All team
Use this mode for a full-team huddle or onboarding review.
Interactive educational resource
Can your team spot unsafe AI use before patient information gets exposed?
Use this educational quiz to see whether your dental team can spot risky AI habits before patient information, payer details, EOBs, screenshots, or practice workflows move into the wrong tool. Each answer explains the safer choice, the compliance risk if missed, why the authority guidance applies, and the next team-training action.
Rotating quiz format: All-team mode covers all 8 safety categories and adds 2 rotating workflow deep dives from the scenario bank. Role modes rotate through the scenarios most relevant to that team. The full bank currently includes 24 dental AI safety scenarios.
Last reviewed: June 20, 2026. Educational self-check for dental teams. Do not enter patient names, charts, screenshots, EOBs, portal messages, voicemail transcripts, or other PHI. Scenarios distinguish personal, public, or otherwise unapproved AI tools from practice-owned workflows like Smarter Practice AI.
Use it as a team training check. The goal is to spot where staff need clearer AI rules.
Use this mode for a full-team huddle or onboarding review.
Best for team members who handle calls, texts, scheduling, patient messages, and portal requests.
Best for billing coordinators, insurance follow-up, treatment coordinators, and anyone handling payer or balance details.
Best for assistants, hygienists, providers, and anyone drafting or reviewing clinical patient communication.
Best for owners, office managers, privacy leads, and team members responsible for policy and training.
Privacy, Security, Breach Notification, de-identification, vendor, cloud, tracking, and workforce-training guidance for covered dental practices and business associates.
Authority links: HHS Privacy Rule summary HHS minimum necessary requirement HHS de-identification guidance HHS business associate guidance HHS cloud service and BAA guidance HHS online tracking technologies bulletin HHS resources for mobile health apps HHS Breach Notification Rule
Useful context for AI vendors, consumer health apps, marketing claims, privacy promises, and data-use statements. It does not replace HIPAA obligations.
Authority links: FTC health privacy guidance FTC AI claims guidance FTC AI privacy and confidentiality guidance
Dental-specific AI standards and professional context for owners evaluating AI in clinical, payer, and operational workflows.
Authority links: ADA artificial intelligence in dentistry
Practice workflow bridge
The quiz identifies the risk. Smarter Practice AI can help the team organize prompts, SOP language, owner rules, fictional examples, and training notes that stay inside the practice workflow.
Define which AI tools the team can use, what data is prohibited, and who owns the workflow before staff use AI for patient, payer, or practice workflows.
Useful output: Tool list, prohibited-input rule, and owner checklist
Convert risky real-world moments into fictional scenarios the team can reuse without preserving patient names, chart facts, EOB details, or message history.
Useful output: Reusable huddle examples and onboarding questions
Set clear owners for clinical language, insurance estimates, billing explanations, urgent symptoms, vendor decisions, and policy changes.
Useful output: Owner map for front desk, billing, clinical, and manager teams
Give the team a simple next step when someone may have used the wrong AI tool or exposed information that should have stayed inside approved systems.
Useful output: Incident intake questions and manager follow-up checklist
Practice-owned review: Use the results to choose the next workflow, policy update, or training habit to improve.
Use the completed quiz as an internal huddle packet: missed categories, discussion script, policy updates, workflow owners, scenario coaching, and next steps.
Here is what this scenario set tested: personal AI accounts, PHI recognition, vendor review, screenshots, patient messages, training examples, owners, and incident escalation. We are using the score to decide which workflow, policy, or training habit needs attention first. For every missed category, we will name the better action, the owner, and whether the policy, prompt, SOP, or vendor checklist needs an update.
Approved AI workspace and personal-account rule are clear. No-PHI prompt examples are available for training and drafting. Vendor/BAA review questions are documented before PHI reaches a tool. Patient-message, billing, clinical, and policy outputs have named owners. Wrong-tool or wrong-recipient escalation path is written and easy to report.
Patient callbacks and scheduling language: Office manager or front desk lead Claims, EOBs, balances, and payer language: Billing lead or office manager Clinical symptoms, post-op wording, and urgency: Dentist or clinical lead Vendor, BAA, AI policy, and incident escalation: Owner, privacy lead, or office manager
Completion record: Completion record: use this packet as the starting point for the team's next workflow update.
