New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Clinical care providers
Privacy & Security for Dental Practices
Every principal dentist in Ontario is the PHIPA health information custodian for the charts in their operatory, whether the practice runs two chairs or sits inside a forty-location dental service organization. Privacy Horizon supports Canadian dental practices and the groups acquiring them with outsourced privacy and security work: closing gaps against RCDSO's electronic-records expectations, keeping CDAnet and CDCP billing data defensible, and preparing for the day a cyber insurer, an acquiring DSO or the IPC starts asking questions.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
We work with solo and small-group dental offices across Ontario, British Columbia, Alberta and Quebec, from a two-chair startup practice to offices folded into a fast-consolidating dental service organization. The buyer is usually the principal dentist carrying custodian responsibility personally, an office manager running day-to-day compliance, or, inside a DSO, a director of IT or privacy overseeing many acquired locations at once.
Dentistry sits apart from most of Canadian healthcare because claims rarely touch a provincial health plan. Charges move through CDAnet and ITRANS to private insurers, and a share of visits now bill directly to Sun Life under the federal Canadian Dental Care Plan, putting a second billing intermediary in front of every patient's coverage details.
What separates a dental office from the walk-in clinic or specialist next door is the equipment: digital radiography and CBCT sensors bridged straight into the practice-management software, intraoral cameras, and a chairside workflow where imaging is inseparable from the chart rather than something referred out.
Group practices bring a different pressure. When dentalcorp, 123Dentist or a regional roll-up acquires a practice, records custody has to transfer cleanly under RCDSO's rules, and the acquired office's PMS, imaging setup and staff habits rarely match what the rest of the group already runs.

Services
Privacy & security services for dental practices
Each service below is scoped for how dental practices actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Dental Practices
vCISO for dental practices: security leadership that standardizes PMS, imaging and CDAnet controls across a growing group of acquired offices.
Virtual Privacy Officer
Virtual Privacy Officer for Dental Practices
Virtual Privacy Officer for dental practices: an outsourced PHIPA contact person handling the March 1 IPC filing, chart retention and RCDSO record rules.
Penetration Testing
Penetration Testing for Dental Practices
Penetration testing for dental practices: find out if your PMS server, imaging network and Wi-Fi can be reached the way ransomware actually gets in.
Incident Response Planning
Incident Response Planning for Dental Practices
Incident response plan for dental practices: a ransomware-morning runbook covering PHIPA, IPC, RCDSO, insurer notice and paper-based patient care.
Privacy & Security Policy Development
Privacy & Security Policy Development for Dental Practices
Privacy policy development for dental practices: PHIPA-compliant patient notices, RCDSO disposal rules and Quebec Law 25 clinic policies, written for you.
Privacy & Security Training
Privacy & Security Training for Dental Practices
Privacy and security training for dental practices: role-specific sessions for front desk, assistants, hygienists and associates, built around your PMS.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Dental Practices
Vendor security review for dental practices: vet your cloud PMS, imaging AI and recall-tool vendors on data residency, access and PHIPA fit before signing.
M&A Privacy & Security Due Diligence
M&A Privacy & Security Due Diligence for Dental Practices
Privacy due diligence for dental practice acquisitions: chart-custody review, PMS inventory and RCDSO compliance checks before a DSO closes a deal.
Minimum Viable Privacy Program
Minimum Viable Privacy Program for Dental Practices
Minimum Viable Privacy for dental practices: the baseline contact person, consent, retention and disposal setup a new practice needs before opening day.
What you hold
What a dental practice has to protect, chairside and at the front desk
A dental office holds more concentrated patient detail than its footprint suggests: images of a patient's mouth sit next to their benefit plan and their payment card, all reachable from the same front-desk terminal.
Charts, odontograms and treatment plans
The clinical record is the core custodial asset under PHIPA, built up visit by visit in the practice-management software and carried forward through every associate who treats the patient.
Radiographs, CBCT scans and intraoral images
Digital sensors and cameras feed images straight into the chart, and RCDSO treats imaging-capable practice software as raising its own device-class questions once it leaves a single closed system.
Insurance and CDCP eligibility details
Policy numbers, employer group plans and, since the rollout of the Canadian Dental Care Plan, federal eligibility data all pass through the office on their way to a predetermination or a claim.
The practice-management server and its bridges
Dentrix, ABELDent, ClearDent and similar systems sit at the centre of the office, wired to imaging sensors, the recall list and the claims switch, which makes the server the single highest-value target in the building.
Payment card data at checkout
Copay and cosmetic-treatment payments run through a terminal at the front desk, adding PCI DSS obligations on top of the health-privacy duties already attached to the same workstation.
Regulatory map
The regulatory layers sitting on top of a Canadian dental office
A dental practice answers to more than one authority at once: a privacy statute, a professional college, and in Quebec a health-information act layered over both.
PHIPA custodianship in Ontario
Dentists are health information custodians under PHIPA, carrying breach-notification duties, an electronic audit-log requirement, and administrative penalties that can reach into six figures for an organization.
RCDSO's Electronic Records Management guidelines
The College sets the operative technical bar for Ontario practices: access controls, audit trails, encryption and secure disposal, plus explicit warnings about third-party and cloud hosting arrangements.
