HIPAA & Security
Built to protect sensitive dental case information. DentaTrak gives practices secure controls for managing patient-related case information, files, users, and access while supporting the safeguards important for HIPAA-conscious workflows.
Security at a glance
Business Associate Agreement
A BAA is part of DentaTrak onboarding before a practice begins using the platform for patient information.
Protected patient data
Sensitive patient information is protected using DentaTrak's implemented data-security controls.
Controlled access
Users only access practices and case information they are authorized to use.
Secure file handling
Case attachments are protected rather than exposed as public files.
How DentaTrak protects your practice's information
DentaTrak combines access controls, encryption, audit logging, and secure session handling to help keep patient information protected.
Patient information is protected
Sensitive patient information is encrypted before it is stored. Patient names, dates of birth, dentist names, and case notes are encrypted at the application level using AES-256-CBC, and passwords are hashed with bcrypt. All traffic between your browser and DentaTrak is sent over HTTPS.
Access stays within your practice
Users only see information they are authorized to access. Every user is tied to a practice through a membership record, and every request that accesses case data checks that the user belongs to the right practice. Role-based permissions (admin, user, and owner) control what each person can do, and the Assigned Only setting limits a user to seeing only cases assigned to them.
Files aren't publicly exposed
Case attachments are stored in DentaTrak's cloud storage and are never served as public files. Access uses short-lived signed URLs that expire in minutes, and each download request is validated against the user's practice membership and case assignment before the file is streamed.
Important activity is recorded
DentaTrak records access to protected health information, including who accessed what case, from what IP address, and when. Case status and activity changes are also tracked for accountability and traceability.
Accounts and sessions are protected
Sessions are configured with httpOnly, Secure in production, and SameSite=Lax cookies. Sessions time out after 30 minutes of inactivity and are periodically regenerated. Cross-site request forgery tokens are required for state-changing requests, and optional TOTP two-factor authentication is available.
Your data isn't trapped in DentaTrak
Practice data is retained for 7 years after deactivation, which exceeds HIPAA's minimum 6-year requirement. Practice administrators can export practice data at any time through the application.
DentaTrak uses additional application-level protections and security headers to reduce common web-based risks.
Security is a shared responsibility
DentaTrak provides technical safeguards and access controls, but each practice also plays an essential role. Your practice remains responsible for how staff use the system, who receives access, account security, devices and networks, training, and its own HIPAA policies and procedures. Using DentaTrak does not, by itself, make a practice HIPAA compliant.
What your practice is responsible for
DentaTrak provides the technical controls, but your practice is responsible for managing users, protecting credentials, and following your own policies and procedures.
- Remove access when staff leave or change roles.
- Use strong, unique account credentials.
- Enable two-factor authentication where appropriate.
- Access DentaTrak from appropriately secured devices and networks.
- Train staff on your practice's privacy and HIPAA procedures.
Questions about security or HIPAA?
For questions about HIPAA, our Business Associate Agreement, privacy, or data handling, please contact us at privacy@dentatrak.com.