Compliance

HIPAA Policy

Last updated: July 27, 2026

Summary: DentShieldAI is designed from the ground up to operate within HIPAA requirements. As a Business Associate to dental practices, we require a signed Business Associate Agreement (BAA) before any practice data is connected. We do not sell, share, or use Protected Health Information for any purpose other than providing the Service.

1. Our Role Under HIPAA

Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the HITECH Act, DentShieldAI LLC operates as a Business Associate to dental practices (Covered Entities). As a Business Associate, we are directly obligated to comply with the HIPAA Security Rule and the applicable provisions of the HIPAA Privacy Rule when handling Protected Health Information (PHI) on behalf of our customers.

PHI in the context of DentShieldAI may include patient names, dates of service, or treatment codes that appear in financial transaction records analyzed by our platform.

2. Business Associate Agreement (BAA)

A signed BAA between DentShieldAI and your practice is required before connecting or uploading any practice data. The BAA defines each party's responsibilities regarding PHI, including how it is used, safeguarded, and disclosed.

To request a BAA or ask questions about the agreement, contact us at hello@dentshieldai.com. We will send you the agreement within one business day. You must not connect your practice management software or upload transaction data until the BAA is fully executed.

3. What Data We Access

DentShieldAI accesses financial and ledger transaction data from your practice management software for the sole purpose of detecting anomalous patterns. This may include:

DentShieldAI does not access clinical records, treatment notes, x-rays, or patient health histories. Our analysis is limited to financial transaction data.

4. Technical Safeguards

DentShieldAI implements the following technical safeguards in compliance with the HIPAA Security Rule:

Encryption in Transit

All data transmitted between your practice and our platform is encrypted using TLS 1.2 or higher — the same standard used by financial institutions.

SHA-256 Hashing

Every extracted record is SHA-256 hashed at the point of collection. The cloud engine re-verifies each hash on receipt, making tampering mathematically detectable.

Access Controls

Access to customer data is restricted to authorized personnel only. Role-based access controls limit what each team member can view or modify.

Zero-Trust Architecture

Our infrastructure operates on a zero-trust model — every request is authenticated and authorized regardless of its source, eliminating implicit trust.

Audit Logging

All access to practice data is logged with timestamps and user identifiers, creating a court-ready forensic audit trail.

Minimal Data Retention

CSV-uploaded transaction data is processed in memory and not retained after analysis is complete. Only analysis results and flagged patterns are stored.

5. Administrative Safeguards

In addition to our technical controls, DentShieldAI maintains the following administrative safeguards:

6. Breach Notification

In the event of a security breach involving unsecured PHI, DentShieldAI will:

To report a suspected security incident, contact us immediately at hello@dentshieldai.com.

7. Subcontractors and Subprocessors

DentShieldAI uses the following subprocessors that may have access to data in the course of providing the Service:

Each subprocessor is evaluated for HIPAA compliance and, where required, enters into appropriate data processing agreements. We do not use subprocessors that sell or share your data for their own purposes.

8. Patient Rights

DentShieldAI does not maintain a direct relationship with patients. All patient rights under HIPAA (access, amendment, accounting of disclosures, etc.) are managed by the dental practice as the Covered Entity. If you are a patient with questions about how your data is used, please contact your dental practice directly.

9. Contact Our Privacy & Security Team

For HIPAA-related questions, BAA requests, or to report a security concern:

DentShieldAI LLC — Privacy & Security

Email: hello@dentshieldai.com

Website: www.dentshieldai.com

We aim to respond to all compliance inquiries within one business day.

Legal Disclaimer: DentShieldAI identifies statistical risk indicators and discrepancy patterns that may warrant further investigation. Outputs are not legal conclusions and do not constitute proof of criminal activity. Always consult a qualified forensic accountant or attorney before taking any legal or disciplinary action.