CBCTHubCBCTHub
PricingBlogHelp
 
 
Back to blog
data-protectioncomplianceusahipaahitechhealthcare-dental

Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers

CBCTHub·June 28, 2026
Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers

If your dental imaging center operates in the United States or serves US patients, you are subject to the Health Insurance Portability and Accountability Act (HIPAA, Public Law 104-191) of 1996 and its later reinforcement, the Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009. A single mishandled PHI breach can cost up to USD 1.5 million per year per violation category, plus the reputational damage of the HHS Wall of Shame.

This article explains what PHI is, what each rule requires, why you need a BAA with any cloud provider, and how CBCTHub satisfies the technical, physical, and administrative safeguards required by the Security Rule.

HIPAA in plain English

HIPAA is a set of federal regulations protecting Protected Health Information (PHI) and setting standards for its storage, transmission, and disclosure. It comprises four main rules:

  • Privacy Rule: 45 CFR Part 160 and 164 Subparts A and E. Defines what PHI is and when it can be used.
  • Security Rule: 45 CFR Part 164 Subpart C. Requires technical, physical, and administrative safeguards for electronic PHI (ePHI).
  • Breach Notification Rule: 45 CFR Part 164 Subpart D. Mandates breach notification.
  • Enforcement Rule: 45 CFR Part 160 Subpart C, D, E. Defines the OCR sanctioning regime.

What is PHI and the 18 identifiers

PHI is any health information that can be tied to an individual. The rule defines 18 identifiers that make a piece of data PHI: name, address, dates (except year), phone, email, SSN, MRN, account number, license number, vehicle plate, device identifiers, URL, IP, biometrics, facial photos, generic identifiers, and any other unique identifier. A CBCT scan with the patient name in DICOM metadata is PHI.

Privacy Rule: when you can use and disclose PHI

Use and disclosure of PHI require patient authorization, except in specific cases: treatment, payment, healthcare operations (TPO), public health, IRB-approved research, and others. To send a CBCT to a referring specialist, you are authorized under TPO. To use it in marketing, you need specific written authorization.

Security Rule: the three types of safeguards

Administrative safeguards

  • Designation of a Security Officer.
  • Formal documented risk analysis.
  • Access management policies.
  • Workforce training.
  • Contingency plan and incident response.

Physical safeguards

  • Facility access controls where PHI is stored.
  • Workstation use policy.
  • Device and media controls.

Technical safeguards

  • Unique user authentication.
  • Encryption of ePHI in transit and at rest (addressable, but expected).
  • Audit controls recording ePHI access.
  • Integrity mechanisms.
  • Automatic logoff.

Business Associate Agreement (BAA): mandatory

Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate (BA). You must sign a BAA with each before sharing PHI. This includes any cloud provider (AWS, Google Cloud, Cloudflare, Supabase) and any service that touches PHI (email, storage, analytics). Without a BAA, any use is a HIPAA violation.

HITECH Act: 2009 reinforcement

HITECH tightens the regime: extends HIPAA directly to BAs, raises penalties, mandates breach notification, creates the HHS Wall of Shame (public list of breaches affecting more than 500 individuals), and promotes electronic health record adoption.

Breach notification

Any breach of unsecured ePHI (that was not encrypted per HHS standards) requires notification:

  • To affected individuals: within 60 days.
  • To HHS: within 60 days (or annually for fewer than 500 individuals).
  • To the media: if it affects more than 500 residents of a state or jurisdiction.

OCR penalties

The OCR applies penalties in four tiers based on culpability:

  • Tier 1 (lack of knowledge): USD 100 to USD 50,000 per violation, USD 25,000 max per year per category.
  • Tier 2 (reasonable cause): USD 1,000 to USD 50,000, USD 100,000 per year.
  • Tier 3 (willful neglect, corrected): USD 10,000 to USD 50,000, USD 250,000 per year.
  • Tier 4 (willful neglect, not corrected): USD 50,000 per violation, USD 1.5 million max per year.

Additionally, breaches affecting more than 500 individuals appear on the HHS Wall of Shame, a permanent public list that destroys patient trust.

Concrete risks for a US dental imaging clinic

The laptop with unencrypted DICOM copies stolen from a car, the email sent to the wrong address with a CBCT attached, the misconfigured web portal exposing exams via sequential URLs, the ex-employee downloading PHI before leaving. All generate reportable breaches. Anthem paid USD 16 million in 2018 for a breach; UCLA Health, USD 7.5 million; Memorial Healthcare, USD 5.5 million.

How CBCTHub helps you comply with HIPAA and HITECH

ePHI encryption in transit and at rest

TLS 1.3 on every connection and AES-256 at rest in Cloudflare R2. Meets the HHS safe-harbor encryption standard: if encrypted data is exposed, it is not a reportable breach.

Signable Business Associate Agreement

CBCTHub provides a BAA ready for electronic signature for Pro, Max, and Ultra plan customers. The template covers the entirety of 45 CFR 164.504(e) requirements.

