The hidden data chain behind a dental visit

Dental offices rely on numerous third-party vendors and infrastructure, often without full visibility. Understanding and mapping these data flows is crucial to prevent breaches and maintain patient trust.

Key Highlights

  • Dental practices often depend on a complex network of vendors, making it essential to track how patient data moves through each system.
  • Weak visibility in the 'messy middle' can lead to data breaches, especially when upstream vendors or infrastructure are compromised.
  • Mapping data flows helps practices understand dependencies, identify risks, and ensure compliance beyond just having business associate agreements.
  • Practices should perform simple exercises, like following a single patient journey, to visualize data movement and uncover hidden vulnerabilities.
  • Maintaining transparency and understanding of data dependencies builds trust with patients and strengthens security posture.

A patient walks into a dental office and assumes the entire encounter is managed directly within the office—it’s an independent practice, after all, right? 

You know the story: They fill out their forms. Their medical and dental history is reviewed by a hygienist or an assistant, x-rays are taken, and the dentist does an exam. Then maybe a scan gets sent to a lab or an image to a referring office. The treatment is documented, a claim is submitted, insurance responds, the patient pays their portion, and a follow-up message goes out a few days later. 

See you in six months!  

To the patient, all of that happened in one physical space: their dentist. 

But their information may have traveled through a surprisingly large number of systems and organizations along the way. 

The practice sees “submit claim.” 

The patient sees “my dentist.” 

Between those two vantage points sits what we think of as the messy middle: practice-management software, imaging systems, scanners, laboratories, clearinghouses, payment infrastructure, cloud providers, communication platforms, subcontractors, and people. Keeping an inventory of the vendors, an office uses matters. But what’s even more important is being able to follow the flow of patient data through those vendors and systems. 

Weak visibility or diligence in that messy middle can create real risk of compromised data and breaches, ultimately affecting the patients whose information is moving through it. 

Follow the data, not just the vendor list 

Take a moment and think to yourself: how many vendors and third parties does your practice rely on? 

Five? Fifteen? Don’t know? 

Every office is different, and hopefully there’s tracking somewhere that, at minimum, keeps an inventory of every entity the office works with. But the more useful exercise is to trace the possible patient journeys: where their data goes, who receives it, and what information actually moves through the process.  

Start with intake; was the health history completed on paper, through the practice website, inside a portal, or through a separate forms platform? If it was digital, what technology infrastructure sits behind that experience? 

Now move into the operatory; the clinical record may live in the practice-management system, while radiographs live in separate imaging software. An intraoral camera or digital scanner may operate through another platform. A restorative case can introduce a dental laboratory. A prescription can introduce an e-prescribing workflow. A referral starts another data journey entirely. 

Then we move from treatment to revenue. The front desk submits a claim and the patient pays their portion. That claim may move from the practice-management system through a clearinghouse or RCM partner before reaching a payer. 

Payments may run through another processor, while financing can introduce another company. Patient statements, reminders, records requests, and post-treatment messages may each involve different systems. Underneath many of those visible products can sit infrastructure the practice may not even be aware of: cloud hosting, storage providers, support vendors, and other subprocessors. 

This is one of the realities of the modern dental office. Technology and specialized vendors are critical to the success of many practices, but they can carry unseen risk if the relationships behind them are not properly understood and monitored. 

The most overlooked dependency is often the one the practice never chose—and may not know exists. 

Risk can concentrate far away from the office 

In Patient Protect’s Q1 2026 State of Compliance research, the Secure Care Research Institute identified 207 unique large healthcare breaches affecting approximately 15.9 million people. Four upstream business-associate and platform incidents accounted for 67.6% of all affected individuals while representing only 1.9% of the incidents analyzed.1 

That is the entire point here, a security failure inside one dental office may be relatively contained. A failure at an upstream organization aggregating information across hundreds of healthcare customers can propagate much farther.

The physical practice can be doing many things correctly while substantial exposure exists somewhere the practice cannot see. 

This is one reason the traditional question— “Is our office secure?”—is no longer enough. 

A better question is: what does our office depend on to remain secure? 

Your vendor may have vendors 

Healthcare practices generally understand that certain outside organizations handling protected health information may be business associates and require appropriate agreements. 

The layer that gets less attention is what happens behind that first relationship. 

