Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Vendor security reviews · Clinical care providers

Vendor Security Review & Questionnaire Support for Dental Practices

A vendor security review checks a PMS, imaging or recall vendor before your practice hands them patient data, answering the questions RCDSO expects a dentist to have already asked. Most practices order this before switching practice-management platforms, before connecting an AI x-ray analysis tool, or when a DSO is standardizing which vendors every acquired office is allowed to use. We review the vendor, not your own systems.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What's at stake when a dental practice chooses a vendor

Every vendor connected to the PMS becomes a place your patients' information now lives, whether or not that was the intent when the contract was signed.

Where charts and images are actually hosted

A cloud PMS or imaging platform may store data outside Canada, which changes the legal exposure and the questions a practice needs answered before signing.

Who can access patient data at the vendor

Support staff, subcontractors and AI processing pipelines at the vendor may have access to chart or image data the practice never explicitly authorized.

Custody during a migration

Moving from one PMS to another, or from a server-based system to the cloud, creates a window where two vendors may both hold copies of the same patient records.

What happens if the vendor is breached

A vendor's incident becomes the practice's problem regardless of fault, so their own security posture and breach-notification commitments matter before the contract is signed, not after.

Regulatory map

Why vendor vetting is a dental-specific obligation

RCDSO addresses third-party hosting directly, and the custodian's accountability doesn't transfer just because a vendor is holding the data.

RCDSO's stance on third-party hosting

RCDSO's Electronic Records Management guideline names third-party and cloud hosting arrangements specifically, treating the dentist as the party who stays answerable no matter which vendor's servers the chart actually sits on.

Primary source →

PHIPA accountability for outsourced processing

A custodian remains accountable for personal health information handled by an agent or service provider, which means vendor vetting is part of meeting PHIPA's obligations, not a separate exercise.

Read our guide →

Imaging software as a device-class question

RCDSO treats imaging-capable patient software as raising its own medical device classification questions, a consideration that applies specifically to vendors handling radiographs, CBCT or intraoral images.

Primary source →

CDA certification for claims software

Software submitting claims through CDAnet must be CDA-certified, which is a baseline vetting question distinct from the general privacy and security review of the vendor.

Primary source →

What goes wrong

What an unreviewed vendor exposes you to

These are the specific risk patterns a dental vendor review is designed to catch before a contract is signed, not after.

  • Migration as the highest-risk moment

    Moving records from a server-based PMS to a cloud platform is, in RCDSO's own framing, the point where a practice's data is most exposed, since two vendors may briefly hold the same information during the switch.

    Source →

  • AI imaging tools with unclear data handling

    AI x-ray and diagnostic analysis tools connect to imaging systems and may send patient images off-site for processing, sometimes without the practice having confirmed where that data goes or how long it's retained.

  • Recall and SMS tools reaching outside the PMS

    Appointment reminder and recall services often hold patient names, contact details and appointment information outside the core PMS, a separate vendor relationship that gets reviewed less often than the PMS itself.

Our vendor security reviews for dental practices

What the vendor review covers

The review is built around the vendor categories a dental practice actually contracts with, not a generic SaaS vendor checklist.

Skilled team of developers using modern technologies for testing application online showing to leader, multiracial young crew of students concentrated on working process watching v
  1. PMS vendor review

    Data residency, access controls, breach notification commitments and support-staff access are reviewed for platforms such as Dentrix, ABELDent, ClearDent and comparable systems.

  2. Imaging and AI vendor review

    Where radiographs, CBCT or intraoral images are processed by an AI analysis tool, we review what data leaves the practice, where it's processed, and how it's retained or deleted.

  3. Recall and communication tool review

    Recall lists, appointment reminder and SMS platforms are reviewed for how they store and secure patient contact information outside the PMS.

  4. Contract and data residency confirmation

    We help identify the specific questions to put to the vendor and review their answers and contract terms around hosting location and data ownership.

  5. A migration risk review

    For practices switching PMS platforms, we review what happens to data during the transition and what the outgoing and incoming vendors each commit to.

How the engagement runs

How the vendor review runs

  1. Step 1

    Identify the vendors in scope

    We confirm which vendors touch patient or claims data, including ones added informally over time that may not be on anyone's official list.

  2. Step 2

    Send the vendor questionnaire

    A set of dental-specific questions covering hosting location, access controls and breach commitments goes to each vendor under review.

  3. Step 3

    Assess the responses and contract terms

    We evaluate what the vendor actually commits to against what your practice needs, flagging gaps between marketing claims and contract language.

  4. Step 4

    Report and recommend

    You receive a clear summary of each vendor's standing, with specific questions or contract changes to pursue before signing or renewing.

What it costs

What affects vendor review cost for a dental practice

Cost depends on how many vendors are in scope, whether the review covers a single new tool or a full inventory across PMS, imaging, billing and recall systems, and whether a DSO wants one standardized review applied across multiple acquired practices.

A short conversation about which vendors you're evaluating, and whether this is a one-time decision or an ongoing part of your program, is enough to scope the work.

Dental Practices: Vendor security reviews questions, answered

That depends entirely on the vendor and needs to be confirmed directly rather than assumed. Some cloud PMS platforms host in Canada; others use infrastructure in the United States or elsewhere, which changes the legal considerations around where your patients' data actually sits. A vendor review confirms hosting location in writing rather than relying on a sales conversation.

Ask exactly what image data leaves the practice, where it's processed, whether it's used to train the vendor's models, how long it's retained, and what happens to it if you cancel the service. RCDSO's framing of imaging-capable software as a device-class question also means confirming what regulatory status the tool itself carries, separate from the standard privacy and security questions.

Many recall and appointment-reminder tools are built for general business use and may not be designed with health-privacy obligations in mind, even though they handle patient names and appointment details. A review checks whether the provider has appropriate safeguards, a clear data-handling agreement, and Canadian or otherwise defensible hosting, rather than assuming a popular tool automatically meets the standard.

The same core questions apply regardless of platform: where is data hosted, what access controls exist, what happens to your existing data during migration, and what the vendor commits to in writing around breach notification and support-staff access. Marketed certifications and Canadian hosting claims should be confirmed against the actual contract, not just the vendor's website.

Beyond the standard vendor questions, ask specifically how the migration itself is secured: how existing charts, images and claims history transfer, whether the old server's data is properly wiped afterward, and what access the vendor's migration team has during the transition. RCDSO treats this changeover as the moment a practice's systems carry the most risk, so the migration deserves its own review, not just the destination platform.

Yes, though the questions differ slightly. Claims software needs to be CDA-certified as a baseline, and beyond that a review should confirm how claims data in transit is protected and how long transaction records are retained by the switch. Since claims data overlaps with clinical and insurance information, treating it as a separate, unreviewed system is a common gap.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.