Training · Clinical care providers
Privacy & Security Training for Dental Practices
Privacy and security training for a dental practice teaches front-desk staff, assistants, hygienists and associates the specific behaviours that keep patient charts, images and claims data safe, not generic cybersecurity slides. Practices usually book training after hiring a new front-desk hire who needs to use CDAnet properly, or after realizing staff have never been told the rule against looking up a family member's chart. We build sessions around your actual PMS and imaging workflow.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What dental training has to change in day-to-day behaviour
Most privacy incidents in a dental office come down to a habit, not a technical failure, which is exactly what training is built to correct.
How staff use the practice-management system
Training covers logging in under an individual's own credentials rather than a shared front-desk login, and understanding that every chart opened is recorded.
Handling images and radiographs
Assistants and hygienists learn how intraoral photos, CBCT scans and radiographs move from sensor to chart, and what not to do with them, such as forwarding an image by personal text or email.
Submitting claims through CDAnet
Front desk staff learn what information CDAnet transmits, why credentials for the claims switch aren't shared, and how to spot when a submission looks wrong before it goes out.
Recognizing phishing aimed at the office
Staff learn to recognize the kinds of messages that precede a ransomware incident, since the entry point in most dental office breaches is a person, not a firewall.
Regulatory map
Why training is a compliance expectation, not just good practice
PHIPA and RCDSO both assume staff understand their obligations, and an untrained team is itself a documented gap during any review.
PHIPA's duty of confidentiality
Everyone handling personal health information at a custodian's practice is bound by PHIPA's confidentiality provisions, and training is how a practice demonstrates staff actually understand what that means day to day.
RCDSO's staff competency expectations
RCDSO's Electronic Records Management guideline assumes staff using clinical software understand access controls and appropriate use, which training is the practical way to establish and document.
Quebec's Law 25 training expectations
Quebec clinics operate under Law 25 obligations the Ordre des dentistes has addressed in profession-specific guidance, which assumes staff have been trained on the clinic's incident and privacy procedures.
What goes wrong
What untrained staff actually cause
These are the patterns training is built to stop, drawn from how dental and health-sector privacy incidents actually happen.
Snooping on charts out of curiosity
Ontario's own reporting shows unauthorized chart-browsing, looking up someone you know rather than someone you're treating, sits near the top of self-reported health-privacy incidents year after year, which makes it a behaviour to unlearn rather than a technical gap to patch.
Misdirected records and referrals
A chart, radiograph or referral sent to the wrong recipient by fax, email or the wrong patient's file is another leading cause of reported breaches, usually traced back to a rushed moment rather than malice.
Falling for a phishing message
Ransomware incidents at Canadian dental practices and their vendors have traced back to a phishing message reaching someone with access, which is precisely the entry point staff training is meant to close.
Our training for dental practices
What the training program covers for your practice
Sessions are built around the roles that actually exist in a dental office, not a single one-size-fits-all module.

Front desk and CDAnet handling
Covers claims submission, patient check-in data entry, insurance and CDCP eligibility questions, and how to verify a request before acting on it.
Chairside assistants and imaging handling
Covers proper handling of intraoral images, radiographs and CBCT files, and the rule against sharing them outside the PMS.
Hygienists and clinical staff
Covers chart access limited to patients under active treatment, and what to do if something looks like a privacy concern during a hygiene visit.
New associate onboarding
A confidentiality undertaking and orientation session covering the practice's specific policies, so new associates start with the same expectations as everyone already on staff.
Refresher sessions
Shorter recurring sessions to keep training current as staff turn over and as the practice's systems or provincial obligations change.
How the engagement runs
How training is built and delivered
Step 1
Understand your practice
We review your PMS, imaging setup, provinces of operation and staff roles to shape sessions around how your office actually works.
Step 2
Build role-specific modules
Content is developed separately for front desk, assistants, hygienists and associates, rather than a single generic session for everyone.
Step 3
Deliver live or on-demand
Sessions run live for teams that can gather together, or on-demand for staff working different shifts across the practice.
Step 4
Confirm and document completion
Attendance and completion are tracked so the practice can show training happened, not just that it was scheduled.
What it costs
What affects training cost for a dental practice
Cost depends on how many staff need training, how many distinct roles require separate modules, whether the practice needs Quebec Law 25-specific content alongside PHIPA content, and how often refresher sessions are wanted given staff turnover.
The Virtual Privacy Office retainer includes ongoing training and human risk assessments as part of the monthly service, which is often the more efficient route for a practice that wants training handled continuously rather than as a one-off project.
Dental Practices: Training questions, answered
Front desk staff need to understand what information a CDAnet claim transmits, why individual logins matter for the claims switch, and how to spot a submission that looks incorrect before it goes out to an insurer. This is a distinct skill from general PHIPA awareness, since CDAnet handling touches both clinical and insurance data at the same time and staff often treat it as purely administrative work.
Training makes the rule explicit rather than assumed: charts are accessed only for patients under active treatment by that staff member, full stop. Pairing that message with the fact that PMS access is logged and periodically reviewed tends to be far more effective than a policy line nobody ever reads, since staff understand there's a real chance the access would be noticed.
A confidentiality undertaking specific to the practice, acknowledging that patient charts, images and claims data are accessed only for legitimate treatment purposes, and that the associate understands their obligations under PHIPA or the applicable provincial statute. This is typically paired with a short onboarding session so the associate isn't just signing a document but actually understands what it commits them to.
Yes. A hygienist's day-to-day risk centres on chart access during clinical visits and appropriate handling of what they observe or record, while front desk staff face claims submission, phone requests and check-in data entry as their main exposure points. Training that treats both roles identically tends to spend time on scenarios neither group actually encounters.
New hires need onboarding training before they touch the PMS, not weeks into the job, and a practice with regular turnover benefits from shorter refresher sessions on a more frequent cycle than an annual-only schedule would provide. The goal is that no one is using clinical or claims systems without having received the training that applies to their role.
Assistants should understand that images captured chairside belong in the patient's chart within the PMS, not on a personal device or shared by text or personal email, even temporarily. Training also covers what to do if an image is captured on the wrong patient's file, since correcting that quickly and correctly matters for both clinical accuracy and privacy.
More for dental practices
Other services for this niche
About this service
Answers & guides
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.