FAQ

How do dental labs handle HIPAA?

A straight answer first, then the context behind it, from the technicians who do the work.

THE SHORT ANSWER

Dental labs are HIPAA business associates, which means they must sign a Business Associate Agreement (BAA) with every referring practice before handling case files containing patient identifiers. Compliant labs limit PHI to the minimum necessary, use encrypted file transfer for digital case submissions, restrict internal access by role, and maintain documented breach-response procedures. A lab without a signed BAA exposes your practice to OCR audit risk.

THE CONTEXT

What sits behind it

When a dentist sends a prescription to a lab, that case file often includes the patient's name, date of birth, and treating provider details. Under HIPAA's Privacy and Security Rules, a dental lab receives protected health information as a business associate, not a covered entity. That distinction matters: the lab cannot use PHI beyond fulfilling the case, must apply the same administrative, physical, and technical safeguards your practice does, and must report breaches to you within 60 days of discovery.

For practices submitting digital files, including intraoral scans, CBCT exports, and STL files, encrypted transfer is the baseline requirement. Emailing an unencrypted .STL with a patient name attached is a HIPAA violation regardless of how routine it feels. Compliant labs provide a secure portal, an encrypted FTP path, or a vetted cloud workflow such as 3Shape Communicate or Dental Wings' DWOS Connect. Ask your current lab which specific platform they use and whether the BAA covers that channel explicitly.

From a DSO or multi-practice standpoint, the BAA must cover every office routing cases to the lab, not just the flagship location. A single master BAA with an addendum listing all Tax ID numbers under the group is the cleanest approach. At Dani Dental, the BAA is countersigned before the first case ships and updated whenever a practice adds a location. If your current lab has never sent you a BAA, that gap needs to close before your next OCR compliance review.

RELATED QUESTIONS

People also ask

How do dental labs handle HIPAA?
Dental labs are HIPAA business associates, which means they must sign a Business Associate Agreement (BAA) with every referring practice before handling case files containing patient identifiers. Compliant labs limit PHI to the minimum necessary, use encrypted file transfer for digital case submissions, restrict internal access by role, and maintain documented breach-response procedures. A lab without a signed BAA exposes your practice to OCR audit risk.

GO DEEPER

Read the full guide on all procedures

This question is one piece of a larger workflow. The pillar page covers materials, turnaround, and how we build the case to your specification.

REQUEST A DOCTOR KIT

Try the work before you switch.

Request a Doctor Kit and we'll mail RX pads, a shade guide, and pre-paid shipping for your first three cases. No call, no contract.