
HIPAA Security Overhaul for a Teledentistry Programme
Let's Connect
Overview
What we built
A teledentistry programme screening patients across 30 school and community sites had outgrown its consumer-grade tooling, and its grant funders now wanted proof of HIPAA compliance it could not provide. We moved it onto a compliant stack without interrupting a single screening day.
In plain terms: hygienists were doing valuable clinical work on tools built for everyday consumers. Video consults ran on ordinary consumer apps, intraoral images travelled from personal devices to shared drives, and none of the vendors handling patient data had signed the business associate agreements healthcare rules require. The programme had grown faster than its technology, and when grant funders began asking for evidence of HIPAA compliance, it faced audits it knew it could not pass.
We replaced the stack piece by piece while screening days carried on. Consults moved to a BAA-covered healthcare video platform, images now flow encrypted from managed devices into access-controlled cloud storage, and staff sign in once with permissions matched to their role. Around the technology we ran a Security Rule risk assessment, trained the workforce and built a centralised evidence log. Safeguard coverage rose from 31% to 96% of assessed controls, all 6 vendors signed business associate agreements, and preparing audit evidence for grant reviews now takes 4 days instead of 6 weeks.
The Problem
Patient data on consumer tools
The programme's mission had outrun its tooling. What began as a small screening effort now reached patients across 30 school and community sites, but the technology had never been upgraded to match. Hygienists ran video consults on consumer-grade apps never intended for clinical use, and intraoral images were captured on personal devices and uploaded to shared drives with none of the access controls patient data requires.
The paperwork was just as exposed as the technology. No vendor in the chain, video, storage or otherwise, had signed a business associate agreement, the contractual foundation HIPAA expects whenever a third party handles patient data. There was no documented risk assessment, no structured workforce training and no organised evidence of safeguards, because the programme had grown out of clinical enthusiasm rather than an IT department.
Then the stakes changed. Grant funders began requiring evidence of HIPAA compliance as a condition of the money that kept screening days running. The programme faced audits it could not pass, which put its funding, and with it the dental screening of the communities it serves, at genuine risk.
Consumer video tools
Hygienists ran video consults on consumer-grade apps never designed for clinical use, with no healthcare agreements behind them and patient conversations outside HIPAA cover.
Images on shared drives
Intraoral images were uploaded from personal devices to shared drives, with no encryption, access control or record of who had seen what.
No signed BAAs
Not one vendor handling patient data had signed a business associate agreement, a foundational HIPAA requirement for any third party touching patient information.
Funding at risk
Grant funders now required evidence of HIPAA compliance, and the programme faced audits it could not pass with its existing tooling and records.
What it was costing them
The exposure ran in two directions. Patient trust was at stake every time an intraoral image sat on a shared drive or a consult ran over a consumer app, with no agreements or access controls protecting the data. And the funding was at stake too: with funders demanding compliance evidence the programme could not produce, every grant review threatened the screening days that 30 sites of patients depended on.
The Solution
HIPAA-aligned teledentistry stack
The constraint that shaped everything was continuity: screening days at 30 school and community sites could not stop while the programme modernised. So we sequenced the work as a series of swaps, each replacing one risky practice with a compliant equivalent, and each timed around the screening calendar so hygienists never lost a working day to the transition.
Consults moved to a BAA-covered healthcare video platform, and image capture was rebuilt end to end: encrypted at capture, flowing into access-controlled cloud storage, with personal devices replaced by managed devices at every site. Single sign-on with role-based permissions now governs access, so each staff member reaches exactly what their role requires and nothing more.
Compliance is more than tooling, so we treated the paperwork as a deliverable in its own right. A HIPAA Security Rule risk assessment established where the gaps were and tracked them to closure, workforce training gave hygienists and coordinators clear handling rules, and a centralised evidence log now captures safeguards, agreements and training records in one place, keeping the programme permanently audit-ready rather than scrambling before each review.
Key decisions
Swap tools without stopping screenings
Each risky practice was replaced by a compliant one in sequence, timed around the screening calendar, so clinical work never paused for the modernisation.
Agreements before technology
Every vendor in the new stack signed a business associate agreement, making the contractual foundation part of tool selection rather than an afterthought.
Encrypt from the point of capture
Intraoral images are encrypted as they are captured and land directly in access-controlled cloud storage, taking shared drives and personal devices out of the flow entirely.
Managed devices at every site
Programme-owned, managed devices replaced personal devices across the sites, giving the organisation control over every endpoint that touches patient data.
Evidence as a habit
A centralised compliance log collects safeguards, agreements and training records continuously, so audit evidence is assembled by default rather than reconstructed under deadline.
Measurable Impact
What changed after launch
The programme's HIPAA Security Rule safeguard coverage rose from 31% to 96% of assessed controls across two review cycles, and signed business associate agreements are now in place with all 6 vendors that handle patient data, up from zero. Every patient image, 100% of them, moved off shared drives into encrypted, access-controlled storage within 10 weeks.
For the people running the programme, the clearest change is at review time. Audit evidence preparation for grant reviews dropped from 6 weeks of scrambling to 4 days of assembly from the centralised compliance log. Screening days at the 30 sites never stopped through the transition, and the programme now approaches funder audits as routine rather than existential.
Video consults
Consumer-grade apps with no healthcare agreements
A BAA-covered healthcare video platform
Patient images
Personal devices uploading to shared drives
Encrypted capture into access-controlled cloud storage
Safeguard coverage
31% of assessed Security Rule controls covered
96% coverage across two review cycles
Audit preparation
6 weeks of evidence gathering per review
4 days from the centralised compliance log
Headline results
HIPAA Security Rule safeguard coverage rose from 31% to 96% of assessed controls across two review cycles
100% of patient images migrated off shared drives into encrypted, access-controlled storage within 10 weeks
Signed business associate agreements secured with all 6 vendors handling patient data, up from zero
Audit evidence preparation for grant reviews cut from 6 weeks to 4 days via the centralised compliance log
Tech & Tools Used
What powered the build
Every tool below earned its place in this engagement. Here is the part each one played.
Zoom for Healthcare
The BAA-covered video platform where hygienists now run patient consults, replacing the consumer-grade apps that had no healthcare agreements behind them.
Okta
Provides single sign-on with role-based permissions across the stack, so each staff member reaches only the patient data their role requires.
AWS S3 + KMS
The access-controlled cloud storage where encrypted intraoral images now live, with managed encryption keys replacing the open shared drives they came from.
AWS CloudTrail
Records who accessed what across the cloud environment, giving the programme the trail of activity evidence that HIPAA reviews expect to see.
Vanta
Runs continuous compliance monitoring and feeds the centralised evidence log, tracking safeguard status, agreements and training so the programme stays audit-ready.
Jamf
Manages the programme-owned devices at every site, enforcing encryption and configuration policies on the hardware that replaced personal devices.
Next.js
Powers the web front end of the programme's centralised compliance log, where staff record and retrieve safeguards, agreements and training evidence.
Node.js
Runs the services behind the compliance log and the image-handling workflow, connecting capture, storage and evidence records under the new access controls.
PostgreSQL
Stores the compliance log's structured records, keeping safeguards, vendor agreements and training completions queryable whenever a grant review arrives.
Ready to Build your Teledentistry & Dental Public Health Business with HIPAA & Security Compliance
Ask Byte
Ask Byte
Typically replies instantly
just Now
Hi! I'm OrganByte's assistant. How can I help you today?
AI-generated content may be incorrect

