Last updated: July 27, 2026
Summary: DentShieldAI is designed from the ground up to operate within HIPAA requirements. As a Business Associate to dental practices, we require a signed Business Associate Agreement (BAA) before any practice data is connected. We do not sell, share, or use Protected Health Information for any purpose other than providing the Service.
Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the HITECH Act, DentShieldAI LLC operates as a Business Associate to dental practices (Covered Entities). As a Business Associate, we are directly obligated to comply with the HIPAA Security Rule and the applicable provisions of the HIPAA Privacy Rule when handling Protected Health Information (PHI) on behalf of our customers.
PHI in the context of DentShieldAI may include patient names, dates of service, or treatment codes that appear in financial transaction records analyzed by our platform.
A signed BAA between DentShieldAI and your practice is required before connecting or uploading any practice data. The BAA defines each party's responsibilities regarding PHI, including how it is used, safeguarded, and disclosed.
To request a BAA or ask questions about the agreement, contact us at hello@dentshieldai.com. We will send you the agreement within one business day. You must not connect your practice management software or upload transaction data until the BAA is fully executed.
DentShieldAI accesses financial and ledger transaction data from your practice management software for the sole purpose of detecting anomalous patterns. This may include:
DentShieldAI does not access clinical records, treatment notes, x-rays, or patient health histories. Our analysis is limited to financial transaction data.
DentShieldAI implements the following technical safeguards in compliance with the HIPAA Security Rule:
All data transmitted between your practice and our platform is encrypted using TLS 1.2 or higher — the same standard used by financial institutions.
Every extracted record is SHA-256 hashed at the point of collection. The cloud engine re-verifies each hash on receipt, making tampering mathematically detectable.
Access to customer data is restricted to authorized personnel only. Role-based access controls limit what each team member can view or modify.
Our infrastructure operates on a zero-trust model — every request is authenticated and authorized regardless of its source, eliminating implicit trust.
All access to practice data is logged with timestamps and user identifiers, creating a court-ready forensic audit trail.
CSV-uploaded transaction data is processed in memory and not retained after analysis is complete. Only analysis results and flagged patterns are stored.
In addition to our technical controls, DentShieldAI maintains the following administrative safeguards:
In the event of a security breach involving unsecured PHI, DentShieldAI will:
To report a suspected security incident, contact us immediately at hello@dentshieldai.com.
DentShieldAI uses the following subprocessors that may have access to data in the course of providing the Service:
Each subprocessor is evaluated for HIPAA compliance and, where required, enters into appropriate data processing agreements. We do not use subprocessors that sell or share your data for their own purposes.
DentShieldAI does not maintain a direct relationship with patients. All patient rights under HIPAA (access, amendment, accounting of disclosures, etc.) are managed by the dental practice as the Covered Entity. If you are a patient with questions about how your data is used, please contact your dental practice directly.
For HIPAA-related questions, BAA requests, or to report a security concern:
DentShieldAI LLC — Privacy & Security
Email: hello@dentshieldai.com
Website: www.dentshieldai.com
We aim to respond to all compliance inquiries within one business day.
Legal Disclaimer: DentShieldAI identifies statistical risk indicators and discrepancy patterns that may warrant further investigation. Outputs are not legal conclusions and do not constitute proof of criminal activity. Always consult a qualified forensic accountant or attorney before taking any legal or disciplinary action.