Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Policy development · Clinical care providers

Privacy & Security Policy Development for Dental Practices

A dental practice needs a written information-practices notice PHIPA requires patients be able to see, an internal disposal policy that satisfies RCDSO, and, for a Quebec office, a Law 25 policy naming who is responsible for personal information. Most practices come to us because they're opening a new location, being asked for documentation during a DSO acquisition, or realizing they have never actually written any of this down. We draft the specific policies your practice needs, not a generic template.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What a dental practice's policies actually have to cover

The policies exist to answer two audiences at once: patients who want to know what happens to their information, and regulators who want to see it documented.

The patient-facing notice

A plain-language statement of what information the practice collects, why, and who patients can contact with questions, posted or provided the way PHIPA expects.

Retention and disposal rules

Written guidance on how long charts, radiographs and old PMS hardware are kept, and exactly how they're destroyed once retention ends, covering both paper and digital records.

Consent and use of records

Clear language on what patients consent to when treatment is recorded and imaged, and how that consent applies when a chart is shared with a specialist, lab or insurer.

Associate and staff conduct

Internal rules for associates and staff on accessing charts, using CDAnet credentials and handling patient images, so expectations aren't left to informal office culture.

Regulatory map

Why the written policy has to be dental-specific

A borrowed corporate privacy policy misses the obligations that are unique to a dental office, and regulators can tell the difference.

PHIPA's written information practices

Custodians must make information about their privacy practices available to patients, in a form patients can actually access, not buried in a document no one has read.

Read our guide →

RCDSO's disposal and retention standard

RCDSO's Electronic Records Management guideline sets out expectations for secure disposal of both records and the hardware that stored them, which a written policy needs to reflect precisely.

Primary source →

RCDSO's retention timelines

RCDSO sets retention at a decade from a chart's last entry, or until a patient turns twenty-eight if the record was made while they were a minor, and the written policy needs to spell out both timelines explicitly.

Primary source →

Quebec's Law 25 and clinic guidance

In Quebec, the policy has to name who is responsible for protecting personal information, describe how the clinic keeps its incident register, and set out when the CAI gets notified, following the profession-specific direction the Ordre des dentistes has already published.

Primary source →

What goes wrong

What happens when the policy exists only in someone's head

The gaps below are real IPC enforcement outcomes, not theoretical risks, and every one traces back to a missing or unclear written policy.

  • Disposal without a documented standard

    One noteworthy IPC finding involved health records simply thrown into a recycling bin rather than destroyed, an outcome a written and followed disposal procedure is meant to make impossible.

    Source →

  • Files left where a passerby could find them

    A separate matter arose after patient files from a medical building ended up scattered outdoors, the kind of outcome traced back to storage and disposal habits nobody had put in writing.

    Source →

  • No answer when a patient asks about their information

    Without a written notice, front-desk staff are left improvising an answer when a patient asks what happens to their chart, which is exactly the kind of inconsistency an IPC review looks for.

Our policy development for dental practices

What the policy development engagement produces

The deliverables are written for how your practice actually operates, not adapted from a template built for a different kind of business.

Two data analysts Working on data analysis dashboard for business strategy
  1. A patient-facing information practices notice

    A clear statement of what your practice collects and why, in language patients will actually read, satisfying PHIPA's disclosure requirement.

  2. An internal PHIPA policy

    The operational document your staff follow: who the designated contact is, how access requests are handled, and how incidents get escalated.

  3. A retention and disposal policy

    Specific timelines matched to RCDSO's rules, and a documented disposal procedure covering paper, radiographs and retired PMS or imaging hardware.

  4. A Quebec Law 25 policy where relevant

    For a Quebec clinic, a policy naming the person responsible for personal information, describing the incident register and setting out CAI notification steps.

  5. An associate and staff acceptable-use policy

    Rules covering chart access, CDAnet credential use and handling of patient images and CDCP eligibility data, tailored to each role in the practice.

How the engagement runs

How we draft your practice's policies

  1. Step 1

    Review current practices

    We look at what your practice actually does today, from how consent is captured to how old charts and hard drives are disposed of.

  2. Step 2

    Draft the documents

    Policies are written around your PMS, your provinces of operation and your patient volume, not copied from a generic compliance package.

  3. Step 3

    Review with your team

    We walk through the drafts with the principal dentist and office manager to confirm the language matches how the practice actually runs.

  4. Step 4

    Finalize and roll out

    Final policies are issued alongside guidance for introducing them to staff and posting the patient-facing notice where it needs to be seen.

  5. Step 5

    Update as things change

    Policies are revisited when the practice adds a location, changes PMS platforms or when RCDSO or provincial requirements shift.

What it costs

What affects the cost of policy development for a dental office

Cost depends on how many provinces your practice operates in, whether a Quebec Law 25 policy is needed alongside an Ontario PHIPA policy, how many distinct systems and vendors the policies need to cover, and how much of your current documentation already exists versus needs to be built from nothing.

Policy development is also included as part of the Minimum Viable Privacy program for a practice building its whole privacy foundation at once. A short conversation is enough to confirm which route makes sense for your office.

Dental Practices: Policy development questions, answered

PHIPA requires custodians to make a general description of their information practices available to patients, covering what personal health information is collected, how it's used, and who to contact with questions or complaints. This is usually satisfied with a posted or handed-out notice written in plain language, distinct from the internal policy staff follow, which can be more detailed and procedural.

It should specify that paper records are cross-cut shredded or professionally destroyed rather than placed in general recycling or waste, and that hard drives and PMS hardware are wiped or physically destroyed before disposal, not simply deleted. The policy should also name who is responsible for confirming disposal happened and how that confirmation gets documented, since an undocumented disposal is difficult to defend if ever questioned.

It needs to name a person responsible for the protection of personal information, along with their contact details, and describe how the clinic maintains its incident register and when it notifies the CAI and affected patients. The Ordre des dentistes has published guidance specific to dental clinics that the policy should follow, rather than a generic Quebec business template that doesn't reflect health-information practice.

Not necessarily a standalone document, but your existing PHIPA and retention policies need to explicitly cover federal eligibility data received through Sun Life Direct for the Canadian Dental Care Plan, since it's personal information flowing through a channel your existing policies may not have anticipated. We build this in as part of the core policy rather than creating a separate document to maintain.

It should state plainly whether associates may access the PMS, patient images or CDAnet from personal devices, and if so, what security measures are required, such as encryption and screen locks. Leaving this unaddressed is a common gap we find, since associates often assume personal-device access is fine unless told otherwise, which creates exposure the policy is meant to prevent.

The patient-facing notice is a short, plain-language summary meeting PHIPA's disclosure requirement, meant for patients to read. The internal policy is the longer operational document your staff actually follow: who the designated contact is, how access requests and incidents are handled, and the retention and disposal rules. Both are needed, and conflating them usually produces a notice too dense for patients or a policy too vague for staff.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.