Interactive educational resource

Dental HIPAA & AI Safety Quiz

Can your team spot unsafe AI use before patient information gets exposed?

Use this educational quiz to see whether your dental team can spot risky AI habits before patient information, payer details, EOBs, screenshots, or practice workflows move into the wrong tool. Each answer explains the safer choice, the compliance risk if missed, why the authority guidance applies, and the next team-training action.

Rotating quiz format: All-team mode covers all 8 safety categories and adds 2 rotating workflow deep dives from the scenario bank. Role modes rotate through the scenarios most relevant to that team. The full bank currently includes 24 dental AI safety scenarios.

Last reviewed: June 20, 2026. Educational self-check for dental teams. Do not enter patient names, charts, screenshots, EOBs, portal messages, voicemail transcripts, or other PHI. Scenarios distinguish personal, public, or otherwise unapproved AI tools from practice-owned workflows like Smarter Practice AI.

Use it as a team training check. The goal is to spot where staff need clearer AI rules.

Role-based quiz modes

All team

Use this mode for a full-team huddle or onboarding review.

Front desk

Best for team members who handle calls, texts, scheduling, patient messages, and portal requests.

Billing

Best for billing coordinators, insurance follow-up, treatment coordinators, and anyone handling payer or balance details.

Clinical

Best for assistants, hygienists, providers, and anyone drafting or reviewing clinical patient communication.

Manager

Best for owners, office managers, privacy leads, and team members responsible for policy and training.

Authority guide used by this quiz

ADA dentistry AI context

Dental-specific AI standards and professional context for owners evaluating AI in clinical, payer, and operational workflows.

Authority links: ADA artificial intelligence in dentistry

Practice workflow bridge

Turn quiz findings into a practice-owned AI workflow

The quiz identifies the risk. Smarter Practice AI can help the team organize prompts, SOP language, owner rules, fictional examples, and training notes that stay inside the practice workflow.

Document the approved-use rule

Define which AI tools the team can use, what data is prohibited, and who owns the workflow before staff use AI for patient, payer, or practice workflows.

Useful output: Tool list, prohibited-input rule, and owner checklist

Create fictional training examples

Convert risky real-world moments into fictional scenarios the team can reuse without preserving patient names, chart facts, EOB details, or message history.

Useful output: Reusable huddle examples and onboarding questions

Assign owners

Set clear owners for clinical language, insurance estimates, billing explanations, urgent symptoms, vendor decisions, and policy changes.

Useful output: Owner map for front desk, billing, clinical, and manager teams

Write the escalation path

Give the team a simple next step when someone may have used the wrong AI tool or exposed information that should have stayed inside approved systems.

Useful output: Incident intake questions and manager follow-up checklist

Practice-owned review: Use the results to choose the next workflow, policy update, or training habit to improve.

Manager Training Packet

Use the completed quiz as an internal huddle packet: missed categories, discussion script, policy updates, workflow owners, scenario coaching, and next steps.

Huddle script

Here is what this scenario set tested: personal AI accounts, PHI recognition, vendor review, screenshots, patient messages, training examples, owners, and incident escalation. We are using the score to decide which workflow, policy, or training habit needs attention first. For every missed category, we will name the better action, the owner, and whether the policy, prompt, SOP, or vendor checklist needs an update.

Policy update checklist

Approved AI workspace and personal-account rule are clear. No-PHI prompt examples are available for training and drafting. Vendor/BAA review questions are documented before PHI reaches a tool. Patient-message, billing, clinical, and policy outputs have named owners. Wrong-tool or wrong-recipient escalation path is written and easy to report.

Practice lead map

Patient callbacks and scheduling language: Office manager or front desk lead Claims, EOBs, balances, and payer language: Billing lead or office manager Clinical symptoms, post-op wording, and urgency: Dentist or clinical lead Vendor, BAA, AI policy, and incident escalation: Owner, privacy lead, or office manager

Completion record: Completion record: use this packet as the starting point for the team's next workflow update.

Quiz categories

01 Personal AI accounts

Personal AI accounts may be fine for generic learning, but they are not the right default home for patient, payer, practice, or reusable workflow context.

Risk if missed: Useful office answers can drift into employee-owned chat history, memory, files, or tools the practice cannot audit or update.

Practice action: Publish an approved-tool rule and give the team safe no-PHI examples for generic drafting.

