Dental laboratories have long operated at the intersection of clinical care and skilled manufacturing. What has been less clear for labs, for the practices they serve, and for regulators is where patient privacy obligations begin and end in that relationship.
How Dental Labs Think About Their Work
A dental laboratory's identity is built around craft and precision. You receive a prescription, you fabricate a restoration, you deliver a finished product. The clinical relationship belongs to the dentist. The patient belongs to the practice. Your role is technical, not medical, and most labs have operated comfortably within that framing for decades.
That framing is not wrong. But it is incomplete. And the gap between how dental laboratories understand their work and how HIPAA defines it has created a compliance gray area that affects every lab in the country regardless of size, specialty, or how long you have been in business.
This series is not about blame or burden. It is about understanding a relationship that has grown more complex as patient data has become more digital, more portable, and more valuable and giving every participant in that relationship the information they need to navigate it responsibly.
What Travels with the Prescription
Think about what arrives with a typical case. A dental prescription carries the patient's name. Sometimes a date of birth. Tooth numbers and clinical notes describing the existing condition of the mouth. Shade selections tied to the patient's specific dentition. In digital workflows, a scan file that may contain a three-dimensional rendering of the patient's oral anatomy imagery that is, by its nature, identifiable.
Under HIPAA, protected health information is defined broadly: any individually identifiable health information held or transmitted by a covered entity or its business associate. A patient name paired with a dental prescription and clinical notes meets that definition. A digital scan file associated with a patient record meets that definition. The restoration itself - a physical object - does not. But the information that traveled with it almost certainly does.
This is not a technicality. It is the threshold question that determines how HIPAA applies to the practice-lab relationship, and it is one that many labs have not had reason to ask before now.
|
ADA / OCR 2017 In March 2017, the American Dental Association formally asked HHS Office for Civil Rights to clarify the HIPAA status of dental laboratories. OCR responded that a dental lab is generally considered a health care provider and that no Business Associate Agreement is required for treatment-purpose disclosures from a practice to its lab. That guidance reflects the most permissive reading of the relationship and remains the most widely cited position in the dental industry. |
The Question OCR's Guidance Left Open
OCR's 2017 response gave practices and labs a defensible baseline. But it rested on an assumption that not every lab meets: that the laboratory qualifies as a covered health care provider under HIPAA's statutory definition.
Under 45 CFR § 160.103, a health care provider qualifies as a covered entity only if it transmits health information in electronic form in connection with a HIPAA-covered transaction - electronic claims, eligibility inquiries, remittance advice, and similar billing-related exchanges. Dental laboratories do not bill insurance. They do not submit electronic claims.
|
FISHER PHILLIPS 2019 The law firm Fisher Phillips examined this question in April 2019 and reached a more cautious conclusion. Their analysis noted that a dental laboratory without HIPAA-covered electronic transaction activity may not meet the statutory definition of covered health care provider — which would mean the treatment exception does not apply, and the lab is functioning as a business associate of the practices it serves. Their recommendation: do not assume covered entity status. Document the determination, and when the answer is uncertain, execute a Business Associate Agreement. |
The Fisher Phillips analysis is not a contradiction of OCR's position. It is a refinement of it. OCR addressed labs that qualify as healthcare providers. Fisher Phillips addressed labs that may not be a covered entity. Both sources agree on one thing: the answer matters, and it should be documented.
Covered Entity or Business Associate - What It Means in Practice
If a dental laboratory is a covered entity, it has independent HIPAA obligations - its own Privacy Rule requirements, its own Security Rule requirements, and its own breach notification obligations. The practice can share PHI with it for treatment purposes without a BAA, under the treatment exception.
If a dental laboratory is a business associate, those independent obligations exist only to the extent they are established in a Business Associate Agreement with each practice partner. Without that agreement, there is no defined security baseline, no breach notification obligation, and no contractual framework governing what happens to the patient data the lab receives.
Most dental laboratories seem today to operate in the second category - as business associates - whether or not they have formalized that status. They receive PHI from dental practices, they process it as part of fabricating restorations, and they return the finished case. That workflow makes them a business associate under HIPAA's definition. The BAA is the document that makes that relationship explicit, allocates responsibility appropriately, and protects both the lab and the practice if something goes wrong.
|
A Business Associate Agreement is not an accusation. It is not a finding that a lab has done something wrong. It is a mutual agreement between two partners that defines how patient information will be handled, what security standards apply, and what each side is responsible for in the event of a security incident. It is, in that sense, the document that makes the partnership official. |
The dental laboratory industry is not uniquely exposed. But it is navigating a regulatory environment that has grown more sophisticated around data protection, and the standards for how business associates handle PHI are rising. The 2024 HIPAA Security Rule proposed update - the first significant proposed revision since 2003 - would require mandatory encryption of all ePHI in transit and at rest, multi-factor authentication on all systems accessing patient data, and written incident response planning. These are not distant requirements. They reflect where the regulatory environment is heading.
For dental labs, the practical starting point is straightforward: Understand what data you receive, recognize that it likely constitutes PHI, determine your status under HIPAA with the help of a compliance professional. if you decide you want to act as a covered entity, then develop and implement all of the appropriate HIPAA mandated controls. If the determination is you are operating as a business associate, formalize that status through properly executed BAAs with your practice partners.
That is not a compliance burden. It is a professional posture one that strengthens the lab's relationship with every practice it serves and positions it as a trusted partner in patient care rather than an unexamined link in the chain.
|
Covered Entity⇒ Develop and implement all of the appropriate HIPAA mandated controls. |
|
Business Associate⇒ Formalize status through properly executed BAAs with your practice partners. |
Don't guess where your lab stands under HIPAA - find out. SafeLink's Dental Lab HIPAA Compliance Review gives you a clear picture of your Covered Entity or Business Associate status, along with a gap analysis, privacy and security risk review, and documentation review — most reviews are completed remotely within 1–2 days. Schedule Your HIPAA Review.
Need support with HIPAA compliance for your dental lab or practice? Discover how SafeLink Consulting’s experts can partner with your team to strengthen privacy practices and security rules.

