HIPAA & Security
Security is built into how DentaTrak handles every practice, user, case, and file. DentaTrak combines encrypted data handling, server-enforced practice isolation, role-based access controls, two-factor authentication, private file delivery, audit logging, session protections, automated backups, and Business Associate Agreements to help protect dental case information.
DentaTrak is designed and operated to support HIPAA-compliant use. Each dental practice remains responsible for its own workforce practices, devices, policies, and appropriate use of the platform. Learn more about DentaTrak's dental case tracking software for dental practices.
Security at a glance
Encryption in transit and at rest
Traffic is protected over HTTPS, and stored data is encrypted at both the application and infrastructure layers.
Application-level encryption
Sensitive patient fields are encrypted with AES-256-CBC before they are stored.
Two-factor authentication
Optional authenticator-app verification adds a second layer of protection beyond a password.
Practice data isolation
Practice membership and case authorization are verified on the server for every protected request.
Role-based access
Owner, administrator, and user permissions, plus optional Assigned Only case restrictions.
Immediate access revocation
Removing a user from a practice revokes their access on the next request.
Audit and activity logging
Case record access and case activity are recorded with the user, timestamp, and IP address.
Private file storage
Case attachments stay in private cloud storage and are served only through short-lived signed URLs.
Automatic session timeout
Inactive sessions expire automatically, with an advance warning before sign-out.
Automated backups
Managed database backups and point-in-time recovery reduce the risk of data loss.
Business Associate Agreements
A Business Associate Agreement is part of onboarding for practices using DentaTrak with protected health information.
How DentaTrak encrypts your information
DentaTrak applies encryption at several layers, so sensitive information is protected in transit and at rest.
Application-level encryption
DentaTrak encrypts sensitive patient fields — including patient name, date of birth, dentist name, and case notes — using AES-256-CBC before they are written to the database. These fields are not stored as readable text.
Infrastructure-level encryption at rest
DentaTrak is hosted on Google Cloud. The managed database and private cloud storage encrypt stored data at rest at the infrastructure level, independently of application-level encryption.
Encryption in transit
Traffic between your browser and DentaTrak is served over HTTPS/TLS, and unencrypted requests are redirected to HTTPS.
Password protection
Passwords are hashed with bcrypt, a one-way password hashing algorithm, and are never stored in readable form. New passwords must also meet minimum strength requirements.
Access and account protection
Access to protected information depends on who the user is, which practice they belong to, and what they are authorized to see — and it is enforced on the server, not just in the interface.
Two-factor authentication
DentaTrak supports two-factor authentication (2FA) using time-based one-time passwords from an authenticator app. When a user enables 2FA, signing in requires a verification code in addition to their password, for both email/password and Google sign-in.
Practice data isolation
Every request for practice or case information is authorized on the server. DentaTrak verifies that the signed-in user is an active member of an active practice, and that they are authorized for the specific case, before protected information is returned. What a user can see in the interface is never treated as authorization.
Role-based and Assigned Only access
Practice members receive role-based permissions, including owner and administrator capabilities, with separate controls for analytics access and case editing. Practices can also enable Assigned Only access, which restricts a user to cases assigned to them. These restrictions are enforced server-side.
Immediate access revocation
Practice administrators control membership through practice settings. Because membership and account status are re-verified on the server each time protected data is requested, removing a user from a practice revokes their access to that practice's cases and files on their next request.
Session protection
Sessions are stored server-side and expire after a period of inactivity, with a warning shown in advance so users can remain signed in when appropriate. Session cookies are configured with HttpOnly, Secure in production, and SameSite protections, and session identifiers are periodically regenerated. The "Remember my email" option only pre-fills the sign-in form - it never keeps you signed in or bypasses authentication.
Sign-in protection
Email and password accounts must verify their email address before signing in. Repeated failed sign-in attempts trigger a temporary account lockout to protect against brute-force attacks, without revealing whether an account exists.