Authority guidance: Start with HIPAA Privacy Rule and minimum-necessary principles before deciding where patient or practice context can be used.

Category authority links: HHS Privacy Rule summary HHS minimum necessary requirement

02 PHI recognition

A fake name does not remove risk before personal or unapproved AI use if the prompt still describes a real patient through symptoms, treatment, dates, payer details, balances, or rare facts.

Risk if missed: Staff may think a personal or unapproved AI prompt is safe after changing the name while leaving enough context to identify or describe the patient.

Practice action: Use a PHI screening checklist before any patient-derived prompt enters a personal, public, or otherwise unapproved AI tool.

Authority guidance: Use HHS de-identification and minimum-necessary guidance as the review lens.

Category authority links: HHS de-identification guidance HHS minimum necessary requirement

03 Vendor BAAs

A vendor demo is not a launch plan. If the tool may create, receive, maintain, or transmit PHI, the owner needs the agreement and data practices reviewed.

Risk if missed: Patient data can enter a service before the practice understands BAA status, retention, training use, deletion, or subcontractors.

Practice action: Use a vendor checklist before PHI reaches an AI, cloud, transcription, analytics, or PMS-connected tool.

Authority guidance: Use HHS business associate and cloud guidance, plus FTC privacy/AI claim context where vendor promises are involved.

Category authority links: HHS business associate guidance HHS cloud service and BAA guidance FTC AI privacy and confidentiality guidance

04 EOB screenshots

EOBs and screenshots often contain patient, payer, claim, balance, appointment, and treatment context even when the name is not the only concern.

Risk if missed: A quick screenshot upload can expose more PHI and billing detail than the team intended.

Practice action: Create a billing-data workflow that uses the right tools, the right fields, and trained staff review.

Authority guidance: Apply Privacy Rule, Security Rule, minimum-necessary, and business associate guidance before EOB or screenshot use.

Category authority links: HHS Privacy Rule summary HHS Security Rule HHS minimum necessary requirement HHS business associate guidance

05 Patient messages

AI can help organize draft language, but patient-facing messages still need review for facts, tone, urgency, clinical boundaries, insurance caveats, and privacy.

Risk if missed: A polished answer can still contain the wrong clinical handoff, payer promise, balance statement, or escalation rule.

Practice action: Set patient-message review rules by risk type before staff use AI-generated wording.

Authority guidance: Use HIPAA training, Privacy Rule, and minimum-necessary guidance for message handling and workforce habits.

Category authority links: HHS HIPAA training materials HHS Privacy Rule summary HHS minimum necessary requirement

06 Reusable training examples

Real incidents can teach the team, but the reusable training version should be fictionalized and approved.

Risk if missed: A good lesson can accidentally preserve patient-specific facts in onboarding material, huddle notes, or personal AI history.

Practice action: Create fictional no-PHI scenarios for huddles, onboarding, and role-based quizzes.

Authority guidance: Use workforce training, de-identification, and minimum-necessary guidance when turning incidents into examples.

Category authority links: HHS HIPAA training materials HHS de-identification guidance HHS minimum necessary requirement

07 Practice approval

The owner should match the work. A dentist, billing lead, office manager, owner, or privacy lead may each own different outputs.

Risk if missed: The team may rely on AI for clinical urgency, billing accuracy, payer language, or policy decisions without the right person approving it.

Practice action: Publish an owner matrix for clinical, billing, patient-message, policy, and vendor outputs.

Authority guidance: Use workforce training, Privacy Rule, Security Rule, and dentistry-specific AI context to keep practice judgment in the workflow.

Category authority links: HHS HIPAA training materials HHS Privacy Rule summary HHS Security Rule ADA artificial intelligence in dentistry

08 Incident escalation

Staff need a calm reporting path when a wrong AI tool, wrong recipient, or risky upload may have happened.

Risk if missed: A small mistake can become harder to evaluate if no one preserves facts, reports promptly, or routes the issue to the right owner.

Practice action: Write first-hour incident intake questions and the owner/privacy-lead escalation path.

Authority guidance: Use Security Rule, risk analysis, breach notification, and OCR enforcement guidance as the source layer for incident response.

Category authority links: HHS Security Rule HHS Security Rule risk analysis guidance HHS Breach Notification Rule HHS OCR enforcement process

Scenario bank and safe-answer guidance

Question 1 - Personal AI accounts

A patient leaves a detailed callback request. A front desk team member writes a note with the patient's name, phone number, appointment date, and reason for the call, then wants to paste that note into a personal AI account to draft a reply. What is the safest next step?

