1. The roles
For HIPAA purposes the clinic is the Covered Entity for any Protected Health Information you submit. The portal software operator is a Business Associate that processes PHI strictly under the clinic's written instruction (a signed Business Associate Agreement is on file before the portal is used with real patient data).
2. What data the portal collects
2.1 From referring providers + clinical workforce
- Account fields: name, email, role, optional signature line.
- Sign-in records: time, IP address, user agent (encrypted at rest, retained for 6 years for audit).
- Activity: what records you opened or changed — this becomes part of the tamper-evident audit log.
2.2 From patients (via public intake form or by referral)
- Name, date of birth, contact information.
- Clinical information you choose to provide (chief complaint, history).
- Attachments (X-rays, scans) if you upload them.
Direct identifiers (name, DOB, email, phone, address) are additionally encrypted at the field level with a separate key before being written to the database.
3. How the portal uses data
The portal uses the data you submit to:
- Route a referral to the clinical workforce.
- Generate and store reports and PDFs the clinic produces for the patient and the referring provider.
- Send transactional emails (welcome, password reset, report delivery notification, appointment information).
- Maintain an audit log of who accessed what.
- Operate the system: monitoring, backups, troubleshooting.
The portal does not use your data for advertising, profiling unrelated to care, or sale to any third party.
4. Cookies + tracking
The portal sets only operational cookies:
dental_session— HttpOnly session cookie. Carries your sign-in. Expires when you log out or after the configured absolute session lifetime.dental_csrf— a CSRF token the front-end echoes back on state-changing requests. Same lifetime as the session cookie.dental_mfa_challenge— short-lived (5 minutes) cookie used while completing the second-factor step at sign-in. Cleared the moment that step finishes.
No third-party analytics, advertising trackers, or cross-site cookies are set by the portal.
5. Where the data lives
Data is stored in a database hosted by a major cloud provider (Amazon Web Services) operating under a HIPAA Business Associate Agreement. Storage is encrypted at rest; data in transit uses TLS 1.2+. Daily backups go to a separate encrypted bucket in the same cloud region.
6. Who sees the data
- The clinical workforce members granted access by the clinic — only to the records their role permits.
- The patient, when they request a copy under HIPAA right of access.
- Sub-processors that AWS uses to provide the underlying service, under their own BAA.
- Authorities, when compelled by a valid legal process; we will tell the clinic where permitted.
The portal does not share data with any third party for marketing or advertising purposes.
7. How long the data is kept
- Clinical records: per the clinic's records-retention policy (typically 7+ years).
- Audit log: 6 years (HIPAA minimum).
- Login records: 6 years.
- Backups: 30-day rolling window.
- Closed accounts: the user row is retained for audit integrity; PII is redacted when feasible upon explicit clinic request.
8. Your rights
If you are a patient, the clinic's Notice of Privacy Practices spells out your rights under HIPAA — including the right to inspect, amend, restrict, and obtain an accounting of disclosures. Send those requests to the clinic.
If you are a referring provider or workforce member, you may request a copy of the account data the portal holds about you, or have your account closed, by contacting the clinic.
9. Security
The portal implements the technical safeguards required by HIPAA, including multi-factor authentication, idle-session timeout, encryption at rest and in transit, audit logging with tamper-evidence, and least-privilege access controls. The internal Security Plan documents specifics; an auditor may review it under NDA.
10. Breach notification
If we discover a breach of unsecured PHI affecting you, you will be notified per HIPAA's 60-day rule. Contact information for the clinic's Privacy Officer is in the Notice of Privacy Practices.
11. Children
The portal is not directed at children under 13 as a general-public service. Pediatric patients are handled through their parent or legal guardian under the clinic's standard intake process.
12. Changes to this policy
We may update this Privacy Policy from time to time. The effective date at the top of the page reflects the most recent change. Material changes will be announced through the portal or via email.
13. Contact
For privacy-related questions about the portal software, contact the clinic's Privacy Officer (see the Notice of Privacy Practices). For technical questions about the portal, the same contact applies — the clinic owns the relationship.
This policy applies only to the portal software. The clinic maintains its own Notice of Privacy Practices for in-office services and any other channels it operates.