Data, files, and platform safeguards
Beyond account access, DentaTrak protects the information itself: where files live, how activity is recorded, and how the platform is operated.
Case attachments remain private
Case attachments are stored in private cloud storage rather than exposed through public links. Before providing access to an attachment, DentaTrak validates the user's practice membership and authorization for the associated case, and files are uploaded and downloaded through short-lived signed URLs that expire after a limited period. Uploads are checked against file-type and size limits and verified against the stored object before being attached to a case.
Audit and activity logging
DentaTrak records access to protected case records — including viewing and printing — with the user, practice, case, date and time, IP address, and browser information. Case activity such as creation, status changes, assignment changes, comments, and file-archive downloads is recorded with the acting user and timestamp, and denied-access security events are logged to support investigation.
Application safeguards
Cross-site request forgery (CSRF) tokens are required for requests that change application data, and responses include security headers such as a content security policy, frame blocking, and content-type protections. Access restrictions are enforced by the server and never depend solely on whether a control or page element is visible in the browser.
Cloud infrastructure
DentaTrak runs on Google Cloud, using a managed database (Cloud SQL) and private object storage (Cloud Storage). Application credentials and encryption keys are supplied through protected environment configuration rather than stored in the codebase.
Backups and recovery
DentaTrak uses managed database backup and recovery capabilities, including automated backups and point-in-time recovery, to reduce the risk of data loss and support recovery from operational incidents.
Practices retain control of their information
Practice administrators can export practice data through DentaTrak, subject to their role and access permissions. Following practice deactivation, DentaTrak retains practice data for seven years in accordance with its data-retention policy. Retention and deletion are managed under DentaTrak's applicable agreements, policies, and legal obligations.
Security is a shared responsibility
DentaTrak provides safeguards for the platform and the information processed through it. Each practice remains responsible for how its workforce uses DentaTrak and for maintaining its own HIPAA compliance program.
Using DentaTrak does not, by itself, make a practice HIPAA compliant.
Your practice's responsibilities
Each practice should:
- Provide access only to people who need it for their work.
- Assign the minimum permissions appropriate for each user.
- Remove or update access promptly when responsibilities change or employment ends.
- Use strong, unique passwords and protect account credentials.
- Enable two-factor authentication where appropriate.
- Review user access and account activity periodically.
- Use appropriately secured devices, browsers, and networks.
- Keep devices and software updated.
- Train workforce members on privacy, security, and HIPAA procedures.
- Avoid placing protected health information in unnecessary fields, messages, or communications.
- Report suspected unauthorized access or security incidents promptly.
Business Associate Agreements
DentaTrak enters into Business Associate Agreements with dental practices that use the platform to manage protected health information. A Business Associate Agreement is included as part of DentaTrak onboarding where applicable, and acceptance is required before a practice uses the platform for protected health information. The accepted agreement is recorded with the signer, date, and version, and is available to the practice for its records.
DentaTrak also maintains a Business Associate Agreement with its cloud hosting provider for the services used to store and process protected health information.
These agreements define responsibilities for safeguarding protected health information and supporting applicable HIPAA requirements.
Compliance and assurance
DentaTrak is designed and operated to support HIPAA-compliant use and provides Business Associate Agreements to dental practices where applicable.
HIPAA does not provide an official government certification for software products, and no product alone can make a practice compliant. Compliance depends on how each practice configures and uses the platform, together with the administrative and physical safeguards under the practice's control.
DentaTrak does not currently claim SOC 2 or ISO 27001 certification. The controls described on this page reflect implemented product and infrastructure behavior.
Report a security concern
If you believe you have identified a security issue or vulnerability in DentaTrak, or suspect that protected health information may have been exposed, contact security@dentatrak.com with a description of the concern. Please do not include patient health information in your report.
Questions about HIPAA or security?
For questions about DentaTrak security, privacy, data handling, or Business Associate Agreements, contact security@dentatrak.com.