Safe answer: Use an approved practice workflow or a fictional no-PHI template instead of pasting patient-derived details into a personal account.

Why it matters: A callback note with patient identifiers and appointment context should not be moved into a personal or unapproved AI account. Replacing the name with a fake name is not enough if dates, symptoms, phone numbers, rare details, or other patient-specific facts remain.

Risk if missed: The wrong move can turn a simple drafting task into an impermissible disclosure review. The practice may need to document what PHI left the approved workflow, assess whether breach notification is required, and retrain the team.

Why these sources apply: This guidance applies because the scenario asks whether patient-derived details or reusable practice guidance can leave approved, practice-owned workflows.

Authority guidance: HHS Privacy Rule summary HHS de-identification guidance HHS minimum necessary requirement

Question 2 - PHI recognition

A staff member removes the patient's name but leaves the procedure, appointment date, payer, claim status, and balance question before pasting the prompt into a personal or otherwise unapproved AI account. Is that automatically safe?

Safe answer: No. In a personal or unapproved AI account, the remaining details can still identify or describe a patient-specific situation.

Why it matters: The issue is the destination and the details. A personal, public, or otherwise unapproved AI account is not the place for patient-derived procedure, date, payer, claim, or balance context. In a practice-owned workflow, the team still uses the right input and the right owner.

Risk if missed: Treating a fake name as de-identification can leave patient-specific facts in a personal or unapproved system. That creates documentation, breach-assessment, and corrective-training work if the disclosure is later questioned.

Why these sources apply: This guidance applies because the scenario tests whether patient context remains identifiable or unnecessary before it enters a personal, public, or otherwise unapproved AI tool.

Authority guidance: HHS de-identification guidance HHS Privacy Rule summary

Question 3 - Vendor BAAs

A new AI scheduling vendor says it is HIPAA-ready, but the practice has not reviewed or signed a business associate agreement. The vendor demo requires real patient call summaries. What should happen first?

Safe answer: Verify the agreement, permitted data use, retention, subcontractors, access controls, and breach process before PHI enters the workflow.

Why it matters: A marketing claim is not the same as an approved vendor workflow. If a vendor will create, receive, maintain, or transmit PHI for the practice, the practice should verify the agreement and safeguards before use.

Risk if missed: Sending real patient data before the agreement is approved can create a vendor-compliance problem, not just a bad demo. The practice may have to stop the workflow, cure or end the vendor relationship, and report unresolved issues if required.

Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.

Authority guidance: HHS business associate guidance HHS cloud service and BAA guidance

Question 4 - Vendor BAAs

An AI receptionist vendor asks the practice to upload recent patient call transcripts so it can tune the handoff rules. The owner has not confirmed whether the vendor may receive PHI, retain transcripts, use them for training, or share them with subcontractors. What is the safest next step?

Safe answer: Use fictional examples or formally reviewed de-identified examples until the BAA, data use, retention, training, access, and subcontractor terms are reviewed.

Why it matters: A vendor configuration step can still create, receive, maintain, or transmit ePHI. Real transcripts should not enter a vendor workflow until the practice verifies the agreement, permitted use, retention, training limits, access controls, and owner.

Risk if missed: Real transcripts can expose many patient details at once. If the vendor is not approved to receive, retain, or train on that data, the practice may face incident review, vendor remediation, and broader corrective action.

Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.

Authority guidance: HHS business associate guidance HHS cloud service and BAA guidance HHS Security Rule

Question 5 - EOB screenshots

A billing coordinator wants AI to summarize why an EOB denied a claim. The easiest input is a screenshot showing patient name, subscriber ID, CDT code, payer response, and amount. What is the best answer?

Safe answer: Use only the practice workflow and the details needed for the task, with trained billing review before any action.

Why it matters: EOBs and screenshots often contain identifiers, payer details, financial information, and claim context. AI can help organize review work inside a practice workflow with the right input and trained staff verification.

Risk if missed: An EOB screenshot can disclose identifiers, payer data, claim details, and financial information in one file. If it goes to the wrong tool, the practice may need to assess the disclosure and document why notification is or is not required.

Why these sources apply: This guidance applies because EOBs, billing exports, screenshots, and claim details can combine identifiers, payer data, financial details, and treatment context.

Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary HHS Security Rule

Question 6 - EOB screenshots

The billing team wants AI to find patterns in overdue balances. Someone suggests uploading a patient aging report with names, balances, insurance plans, last payment dates, and notes from recent calls. What should the practice do first?

Safe answer: Use a practice workflow with aggregate fields where possible, and keep patient-level exports out of personal tools.

Why it matters: Dental billing exports can combine patient identifiers, plan details, financial balances, dates, and call notes. Pattern work should use aggregate inputs inside a practice workflow with trained billing review.

Risk if missed: A patient-level aging export can expand a mistake from one patient to many. Larger files increase the number of records to assess, the remediation burden, and the chance of patient notification or OCR scrutiny.

Why these sources apply: This guidance applies because EOBs, billing exports, screenshots, and claim details can combine identifiers, payer data, financial details, and treatment context.

Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary HHS Security Rule

Question 7 - Patient messages

AI drafts a patient-facing message about treatment timing and insurance. It sounds polished, but it says, for example, "your insurance should cover most of the crown" and "you should schedule this week before the tooth gets worse." Who should approve it before use?

Safe answer: The right owner: billing for coverage language, the dentist for clinical boundaries, and the office manager for tone and policy.

Why it matters: AI output can sound more certain than the practice should be. Patient-facing messages need review for clinical boundaries, payer uncertainty, estimate caveats, tone, and policy.

Risk if missed: A polished but wrong patient message can create patient confusion, complaints, rework, and policy exposure. If the message also includes unnecessary PHI or uses the wrong channel, the privacy review becomes harder.

Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.

Authority guidance: HHS Privacy Rule summary HHS minimum necessary requirement HHS HIPAA training materials

Question 8 - Patient messages

A treatment coordinator asks AI to turn an estimate note into a short text message. The draft says, for example, "your insurance will probably cover most of the visit" and "schedule this week before your benefits change." What should happen before sending?

Safe answer: Review and revise it for estimate caveats, payer uncertainty, clinical accuracy, tone, and practice policy before sending.

Why it matters: AI can make payer and urgency language sound more certain than the practice should be. Patient messages about treatment, estimates, or benefits need the right practice approval before they leave the office.

Risk if missed: Overconfident estimate or urgency language can create patient-trust and documentation problems. The practice may have to unwind the message, correct the record, and reinforce who approves billing and clinical statements.

Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.

Authority guidance: HHS Privacy Rule summary HHS minimum necessary requirement HHS HIPAA training materials

Question 9 - Reusable training examples

A manager wants to use a recent patient situation in team training because it shows what went wrong. What makes the example safer to reuse?

Safe answer: Remove identifiers and unnecessary details, generalize the scenario, and have the manager or privacy lead approve it.

Why it matters: Reusable training should teach the rule without preserving unnecessary patient-specific detail. The safer asset is a generalized scenario, approved for team use.

Risk if missed: A memorable patient story can become an unnecessary internal disclosure if it keeps identifying details. The practice may need to remove the training asset, document the exposure, and retrain managers on approved examples.

Why these sources apply: This guidance applies because reusable examples should teach the rule without preserving unnecessary patient-specific details or raw message history.

Authority guidance: HHS de-identification guidance HHS minimum necessary requirement HHS HIPAA training materials

Question 10 - Reusable training examples

An office manager is building a prompt library for new hires and wants to save examples copied from real patient texts because they show the tone staff should use. What is the better approach?

Safe answer: Create fictional or generalized examples that teach the same rule, then approve and store them as practice-owned training assets.

Why it matters: A prompt library should be reusable without carrying raw patient details forward. Generalized examples are easier to approve, audit, and update when policy changes.

Risk if missed: Saving real patient texts in a reusable prompt library repeats the exposure every time staff reuse the example. That can turn one poor judgment call into a systemic policy and training failure.

Why these sources apply: This guidance applies because reusable examples should teach the rule without preserving unnecessary patient-specific details or raw message history.

Authority guidance: HHS de-identification guidance HHS minimum necessary requirement HHS HIPAA training materials

Question 11 - Practice approval

A patient message says the patient has swelling and pain. AI suggests a response and labels the case as low urgency. What should the team do?

Safe answer: Follow the practice's clinical escalation policy and involve the dentist or clinical lead.