A software company may depend on cloud infrastructure. An RCM company may use additional service providers. A patient-engagement platform may connect to other systems. Increasingly, AI capabilities may also be embedded inside products the practice has used for years, even if the practice never intentionally purchased an “AI product.” 

HHS specifically recognizes these downstream dependencies. A subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate can itself be a business associate.2 In other words, the data chain does not necessarily end with the company whose logo is on the contract. 

That doesn’t mean practices should stop using outside technology. Modern dentistry could not function efficiently without it. It does, however, mean that outsourcing a function should not be confused with losing interest in what happens next. 

A BAA is important, but it’s not a proper map 

A business associate agreement establishes important obligations. But it does not tell the practice, on its own, how information actually moves through the organization or environment. That requires a different exercise. 

At Patient Protect, one of the methodologies we use is ePHI data-flow mapping: identifying where patient information is created, received, stored, transmitted, and accessed across the practice and its outside relationships.3 The concept is simple enough to do without specialized software. 

First, choose a common patient journey and draw it by answering these questions: 

  • Where does the information begin?  

  • Which system receives it next? 

  • Does that system send it anywhere else? 

  • Who can access it? 

  • What information does each party actually need?

  • Where does the data remain or get stored after the transaction is over? 

Repeat that exercise until the patient reaches the end of the workflow. 

The resulting picture is usually more useful than a spreadsheet. Maintaining visibility into your vendors and business associates matters, but understanding the layers behind those relationships can reveal risks that a vendor list alone cannot. 

And dependencies are what matter when something fails. 

 

The goal is not zero vendors 

None of this is an argument against technology or specialized vendors because modern dental practices depend on outsourcing the “busy work” to increase efficiency and focus on patient care. 

A technology that securely removes hours of manual work can be enormously valuable. A clearinghouse, a payment processor, a lab, an imaging platform, or a communication system may exist because it performs a function better and more securely than the practice could reasonably perform itself. 

The issue is unnecessary complexity—more importantly, invisible complexity. 

Every additional handoff should have a reason to exist. Every handoff should be deliberate, with the information shared matched to the function being performed. And the practice should have some reasonable mechanism for understanding the relationships that remain. 

That doesn’t mean knowing every line of code. It doesn’t mean becoming an IT department. It means being able to explain where patient information goes and why. 

The patient still sees one practice 

Patients generally do not know which clearinghouse processes their dental claim. They do not know which cloud provider sits underneath their imaging software. They may never hear the name of the RCM company working behind the scenes. 

They know and trust their dentist. 

Healthcare has become an ecosystem of interconnected technology, but trust has not fragmented in the same way. 

The patient still places that trust primarily in the practice and the people caring for them. 

So start with one deceptively simple exercise: Pick one patient and follow the data

If you cannot draw the journey from intake through treatment and payment, there are probably dependencies in your practice that you do not fully understand—and may not need. 

So take a moment or two and perform this simple exercise at your next team meeting or with your HIPAA security officer. You cannot govern what you cannot see. 

References 

1. Perrin A. State of compliance: Q1 2026 healthcare breach review. The State of Compliance Series. 1(1). Secure Care Research Institute, Patient Protect LLC; 2026. https://patient-protect.com/research/state-of-compliance-q1-2026  

2. U.S. Department of Health and Human Services, Office for Civil Rights. Business associates. July 30, 2026. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html  

3. Patient Protect. Free ePHI data flow mapper—find missing BAAs & HIPAA gaps. 2026. https://patient-protect.com/hipaa-ephi-data-flow 

About the Author

Alex Perrin

Alex Perrin

Alex Perrin is co-founder and CEO of Patient Protect, a security-first HIPAA compliance platform for independent healthcare practices. He spent two decades leading growth and strategy across enterprise technology and now directs Patient Protect’s product strategy, research program, and market development. He is the primary author of the Secure Care Research Institute’s State of Compliance series. As a co-founder, he has a financial relationship with Patient Protect, which is mentioned in this article. 

Angie Perrin, RDH, CHPC

Angie Perrin, RDH, CHPC

Angie Perrin, RDH, CHPC, is co-founder and Chief Security Officer of Patient Protect and an adjunct dental instructor. An RDH since 2013, she has operated for 15 years inside independent dental practices. Her clinical experience shapes Patient Protect’s HIPAA training, clinical-risk methodology, and practice implementation. As a co-founder, she has a financial relationship with Patient Protect, which is mentioned in this article

Sign up for our eNewsletters
Get the latest news and updates