Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers
If your dental imaging center operates in the United States or serves US patients, you are subject to the Health Insurance Portability and Accountability Act (HIPAA, Public Law 104-191) of 1996 and its later reinforcement, the Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009. A single mishandled PHI breach can cost up to USD 1.5 million per year per violation category, plus the reputational damage of the HHS Wall of Shame.
This article explains what PHI is, what each rule requires, why you need a BAA with any cloud provider, and how CBCTHub satisfies the technical, physical, and administrative safeguards required by the Security Rule.
HIPAA in plain English
HIPAA is a set of federal regulations protecting Protected Health Information (PHI) and setting standards for its storage, transmission, and disclosure. It comprises four main rules:
- Privacy Rule: 45 CFR Part 160 and 164 Subparts A and E. Defines what PHI is and when it can be used.
- Security Rule: 45 CFR Part 164 Subpart C. Requires technical, physical, and administrative safeguards for electronic PHI (ePHI).
- Breach Notification Rule: 45 CFR Part 164 Subpart D. Mandates breach notification.
- Enforcement Rule: 45 CFR Part 160 Subpart C, D, E. Defines the OCR sanctioning regime.
What is PHI and the 18 identifiers
PHI is any health information that can be tied to an individual. The rule defines 18 identifiers that make a piece of data PHI: name, address, dates (except year), phone, email, SSN, MRN, account number, license number, vehicle plate, device identifiers, URL, IP, biometrics, facial photos, generic identifiers, and any other unique identifier. A CBCT scan with the patient name in DICOM metadata is PHI.
Privacy Rule: when you can use and disclose PHI
Use and disclosure of PHI require patient authorization, except in specific cases: treatment, payment, healthcare operations (TPO), public health, IRB-approved research, and others. To send a CBCT to a referring specialist, you are authorized under TPO. To use it in marketing, you need specific written authorization.
Security Rule: the three types of safeguards
Administrative safeguards
- Designation of a Security Officer.
- Formal documented risk analysis.
- Access management policies.
- Workforce training.
- Contingency plan and incident response.
Physical safeguards
- Facility access controls where PHI is stored.
- Workstation use policy.
- Device and media controls.
Technical safeguards
- Unique user authentication.
- Encryption of ePHI in transit and at rest (addressable, but expected).
- Audit controls recording ePHI access.
- Integrity mechanisms.
- Automatic logoff.
Business Associate Agreement (BAA): mandatory
Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate (BA). You must sign a BAA with each before sharing PHI. This includes any cloud provider (AWS, Google Cloud, Cloudflare, Supabase) and any service that touches PHI (email, storage, analytics). Without a BAA, any use is a HIPAA violation.
HITECH Act: 2009 reinforcement
HITECH tightens the regime: extends HIPAA directly to BAs, raises penalties, mandates breach notification, creates the HHS Wall of Shame (public list of breaches affecting more than 500 individuals), and promotes electronic health record adoption.
Breach notification
Any breach of unsecured ePHI (that was not encrypted per HHS standards) requires notification:
- To affected individuals: within 60 days.
- To HHS: within 60 days (or annually for fewer than 500 individuals).
- To the media: if it affects more than 500 residents of a state or jurisdiction.
OCR penalties
The OCR applies penalties in four tiers based on culpability:
- Tier 1 (lack of knowledge): USD 100 to USD 50,000 per violation, USD 25,000 max per year per category.
- Tier 2 (reasonable cause): USD 1,000 to USD 50,000, USD 100,000 per year.
- Tier 3 (willful neglect, corrected): USD 10,000 to USD 50,000, USD 250,000 per year.
- Tier 4 (willful neglect, not corrected): USD 50,000 per violation, USD 1.5 million max per year.
Additionally, breaches affecting more than 500 individuals appear on the HHS Wall of Shame, a permanent public list that destroys patient trust.
Concrete risks for a US dental imaging clinic
The laptop with unencrypted DICOM copies stolen from a car, the email sent to the wrong address with a CBCT attached, the misconfigured web portal exposing exams via sequential URLs, the ex-employee downloading PHI before leaving. All generate reportable breaches. Anthem paid USD 16 million in 2018 for a breach; UCLA Health, USD 7.5 million; Memorial Healthcare, USD 5.5 million.
