Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Training · Clinical care providers

Privacy & Security Training for Dental Practices

Privacy and security training for a dental practice teaches front-desk staff, assistants, hygienists and associates the specific behaviours that keep patient charts, images and claims data safe, not generic cybersecurity slides. Practices usually book training after hiring a new front-desk hire who needs to use CDAnet properly, or after realizing staff have never been told the rule against looking up a family member's chart. We build sessions around your actual PMS and imaging workflow.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What dental training has to change in day-to-day behaviour

Most privacy incidents in a dental office come down to a habit, not a technical failure, which is exactly what training is built to correct.

How staff use the practice-management system

Training covers logging in under an individual's own credentials rather than a shared front-desk login, and understanding that every chart opened is recorded.

Handling images and radiographs

Assistants and hygienists learn how intraoral photos, CBCT scans and radiographs move from sensor to chart, and what not to do with them, such as forwarding an image by personal text or email.

Submitting claims through CDAnet

Front desk staff learn what information CDAnet transmits, why credentials for the claims switch aren't shared, and how to spot when a submission looks wrong before it goes out.

Recognizing phishing aimed at the office

Staff learn to recognize the kinds of messages that precede a ransomware incident, since the entry point in most dental office breaches is a person, not a firewall.

Regulatory map

Why training is a compliance expectation, not just good practice

PHIPA and RCDSO both assume staff understand their obligations, and an untrained team is itself a documented gap during any review.

PHIPA's duty of confidentiality

Everyone handling personal health information at a custodian's practice is bound by PHIPA's confidentiality provisions, and training is how a practice demonstrates staff actually understand what that means day to day.

Read our guide →

RCDSO's staff competency expectations

RCDSO's Electronic Records Management guideline assumes staff using clinical software understand access controls and appropriate use, which training is the practical way to establish and document.

Primary source →

Quebec's Law 25 training expectations

Quebec clinics operate under Law 25 obligations the Ordre des dentistes has addressed in profession-specific guidance, which assumes staff have been trained on the clinic's incident and privacy procedures.

Primary source →

What goes wrong

What untrained staff actually cause

These are the patterns training is built to stop, drawn from how dental and health-sector privacy incidents actually happen.

  • Snooping on charts out of curiosity

    Ontario's own reporting shows unauthorized chart-browsing, looking up someone you know rather than someone you're treating, sits near the top of self-reported health-privacy incidents year after year, which makes it a behaviour to unlearn rather than a technical gap to patch.

    Source →

  • Misdirected records and referrals

    A chart, radiograph or referral sent to the wrong recipient by fax, email or the wrong patient's file is another leading cause of reported breaches, usually traced back to a rushed moment rather than malice.

  • Falling for a phishing message

    Ransomware incidents at Canadian dental practices and their vendors have traced back to a phishing message reaching someone with access, which is precisely the entry point staff training is meant to close.

Our training for dental practices

What the training program covers for your practice

Sessions are built around the roles that actually exist in a dental office, not a single one-size-fits-all module.

UX designer creative group working about planing mobile application project with sticky notes. User experience concept
  1. Front desk and CDAnet handling

    Covers claims submission, patient check-in data entry, insurance and CDCP eligibility questions, and how to verify a request before acting on it.

  2. Chairside assistants and imaging handling

    Covers proper handling of intraoral images, radiographs and CBCT files, and the rule against sharing them outside the PMS.

  3. Hygienists and clinical staff

    Covers chart access limited to patients under active treatment, and what to do if something looks like a privacy concern during a hygiene visit.

  4. New associate onboarding

    A confidentiality undertaking and orientation session covering the practice's specific policies, so new associates start with the same expectations as everyone already on staff.

  5. Refresher sessions

    Shorter recurring sessions to keep training current as staff turn over and as the practice's systems or provincial obligations change.

How the engagement runs

How training is built and delivered

  1. Step 1

    Understand your practice

    We review your PMS, imaging setup, provinces of operation and staff roles to shape sessions around how your office actually works.

  2. Step 2

    Build role-specific modules

    Content is developed separately for front desk, assistants, hygienists and associates, rather than a single generic session for everyone.

  3. Step 3

    Deliver live or on-demand

    Sessions run live for teams that can gather together, or on-demand for staff working different shifts across the practice.

  4. Step 4

    Confirm and document completion

    Attendance and completion are tracked so the practice can show training happened, not just that it was scheduled.

What it costs

What affects training cost for a dental practice

Cost depends on how many staff need training, how many distinct roles require separate modules, whether the practice needs Quebec Law 25-specific content alongside PHIPA content, and how often refresher sessions are wanted given staff turnover.

The Virtual Privacy Office retainer includes ongoing training and human risk assessments as part of the monthly service, which is often the more efficient route for a practice that wants training handled continuously rather than as a one-off project.

Dental Practices: Training questions, answered

Front desk staff need to understand what information a CDAnet claim transmits, why individual logins matter for the claims switch, and how to spot a submission that looks incorrect before it goes out to an insurer. This is a distinct skill from general PHIPA awareness, since CDAnet handling touches both clinical and insurance data at the same time and staff often treat it as purely administrative work.

Training makes the rule explicit rather than assumed: charts are accessed only for patients under active treatment by that staff member, full stop. Pairing that message with the fact that PMS access is logged and periodically reviewed tends to be far more effective than a policy line nobody ever reads, since staff understand there's a real chance the access would be noticed.

A confidentiality undertaking specific to the practice, acknowledging that patient charts, images and claims data are accessed only for legitimate treatment purposes, and that the associate understands their obligations under PHIPA or the applicable provincial statute. This is typically paired with a short onboarding session so the associate isn't just signing a document but actually understands what it commits them to.

Yes. A hygienist's day-to-day risk centres on chart access during clinical visits and appropriate handling of what they observe or record, while front desk staff face claims submission, phone requests and check-in data entry as their main exposure points. Training that treats both roles identically tends to spend time on scenarios neither group actually encounters.

New hires need onboarding training before they touch the PMS, not weeks into the job, and a practice with regular turnover benefits from shorter refresher sessions on a more frequent cycle than an annual-only schedule would provide. The goal is that no one is using clinical or claims systems without having received the training that applies to their role.

Assistants should understand that images captured chairside belong in the patient's chart within the PMS, not on a personal device or shared by text or personal email, even temporarily. Training also covers what to do if an image is captured on the wrong patient's file, since correcting that quickly and correctly matters for both clinical accuracy and privacy.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.