NBDHE Review · Professional Responsibility (Provision of Clinical Dental Hygiene Services)
HIPAA: Privacy, Security, and Patient Rights
On this page 7 sections
In 30 seconds
HIPAA (Health Insurance Portability and Accountability Act) compliance is tested on the NBDHE under professional responsibility and legal/ethical domains. The exam tests your understanding of protected health information (PHI), the Privacy Rule, the Security Rule, the minimum necessary standard, patient rights under HIPAA, and breach notification requirements. You must also recognize HIPAA violations in clinical scenarios. Expect 2-4 questions.
The college version
Core Review
What Is HIPAA?
The Health Insurance Portability and Accountability Act of 1996 is a federal law with several components relevant to dental practice:
- Privacy Rule: Establishes national standards for the protection of PHI. Governs ALL forms of PHI (paper, electronic, oral).
- Security Rule: Establishes national standards for protecting electronic PHI (ePHI). Only applies to electronic information.
- Breach Notification Rule: Requires covered entities to notify affected individuals, HHS, and (in some cases) the media of breaches of unsecured PHI.
- Enforcement Rule: Establishes penalties for HIPAA violations.
Who Must Comply?
- Covered Entities: Healthcare providers (including dental practices), health plans, and healthcare clearinghouses that transmit health information electronically
- Business Associates: Organizations or individuals that perform services for a covered entity involving PHI (e.g., billing companies, IT support, shredding services, answering services). Business associates must sign a Business Associate Agreement (BAA).
Protected Health Information (PHI)
PHI is ANY health information that can identify an individual patient. HIPAA identifies 18 specific identifiers:
- Name
- Geographic subdivisions smaller than a state (address, ZIP code)
- Dates directly related to an individual (birth date, admission date, treatment date — year alone is generally permitted)
- Telephone numbers
- Fax numbers
- Email addresses
- Social security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers (including license plates)
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voice prints)
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
De-identification: If ALL 18 identifiers are removed and the covered entity has no reasonable basis to believe the information can be used to identify the patient, the information is no longer PHI and is not subject to HIPAA restrictions.
The Privacy Rule
The Privacy Rule establishes the conditions under which PHI may be used (internally) and disclosed (to external parties).
Permitted Uses and Disclosures WITHOUT Patient Authorization:
- Treatment: Sharing PHI among healthcare providers for the purpose of treating the patient
- Example: A dental hygienist sending a periodontal chart to a periodontist for a referral — this is a treatment disclosure and does not require patient authorization.
- Payment: Using or disclosing PHI to obtain payment for services
- Example: Submitting a claim to the patient's insurance company including procedure codes and diagnostic information.
- Healthcare Operations: Administrative, quality improvement, training, and business functions
- Example: Reviewing patient charts for a quality assurance audit.
Other Permitted Disclosures Without Authorization (specific circumstances):
- Required by law (court order, subpoena)
- Public health activities (disease reporting to health departments)
- Reporting abuse, neglect, or domestic violence
- Health oversight activities (state board investigations)
- Judicial and administrative proceedings
- Law enforcement purposes
- Organ and tissue donation
- Research (with Institutional Review Board waiver)
- Workers' compensation
Disclosures REQUIRING Patient Authorization:
- Marketing purposes
- Sale of PHI
- Psychotherapy notes (special protections)
- Most research uses
- Disclosing PHI to an employer (for purposes other than workers' compensation)
The Minimum Necessary Standard: When using or disclosing PHI (except for treatment purposes), the covered entity must make reasonable efforts to limit PHI to the MINIMUM NECESSARY to accomplish the intended purpose.
- Example: If an insurance company requests records to verify a specific procedure, do NOT send the entire patient record — send only the information relevant to that procedure.
- The minimum necessary standard does NOT apply to treatment purposes (clinicians need full access to make treatment decisions) or to disclosures to the patient themselves.
Notice of Privacy Practices (NPP):
- Every patient must receive a Notice of Privacy Practices that explains how their PHI will be used and their rights
- The patient must sign an acknowledgment of receipt (or the practice must document a good-faith attempt to obtain acknowledgment)
- The NPP must be posted in the practice and available on the practice website
The Security Rule
The Security Rule applies specifically to electronic PHI (ePHI). It requires covered entities and business associates to implement administrative, physical, and technical safeguards.
Administrative Safeguards:
- Security management process (risk analysis and risk management)
- Designation of a security officer
- Workforce training on security policies
- Policies for authorizing access to ePHI
- Contingency planning (data backup, disaster recovery, emergency mode operations)
Physical Safeguards:
- Facility access controls (limited physical access to areas where ePHI is stored)
- Workstation security (positioning screens so unauthorized persons cannot view them)
- Device and media controls (secure disposal of electronic media containing ePHI)
Technical Safeguards:
- Access controls (unique user IDs, automatic logoff)
- Audit controls (recording and examining access to ePHI)
- Integrity controls (ensuring ePHI is not improperly altered or destroyed)
- Transmission security (encryption of ePHI when transmitted electronically)
Patient Rights Under HIPAA
Patients have specific rights regarding their PHI:
- Right to Access: Patients may inspect and obtain a copy of their PHI. The covered entity must provide access within 30 days. Reasonable cost-based fees may be charged for copies.