Quebec's Law 25 and health-information framework
Every clinic in Quebec needs a person responsible for personal information, an incident register and CAI notification duties, and the Ordre des dentistes has issued clinic-specific guidance on top of the province's private health-facility rules.
BC and Alberta's PIPA baseline
Outside Ontario and Quebec, provincial private-sector privacy law sets the floor, with British Columbia requiring a designated privacy officer and reasonable safeguards for every practice.
CDAnet, claims software certification and PIPEDA
Submitting predeterminations and claims through CDAnet and ITRANS requires CDA-certified software, and commercial activity that falls outside provincial health law still answers to PIPEDA.
What goes wrong
How dental practices actually get hurt in Canada
The incidents shaping this niche are documented, not hypothetical, and they repeat because the same conditions exist in most offices.
Ransomware on the office network
A Toronto dental clinic had its network encrypted by Ryuk ransomware, with the attackers escalating their demand mid-negotiation before the practice restored operations from backup.
A benefits administrator holding the data instead
A ransomware attack on the Alberta Dental Service Corporation, the administrator handling provincial dental benefits, showed how a compromise upstream of the chairside office can still expose patient data.
Staff looking at charts they have no reason to open
Snooping by employees who access a family member's or coworker's chart out of curiosity is a leading cause of self-reported health-privacy breaches in Ontario, and it is almost always preventable with access logging and clear rules.
Paper and hardware disposed of the wrong way
The IPC has ordered a clinic over patient records recoverable from a recycling bin, a reminder that shredding and drive destruction are enforceable, not optional.
Encryption alone still counts as a breach
Recent IPC decisions treat records encrypted by ransomware, even without confirmed exfiltration, as a loss requiring notification, closing the argument that an untouched backup means nothing to report.
When organisations call us
The moments that bring a practice to Privacy Horizon
Interest in privacy and security work rarely starts as a proactive project. It follows a specific event landing on the principal dentist's desk.
A ransomware headline close to home
News of an attack on a nearby practice or on a benefits administrator the office relies on turns an abstract risk into an urgent question about the office's own network.
A tougher cyber-insurance renewal
Insurers now ask specific questions about MFA, backups and access controls before renewing coverage, and vague answers show up as higher premiums or added exclusions.
A DSO acquisition on the table
An offer to join a dental service organization brings due-diligence questions about records custody, PMS condition and past incidents that a seller needs to be ready to answer.
Moving off a server-based PMS
RCDSO flags the transition from an in-office server to a cloud-hosted practice-management system as the riskiest stretch in a system's life, which is exactly when practices come looking for guidance.
An RCDSO inspection or patient complaint
A College practice inspection, or a complaint escalated to the IPC, forces a practice to demonstrate its safeguards on a timeline it did not choose.
Onboarding to the Canadian Dental Care Plan
Setting up direct billing to Sun Life under the CDCP means a new data flow and a new set of questions about who can see federal eligibility information.
Dental Practices: privacy & security questions, answered
Yes. PHIPA does not exempt small offices: any dentist providing health care in Ontario is a health information custodian under the Act, whether they practise alone or with a dozen associates. The same breach-notification duties, the same audit-log expectation and the same exposure to IPC review apply regardless of headcount. Size affects how much infrastructure is needed to meet the standard, not whether the standard applies.
A Virtual Privacy Officer takes on the PHIPA-facing work: designated contact duties, patient consent questions, retention rules and the annual IPC filing. A vCISO takes on the technical security side: risk assessment, MFA and network design, and standardizing controls across multiple acquired locations. A solo practice often needs one or the other; a multi-location DSO usually ends up wanting both, working from the same facts.
No. A solo practice mainly needs a defensible baseline: a designated contact, a written policy, retention and disposal rules, and staff who know not to browse charts out of curiosity. A DSO-owned practice adds a layer: standardizing that baseline across offices that came in with different PMS platforms, different IT habits and different histories, while satisfying acquisition due-diligence and group-wide insurer requirements at the same time.
No, and treating them as identical is a common mistake. Ontario dentists carry PHIPA custodian duties layered under RCDSO guidance. British Columbia and Alberta clinics generally operate under provincial PIPA, with different notification triggers than Ontario. Quebec adds Law 25 obligations and health-information rules specific to private clinics, with its own regulator and its own incident register requirement. A practice operating in more than one province needs each layer addressed on its own terms.
Start with an honest look at what's missing against PHIPA and RCDSO expectations, then fix what's concentrated and cheap to fix first: a named contact person, access controls on the PMS and imaging systems, a written retention and disposal rule, and a short policy patients can actually read. Training and vendor questions follow once that baseline is in place. A packaged starting point exists specifically so a busy practice doesn't have to design this from scratch.
The acquiring group will expect records custody to transfer cleanly under RCDSO's rules, alongside a working answer to how the practice's PMS, imaging setup and staff training compare to its existing standard. Practices that walk into that conversation with documented policies, a clean access-control history and no unresolved incidents negotiate from a stronger position than ones producing the paperwork for the first time during diligence.
Related industries
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.