Ask for a process you can inspect
Is outsourced dental billing secure? What to verify
Security depends on agreements, access controls and day-to-day handling—not simply where the billing team works.
Outsourced billing can be operated with appropriate safeguards, but no provider can promise that risk disappears. A useful review follows the information: who can access it, where it can go, how activity is recorded and what happens when something goes wrong.
01 / Define the relationship
Start with the business associate relationship
For a HIPAA-covered dental practice, an outside billing company that handles protected health information on its behalf generally acts as a business associate. HHS specifically includes billing among business associate activities.
The business associate agreement should address permitted uses, safeguards and relevant reporting obligations. A general confidentiality promise is not a substitute for the required agreement. The arrangement also needs to account for subcontractors handling the information.
A signed document is the starting point
Ask how its requirements show up in actual work: account creation, record exchange, incident reporting and offboarding. An agreement cannot compensate for an uncontrolled shared login or records routinely sent through an unapproved channel.
Smart Dental Billing signs a BAA with each client and reports annual HIPAA training for its team. Those are specific practices the company can discuss; they are not a claim of independent security certification.
02 / Replace broad assurances with evidence
Six questions that produce useful answers
| Ask the provider | Look for a concrete answer |
|---|---|
| Who will access our records? | The roles involved, how access is approved, whether subcontractors are used, and how changes are communicated. |
| How are users identified? | Individual accounts or supported delegated access, with activity attributable to the person doing the work. |
| Where can information be stored? | An inventory of approved systems, devices and transfer methods; a clear policy on local downloads and retention. |
| How do you manage security risks? | A documented risk-analysis and risk-management process appropriate to the environment, not only a training certificate. |
| How will an incident reach us? | Named contacts, an escalation route and reporting commitments consistent with the agreement and applicable requirements. |
| What happens when service ends? | Return or retention handling, removal of access, transfer of open work and preservation of the practice’s records. |
HHS describes risk analysis as foundational to selecting appropriate safeguards. A review should consider the actual systems and information involved, including remote access and information held outside the practice software.
03 / Make permissions deliberate
Limit access to the work being performed
The minimum necessary standard generally requires reasonable limits on PHI used or disclosed for payment activities. Build access around the assigned role and task, rather than granting unrestricted privileges by default.
Identify each user
HHS explains that systems maintaining electronic PHI need unique user identification so activity can be tracked. Avoid generic accounts that conceal who made a change.
Protect the access path
Ask your IT and security contacts to configure suitable authentication, secure remote access, device protections and session controls. Multi-factor authentication is a valuable control where supported.
Keep a usable record
Agree where notes, remittances and attachments belong. Verify that the practice can review relevant activity and retrieve records without relying on someone’s personal inbox.
The applicable Security Rule requires administrative, physical and technical safeguards. Specific implementation decisions should follow your risk analysis and current requirements; this checklist is not a complete compliance assessment.
Smart Dental Billing works in the practice’s software and does not require bank-account or payment-processing control. This keeps movement of funds with the practice, but it does not remove the need to protect billing-system access.
04 / Cover the whole relationship
Plan for incidents, staff changes and the end of service
When something looks wrong
Know whom to contact if records reach the wrong recipient, a device is lost or an account behaves unexpectedly. Preserve relevant evidence and follow the incident process. Do not assume an event is harmless, or automatically label every event a reportable breach without the required assessment.
When a person leaves
Assign someone to remove access promptly, review delegated permissions and transfer unfinished work. A new team member should receive their own approved access rather than inherit a departing person’s credentials.
When the engagement ends
Record which accounts and integrations must be disabled. Agree how necessary records and open-item notes will be transferred, and how any retained information remains protected. The practice should still be able to understand its own ledger and pending claims.
Build these steps into onboarding while both teams are defining the relationship. The preparation checklist helps identify the people and systems involved.
Practical questions
Details worth clarifying
Does a US-based team automatically make a service secure?
No. Location does not establish appropriate permissions, secure devices or good incident handling. Review the controls and agreements regardless of where the team works.
Is annual HIPAA training enough?
No. Training is one part of a broader program. Access management, risk analysis, safeguards, policies and incident procedures also matter.
Should we share the owner’s administrator login?
Use an individual account with appropriate permissions or the system’s supported delegated access. Ask your IT contact how to configure it without giving unnecessary administrative control.
Get practical help
Discuss access before the work starts
Review the proposed workflow, BAA and division of responsibilities with our team.