AI and HIPAA in dentistry: What your team doesn't know can hurt you

The scenario is simple and increasingly common: A dental assistant is running behind on notes at the end of a long day. She copies a patient's name, chief complaint, and a few health details into ChatGPT, asks it to clean up the language, and gets back a perfectly formatted clinical note in seconds. It looks like a win. 

However, Olivia Wann, a dental compliance consultant and attorney in her 26th year advising the dental industry, says it may be a reportable HIPAA breach.

In this episode of The DrBicuspid.com Podcast, Editor-in-Chief Kevin Henry sits down with Wann to walk through the AI compliance problem that is building quietly inside dental practices right now -- not through bad intentions but through a lack of policy and training. The core issue is that most dental teams have not been told which AI platforms are approved and which are off-limits. Without that guidance, they default to whatever is free, fast, and familiar.

Olivia Wann.Olivia Wann.

Wann's first recommendation is to treat AI the same way practices treat any HIPAA-covered vendor: with a written policy, a list of approved and prohibited platforms, and a business associate agreement (BAA) with any AI company that touches patient data.

That last point catches many practices off guard. Even well-regarded dental-specific AI tools may require a BAA, and when a practice ends that relationship, the BAA should specify that patient data is returned or destroyed, not retained to train the platform.

The staff training piece is equally urgent. Wann is currently updating HIPAA training programs to weave in AI guidance for her clients. These program elements include signed acknowledgment forms for employees who miss a group training session or who come on board as new hires or temporary staff afterward. A temp hygienist filling in for a week, she notes, needs the same AI policy orientation as a full-time employee.

On the audit side, Wann draws on her experience working dental data breaches as a lawyer. Auditors do not accept a checked checkbox. They want training rosters, vendor invoices, and documented proof of recognized security practices. They will ask a practice what it was doing in the 30 days before a breach occurred. That level of accountability is what practices need to prepare for -- not after a breach -- but now.

Wann and her team at Modern Practice Solutions can be reached at modernpracticesolutions.com, oliviawann.com, or by calling 931-232-7738.

Listen to the full conversation below.