HIPAA & Security

Built to protect sensitive dental case information. DentaTrak gives practices secure controls for managing patient-related case information, files, users, and access while supporting the safeguards important for HIPAA-conscious workflows.

Security at a glance

Business Associate Agreement

A BAA is part of DentaTrak onboarding before a practice begins using the platform for patient information.

Protected patient data

Sensitive patient information is protected using DentaTrak's implemented data-security controls.

Controlled access

Users only access practices and case information they are authorized to use.

Secure file handling

Case attachments are protected rather than exposed as public files.

How DentaTrak protects your practice's information

DentaTrak combines access controls, encryption, audit logging, and secure session handling to help keep patient information protected.

Patient information is protected

Sensitive patient information is encrypted before it is stored. Patient names, dates of birth, dentist names, and case notes are encrypted at the application level using AES-256-CBC, and passwords are hashed with bcrypt. All traffic between your browser and DentaTrak is sent over HTTPS.

Access stays within your practice

Users only see information they are authorized to access. Every user is tied to a practice through a membership record, and every request that accesses case data checks that the user belongs to the right practice. Role-based permissions (admin, user, and owner) control what each person can do, and the Assigned Only setting limits a user to seeing only cases assigned to them.

Files aren't publicly exposed

Case attachments are stored in DentaTrak's cloud storage and are never served as public files. Access uses short-lived signed URLs that expire in minutes, and each download request is validated against the user's practice membership and case assignment before the file is streamed.

Important activity is recorded

DentaTrak records access to protected health information, including who accessed what case, from what IP address, and when. Case status and activity changes are also tracked for accountability and traceability.

Accounts and sessions are protected

Sessions are configured with httpOnly, Secure in production, and SameSite=Lax cookies. Sessions time out after 30 minutes of inactivity and are periodically regenerated. Cross-site request forgery tokens are required for state-changing requests, and optional TOTP two-factor authentication is available.

Your data isn't trapped in DentaTrak

Practice data is retained for 7 years after deactivation, which exceeds HIPAA's minimum 6-year requirement. Practice administrators can export practice data at any time through the application.

DentaTrak uses additional application-level protections and security headers to reduce common web-based risks.

Security is a shared responsibility

DentaTrak provides technical safeguards and access controls, but each practice also plays an essential role. Your practice remains responsible for how staff use the system, who receives access, account security, devices and networks, training, and its own HIPAA policies and procedures. Using DentaTrak does not, by itself, make a practice HIPAA compliant.

What your practice is responsible for

DentaTrak provides the technical controls, but your practice is responsible for managing users, protecting credentials, and following your own policies and procedures.

Questions about security or HIPAA?

For questions about HIPAA, our Business Associate Agreement, privacy, or data handling, please contact us at privacy@dentatrak.com.