification copies filed before the first shift | Copies in the personnel file | State dental board |
Staff departure | System access disabled on the last day, keys and devices collected | Offboarding checklist in the personnel file | HIPAA Security Rule |
Exposure incident | Immediate post-exposure evaluation and follow-up at no cost to the employee | Confidential medical file, locked and separate from personnel files | OSHA 1910.1030 |
Failed spore test | Sterilizer out of service, retest with a control, loads recalled if it fails again | Spore log with corrective action in the sterilization binder | CDC 2003 guidelines |
Serious injury | Death reported to OSHA within 8 hours, hospitalization within 24 hours | Report confirmation in the compliance binder | OSHA 1904.39 |
Data breach | Risk assessment done, patients notified within 60 days of discovery | Breach log and copies of notices in the HIPAA folder, kept for 6 years | HIPAA Breach Notification Rule |
Sterilizers with built-in cycle logging shorten several of these logs, as our guide to choosing sterilization equipment explains.
How Do You Build A Dental Compliance Program?
A compliance program turns scattered tasks into a system with owners, deadlines, and proof. Small practices can build one in a few weeks.
Name a compliance lead, plus a HIPAA privacy officer and security officer
Run a self-audit against HIPAA, OSHA, CDC, and state board rules
Write or update policies for each area, dated and signed
Build a training calendar with hire-date and annual sessions
Choose one system to store records, logs, and signed forms
Run a mock inspection with someone outside the daily routine
Review the whole program every year and after any incident
One person can hold several roles in a small office. Each role still needs a named owner. Strong office administrator skills make that person far more effective. New offices can fold these steps into their new dental practice checklist.
Clinical documentation belongs in the program too. A signed dental treatment plan with informed consent protects the practice during complaints and audits.
What Happens During A Compliance Inspection?
Each regulator inspects differently, and knowing the pattern lowers the stress. Most visits follow a complaint, an incident, or a routine board schedule.
Inspection | Common trigger | Documents to have ready |
|---|---|---|
OSHA | Employee complaint, serious injury, or referral | Exposure control plan, training records, vaccination files, hazard communication program, safety data sheets |
OCR (HIPAA) | Patient complaint or reported breach | Security risk analysis, policies, training records, business associate agreements, breach log |
State dental board | Complaint, license renewal, or routine inspection | Licenses, CE records, sterilizer logs, spore test results, radiography certificates |
OSHA inspectors compare the written plan with what they see in the operatory. A plan that describes safety syringes the office never bought counts against it. Honest, current documents do more than any polished binder.
How Does Dentistry Compliance Work Outside The US?
Dentistry compliance in the UK follows a different set of regulators. Each of the four nations has its own inspection body.
England: Care Quality Commission (CQC)
Wales: Healthcare Inspectorate Wales (HIW)
Scotland: Healthcare Improvement Scotland (HIS)
Northern Ireland: Regulation and Quality Improvement Authority (RQIA)
Every UK dental professional also registers with the General Dental Council and logs verifiable CPD. Decontamination follows HTM 01-05 in England, and radiation work falls under IRR17 and IR(ME)R 2017. Patient data falls under UK GDPR and the Data Protection Act 2018. The core principles match the US model, with written policies, trained staff, and records that prove both.
Bottom Line
Dental compliance rests on five areas: privacy, workplace safety, infection control, licensing, and billing. Two documents carry the most weight in any inspection. They are the HIPAA security risk analysis and the OSHA exposure control plan.
Keeping both current, training on schedule, and logging every sterilizer cycle covers most risk. A yearly review of the full dental office compliance checklist catches the rest.
This article is for informational purposes only and does not constitute legal advice. Requirements vary by state, so confirm details with the relevant regulator or a healthcare attorney.
Frequently Asked Questions
What is dental compliance?
Dental compliance is a practice's adherence to the laws and guidelines that govern dental care. It covers HIPAA privacy, OSHA safety, CDC infection control, state licensing, and billing rules. Each area has its own enforcer and required records.
What are the OSHA requirements for a dental office?
A dental office needs a written exposure control plan and yearly bloodborne pathogens training. Exposed staff must be offered free hepatitis B vaccination. The office also needs a hazard communication program with safety data sheets. A dental OSHA compliance checklist helps track each item.
Does HIPAA apply to every dental practice?
HIPAA applies to any practice that sends claims, eligibility checks, or other transactions electronically. That includes nearly every US dental office. A rare cash-only practice with no electronic transactions may fall outside it. State privacy laws still apply.
How often should a dental office do a HIPAA risk assessment?
HIPAA requires an accurate, ongoing risk analysis without a fixed schedule. A yearly update works well, plus one after major changes such as new software. The proposed Security Rule update would make yearly reviews mandatory for dental HIPAA compliance.
What records must a dental office keep for OSHA?
Keep the exposure control plan, hazard communication program, safety data sheets, and PPE assessment. Training records stay for three years. Employee vaccination and exposure records stay for the length of employment plus 30 years.
Who enforces dental compliance in the US?
The HHS Office for Civil Rights enforces HIPAA. OSHA or a state plan covers workplace safety. State dental boards handle licensing and often infection control. The HHS Office of Inspector General and state Medicaid agencies police billing.