MVP program · Clinical care providers
Minimum Viable Privacy Program for Dental Practices
Minimum Viable Privacy gives a new dental practice the baseline it needs to open defensibly: a named contact person, a consent process, retention rules for charts and images, and a disposal procedure, built in weeks rather than assembled piecemeal over the first year. This is built for a startup or newly independent practice opening its first location, before it has the volume or budget for a full retainer. We prioritize what a two-chair office actually needs first.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What a new practice needs covered from day one
A startup practice doesn't need everything a large group needs, but it does need the specific pieces that a regulator or an early complaint would look for immediately.
The very first chart
From the first patient record entered into the PMS, the practice is operating as a PHIPA custodian, so the baseline needs to be in place before, not after, opening day.
PMS and imaging credentials
Default and shared logins on a newly installed practice-management system or imaging workstation are common in a fast setup, and MVP closes that gap before it becomes a habit.
CDAnet claim submission access
A new practice's CDAnet credentials need to be secured and used properly from the first claim submitted, not retrofitted once volume picks up.
The consent conversation with new patients
A consistent, documented approach to what patients are told and asked to consent to when their first chart is opened, rather than an informal explanation that varies by staff member.
Regulatory map
What a startup practice is already on the hook for
PHIPA and RCDSO apply from the moment a practice starts treating patients, regardless of size or how long it's been open.
Custodian status from day one
A newly opened practice is a health information custodian under PHIPA from its first patient, with the same obligations as an established office, just with less time to have built them.
The designated contact requirement
PHIPA section 15 assumes a custodian has someone able to receive complaints and handle privacy matters, and a startup practice needs this named before it has its first difficult conversation with a patient.
RCDSO's baseline for a new office
RCDSO's recordkeeping guidance applies the same retention and access-control expectations to a brand-new practice as to a decades-old one, with no grace period for being newly opened.
What goes wrong
What skipping the baseline actually costs a new practice
The risk for a startup isn't usually a dramatic breach in year one, it's a foundation that has to be rebuilt under pressure later.
A patient complaint with no clear owner
Without a designated contact, a patient's question or concern about their information has nowhere defined to go, which can escalate a small issue into an IPC complaint.
No retention plan means no disposal plan
A practice that never set retention rules also never built a disposal process, leaving old radiographs and charts to accumulate without anyone responsible for eventually destroying them properly.
Growing into gaps instead of a foundation
A practice that adds staff, associates or a second chair without ever having built the baseline ends up retrofitting policies onto an operation that's already running, which is harder than building them first.
Our mvp program for dental practices
What the Minimum Viable Privacy program delivers
MVP is built to establish the essentials a new dental practice needs, sized for a startup rather than a mature multi-location group.

A baseline gap review
A quick assessment of where your practice's current setup, PMS configuration and consent process already meet PHIPA and RCDSO expectations and where they don't yet.
Designated contact person setup
Guidance on naming and documenting your practice's designated contact, whether that's the principal dentist, an office manager, or an outsourced role.
Core policy development
Your patient-facing notice, internal PHIPA policy, and a retention and disposal policy aligned with RCDSO's rules, built for your practice specifically.
Essential safeguard planning
Practical guidance on securing your PMS and imaging systems from the start, including access controls that are simple to maintain as staff join.
A structure that scales
The baseline is built so it can grow into a full Virtual Privacy Office retainer as the practice adds chairs, associates or a second location, rather than needing to be redone.
How the engagement runs
How MVP gets a new practice ready to open
Step 1
Pre-opening assessment
We assess your practice's setup, whether you're pre-opening or newly operating, against what PHIPA and RCDSO require.
Step 2
Prioritize what matters first
We identify the highest-impact gaps, such as a missing designated contact or an undocumented consent process, and address those first.
Step 3
Build the core documents
Policies, the patient-facing notice, and retention and disposal rules are drafted and finalized within the program's defined scope.
Step 4
Hand off with a clear path forward
You leave the program with a working baseline and a clear sense of what to add next as the practice grows, including whether a VPO retainer makes sense down the line.
What it costs
What Minimum Viable Privacy costs for a dental practice
Minimum Viable Privacy is priced at $5,499 CAD per year on a twelve-month term. It bundles coaching, policy development, readiness assessment workshops, and training with human risk assessments for a defined number of seats, sized to get a new or small practice to a defensible baseline without the ongoing scope of a full retainer.
This is typically the right starting point for a single-location practice opening its first chair or two, or an existing practice that has never formally documented its privacy program. Practices that outgrow the baseline, or that operate multiple locations from the start, are usually better served moving to a Virtual Privacy Office retainer.
Dental Practices: MVP program questions, answered
At minimum, a startup needs a named designated contact person, a documented consent process for new patients, a written retention and disposal policy aligned with RCDSO's rules, and basic authentication on the practice-management and imaging systems from the day the first patient is seen. These pieces are deliberately scoped to be achievable for a small practice without the ongoing overhead a larger group would carry.
Yes, in practical terms. PHIPA's obligations apply from your very first patient record, so a practice opening without a written information-practices notice or internal policy is already operating with a gap on day one. Building the core policies before opening, rather than after, also means staff start with clear expectations instead of developing informal habits that need to be corrected later.
It's typically the principal dentist or an office manager who will actually be reachable for patient questions and complaints, though the role can also be handled through an outsourced arrangement if no one on a small founding team wants to take it on personally. What matters is that someone is formally named and documented before the practice opens, not left undecided until a question arises.
You need the policy written before your first patient's chart eventually needs to be disposed of, which for most records is years away, but building the policy at the start means retention decisions are made once, correctly, rather than guessed at later when volume has grown and the stakes are higher. It's one of the lower-effort baseline pieces to get right early.
Set up individual CDAnet credentials for each person submitting claims rather than a shared login, confirm the claims software is properly CDA-certified, and make sure the workstation submitting claims has the same basic access controls as the rest of your PMS. These are quick to establish correctly at setup and considerably harder to unwind once shared credentials become a habit.
More for dental practices
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.