Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

MVP program · Clinical care providers

Minimum Viable Privacy Program for Dental Practices

Minimum Viable Privacy gives a new dental practice the baseline it needs to open defensibly: a named contact person, a consent process, retention rules for charts and images, and a disposal procedure, built in weeks rather than assembled piecemeal over the first year. This is built for a startup or newly independent practice opening its first location, before it has the volume or budget for a full retainer. We prioritize what a two-chair office actually needs first.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What a new practice needs covered from day one

A startup practice doesn't need everything a large group needs, but it does need the specific pieces that a regulator or an early complaint would look for immediately.

The very first chart

From the first patient record entered into the PMS, the practice is operating as a PHIPA custodian, so the baseline needs to be in place before, not after, opening day.

PMS and imaging credentials

Default and shared logins on a newly installed practice-management system or imaging workstation are common in a fast setup, and MVP closes that gap before it becomes a habit.

CDAnet claim submission access

A new practice's CDAnet credentials need to be secured and used properly from the first claim submitted, not retrofitted once volume picks up.

The consent conversation with new patients

A consistent, documented approach to what patients are told and asked to consent to when their first chart is opened, rather than an informal explanation that varies by staff member.

Regulatory map

What a startup practice is already on the hook for

PHIPA and RCDSO apply from the moment a practice starts treating patients, regardless of size or how long it's been open.

Custodian status from day one

A newly opened practice is a health information custodian under PHIPA from its first patient, with the same obligations as an established office, just with less time to have built them.

Read our guide →

The designated contact requirement

PHIPA section 15 assumes a custodian has someone able to receive complaints and handle privacy matters, and a startup practice needs this named before it has its first difficult conversation with a patient.

Read our guide →

RCDSO's baseline for a new office

RCDSO's recordkeeping guidance applies the same retention and access-control expectations to a brand-new practice as to a decades-old one, with no grace period for being newly opened.

Primary source →

What goes wrong

What skipping the baseline actually costs a new practice

The risk for a startup isn't usually a dramatic breach in year one, it's a foundation that has to be rebuilt under pressure later.

  • A patient complaint with no clear owner

    Without a designated contact, a patient's question or concern about their information has nowhere defined to go, which can escalate a small issue into an IPC complaint.

  • No retention plan means no disposal plan

    A practice that never set retention rules also never built a disposal process, leaving old radiographs and charts to accumulate without anyone responsible for eventually destroying them properly.

  • Growing into gaps instead of a foundation

    A practice that adds staff, associates or a second chair without ever having built the baseline ends up retrofitting policies onto an operation that's already running, which is harder than building them first.

Our mvp program for dental practices

What the Minimum Viable Privacy program delivers

MVP is built to establish the essentials a new dental practice needs, sized for a startup rather than a mature multi-location group.

Mother and child interacting with a medical professional in a bright clinic setting during a consultation
  1. A baseline gap review

    A quick assessment of where your practice's current setup, PMS configuration and consent process already meet PHIPA and RCDSO expectations and where they don't yet.

  2. Designated contact person setup

    Guidance on naming and documenting your practice's designated contact, whether that's the principal dentist, an office manager, or an outsourced role.

  3. Core policy development

    Your patient-facing notice, internal PHIPA policy, and a retention and disposal policy aligned with RCDSO's rules, built for your practice specifically.

  4. Essential safeguard planning

    Practical guidance on securing your PMS and imaging systems from the start, including access controls that are simple to maintain as staff join.

  5. A structure that scales

    The baseline is built so it can grow into a full Virtual Privacy Office retainer as the practice adds chairs, associates or a second location, rather than needing to be redone.

How the engagement runs

How MVP gets a new practice ready to open

  1. Step 1

    Pre-opening assessment

    We assess your practice's setup, whether you're pre-opening or newly operating, against what PHIPA and RCDSO require.

  2. Step 2

    Prioritize what matters first

    We identify the highest-impact gaps, such as a missing designated contact or an undocumented consent process, and address those first.

  3. Step 3

    Build the core documents

    Policies, the patient-facing notice, and retention and disposal rules are drafted and finalized within the program's defined scope.

  4. Step 4

    Hand off with a clear path forward

    You leave the program with a working baseline and a clear sense of what to add next as the practice grows, including whether a VPO retainer makes sense down the line.

What it costs

What Minimum Viable Privacy costs for a dental practice

Minimum Viable Privacy is priced at $5,499 CAD per year on a twelve-month term. It bundles coaching, policy development, readiness assessment workshops, and training with human risk assessments for a defined number of seats, sized to get a new or small practice to a defensible baseline without the ongoing scope of a full retainer.

This is typically the right starting point for a single-location practice opening its first chair or two, or an existing practice that has never formally documented its privacy program. Practices that outgrow the baseline, or that operate multiple locations from the start, are usually better served moving to a Virtual Privacy Office retainer.

Dental Practices: MVP program questions, answered

At minimum, a startup needs a named designated contact person, a documented consent process for new patients, a written retention and disposal policy aligned with RCDSO's rules, and basic authentication on the practice-management and imaging systems from the day the first patient is seen. These pieces are deliberately scoped to be achievable for a small practice without the ongoing overhead a larger group would carry.

Yes, in practical terms. PHIPA's obligations apply from your very first patient record, so a practice opening without a written information-practices notice or internal policy is already operating with a gap on day one. Building the core policies before opening, rather than after, also means staff start with clear expectations instead of developing informal habits that need to be corrected later.

It's typically the principal dentist or an office manager who will actually be reachable for patient questions and complaints, though the role can also be handled through an outsourced arrangement if no one on a small founding team wants to take it on personally. What matters is that someone is formally named and documented before the practice opens, not left undecided until a question arises.

You need the policy written before your first patient's chart eventually needs to be disposed of, which for most records is years away, but building the policy at the start means retention decisions are made once, correctly, rather than guessed at later when volume has grown and the stakes are higher. It's one of the lower-effort baseline pieces to get right early.

Set up individual CDAnet credentials for each person submitting claims rather than a shared login, confirm the claims software is properly CDA-certified, and make sure the workstation submitting claims has the same basic access controls as the rest of your PMS. These are quick to establish correctly at setup and considerably harder to unwind once shared credentials become a habit.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.