Dental practices carry an unusual compliance load. A medical office deals primarily with HIPAA and OSHA. A dental office deals with those, plus an EPA effluent rule that applies to almost nobody else, plus a state dental board with its own inspection regime and its own rules on radiography and sedation.
The result is that dental compliance is genuinely harder to coordinate than medical compliance — not because any single requirement is complicated, but because the requirements come from four different places that do not talk to each other.
Layer 1: HIPAA — the same as everyone else
Dental practices are covered entities. The obligations are identical to any other provider: a Security Risk Assessment, written policies, workforce training, Business Associate Agreements with every vendor that touches patient information, breach notification procedures, and patient rights processes.
Two areas trip up dental practices more than most.
Radiographs are protected health information. Imaging is patient data. How it is stored, who can access it, and how it is transmitted when a patient transfers all fall under HIPAA. Practices that email images to specialists without considering the transmission method are creating exposure.
Practice management vendors are business associates. Your imaging software vendor, your cloud backup provider, your billing service, and usually your IT company all require Business Associate Agreements. The IT company is the one most frequently missed — if they can access systems containing patient data, they need an agreement, whether or not they ever open a record.
Layer 2: OSHA — heavier than a typical medical office
The Bloodborne Pathogens standard applies in full. Dental practices need a written Exposure Control Plan, reviewed and updated annually, with training for anyone with reasonably anticipated exposure.
Beyond that, dental settings commonly involve hazard communication for chemicals, sharps injury logging, and personal protective equipment programs. Practices using nitrous oxide have scavenging systems to maintain. Practices with X-ray equipment fall under state radiation control requirements on top of everything else.
Layer 3: The EPA amalgam rule — dental-specific
This one applies to dental offices and essentially no other healthcare setting, which is exactly why it gets missed.
Under 40 CFR Part 441, dental practices that place or remove amalgam must operate an amalgam separator meeting a minimum 95 percent removal efficiency. Separators installed after June 14, 2017 must comply with ANSI/ADA Specification 108 (2009) with its 2011 Technical Addendum, or ISO 11143 (2008), or a later version meeting the same 95 percent threshold.
The rule also requires a One-Time Compliance Report submitted to your Control Authority — generally your local wastewater utility, a state agency, or an EPA regional office. For practices already operating when the rule took effect, that report was due by October 12, 2020. New practices submit on becoming subject to the rule.
Two practices are prohibited outright: discharging scrap amalgam to the sewer, and using line cleaners that dissolve amalgam.
Records must be kept for a minimum of three years and made available for inspection.
There is an exemption. Dental dischargers that do not place amalgam, and do not remove it except in limited emergency or unplanned circumstances, can certify that to their Control Authority and fall outside the ongoing requirements. Many orthodontic and oral surgery practices qualify — but the exemption is not automatic. It requires the certification.
Layer 4: Your state dental board — the layer that varies
This is where dental compliance stops being uniform, and where most practices get caught out.
State dental boards independently set requirements for radiography certification of dental assistants, sedation and anesthesia permit tiers, infection control continuing education, sterilization monitoring frequency, and dental unit waterline testing. These vary substantially between states.
Two examples of how that plays out.
Sterilization monitoring. The CDC recommends spore testing sterilizers at least weekly using a biological indicator with a matching control from the same lot. Some states write that weekly frequency into board rule; others leave it as a professional standard. The practical answer is the same — test weekly, keep the logs — but whether it is a legal requirement depends on where you practice.
Dental unit waterlines. Dental unit water should meet the EPA drinking water standard of fewer than 500 CFU/mL of heterotrophic bacteria. Testing frequency generally follows the manufacturer's instructions for use, with quarterly testing common in practice. Again, some states mandate a frequency; others do not.
The lesson: do not assume a national standard covers you. Check your board's current rules directly, and check again after any rule revision.
What an inspector actually asks for
Across all four layers, an inspection comes down to documentation. Practically, that means being able to produce:
- A current Security Risk Assessment with a corrective action plan
- Written HIPAA policies with staff acknowledgment records
- Training completion records for every current employee
- The written Exposure Control Plan, reviewed within the last year
- The sharps injury log
- Sterilizer spore test logs, with results
- Waterline test results
- Amalgam separator inspection and maintenance records, plus proof of the One-Time Compliance Report
- Current radiography certifications for assistants who take images
- Sedation permits, if applicable
- Executed BAAs for every vendor with access to patient data
The part that cannot be fixed later
Notice how much of that list is a log rather than a document. Dental compliance is unusually recurring — weekly spore tests, periodic waterline tests, ongoing separator maintenance. A binder assembled once and shelved will not survive an inspection, because the inspector is checking whether the practice has been doing the thing continuously.
If you are behind, start in this order: the Security Risk Assessment, because it is the most frequently requested and most commonly missing. Then Business Associate Agreements, because gaps there are the easiest to find and hardest to explain. Then the recurring logs.
Everything else can be built after the fact. The logs are the part where starting late genuinely costs you — a spore test you did not run in March cannot be run retroactively.
Part of our guide to
HIPAA ComplianceSee how GuardWell helps medical practices manage hipaa compliance end to end — checklists, policies, training, and audit-ready documentation in one platform.
Ready to simplify compliance?
GuardWell brings HIPAA, OSHA, OIG, and 12 more compliance modules into one affordable platform built for medical practices. Start your 7-day free trial today.
Start free trialRelated Articles
OSHA Requirements for Medical Offices: A Complete Guide
Everything medical offices need to know about OSHA compliance — bloodborne pathogens, hazard communication, emergency action plans, PPE, and recordkeeping requirements explained.
HIPAAHIPAA Compliance Checklist for Small Medical Practices in 2026
A practical HIPAA compliance checklist for small medical practices covering the Privacy Rule, Security Rule, breach notification, risk assessments, and staff training requirements.
OSHABloodborne Pathogens Exposure Control Plan: What Every Practice Needs
Learn how to create and maintain a compliant Bloodborne Pathogens Exposure Control Plan for your medical practice, covering OSHA requirements, engineering controls, and post-exposure procedures.
HIPAASecurity Risk Assessment: A Step-by-Step Guide for Medical Practices
Learn how to conduct a thorough HIPAA Security Risk Assessment for your medical practice with this detailed step-by-step walkthrough covering scope, threats, vulnerabilities, and remediation.
