
AI Security and Compliance Programme for a 55-Office Dental Group Adopting Radiograph Claims AI
Let's Connect
Overview
What we built
A 55-office dental group was rolling out AI-reviewed radiograph claims with patient imaging about to flow to a third party and no formal risk assessment behind it. We built the security and compliance programme that made the rollout defensible.
In plain terms: this 55-office dental support organisation had chosen a regulator-cleared AI service to review radiographs attached to insurance claims, but the rollout was running ahead of its own governance. Patient imaging was about to start flowing to a third party with no formal vendor risk assessment completed, individual offices were enrolling on an ad hoc basis using shared logins, and compliance leadership had no audit trail showing where PHI travelled or who had accessed the AI outputs it produced.
We delivered the security and compliance programme the rollout needed: full PHI data-flow mapping, a vendor risk assessment against HIPAA and SOC 2 controls, an encrypted gateway stripping extraneous patient identifiers before radiographs left the network, role-based single sign-on replacing shared logins, and centralised audit logging with quarterly access reviews across all 55 offices. Data flows were mapped and documented across every office in 10 weeks, over 400 staff moved off shared credentials, and compliance audit preparation time fell from 3 weeks to 4 days per cycle.
The Problem
PHI exposure across AI rollout
The dental group had made a sound clinical choice, a regulator-cleared AI service that reviews radiographs attached to insurance claims across its 55 offices, but the compliance work behind that choice had not kept pace. Patient imaging was about to start flowing to a third party, and nobody had completed a formal vendor risk assessment before that traffic began.
Access control at the office level was just as loose. Offices were enrolling in the AI service ad hoc, each on its own timetable, and staff were logging in with shared credentials rather than individual accounts. That meant no one could say with confidence which staff member had actually viewed a given patient's radiograph or AI output.
Compliance leadership felt the gap most directly. There was no audit trail showing where PHI travelled once it left an office, no record of who accessed AI outputs, and no consistent way to demonstrate control across all 55 offices at once. Every regulator question about this new AI channel had to be answered from memory rather than from a log.
No vendor risk assessment
Patient imaging was about to flow to a third-party AI service with no formal risk assessment completed against HIPAA and SOC 2 controls.
Ad hoc office enrolment
Offices joined the AI rollout on their own timetable, so no consistent onboarding or access standard existed across the 55-office estate.
Shared login credentials
Staff accessed the AI service through shared logins rather than individual accounts, making it impossible to attribute a given access to a person.
No PHI audit trail
Compliance leadership had no record showing where patient imaging travelled or who had accessed the AI outputs it produced across any of the 55 offices.
What it was costing them
Every radiograph sent to the AI service without a completed risk assessment was an unassessed exposure of patient imaging, and shared logins meant a compliance question about a single access event had no answer. Preparing for an audit meant reconstructing activity from memory across all 55 offices, a slow and unreliable process, while leadership carried the risk of a regulator asking a question the organisation simply could not answer from any log.
The Solution
Security and compliance programme
We started with full PHI data-flow mapping, tracing exactly where patient imaging travelled from the moment a radiograph left an office through to the AI service and back into the claim. That map became the foundation for a formal vendor risk assessment against HIPAA and SOC 2 controls, closing the gap that had let imaging flow with no assessment behind it.
We then built the technical controls the rollout needed. An encrypted gateway now strips extraneous patient identifiers before radiographs leave the network, reducing what actually reaches the third party, while role-based single sign-on replaced the shared logins offices had been using, giving every access event a named owner rather than an anonymous shared account across the estate.
Finally we made oversight continuous rather than reactive. Centralised audit logging now records every access to PHI and AI outputs, and quarterly access reviews run across all 55 offices, giving compliance leadership a standing answer to where PHI travelled and who touched the AI outputs it produced at any point.
Key decisions
Map data flows before assessing risk
Full PHI data-flow mapping came first, giving the vendor risk assessment against HIPAA and SOC 2 controls a complete picture to evaluate.
Strip identifiers at the gateway
An encrypted gateway removes extraneous patient identifiers before radiographs leave the network, reducing exactly what reaches the third-party AI service on every transfer.
Replace shared logins with SSO
Role-based single sign-on gave every staff member an individual, audited account, ending the practice of shared credentials across all 55 offices.
Centralise audit logging
Every access to PHI or AI outputs is now logged centrally, giving compliance leadership one place to answer any regulator question.
Run quarterly access reviews
Quarterly access reviews across all 55 offices turned oversight into a recurring habit rather than a one-off exercise tied to the rollout.
Measurable Impact
What changed after launch
The programme turned an ungoverned rollout into a documented one. PHI data flows for the claims AI were mapped and documented across all 55 offices in 10 weeks, and 100% of AI-bound radiograph transfers now route through the encrypted de-identification gateway before leaving the network.
Access moved from anonymous to accountable. Shared credentials were eliminated, with over 400 staff moved to individually audited role-based accounts, and compliance audit preparation time fell from 3 weeks to 4 days per cycle, since the evidence auditors need now lives in the centralised log rather than in memory.
Vendor risk
No formal assessment before imaging flowed to the AI service
Full HIPAA and SOC 2 risk assessment completed
Data-flow visibility
No documented map of where PHI travelled
Flows mapped across all 55 offices in 10 weeks
Staff access
Shared logins with no individual attribution
Over 400 staff on audited role-based accounts
Audit preparation
Around 3 weeks reconstructing activity from memory
4 days per cycle using the centralised log
Headline results
PHI data flows for the claims AI mapped and documented across all 55 offices in 10 weeks
100% of AI-bound radiograph transfers routed through the encrypted de-identification gateway
Shared credentials eliminated, with over 400 staff moved to individually audited role-based accounts
Compliance audit preparation time reduced from 3 weeks to 4 days per cycle
Tech & Tools Used
What powered the build
Every tool below earned its place in this engagement. Here is the part each one played.
Python (FastAPI)
Runs the gateway service that strips extraneous patient identifiers from radiographs before they leave the network en route to the AI service.
AWS KMS
Manages the encryption keys protecting patient imaging and audit data in transit and at rest, underpinning the gateway's de-identification process.
AWS CloudTrail
Records infrastructure-level activity around the compliance programme, feeding the centralised audit logging reviewed each quarter across every office.
HashiCorp Vault
Stores the credentials and secrets the gateway and access services depend on, keeping them out of application code and configuration files.
Okta SSO
Delivers the role-based single sign-on that replaced shared logins, giving each of the over 400 staff an individually audited account.
Orthanc (DICOM)
Handles the DICOM radiograph traffic passing through the gateway, giving the compliance programme a consistent point to apply de-identification.
PostgreSQL
Stores the mapped PHI data flows and the audit log behind every access event across all 55 offices.
Terraform
Provisions the gateway, access-control and logging infrastructure consistently, so the same controls apply whichever office is being onboarded.
Grafana
Displays the dashboards compliance leadership uses during quarterly access reviews to check activity and access patterns across all 55 offices.
Ready to Build your Dental Healthcare Business with AI Security & Data Privacy
Ask Byte
Ask Byte
Typically replies instantly
just Now
Hi! I'm OrganByte's assistant. How can I help you today?
AI-generated content may be incorrect