Personal AI accounts may be fine for generic learning, but they are not the right default home for patient, payer, practice, or reusable workflow context.
Risk if missed: Useful office answers can drift into employee-owned chat history, memory, files, or tools the practice cannot audit or update.
Practice action: Publish an approved-tool rule and give the team safe no-PHI examples for generic drafting.
Authority guidance: Start with HIPAA Privacy Rule and minimum-necessary principles before deciding where patient or practice context can be used.
Category authority links: HHS Privacy Rule summary HHS minimum necessary requirement
A fake name does not remove risk before personal or unapproved AI use if the prompt still describes a real patient through symptoms, treatment, dates, payer details, balances, or rare facts.
Risk if missed: Staff may think a personal or unapproved AI prompt is safe after changing the name while leaving enough context to identify or describe the patient.
Practice action: Use a PHI screening checklist before any patient-derived prompt enters a personal, public, or otherwise unapproved AI tool.
Authority guidance: Use HHS de-identification and minimum-necessary guidance as the review lens.
Category authority links: HHS de-identification guidance HHS minimum necessary requirement
A vendor demo is not a launch plan. If the tool may create, receive, maintain, or transmit PHI, the owner needs the agreement and data practices reviewed.
Risk if missed: Patient data can enter a service before the practice understands BAA status, retention, training use, deletion, or subcontractors.
Practice action: Use a vendor checklist before PHI reaches an AI, cloud, transcription, analytics, or PMS-connected tool.
Authority guidance: Use HHS business associate and cloud guidance, plus FTC privacy/AI claim context where vendor promises are involved.
Category authority links: HHS business associate guidance HHS cloud service and BAA guidance FTC AI privacy and confidentiality guidance
EOBs and screenshots often contain patient, payer, claim, balance, appointment, and treatment context even when the name is not the only concern.
Risk if missed: A quick screenshot upload can expose more PHI and billing detail than the team intended.
Practice action: Create a billing-data workflow that uses the right tools, the right fields, and trained staff review.
Authority guidance: Apply Privacy Rule, Security Rule, minimum-necessary, and business associate guidance before EOB or screenshot use.
Category authority links: HHS Privacy Rule summary HHS Security Rule HHS minimum necessary requirement HHS business associate guidance
AI can help organize draft language, but patient-facing messages still need review for facts, tone, urgency, clinical boundaries, insurance caveats, and privacy.
Risk if missed: A polished answer can still contain the wrong clinical handoff, payer promise, balance statement, or escalation rule.
Practice action: Set patient-message review rules by risk type before staff use AI-generated wording.
Authority guidance: Use HIPAA training, Privacy Rule, and minimum-necessary guidance for message handling and workforce habits.
Category authority links: HHS HIPAA training materials HHS Privacy Rule summary HHS minimum necessary requirement
Real incidents can teach the team, but the reusable training version should be fictionalized and approved.
Risk if missed: A good lesson can accidentally preserve patient-specific facts in onboarding material, huddle notes, or personal AI history.
Practice action: Create fictional no-PHI scenarios for huddles, onboarding, and role-based quizzes.
Authority guidance: Use workforce training, de-identification, and minimum-necessary guidance when turning incidents into examples.
Category authority links: HHS HIPAA training materials HHS de-identification guidance HHS minimum necessary requirement
The owner should match the work. A dentist, billing lead, office manager, owner, or privacy lead may each own different outputs.
Risk if missed: The team may rely on AI for clinical urgency, billing accuracy, payer language, or policy decisions without the right person approving it.
Practice action: Publish an owner matrix for clinical, billing, patient-message, policy, and vendor outputs.
Authority guidance: Use workforce training, Privacy Rule, Security Rule, and dentistry-specific AI context to keep practice judgment in the workflow.
Category authority links: HHS HIPAA training materials HHS Privacy Rule summary HHS Security Rule ADA artificial intelligence in dentistry
Staff need a calm reporting path when a wrong AI tool, wrong recipient, or risky upload may have happened.
Risk if missed: A small mistake can become harder to evaluate if no one preserves facts, reports promptly, or routes the issue to the right owner.
Practice action: Write first-hour incident intake questions and the owner/privacy-lead escalation path.
Authority guidance: Use Security Rule, risk analysis, breach notification, and OCR enforcement guidance as the source layer for incident response.
