Policy development · Clinical care providers
Privacy & Security Policy Development for Dental Practices
A dental practice needs a written information-practices notice PHIPA requires patients be able to see, an internal disposal policy that satisfies RCDSO, and, for a Quebec office, a Law 25 policy naming who is responsible for personal information. Most practices come to us because they're opening a new location, being asked for documentation during a DSO acquisition, or realizing they have never actually written any of this down. We draft the specific policies your practice needs, not a generic template.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What a dental practice's policies actually have to cover
The policies exist to answer two audiences at once: patients who want to know what happens to their information, and regulators who want to see it documented.
The patient-facing notice
A plain-language statement of what information the practice collects, why, and who patients can contact with questions, posted or provided the way PHIPA expects.
Retention and disposal rules
Written guidance on how long charts, radiographs and old PMS hardware are kept, and exactly how they're destroyed once retention ends, covering both paper and digital records.
Consent and use of records
Clear language on what patients consent to when treatment is recorded and imaged, and how that consent applies when a chart is shared with a specialist, lab or insurer.
Associate and staff conduct
Internal rules for associates and staff on accessing charts, using CDAnet credentials and handling patient images, so expectations aren't left to informal office culture.
Regulatory map
Why the written policy has to be dental-specific
A borrowed corporate privacy policy misses the obligations that are unique to a dental office, and regulators can tell the difference.
PHIPA's written information practices
Custodians must make information about their privacy practices available to patients, in a form patients can actually access, not buried in a document no one has read.
RCDSO's disposal and retention standard
RCDSO's Electronic Records Management guideline sets out expectations for secure disposal of both records and the hardware that stored them, which a written policy needs to reflect precisely.
RCDSO's retention timelines
RCDSO sets retention at a decade from a chart's last entry, or until a patient turns twenty-eight if the record was made while they were a minor, and the written policy needs to spell out both timelines explicitly.
Quebec's Law 25 and clinic guidance
In Quebec, the policy has to name who is responsible for protecting personal information, describe how the clinic keeps its incident register, and set out when the CAI gets notified, following the profession-specific direction the Ordre des dentistes has already published.
What goes wrong
What happens when the policy exists only in someone's head
The gaps below are real IPC enforcement outcomes, not theoretical risks, and every one traces back to a missing or unclear written policy.
Disposal without a documented standard
One noteworthy IPC finding involved health records simply thrown into a recycling bin rather than destroyed, an outcome a written and followed disposal procedure is meant to make impossible.
Files left where a passerby could find them
A separate matter arose after patient files from a medical building ended up scattered outdoors, the kind of outcome traced back to storage and disposal habits nobody had put in writing.
No answer when a patient asks about their information
Without a written notice, front-desk staff are left improvising an answer when a patient asks what happens to their chart, which is exactly the kind of inconsistency an IPC review looks for.
Our policy development for dental practices
What the policy development engagement produces
The deliverables are written for how your practice actually operates, not adapted from a template built for a different kind of business.

A patient-facing information practices notice
A clear statement of what your practice collects and why, in language patients will actually read, satisfying PHIPA's disclosure requirement.
An internal PHIPA policy
The operational document your staff follow: who the designated contact is, how access requests are handled, and how incidents get escalated.
A retention and disposal policy
Specific timelines matched to RCDSO's rules, and a documented disposal procedure covering paper, radiographs and retired PMS or imaging hardware.
A Quebec Law 25 policy where relevant
For a Quebec clinic, a policy naming the person responsible for personal information, describing the incident register and setting out CAI notification steps.
An associate and staff acceptable-use policy
Rules covering chart access, CDAnet credential use and handling of patient images and CDCP eligibility data, tailored to each role in the practice.
How the engagement runs
How we draft your practice's policies
Step 1
Review current practices
We look at what your practice actually does today, from how consent is captured to how old charts and hard drives are disposed of.
Step 2
Draft the documents
Policies are written around your PMS, your provinces of operation and your patient volume, not copied from a generic compliance package.
Step 3
Review with your team
We walk through the drafts with the principal dentist and office manager to confirm the language matches how the practice actually runs.
Step 4
Finalize and roll out
Final policies are issued alongside guidance for introducing them to staff and posting the patient-facing notice where it needs to be seen.
Step 5
Update as things change
Policies are revisited when the practice adds a location, changes PMS platforms or when RCDSO or provincial requirements shift.
What it costs
What affects the cost of policy development for a dental office
Cost depends on how many provinces your practice operates in, whether a Quebec Law 25 policy is needed alongside an Ontario PHIPA policy, how many distinct systems and vendors the policies need to cover, and how much of your current documentation already exists versus needs to be built from nothing.
Policy development is also included as part of the Minimum Viable Privacy program for a practice building its whole privacy foundation at once. A short conversation is enough to confirm which route makes sense for your office.
Dental Practices: Policy development questions, answered
PHIPA requires custodians to make a general description of their information practices available to patients, covering what personal health information is collected, how it's used, and who to contact with questions or complaints. This is usually satisfied with a posted or handed-out notice written in plain language, distinct from the internal policy staff follow, which can be more detailed and procedural.
It should specify that paper records are cross-cut shredded or professionally destroyed rather than placed in general recycling or waste, and that hard drives and PMS hardware are wiped or physically destroyed before disposal, not simply deleted. The policy should also name who is responsible for confirming disposal happened and how that confirmation gets documented, since an undocumented disposal is difficult to defend if ever questioned.
It needs to name a person responsible for the protection of personal information, along with their contact details, and describe how the clinic maintains its incident register and when it notifies the CAI and affected patients. The Ordre des dentistes has published guidance specific to dental clinics that the policy should follow, rather than a generic Quebec business template that doesn't reflect health-information practice.
Not necessarily a standalone document, but your existing PHIPA and retention policies need to explicitly cover federal eligibility data received through Sun Life Direct for the Canadian Dental Care Plan, since it's personal information flowing through a channel your existing policies may not have anticipated. We build this in as part of the core policy rather than creating a separate document to maintain.
It should state plainly whether associates may access the PMS, patient images or CDAnet from personal devices, and if so, what security measures are required, such as encryption and screen locks. Leaving this unaddressed is a common gap we find, since associates often assume personal-device access is fine unless told otherwise, which creates exposure the policy is meant to prevent.
The patient-facing notice is a short, plain-language summary meeting PHIPA's disclosure requirement, meant for patients to read. The internal policy is the longer operational document your staff actually follow: who the designated contact is, how access requests and incidents are handled, and the retention and disposal rules. Both are needed, and conflating them usually produces a notice too dense for patients or a policy too vague for staff.
More for dental practices
Other services for this niche
About this service
Answers & guides
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.