Ask for a process you can inspect

Is outsourced dental billing secure? What to verify

Security depends on agreements, access controls and day-to-day handling—not simply where the billing team works.

Outsourced billing can be operated with appropriate safeguards, but no provider can promise that risk disappears. A useful review follows the information: who can access it, where it can go, how activity is recorded and what happens when something goes wrong.

01 / Define the relationship

Start with the business associate relationship

For a HIPAA-covered dental practice, an outside billing company that handles protected health information on its behalf generally acts as a business associate. HHS specifically includes billing among business associate activities.

The business associate agreement should address permitted uses, safeguards and relevant reporting obligations. A general confidentiality promise is not a substitute for the required agreement. The arrangement also needs to account for subcontractors handling the information.

A signed document is the starting point

Ask how its requirements show up in actual work: account creation, record exchange, incident reporting and offboarding. An agreement cannot compensate for an uncontrolled shared login or records routinely sent through an unapproved channel.

Smart Dental Billing signs a BAA with each client and reports annual HIPAA training for its team. Those are specific practices the company can discuss; they are not a claim of independent security certification.

02 / Replace broad assurances with evidence

Six questions that produce useful answers

A provider conversation guide · On small screens, scroll to see all columns.
Ask the providerLook for a concrete answer
Who will access our records?The roles involved, how access is approved, whether subcontractors are used, and how changes are communicated.
How are users identified?Individual accounts or supported delegated access, with activity attributable to the person doing the work.
Where can information be stored?An inventory of approved systems, devices and transfer methods; a clear policy on local downloads and retention.
How do you manage security risks?A documented risk-analysis and risk-management process appropriate to the environment, not only a training certificate.
How will an incident reach us?Named contacts, an escalation route and reporting commitments consistent with the agreement and applicable requirements.
What happens when service ends?Return or retention handling, removal of access, transfer of open work and preservation of the practice’s records.

HHS describes risk analysis as foundational to selecting appropriate safeguards. A review should consider the actual systems and information involved, including remote access and information held outside the practice software.

03 / Make permissions deliberate

Limit access to the work being performed

The minimum necessary standard generally requires reasonable limits on PHI used or disclosed for payment activities. Build access around the assigned role and task, rather than granting unrestricted privileges by default.

01

Identify each user

HHS explains that systems maintaining electronic PHI need unique user identification so activity can be tracked. Avoid generic accounts that conceal who made a change.

02

Protect the access path

Ask your IT and security contacts to configure suitable authentication, secure remote access, device protections and session controls. Multi-factor authentication is a valuable control where supported.

03

Keep a usable record

Agree where notes, remittances and attachments belong. Verify that the practice can review relevant activity and retrieve records without relying on someone’s personal inbox.

The applicable Security Rule requires administrative, physical and technical safeguards. Specific implementation decisions should follow your risk analysis and current requirements; this checklist is not a complete compliance assessment.

Smart Dental Billing works in the practice’s software and does not require bank-account or payment-processing control. This keeps movement of funds with the practice, but it does not remove the need to protect billing-system access.

04 / Cover the whole relationship

Plan for incidents, staff changes and the end of service

When something looks wrong

Know whom to contact if records reach the wrong recipient, a device is lost or an account behaves unexpectedly. Preserve relevant evidence and follow the incident process. Do not assume an event is harmless, or automatically label every event a reportable breach without the required assessment.

When a person leaves

Assign someone to remove access promptly, review delegated permissions and transfer unfinished work. A new team member should receive their own approved access rather than inherit a departing person’s credentials.

When the engagement ends

Record which accounts and integrations must be disabled. Agree how necessary records and open-item notes will be transferred, and how any retained information remains protected. The practice should still be able to understand its own ledger and pending claims.

Build these steps into onboarding while both teams are defining the relationship. The preparation checklist helps identify the people and systems involved.

Practical questions

Details worth clarifying

Does a US-based team automatically make a service secure?

No. Location does not establish appropriate permissions, secure devices or good incident handling. Review the controls and agreements regardless of where the team works.

Is annual HIPAA training enough?

No. Training is one part of a broader program. Access management, risk analysis, safeguards, policies and incident procedures also matter.

Should we share the owner’s administrator login?

Use an individual account with appropriate permissions or the system’s supported delegated access. Ask your IT contact how to configure it without giving unnecessary administrative control.

Get practical help

Discuss access before the work starts

Review the proposed workflow, BAA and division of responsibilities with our team.

© 2026 Smart Dental Billing | About this website