CBCTHubCBCTHub
PricingBlogHelp
 
 
Back to blog
compliancelegalhipaauk-gdprpipeda

Data Privacy Compliance for Dental Imaging Centers: HIPAA, UK GDPR, PIPEDA

CBCTHub·July 15, 2026

Why This Topic Is No Longer Optional

Until a few years ago, data protection compliance at dental imaging centers was handled loosely — nobody audited a small practice. That has changed. Regulators have stepped up enforcement, patients have grown more willing to complain, and professional liability insurers now ask for evidence of compliance before underwriting a policy.

This post isn't legal advice: every jurisdiction has its own nuances, and it's worth consulting a specialized attorney. But here's the general map for the frameworks most relevant to imaging centers operating in the US, UK, and Canada in 2026.

HIPAA (United States)

HIPAA applies to covered entities and their business associates in the US. If your center bills insurance, works with dental practices that require a Business Associate Agreement (BAA), or stores any patient health information electronically, HIPAA applies to you directly.

The core requirement of HIPAA: Protected Health Information (PHI) must be stored encrypted, transmitted encrypted, and accessed with an audit trail. DICOM images with patient identifiers are PHI. Penalties range from $100 to $50,000+ per violation, with annual caps that can reach $1.5 million per violation category.

UK GDPR (United Kingdom)

Since Brexit, the UK operates its own version of the GDPR — the UK GDPR, alongside the Data Protection Act 2018 — enforced by the Information Commissioner's Office (ICO). Medical images count as special category data and receive reinforced protection. Main obligations:

  • Explicit, specific consent from the patient for processing their data.
  • A documented lawful basis for processing special category health data.
  • A record of processing activities (ROPA).
  • Breach notification to the ICO within 72 hours when required.

Fines can reach £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements.

PIPEDA (Canada)

The Personal Information Protection and Electronic Documents Act governs private-sector data handling in Canada, alongside provincial equivalents such as Ontario's PHIPA for health information specifically. Key obligations for imaging centers:

  • Meaningful consent before collecting or sharing health data.
  • Safeguards proportional to the sensitivity of the data — health imaging counts as highly sensitive.
  • Breach reporting to the Office of the Privacy Commissioner when there's a real risk of significant harm.
  • Clear retention and disposal policies for patient records.

Other Frameworks Worth Knowing

  • Australia: the Privacy Act 1988 and the Australian Privacy Principles (APPs), enforced by the OAIC. Health data is "sensitive information" requiring explicit consent.
  • US state laws: several states (California's CCPA/CPRA among them) layer additional requirements on top of HIPAA, especially around breach notification timelines.

The Most Underrated Risk: Lost CDs

Every CD you hand over with unencrypted patient data is a potential data breach. If the patient loses it on the street, in a rideshare, or in the dentist's waiting room, that's technically unauthorized exposure of sensitive health data.

Under HIPAA, that's reportable. Under UK GDPR and PIPEDA, likely reportable too. Most centers never report it because they never find out, but the legal exposure exists regardless.

A platform link with authentication, access logging, and expiration is structurally far more defensible than an unencrypted physical disc.

Minimum Documents Your Center Should Have

  1. A published privacy policy on your website, accessible and written in plain language.
  2. Informed consent signed by every patient, covering data processing.
  3. A record of processing activities (what data, why, for how long, who it's shared with).
  4. A procedure for handling data subject requests (access, correction, deletion, objection).
  5. Contracts with data processors (your PACS vendor, viewer platform, etc.) that include data protection clauses — a BAA in the US context.
  6. An incident response protocol with clear notification timelines.

Technology That Helps You Comply

  • Encryption at rest (AES-256) and in transit (TLS 1.2+).
  • Authentication required to access each study.
  • Audit logs: who accessed what, when, and from where.
  • Configurable expiration for access links.
  • Hosting in a jurisdiction appropriate for your applicable regime.

The Business Case Is Real

Large group practices and dental service organizations (DSOs) have started auditing their imaging vendors. If your center can't show basic evidence of compliance, you start getting dropped from approved vendor lists. This is a newer trend, but it's growing fast.

Platforms with encryption, logging, and retention policies built in make compliance easier without having to build it from scratch. You can try CBCTHub free and see how access and audit logging work from your very first study.

Try free viewerSee solutions

Try CBCTHub for free

Upload, view, and share DICOM scans in the cloud. Nothing to install.

Create free account

Related articles

Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers

Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers

How to comply with HIPAA (Public Law 104-191), Privacy Rule, Security Rule, and HITECH Act in a dental imaging clinic. PHI, BAA, OCR fines up to USD 1.5M per year.

HIPAA-compliant dental imaging APIs: security checklist for US healthcare integrations

A 10-point HIPAA security checklist for any dental imaging API integration in the US. Encryption, BAAs, audit logs, breach notification, patient rights.

Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers

Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers

How a dental imaging center complies with Spain's LOPDGDD 3/2018, EU GDPR, and Law 41/2002 on clinical records. Obligations, penalties up to EUR 20M, and how CBCTHub helps.

CBCTHubCBCTHub

Digital CBCT delivery. 100% local processing. No CDs, ever.

Download on theApp Store
Get it onGoogle Play

Solutions

Imaging centersDental radiologistsOnline CBCT viewer

Product

FeaturesPricingBlogAlternativesLearnEducationNewDevelopersAPIDemo

Support

Help centerFAQContactsoporte@cbcthub.comStatus+56 9 7632 9096

Company

AboutSecurityTerms of servicePrivacy policy

By country

United StatesUnited KingdomCanadaAustralia
HIPAA-readyGDPRLGPDLey 21.719

© 2026 CBCTHub. All rights reserved.

AppLab Software LLC · 1021 E Lincolnway, Cheyenne, WY 82001