Why it matters: AI should not make final clinical urgency decisions. Symptoms, pain, swelling, medication questions, and post-op concerns need the practice's clinical handoff path.

Risk if missed: The main risk is patient safety and delayed clinical escalation, with privacy risk if the symptoms were also entered into the wrong AI tool. A missed handoff can create complaints, chart corrections, and urgent workflow retraining.

Why these sources apply: This guidance applies because AI can draft language, but trained humans must control clinical, billing, policy, and patient-facing decisions.

Authority guidance: HHS HIPAA training materials HHS Privacy Rule summary

Question 12 - Practice approval

A dental assistant asks AI to rewrite post-op instructions for a patient who mentions bleeding, medication questions, and a bad taste after an extraction. The draft sounds calm and complete. What is still required?

Safe answer: Route it through the dentist or clinical lead before any patient-facing response is used.

Why it matters: Medication questions, bleeding, possible infection signs, and post-op symptoms are clinical boundaries. AI may help draft language, but the practice controls the final response.

Risk if missed: Routine-looking post-op language can hide a clinical issue. If staff send an AI draft without review, the practice may face patient-care, documentation, and complaint risk in addition to any privacy issue from the prompt.

Why these sources apply: This guidance applies because AI can draft language, but trained humans must control clinical, billing, policy, and patient-facing decisions.

Authority guidance: HHS HIPAA training materials HHS Privacy Rule summary

Question 13 - Incident escalation

A team member realizes they pasted patient details into an unapproved AI tool while drafting a response. What is the best next action?

Safe answer: Stop using the output, notify the practice's manager or privacy lead, document what happened, and follow the practice's incident process.

Why it matters: The practice needs a defined incident path. Deleting a chat is not a substitute for internal review, documentation, and any required next steps under the practice's policy.

Risk if missed: Deleting the chat and staying quiet removes facts the practice needs for its breach analysis and burden of proof. It can make a small incident harder to defend, correct, and explain if OCR or a patient asks what happened.

Why these sources apply: This guidance applies because a possible wrong-tool disclosure requires documentation, risk analysis, and the practice's incident process.

Authority guidance: HHS Breach Notification Rule HHS Security Rule HHS Security Rule risk analysis guidance HHS OCR enforcement process

Question 14 - Incident escalation

A staff member realizes they uploaded a screenshot of a patient portal message to a free image-to-text tool to save typing time. The screenshot included the patient's name, appointment date, and symptoms. What should happen next?

Safe answer: Stop using the output, notify the manager or privacy lead, document what was uploaded, and follow the incident process.

Why it matters: Screenshots can expose PHI even when staff use them for convenience. The practice needs a calm, documented escalation path so leaders can assess the facts and take required next steps.

Risk if missed: A screenshot upload can disclose identifiers and symptoms outside the approved workflow. The practice may need to preserve the facts, assess whether PHI was compromised, notify if required, and correct the convenience habit that caused it.

Why these sources apply: This guidance applies because a possible wrong-tool disclosure requires documentation, risk analysis, and the practice's incident process.

Authority guidance: HHS Breach Notification Rule HHS Security Rule HHS minimum necessary requirement HHS OCR enforcement process

Question 15 - PHI recognition

The office wants AI to draft a generic cancellation policy. A staff member suggests uploading last month's full schedule so the AI understands the problem. What should the practice do?

Safe answer: Use generic examples, aggregate patterns, and the current policy instead of unnecessary patient-level schedule data.

Why it matters: The input should match the task. A generic policy usually does not need patient-level schedule data. Keep reusable policy assets free of unnecessary identifiers.

Risk if missed: Unnecessary patient-level data makes every later mistake bigger. More dates, names, and schedule details mean more facts to assess, more patients potentially affected, and more corrective action to document.

Why these sources apply: This guidance applies because the scenario tests whether patient context remains identifiable or unnecessary before it enters a personal, public, or otherwise unapproved AI tool.

Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary

Question 16 - Personal AI accounts

After the team approves a useful AI-assisted answer for insurance estimate caveats, where should that reusable guidance live?

Safe answer: In a practice-owned knowledge base or SOP location with an owner and review date.

Why it matters: The useful output should become practice-owned guidance, not employee-owned memory. Assign an owner, review date, and allowed-use boundary so staff can reuse it consistently.

Risk if missed: Personal AI memory is not a controlled SOP location. The practice loses ownership, review history, and update control, which can create inconsistent patient messaging and weak evidence of workforce training.