How CBCTHub helps you comply with HIPAA and HITECH
ePHI encryption in transit and at rest
TLS 1.3 on every connection and AES-256 at rest in Cloudflare R2. Meets the HHS safe-harbor encryption standard: if encrypted data is exposed, it is not a reportable breach.
Signable Business Associate Agreement
CBCTHub provides a BAA ready for electronic signature for Pro, Max, and Ultra plan customers. The template covers the entirety of 45 CFR 164.504(e) requirements.
Comprehensive audit controls
Every exam access, download, and modification is logged with timestamp, IP, and user_id. Meets Audit Controls under 164.312(b). The log exports to CSV for OCR auditors.
Unique authentication and access control
Each user has an individual authenticated account. We support SSO with Google and Apple, and MFA on higher tiers. Meets Unique User Identification under 164.312(a)(2)(i).
Automatic session timeout
Sessions expire after configurable inactivity. Meets Automatic Logoff under 164.312(a)(2)(iii).
Row Level Security (RLS) on Supabase
Strict isolation between clinics. Even CBCTHub staff cannot see PHI without explicit, logged access.
PIN and unique links
Every exam has a unique opaque URL with optional PIN. The patient or referring dentist only accesses with the specific link and, if enabled, the PIN. Meets Access Control under 164.312(a).
Automatic link expiration
Shared links expire per the policy you configure. Honors the minimum-necessary principle under 164.502(b).
Secure deletion
DELETE /api/v1/exams/{id} removes ePHI irreversibly. Meets Media Re-use under 164.310(d)(2)(ii).
Breach notification procedure
We have a documented plan that meets the 60-day client notification timeline. If a breach affects a customer, we notify them so they can escalate to HHS within the deadline.
US-based hosting
Data for US clinics is hosted in US regions. Cloudflare R2 and Supabase offer US-East and US-West regions.
HIPAA compliance checklist for your center
- Designate Security Officer and Privacy Officer.
- Complete documented Risk Analysis and update annually.
- Sign BAA with CBCTHub and every BA.
- Written policies on PHI use and disclosure.
- HIPAA workforce training at onboarding and annually.
- Breach response plan with 60-day clock.
- State-specific PHI retention policy (minimum 6 years for HIPAA docs).
- Annual ePHI access audit.
- Full-disk encryption on every device storing ePHI.
FAQ
Can I send a CBCT via standard Gmail?
No. Standard Gmail is not HIPAA-compliant because Google does not offer a BAA for the consumer product. Google Workspace with a BAA is HIPAA-compliant only if you have the contract signed and configured. The safest option is a CBCTHub link.
How long must I retain PHI?
HIPAA requires 6 years for administrative documentation. Clinical PHI retention depends on the state: Florida requires 4 years after last contact, Texas 7, California permanent for minors.
What happens if I lose a laptop with PHI?
If the laptop was encrypted per HHS standard, it is not a reportable breach. If not, you have 60 days to notify the patient and HHS. A Massachusetts clinic paid USD 1.55M in 2016 for a stolen unencrypted laptop.
Do I need to sign anything with CBCTHub?
Yes, a BAA. Available for Pro, Max, and Ultra plans. Request it from your account dashboard.
Official resources
Request the CBCTHub BAA | US dental imaging center solution | Plans and pricing
This article is informational and does not constitute legal advice. Consult with a HIPAA-specialized lawyer for your specific case.
Try CBCTHub for free
Upload, view, and share DICOM scans in the cloud. Nothing to install.
Create free accountRelated articles
Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers
How a dental imaging center complies with Spain's LOPDGDD 3/2018, EU GDPR, and Law 41/2002 on clinical records. Obligations, penalties up to EUR 20M, and how CBCTHub helps.
Patient data protection in Mexico: LFPDPPP, INAI, and NOM-024 compliance guide for dental imaging centers
How to comply with Mexico's LFPDPPP, its regulation, NOM-024-SSA3-2012, and NOM-004 at a dental imaging clinic. INAI, Privacy Notice, UMA-based fines. How CBCTHub helps.
Patient data protection in Chile: Law 19.628 and the new Law 21.719 for dental imaging centers
Complete guide to Chile's current Law 19.628, the new Law 21.719 effective December 2026, and Law 20.584 on patient rights. How CBCTHub helps you comply today and tomorrow.