- Right to Amend: Patients may request amendments (corrections) to their PHI if they believe it is inaccurate or incomplete. The covered entity may deny the request but must provide a written explanation.
- Right to an Accounting of Disclosures: Patients may request a list of certain disclosures of their PHI made by the covered entity (excluding disclosures for treatment, payment, and healthcare operations).
- Right to Request Restrictions: Patients may request restrictions on how their PHI is used or disclosed. The covered entity is NOT required to agree, EXCEPT: if the patient pays out of pocket in full for a service and requests that the information not be disclosed to their health plan, the covered entity MUST comply.
- Right to Request Confidential Communications: Patients may request to receive communications in an alternative manner or at an alternative location (e.g., "send my bills to my work address, not my home").
- Right to Receive a Notice of Privacy Practices: As described above.
Breach Notification Rule
A breach is the unauthorized acquisition, access, use, or disclosure of unsecured PHI.
Breach Notification Requirements:
- Affected individuals: Must be notified without unreasonable delay, and no later than 60 days after discovery of the breach.
- HHS: For breaches affecting 500+ individuals, notification must be provided to the Secretary of HHS at the same time as individual notification. For breaches affecting <500 individuals, notification is made via an annual report.
- Media: For breaches affecting 500+ individuals in a state or jurisdiction, prominent media outlets must be notified.
Breach Risk Assessment: Not every unauthorized disclosure is a reportable breach. The covered entity must conduct a risk assessment considering:
- The nature and extent of the PHI involved
- The unauthorized person who received the PHI
- Whether the PHI was actually acquired or viewed
- The extent to which the risk has been mitigated
If the risk assessment determines a low probability that PHI has been compromised, notification may not be required.
Examples of breaches:
- A laptop containing unencrypted patient records is stolen
- A dental practice employee emails a spreadsheet of patient names, dates of birth, and treatment information to their personal email
- Patient records are left in an unsecured area and accessed by unauthorized individuals
- Discussing patient PHI in a public area where it is overheard by others (this is a privacy violation and potentially a breach)
HIPAA Violations in Dental Practice: Common Scenarios
Scenario 1: Social Media A dental hygienist posts a "before and after" photo of a patient's cosmetic procedure on the practice Instagram. The patient's face is visible.
- Violation: Yes. Full-face photos are PHI identifiers. Posting them without written HIPAA authorization is a violation.
Scenario 2: Front Desk The receptionist calls a patient's home number and leaves a voicemail: "This is Dr. Smith's office calling to confirm your root canal appointment tomorrow at 10 AM."
- Potential violation: The content of the message could be overheard by anyone with access to the voicemail. Best practice: "This is Dr. Smith's office calling for [Patient Name]. Please call us back at [number]." — identifying only the practice, not the nature of the appointment.
Scenario 3: Staff Discussion Two staff members are discussing a patient's treatment in the break room. They use the patient's name. Other staff members not involved in the patient's care are present.
- Violation: Yes. Discussing PHI where unauthorized individuals can overhear violates the Privacy Rule and the minimum necessary standard.
Scenario 4: Chart Left Open A clinician leaves a patient's electronic chart open on a computer screen in an operatory while stepping out. The hallway is visible to other patients.
- Violation: Yes. Failing to log off or secure the workstation exposes ePHI to unauthorized viewing.
Scenario 5: Referral A dental hygienist calls a periodontist's office to schedule a referral and provides: patient name, date of birth, and periodontal chart findings.
- NOT a violation: This is a disclosure for TREATMENT purposes, which does not require patient authorization. However, the minimum necessary standard still applies — provide only the information the periodontist needs.
HIPAA Enforcement and Penalties
HIPAA is enforced by the Office for Civil Rights (OCR) within HHS. Penalty tiers:
| Tier | Culpability | Penalty per Violation | Annual Maximum |
|---|---|---|---|
| Tier 1 | Did not know (and could not have known) | $100-$50,000 | $1.5 million |
| Tier 2 | Reasonable cause (not willful neglect) | $1,000-$50,000 | $1.5 million |
| Tier 3 | Willful neglect, corrected within 30 days | $10,000-$50,000 | $1.5 million |
| Tier 4 | Willful neglect, not corrected | $50,000+ | $1.5 million |
Criminal penalties (Department of Justice):
- Knowingly obtaining/disclosing PHI: up to 1 year imprisonment + fine
- Obtaining PHI under false pretenses: up to 5 years + fine
- Obtaining PHI with intent to sell or for malicious harm: up to 10 years + fine
HIPAA and State Laws
HIPAA is a FEDERAL floor — it sets minimum standards. State laws that provide GREATER protection to patient privacy preempt (override) HIPAA. For example, many states have additional privacy protections for mental health records, HIV status, or substance abuse treatment records. Dental professionals must comply with BOTH HIPAA and applicable state privacy laws.