Why these sources apply: This guidance applies because the scenario asks whether patient-derived details or reusable practice guidance can leave approved, practice-owned workflows.

Authority guidance: HHS Security Rule HHS Security Rule risk analysis guidance HHS HIPAA training materials

Question 17 - Vendor BAAs

The practice adds an online scheduling widget and analytics tag to its website. The widget can capture appointment reason, preferred date, phone number, and the page the visitor used before requesting care. What should the owner verify before launch?

Safe answer: Whether any patient or appointment-related information is disclosed to the vendor, whether a BAA is needed, and whether tracking is configured to avoid impermissible PHI disclosure.

Why it matters: Scheduling widgets, forms, and tracking tags can collect identifiers and health-care context. The practice should understand what is sent, who receives it, whether the vendor is a business associate, and how tracking is configured.

Risk if missed: Tracking tools can disclose appointment or health-care interest data outside the approved workflow. The practice may need vendor remediation, configuration changes, breach analysis, and patient-facing correction if PHI was disclosed improperly.

Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.

Authority guidance: HHS online tracking technologies bulletin HHS business associate guidance HHS Security Rule

Question 18 - Vendor BAAs

A manager wants to use a low-cost transcription app to summarize calls and clinical handoff notes. The recordings may include patient names, symptoms, medication questions, appointment dates, and payment concerns. What has to happen first?

Safe answer: Confirm the approved workflow, BAA status, data retention, training use, access controls, and deletion process before patient audio or transcripts enter the app.

Why it matters: Audio and transcripts can contain many identifiers and clinical, financial, or scheduling details. A transcription workflow should be approved before it touches patient-derived content.

Risk if missed: Unapproved transcription can turn one call into a durable transcript outside practice control. That increases the scope of any incident review and can expose symptoms, medication questions, balances, and contact details.

Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.

Authority guidance: HHS business associate guidance HHS resources for mobile health apps HHS Security Rule

Question 19 - Patient messages

AI drafts a public response to a negative review. The draft says, for example, "our AI-assisted care prevents missed diagnoses" and hints that the reviewer missed a recommended crown appointment. What should happen before posting?

Safe answer: Remove patient-specific hints, avoid unsupported AI or clinical claims, and have the manager approve a neutral, privacy-safe response.

Why it matters: Public review responses should not confirm patient status, treatment, or appointment history. AI and clinical performance claims should also be accurate, supported, and approved before use.

Risk if missed: A public response can create a privacy problem and a marketing-claim problem at the same time. The practice may have to remove the post, correct the statement, document the disclosure risk, and retrain the manager.

Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.

Authority guidance: HHS Privacy Rule summary FTC AI claims guidance ADA artificial intelligence in dentistry

Question 20 - Patient messages

A spouse calls asking whether the patient really needs the extraction that was discussed yesterday. A staff member wants AI to draft a detailed explanation using the chart note, tooth number, symptoms, and estimate. What is the safer workflow?

Safe answer: Follow the practice's authorization and disclosure policy, use only the details needed, and route clinical language to the dentist or clinical lead.

Why it matters: Family involvement does not automatically authorize a detailed clinical or financial disclosure. The team needs the practice's disclosure rule, the right owner, and only the information needed.

Risk if missed: Over-sharing with a family member can create a privacy complaint, patient-trust problem, and chart-correction issue even if the staff member was trying to be helpful.

Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.

Authority guidance: HHS Privacy Rule summary HHS minimum necessary requirement HHS HIPAA training materials

Question 21 - Patient messages

The practice wants AI to segment patients for text outreach. Someone suggests uploading a list with names, balances, unscheduled treatment type, insurance plan, last visit, and cancellation history. What should the practice do first?

Safe answer: Use practice tools, aggregate fields, and manager-ready message categories before patient-level outreach data is processed.

Why it matters: Outreach lists can combine PHI, financial context, insurance information, and behavioral patterns. AI segmentation should use approved workflows and only the data needed for the task.

Risk if missed: A broad outreach export can multiply one mistake across many patients. It can also create inconsistent messaging, privacy review work, and patient complaints if sensitive categories are exposed.

Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.

Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary HHS online tracking technologies bulletin

Question 22 - Vendor BAAs

A vendor says patient messages and call transcripts may be used to improve its AI models unless the practice opts out in account settings. What should the practice do before using real patient data?