Category authority links: HHS Security Rule HHS Security Rule risk analysis guidance HHS Breach Notification Rule HHS OCR enforcement process
Question 1 - Personal AI accounts
Safe answer: Use an approved practice workflow or a fictional no-PHI template instead of pasting patient-derived details into a personal account.
Why it matters: A callback note with patient identifiers and appointment context should not be moved into a personal or unapproved AI account. Replacing the name with a fake name is not enough if dates, symptoms, phone numbers, rare details, or other patient-specific facts remain.
Risk if missed: The wrong move can turn a simple drafting task into an impermissible disclosure review. The practice may need to document what PHI left the approved workflow, assess whether breach notification is required, and retrain the team.
Why these sources apply: This guidance applies because the scenario asks whether patient-derived details or reusable practice guidance can leave approved, practice-owned workflows.
Authority guidance: HHS Privacy Rule summary HHS de-identification guidance HHS minimum necessary requirement
Question 2 - PHI recognition
Safe answer: No. In a personal or unapproved AI account, the remaining details can still identify or describe a patient-specific situation.
Why it matters: The issue is the destination and the details. A personal, public, or otherwise unapproved AI account is not the place for patient-derived procedure, date, payer, claim, or balance context. In a practice-owned workflow, the team still uses the right input and the right owner.
Risk if missed: Treating a fake name as de-identification can leave patient-specific facts in a personal or unapproved system. That creates documentation, breach-assessment, and corrective-training work if the disclosure is later questioned.
Why these sources apply: This guidance applies because the scenario tests whether patient context remains identifiable or unnecessary before it enters a personal, public, or otherwise unapproved AI tool.
Authority guidance: HHS de-identification guidance HHS Privacy Rule summary
Question 3 - Vendor BAAs
Safe answer: Verify the agreement, permitted data use, retention, subcontractors, access controls, and breach process before PHI enters the workflow.
Why it matters: A marketing claim is not the same as an approved vendor workflow. If a vendor will create, receive, maintain, or transmit PHI for the practice, the practice should verify the agreement and safeguards before use.
Risk if missed: Sending real patient data before the agreement is approved can create a vendor-compliance problem, not just a bad demo. The practice may have to stop the workflow, cure or end the vendor relationship, and report unresolved issues if required.
Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.
Authority guidance: HHS business associate guidance HHS cloud service and BAA guidance
Question 4 - Vendor BAAs
Safe answer: Use fictional examples or formally reviewed de-identified examples until the BAA, data use, retention, training, access, and subcontractor terms are reviewed.
Why it matters: A vendor configuration step can still create, receive, maintain, or transmit ePHI. Real transcripts should not enter a vendor workflow until the practice verifies the agreement, permitted use, retention, training limits, access controls, and owner.
Risk if missed: Real transcripts can expose many patient details at once. If the vendor is not approved to receive, retain, or train on that data, the practice may face incident review, vendor remediation, and broader corrective action.
Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.
Authority guidance: HHS business associate guidance HHS cloud service and BAA guidance HHS Security Rule
Question 5 - EOB screenshots
Safe answer: Use only the practice workflow and the details needed for the task, with trained billing review before any action.
Why it matters: EOBs and screenshots often contain identifiers, payer details, financial information, and claim context. AI can help organize review work inside a practice workflow with the right input and trained staff verification.
Risk if missed: An EOB screenshot can disclose identifiers, payer data, claim details, and financial information in one file. If it goes to the wrong tool, the practice may need to assess the disclosure and document why notification is or is not required.
Why these sources apply: This guidance applies because EOBs, billing exports, screenshots, and claim details can combine identifiers, payer data, financial details, and treatment context.
Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary HHS Security Rule
Question 6 - EOB screenshots
Safe answer: Use a practice workflow with aggregate fields where possible, and keep patient-level exports out of personal tools.
Why it matters: Dental billing exports can combine patient identifiers, plan details, financial balances, dates, and call notes. Pattern work should use aggregate inputs inside a practice workflow with trained billing review.
Risk if missed: A patient-level aging export can expand a mistake from one patient to many. Larger files increase the number of records to assess, the remediation burden, and the chance of patient notification or OCR scrutiny.