Clinical Application
A patient requests a copy of their complete dental record, including radiographs and periodontal charting. The receptionist says, "We can't give you the original, but we can provide copies for a copying fee."
HIPAA analysis: The patient is exercising their right to access. The practice must provide access within 30 days. A reasonable cost-based fee for copies is permitted. Radiographs must also be provided (patients have a right to all PHI, including images). The practice cannot withhold records for unpaid bills (this may violate HIPAA and state law).
Common Traps
- TRAP: Thinking that de-identified patient information (e.g., "a 45-year-old female with periodontitis") is always HIPAA-compliant to share. Must remove ALL 18 identifiers to be truly de-identified.
- TRAP: Requiring patient authorization for every disclosure. TPO disclosures do not require authorization. Referral to a specialist is a treatment disclosure.
- TRAP: Thinking the minimum necessary standard applies to treatment. It does not. Clinicians need unrestricted access to PHI to provide care.
- TRAP: Posting clinical photos on social media with "patient permission" but without written HIPAA authorization. Verbal permission is insufficient for marketing/social media use.

Eli explains
The same idea, in plain words
Explain it like I’m 10
HIPAA is a federal privacy law that keeps your health information private. Anything that could identify you — your name, birthday, address, photos of your face, even your ZIP code — combined with health information is "protected health information" (PHI). Your dental office can use your information to treat you, bill your insurance, and run their business without asking each time. They can share it with a specialist they refer you to without a signed form. But they cannot post your "after" photos on Instagram, gossip about you in the hallway, or leave your chart open on a computer screen where other patients can see it. You have the right to see your records, ask for corrections, and find out who has looked at your information. If there is a data breach, the office has to tell you within 60 days. HIPAA is why the receptionist does not leave a message saying, "Your root canal is at 10 AM" — they just say, "Please call us back."
Key takeaways
- PHI = health information + identifier; 18 HIPAA identifiers
- Privacy Rule: governs ALL forms of PHI (paper, electronic, oral)
- Security Rule: governs ePHI only (administrative, physical, technical safeguards)
- Treatment, Payment, and Operations (TPO): disclosures permitted WITHOUT authorization
- Minimum necessary standard: limit PHI to what is needed (does not apply to treatment)
- Patient rights: access, amendment, accounting, restrictions, confidential communications, NPP
- Breach notification: within 60 days to affected individuals
- Social media posts with patient info/photo = HIPAA violation without written authorization
- Referrals = treatment disclosure = no authorization needed (but minimum necessary applies)
- State laws can provide MORE protection than HIPAA
- Question 1: A dental hygienist refers a patient to a periodontist and sends the patient's periodontal chart and radiographs to the periodontist's office. Under HIPAA, this disclosure:
- ---
- Question 2: Which of the following is NOT an 18 HIPAA identifier?
- ---
- Question 3: A dental practice discovers that an unencrypted laptop containing patient records (500+ patients) was stolen from an employee's car. Under HIPAA, the practice must:
Check yourself
3 review questions from the chapter. Try each one, then open the answer.
A. Requires the patient's written authorization B. Is permitted as a treatment disclosure without authorization C. Violates the minimum necessary standard D. Is only permitted if the periodontist is in the same practice
Show answer
B. Disclosures for treatment purposes (including referrals to other providers) are permitted under HIPAA without patient authorization. The minimum necessary standard applies but sending charting and relevant radiographs is likely appropriate.
A. Patient's name B. Social security number C. Diagnosis code D. Full-face photograph
Show answer
C. Diagnosis codes (ICD codes) are health information, not identifiers. They would need to be combined with an identifier to become PHI. The 18 identifiers include names, SSNs, and full-face photos.
A. Do nothing since the theft was not the practice's fault B. Notify the affected individuals within 60 days and notify HHS and the media C. Only notify HHS D. Replace the laptop but not notify patients
Show answer
B. For a breach affecting 500+ individuals, the covered entity must notify affected individuals within 60 days, notify HHS simultaneously, and notify prominent media outlets. The fact that the theft was not the practice's "fault" does not eliminate the notification obligation.
Quick check
3 questions here. Answers stay hidden until you check.
Which of the following is NOT an 18 HIPAA identifier?
A dental practice discovers that an unencrypted laptop containing patient records (500+ patients) was stolen from an employee's car. Under HIPAA, the practice must:
Study tools & related lessonsYou’ll learn to · Related
You’ll learn to
- Define protected health information (PHI) and identify 18 HIPAA identifiers
- Explain the HIPAA Privacy Rule and its requirements for use and disclosure of PHI
- Apply the minimum necessary standard to clinical situations
- List patient rights under HIPAA
- Distinguish between the Privacy Rule and the Security Rule
- Recognize HIPAA violations and describe breach notification requirements
- Apply HIPAA principles to dental hygiene practice scenarios
Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.