Safe answer: Review the BAA, privacy terms, training-use settings, retention, subcontractors, and whether the vendor's promises match the practice's approved use.

Why it matters: Model training, retention, and secondary data use are core vendor-review questions. The practice needs the agreement, settings, and actual data practices to line up before PHI is used.

Risk if missed: If patient data is used outside the approved purpose, the practice may lose control of downstream use and face vendor remediation, incident review, and trust damage.

Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.

Authority guidance: HHS business associate guidance HHS cloud service and BAA guidance FTC AI privacy and confidentiality guidance

Question 23 - Practice approval

An imaging tool creates an AI summary that says a radiograph shows likely recurrent decay and recommends crown replacement. A team member wants to paste that summary into a patient message. What is required first?

Safe answer: Have the dentist or clinical lead verify the finding, wording, documentation, and patient-facing explanation before use.

Why it matters: AI imaging output may support clinical review, but it should not replace the dentist's judgment or become patient-facing language without qualified review.

Risk if missed: A patient-facing diagnostic statement based only on AI output can create patient-care, documentation, trust, and claims risk if the dentist has not verified it.

Why these sources apply: This guidance applies because AI can draft language, but trained humans must control clinical, billing, policy, and patient-facing decisions.

Authority guidance: HHS HIPAA training materials ADA artificial intelligence in dentistry HHS Privacy Rule summary

Question 24 - Personal AI accounts

A staff member says, "I know personal AI is off limits, but I can paste the same patient prompt into our approved practice AI workspace." What is the best answer?

Safe answer: Not automatically. Even practice tools should receive only the information the workflow needs, with the right practice owner.

Why it matters: Tool approval matters, but it is not a blank check. Staff still need a defined workflow, the right inputs, and the right owner for the output.

Risk if missed: Treating tool approval as unlimited permission can lead to unnecessary PHI use, inconsistent review, and weak evidence that the practice applied its own policy.

Why these sources apply: This guidance applies because the scenario asks whether patient-derived details or reusable practice guidance can leave approved, practice-owned workflows.

Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary HHS HIPAA training materials

Dental AI Safety Team Checklist

Policy

  • Staff know which AI tools are approved and which personal tools are off limits for patient or practice-sensitive work.
  • The practice has a written rule for PHI, fake names, screenshots, EOBs, schedules, message threads, and payer details.
  • Every approved AI workflow has an owner and a review date.

People

  • Front desk, billing, treatment coordination, and clinical teams know which scenarios require escalation.
  • Staff can explain why removing or changing a name may not remove all patient-specific risk.
  • Managers know how to handle a suspected wrong-tool or wrong-recipient AI incident.

Tools

  • Vendors that may handle PHI are reviewed for BAA status, data use, retention, deletion, and subcontractors.
  • Practice-owned guidance is stored where the owner or manager can audit and update it.
  • Reusable prompts and examples avoid unnecessary patient, payer, financial, or screenshot details.

Review

  • Patient-facing messages are checked for tone, payer caveats, clinical boundaries, and financial accuracy.
  • Billing outputs are verified against payer documents, EOBs, CDT references, and staff judgment.
  • Training examples are generalized, approved, and kept separate from raw patient stories.

What changed in this quiz

  • Added role-based quiz modes and rotating scenario sets.
  • Added authority-linked answer explanations and category guidance.
  • Added Manager Training Packet handoff for huddles, policy updates, and workflow owners.
  • Added scenario status labels, the four-part AI safety test, and side-by-side prompt examples.

Source note: HHS Privacy Rule summary HHS de-identification guidance HHS minimum necessary requirement HHS HIPAA training materials HHS Security Rule HHS Security Rule risk analysis guidance HHS business associate guidance HHS cloud service and BAA guidance HHS Breach Notification Rule HHS HIPAA Enforcement Rule HHS OCR enforcement process HHS online tracking technologies bulletin HHS resources for mobile health apps FTC health privacy guidance FTC AI claims guidance FTC AI privacy and confidentiality guidance ADA artificial intelligence in dentistry

Dental HIPAA & AI Safety Quiz | Smarter Practice AI

Try this workflow in Smarter Practice AI

Smarter Practice AI gives dental teams managed ChatGPT access, dental workflows, onboarding, and responsible-use guidance for real workflows, SOPs, scripts, claims, and follow-up decisions.

Start the 15-day trial with one workflow and one reusable practice asset.