Why these sources apply: This guidance applies because EOBs, billing exports, screenshots, and claim details can combine identifiers, payer data, financial details, and treatment context.
Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary HHS Security Rule
Question 7 - Patient messages
Safe answer: The right owner: billing for coverage language, the dentist for clinical boundaries, and the office manager for tone and policy.
Why it matters: AI output can sound more certain than the practice should be. Patient-facing messages need review for clinical boundaries, payer uncertainty, estimate caveats, tone, and policy.
Risk if missed: A polished but wrong patient message can create patient confusion, complaints, rework, and policy exposure. If the message also includes unnecessary PHI or uses the wrong channel, the privacy review becomes harder.
Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.
Authority guidance: HHS Privacy Rule summary HHS minimum necessary requirement HHS HIPAA training materials
Question 8 - Patient messages
Safe answer: Review and revise it for estimate caveats, payer uncertainty, clinical accuracy, tone, and practice policy before sending.
Why it matters: AI can make payer and urgency language sound more certain than the practice should be. Patient messages about treatment, estimates, or benefits need the right practice approval before they leave the office.
Risk if missed: Overconfident estimate or urgency language can create patient-trust and documentation problems. The practice may have to unwind the message, correct the record, and reinforce who approves billing and clinical statements.
Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.
Authority guidance: HHS Privacy Rule summary HHS minimum necessary requirement HHS HIPAA training materials
Question 9 - Reusable training examples
Safe answer: Remove identifiers and unnecessary details, generalize the scenario, and have the manager or privacy lead approve it.
Why it matters: Reusable training should teach the rule without preserving unnecessary patient-specific detail. The safer asset is a generalized scenario, approved for team use.
Risk if missed: A memorable patient story can become an unnecessary internal disclosure if it keeps identifying details. The practice may need to remove the training asset, document the exposure, and retrain managers on approved examples.
Why these sources apply: This guidance applies because reusable examples should teach the rule without preserving unnecessary patient-specific details or raw message history.
Authority guidance: HHS de-identification guidance HHS minimum necessary requirement HHS HIPAA training materials
Question 10 - Reusable training examples
Safe answer: Create fictional or generalized examples that teach the same rule, then approve and store them as practice-owned training assets.
Why it matters: A prompt library should be reusable without carrying raw patient details forward. Generalized examples are easier to approve, audit, and update when policy changes.
Risk if missed: Saving real patient texts in a reusable prompt library repeats the exposure every time staff reuse the example. That can turn one poor judgment call into a systemic policy and training failure.
Why these sources apply: This guidance applies because reusable examples should teach the rule without preserving unnecessary patient-specific details or raw message history.
Authority guidance: HHS de-identification guidance HHS minimum necessary requirement HHS HIPAA training materials
Question 11 - Practice approval
Safe answer: Follow the practice's clinical escalation policy and involve the dentist or clinical lead.
Why it matters: AI should not make final clinical urgency decisions. Symptoms, pain, swelling, medication questions, and post-op concerns need the practice's clinical handoff path.
Risk if missed: The main risk is patient safety and delayed clinical escalation, with privacy risk if the symptoms were also entered into the wrong AI tool. A missed handoff can create complaints, chart corrections, and urgent workflow retraining.
Why these sources apply: This guidance applies because AI can draft language, but trained humans must control clinical, billing, policy, and patient-facing decisions.
Authority guidance: HHS HIPAA training materials HHS Privacy Rule summary
Question 12 - Practice approval
Safe answer: Route it through the dentist or clinical lead before any patient-facing response is used.
Why it matters: Medication questions, bleeding, possible infection signs, and post-op symptoms are clinical boundaries. AI may help draft language, but the practice controls the final response.
Risk if missed: Routine-looking post-op language can hide a clinical issue. If staff send an AI draft without review, the practice may face patient-care, documentation, and complaint risk in addition to any privacy issue from the prompt.
Why these sources apply: This guidance applies because AI can draft language, but trained humans must control clinical, billing, policy, and patient-facing decisions.
Authority guidance: HHS HIPAA training materials HHS Privacy Rule summary
Question 13 - Incident escalation
Safe answer: Stop using the output, notify the practice's manager or privacy lead, document what happened, and follow the practice's incident process.
Why it matters: The practice needs a defined incident path. Deleting a chat is not a substitute for internal review, documentation, and any required next steps under the practice's policy.
