Hero
Modernization
HIPAA & Security Compliance
Teledentistry & Dental Public Health

HIPAA Security Overhaul for a Teledentistry Programme


Let's Connect

Overview

What we built

A teledentistry programme screening patients across 30 school and community sites had outgrown its consumer-grade tooling, and its grant funders now wanted proof of HIPAA compliance it could not provide. We moved it onto a compliant stack without interrupting a single screening day.

In plain terms: hygienists were doing valuable clinical work on tools built for everyday consumers. Video consults ran on ordinary consumer apps, intraoral images travelled from personal devices to shared drives, and none of the vendors handling patient data had signed the business associate agreements healthcare rules require. The programme had grown faster than its technology, and when grant funders began asking for evidence of HIPAA compliance, it faced audits it knew it could not pass.

We replaced the stack piece by piece while screening days carried on. Consults moved to a BAA-covered healthcare video platform, images now flow encrypted from managed devices into access-controlled cloud storage, and staff sign in once with permissions matched to their role. Around the technology we ran a Security Rule risk assessment, trained the workforce and built a centralised evidence log. Safeguard coverage rose from 31% to 96% of assessed controls, all 6 vendors signed business associate agreements, and preparing audit evidence for grant reviews now takes 4 days instead of 6 weeks.

The Problem

Patient data on consumer tools

The programme's mission had outrun its tooling. What began as a small screening effort now reached patients across 30 school and community sites, but the technology had never been upgraded to match. Hygienists ran video consults on consumer-grade apps never intended for clinical use, and intraoral images were captured on personal devices and uploaded to shared drives with none of the access controls patient data requires.

The paperwork was just as exposed as the technology. No vendor in the chain, video, storage or otherwise, had signed a business associate agreement, the contractual foundation HIPAA expects whenever a third party handles patient data. There was no documented risk assessment, no structured workforce training and no organised evidence of safeguards, because the programme had grown out of clinical enthusiasm rather than an IT department.

Then the stakes changed. Grant funders began requiring evidence of HIPAA compliance as a condition of the money that kept screening days running. The programme faced audits it could not pass, which put its funding, and with it the dental screening of the communities it serves, at genuine risk.

Consumer video tools

Hygienists ran video consults on consumer-grade apps never designed for clinical use, with no healthcare agreements behind them and patient conversations outside HIPAA cover.

Images on shared drives

Intraoral images were uploaded from personal devices to shared drives, with no encryption, access control or record of who had seen what.

No signed BAAs

Not one vendor handling patient data had signed a business associate agreement, a foundational HIPAA requirement for any third party touching patient information.

Funding at risk

Grant funders now required evidence of HIPAA compliance, and the programme faced audits it could not pass with its existing tooling and records.

What it was costing them

The exposure ran in two directions. Patient trust was at stake every time an intraoral image sat on a shared drive or a consult ran over a consumer app, with no agreements or access controls protecting the data. And the funding was at stake too: with funders demanding compliance evidence the programme could not produce, every grant review threatened the screening days that 30 sites of patients depended on.

The Solution

HIPAA-aligned teledentistry stack

The constraint that shaped everything was continuity: screening days at 30 school and community sites could not stop while the programme modernised. So we sequenced the work as a series of swaps, each replacing one risky practice with a compliant equivalent, and each timed around the screening calendar so hygienists never lost a working day to the transition.

Consults moved to a BAA-covered healthcare video platform, and image capture was rebuilt end to end: encrypted at capture, flowing into access-controlled cloud storage, with personal devices replaced by managed devices at every site. Single sign-on with role-based permissions now governs access, so each staff member reaches exactly what their role requires and nothing more.

Compliance is more than tooling, so we treated the paperwork as a deliverable in its own right. A HIPAA Security Rule risk assessment established where the gaps were and tracked them to closure, workforce training gave hygienists and coordinators clear handling rules, and a centralised evidence log now captures safeguards, agreements and training records in one place, keeping the programme permanently audit-ready rather than scrambling before each review.