Comprehensive audit controls

Every exam access, download, and modification is logged with timestamp, IP, and user_id. Meets Audit Controls under 164.312(b). The log exports to CSV for OCR auditors.

Unique authentication and access control

Each user has an individual authenticated account. We support SSO with Google and Apple, and MFA on higher tiers. Meets Unique User Identification under 164.312(a)(2)(i).

Automatic session timeout

Sessions expire after configurable inactivity. Meets Automatic Logoff under 164.312(a)(2)(iii).

Row Level Security (RLS) on Supabase

Strict isolation between clinics. Even CBCTHub staff cannot see PHI without explicit, logged access.

PIN and unique links

Every exam has a unique opaque URL with optional PIN. The patient or referring dentist only accesses with the specific link and, if enabled, the PIN. Meets Access Control under 164.312(a).

Automatic link expiration

Shared links expire per the policy you configure. Honors the minimum-necessary principle under 164.502(b).

Secure deletion

DELETE /api/v1/exams/{id} removes ePHI irreversibly. Meets Media Re-use under 164.310(d)(2)(ii).

Breach notification procedure

We have a documented plan that meets the 60-day client notification timeline. If a breach affects a customer, we notify them so they can escalate to HHS within the deadline.

US-based hosting

Data for US clinics is hosted in US regions. Cloudflare R2 and Supabase offer US-East and US-West regions.

HIPAA compliance checklist for your center

  • Designate Security Officer and Privacy Officer.
  • Complete documented Risk Analysis and update annually.
  • Sign BAA with CBCTHub and every BA.
  • Written policies on PHI use and disclosure.
  • HIPAA workforce training at onboarding and annually.
  • Breach response plan with 60-day clock.
  • State-specific PHI retention policy (minimum 6 years for HIPAA docs).
  • Annual ePHI access audit.
  • Full-disk encryption on every device storing ePHI.

FAQ

Can I send a CBCT via standard Gmail?

No. Standard Gmail is not HIPAA-compliant because Google does not offer a BAA for the consumer product. Google Workspace with a BAA is HIPAA-compliant only if you have the contract signed and configured. The safest option is a CBCTHub link.

How long must I retain PHI?

HIPAA requires 6 years for administrative documentation. Clinical PHI retention depends on the state: Florida requires 4 years after last contact, Texas 7, California permanent for minors.

What happens if I lose a laptop with PHI?

If the laptop was encrypted per HHS standard, it is not a reportable breach. If not, you have 60 days to notify the patient and HHS. A Massachusetts clinic paid USD 1.55M in 2016 for a stolen unencrypted laptop.

Do I need to sign anything with CBCTHub?

Yes, a BAA. Available for Pro, Max, and Ultra plans. Request it from your account dashboard.

Official resources

  • HHS HIPAA Home
  • Office for Civil Rights (OCR)
  • HHS Breach Report (Wall of Shame)
  • 45 CFR Subchapter C

Request the CBCTHub BAA | US dental imaging center solution | Plans and pricing

This article is informational and does not constitute legal advice. Consult with a HIPAA-specialized lawyer for your specific case.

Try free viewerSee solutions

Try CBCTHub for free

Upload, view, and share DICOM scans in the cloud. Nothing to install.

Create free account

Related articles

Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers

Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers

How a dental imaging center complies with Spain's LOPDGDD 3/2018, EU GDPR, and Law 41/2002 on clinical records. Obligations, penalties up to EUR 20M, and how CBCTHub helps.

Patient data protection in Mexico: LFPDPPP, INAI, and NOM-024 compliance guide for dental imaging centers

Patient data protection in Mexico: LFPDPPP, INAI, and NOM-024 compliance guide for dental imaging centers

How to comply with Mexico's LFPDPPP, its regulation, NOM-024-SSA3-2012, and NOM-004 at a dental imaging clinic. INAI, Privacy Notice, UMA-based fines. How CBCTHub helps.

Patient data protection in Chile: Law 19.628 and the new Law 21.719 for dental imaging centers

Patient data protection in Chile: Law 19.628 and the new Law 21.719 for dental imaging centers

Complete guide to Chile's current Law 19.628, the new Law 21.719 effective December 2026, and Law 20.584 on patient rights. How CBCTHub helps you comply today and tomorrow.

CBCTHubCBCTHub

Digital CBCT delivery. 100% local processing. No CDs, ever.

Download on theApp Store
Get it onGoogle Play

Solutions

Imaging centersDental radiologistsOnline CBCT viewer

Product

FeaturesPricingBlogAlternativesLearnEducationNewDevelopersAPIDemo

Support

Help centerFAQContactsoporte@cbcthub.comStatus+56 9 7632 9096

Company

AboutSecurityTerms of servicePrivacy policy

By country

United StatesUnited KingdomCanadaAustralia
HIPAA-readyGDPRLGPDLey 21.719

© 2026 CBCTHub. All rights reserved.

AppLab Software LLC · 1021 E Lincolnway, Cheyenne, WY 82001