Risk if missed: Deleting the chat and staying quiet removes facts the practice needs for its breach analysis and burden of proof. It can make a small incident harder to defend, correct, and explain if OCR or a patient asks what happened.
Why these sources apply: This guidance applies because a possible wrong-tool disclosure requires documentation, risk analysis, and the practice's incident process.
Authority guidance: HHS Breach Notification Rule HHS Security Rule HHS Security Rule risk analysis guidance HHS OCR enforcement process
Question 14 - Incident escalation
Safe answer: Stop using the output, notify the manager or privacy lead, document what was uploaded, and follow the incident process.
Why it matters: Screenshots can expose PHI even when staff use them for convenience. The practice needs a calm, documented escalation path so leaders can assess the facts and take required next steps.
Risk if missed: A screenshot upload can disclose identifiers and symptoms outside the approved workflow. The practice may need to preserve the facts, assess whether PHI was compromised, notify if required, and correct the convenience habit that caused it.
Why these sources apply: This guidance applies because a possible wrong-tool disclosure requires documentation, risk analysis, and the practice's incident process.
Authority guidance: HHS Breach Notification Rule HHS Security Rule HHS minimum necessary requirement HHS OCR enforcement process
Question 15 - PHI recognition
Safe answer: Use generic examples, aggregate patterns, and the current policy instead of unnecessary patient-level schedule data.
Why it matters: The input should match the task. A generic policy usually does not need patient-level schedule data. Keep reusable policy assets free of unnecessary identifiers.
Risk if missed: Unnecessary patient-level data makes every later mistake bigger. More dates, names, and schedule details mean more facts to assess, more patients potentially affected, and more corrective action to document.
Why these sources apply: This guidance applies because the scenario tests whether patient context remains identifiable or unnecessary before it enters a personal, public, or otherwise unapproved AI tool.
Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary
Question 16 - Personal AI accounts
Safe answer: In a practice-owned knowledge base or SOP location with an owner and review date.
Why it matters: The useful output should become practice-owned guidance, not employee-owned memory. Assign an owner, review date, and allowed-use boundary so staff can reuse it consistently.
Risk if missed: Personal AI memory is not a controlled SOP location. The practice loses ownership, review history, and update control, which can create inconsistent patient messaging and weak evidence of workforce training.
Why these sources apply: This guidance applies because the scenario asks whether patient-derived details or reusable practice guidance can leave approved, practice-owned workflows.
Authority guidance: HHS Security Rule HHS Security Rule risk analysis guidance HHS HIPAA training materials
Question 17 - Vendor BAAs
Safe answer: Whether any patient or appointment-related information is disclosed to the vendor, whether a BAA is needed, and whether tracking is configured to avoid impermissible PHI disclosure.
Why it matters: Scheduling widgets, forms, and tracking tags can collect identifiers and health-care context. The practice should understand what is sent, who receives it, whether the vendor is a business associate, and how tracking is configured.
Risk if missed: Tracking tools can disclose appointment or health-care interest data outside the approved workflow. The practice may need vendor remediation, configuration changes, breach analysis, and patient-facing correction if PHI was disclosed improperly.
Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.
Authority guidance: HHS online tracking technologies bulletin HHS business associate guidance HHS Security Rule
Question 18 - Vendor BAAs
Safe answer: Confirm the approved workflow, BAA status, data retention, training use, access controls, and deletion process before patient audio or transcripts enter the app.
Why it matters: Audio and transcripts can contain many identifiers and clinical, financial, or scheduling details. A transcription workflow should be approved before it touches patient-derived content.
Risk if missed: Unapproved transcription can turn one call into a durable transcript outside practice control. That increases the scope of any incident review and can expose symptoms, medication questions, balances, and contact details.
Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.
Authority guidance: HHS business associate guidance HHS resources for mobile health apps HHS Security Rule
Question 19 - Patient messages
Safe answer: Remove patient-specific hints, avoid unsupported AI or clinical claims, and have the manager approve a neutral, privacy-safe response.
Why it matters: Public review responses should not confirm patient status, treatment, or appointment history. AI and clinical performance claims should also be accurate, supported, and approved before use.
Risk if missed: A public response can create a privacy problem and a marketing-claim problem at the same time. The practice may have to remove the post, correct the statement, document the disclosure risk, and retrain the manager.
Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.
Authority guidance: HHS Privacy Rule summary FTC AI claims guidance ADA artificial intelligence in dentistry
Question 20 - Patient messages
Safe answer: Follow the practice's authorization and disclosure policy, use only the details needed, and route clinical language to the dentist or clinical lead.
Why it matters: Family involvement does not automatically authorize a detailed clinical or financial disclosure. The team needs the practice's disclosure rule, the right owner, and only the information needed.
Risk if missed: Over-sharing with a family member can create a privacy complaint, patient-trust problem, and chart-correction issue even if the staff member was trying to be helpful.
Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.
Authority guidance: HHS Privacy Rule summary HHS minimum necessary requirement HHS HIPAA training materials
Question 21 - Patient messages
Safe answer: Use practice tools, aggregate fields, and manager-ready message categories before patient-level outreach data is processed.
Why it matters: Outreach lists can combine PHI, financial context, insurance information, and behavioral patterns. AI segmentation should use approved workflows and only the data needed for the task.
Risk if missed: A broad outreach export can multiply one mistake across many patients. It can also create inconsistent messaging, privacy review work, and patient complaints if sensitive categories are exposed.
Why these sources apply: This guidance applies because patient-facing AI output can affect privacy, payer language, clinical boundaries, financial expectations, and workforce training.
Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary HHS online tracking technologies bulletin
Question 22 - Vendor BAAs
Safe answer: Review the BAA, privacy terms, training-use settings, retention, subcontractors, and whether the vendor's promises match the practice's approved use.
Why it matters: Model training, retention, and secondary data use are core vendor-review questions. The practice needs the agreement, settings, and actual data practices to line up before PHI is used.
Risk if missed: If patient data is used outside the approved purpose, the practice may lose control of downstream use and face vendor remediation, incident review, and trust damage.
Why these sources apply: This guidance applies because the scenario involves a vendor that may create, receive, maintain, or transmit PHI for the practice.
Authority guidance: HHS business associate guidance HHS cloud service and BAA guidance FTC AI privacy and confidentiality guidance
Question 23 - Practice approval
Safe answer: Have the dentist or clinical lead verify the finding, wording, documentation, and patient-facing explanation before use.
Why it matters: AI imaging output may support clinical review, but it should not replace the dentist's judgment or become patient-facing language without qualified review.
Risk if missed: A patient-facing diagnostic statement based only on AI output can create patient-care, documentation, trust, and claims risk if the dentist has not verified it.
Why these sources apply: This guidance applies because AI can draft language, but trained humans must control clinical, billing, policy, and patient-facing decisions.
Authority guidance: HHS HIPAA training materials ADA artificial intelligence in dentistry HHS Privacy Rule summary
Question 24 - Personal AI accounts
Safe answer: Not automatically. Even practice tools should receive only the information the workflow needs, with the right practice owner.
Why it matters: Tool approval matters, but it is not a blank check. Staff still need a defined workflow, the right inputs, and the right owner for the output.
Risk if missed: Treating tool approval as unlimited permission can lead to unnecessary PHI use, inconsistent review, and weak evidence that the practice applied its own policy.
Why these sources apply: This guidance applies because the scenario asks whether patient-derived details or reusable practice guidance can leave approved, practice-owned workflows.
Authority guidance: HHS minimum necessary requirement HHS Privacy Rule summary HHS HIPAA training materials
Source note: HHS Privacy Rule summary HHS de-identification guidance HHS minimum necessary requirement HHS HIPAA training materials HHS Security Rule HHS Security Rule risk analysis guidance HHS business associate guidance HHS cloud service and BAA guidance HHS Breach Notification Rule HHS HIPAA Enforcement Rule HHS OCR enforcement process HHS online tracking technologies bulletin HHS resources for mobile health apps FTC health privacy guidance FTC AI claims guidance FTC AI privacy and confidentiality guidance ADA artificial intelligence in dentistry
Dental HIPAA & AI Safety Quiz | Smarter Practice AI
Smarter Practice AI gives dental teams managed ChatGPT access, dental workflows, onboarding, and responsible-use guidance for real workflows, SOPs, scripts, claims, and follow-up decisions.
Start the 15-day trial with one workflow and one reusable practice asset.