Key decisions

01

Swap tools without stopping screenings

Each risky practice was replaced by a compliant one in sequence, timed around the screening calendar, so clinical work never paused for the modernisation.

02

Agreements before technology

Every vendor in the new stack signed a business associate agreement, making the contractual foundation part of tool selection rather than an afterthought.

03

Encrypt from the point of capture

Intraoral images are encrypted as they are captured and land directly in access-controlled cloud storage, taking shared drives and personal devices out of the flow entirely.

04

Managed devices at every site

Programme-owned, managed devices replaced personal devices across the sites, giving the organisation control over every endpoint that touches patient data.

05

Evidence as a habit

A centralised compliance log collects safeguards, agreements and training records continuously, so audit evidence is assembled by default rather than reconstructed under deadline.

Measurable Impact

What changed after launch

The programme's HIPAA Security Rule safeguard coverage rose from 31% to 96% of assessed controls across two review cycles, and signed business associate agreements are now in place with all 6 vendors that handle patient data, up from zero. Every patient image, 100% of them, moved off shared drives into encrypted, access-controlled storage within 10 weeks.

For the people running the programme, the clearest change is at review time. Audit evidence preparation for grant reviews dropped from 6 weeks of scrambling to 4 days of assembly from the centralised compliance log. Screening days at the 30 sites never stopped through the transition, and the programme now approaches funder audits as routine rather than existential.

Video consults

Consumer-grade apps with no healthcare agreements

A BAA-covered healthcare video platform

Patient images

Personal devices uploading to shared drives

Encrypted capture into access-controlled cloud storage

Safeguard coverage

31% of assessed Security Rule controls covered

96% coverage across two review cycles

Audit preparation

6 weeks of evidence gathering per review

4 days from the centralised compliance log

Headline results

HIPAA Security Rule safeguard coverage rose from 31% to 96% of assessed controls across two review cycles

100% of patient images migrated off shared drives into encrypted, access-controlled storage within 10 weeks

Signed business associate agreements secured with all 6 vendors handling patient data, up from zero

Audit evidence preparation for grant reviews cut from 6 weeks to 4 days via the centralised compliance log

Tech & Tools Used

What powered the build

Every tool below earned its place in this engagement. Here is the part each one played.

Zoom for Healthcare logo

Zoom for Healthcare

The BAA-covered video platform where hygienists now run patient consults, replacing the consumer-grade apps that had no healthcare agreements behind them.

Okta logo

Okta

Provides single sign-on with role-based permissions across the stack, so each staff member reaches only the patient data their role requires.

AWS S3 + KMS

The access-controlled cloud storage where encrypted intraoral images now live, with managed encryption keys replacing the open shared drives they came from.

AWS CloudTrail

Records who accessed what across the cloud environment, giving the programme the trail of activity evidence that HIPAA reviews expect to see.

Vanta

Runs continuous compliance monitoring and feeds the centralised evidence log, tracking safeguard status, agreements and training so the programme stays audit-ready.

Jamf

Manages the programme-owned devices at every site, enforcing encryption and configuration policies on the hardware that replaced personal devices.

Next.js logo

Next.js

Powers the web front end of the programme's centralised compliance log, where staff record and retrieve safeguards, agreements and training evidence.

Node.js logo

Node.js

Runs the services behind the compliance log and the image-handling workflow, connecting capture, storage and evidence records under the new access controls.

PostgreSQL logo

PostgreSQL

Stores the compliance log's structured records, keeping safeguards, vendor agreements and training completions queryable whenever a grant review arrives.

Ready to Build your Teledentistry & Dental Public Health Business with HIPAA & Security Compliance

Ask Byte

Ask Byte

Typically replies instantly

just Now

Hi! I'm OrganByte's assistant. How can I help you today?

AI-generated content may be incorrect


OrganByte

Building innovative software solutions that transform businesses and drive digital success.

© 2026 YourCompany. All rights reserved.