HIPAA · SOC 2 · HITECH Compliant Methodology

Your practice runs on trust. Your technology should pass the same standard.

67% of dental practices fail their first HIPAA technology audit. The other 33% had help before the auditor arrived.

0%
of practices fail their first HIPAA tech audit
0
migrations completed — zero data loss incidents
0
days of practice downtime across all migrations
Read the case

Question 01 of 03

"Will my Dentrix data survive the migration?"

Every practice owner asks this first — and they should. The difference between a compliant migration and a catastrophic one is the protocol used before a single record moves. Here is exactly what changes.

DimensionUnmanaged Migration
What most practices attempt
Comply Migration Protocol
What every migration should be
Data transfer
Manual CSV exports prone to encoding errors and field-mapping failures
Automated schema-mapped extraction via certified PMS API connectors — zero manual touch
Downtime window
Practices typically close 2–5 days; staff retrained mid-migration
Parallel-run migration: new system live before legacy decommission — 0 days closure
Image archives
Bitewing and panoramic archives left on local server or burned to DVD
DICOM-compliant cloud transfer with SHA-256 integrity verification per file
Audit trail
No migration log; no way to prove chain of custody if audited
Timestamped migration manifest signed by Comply engineer — audit-ready on day 1
Rollback
Legacy system wiped before go-live; rollback means recreating from backup tapes
Legacy system preserved read-only for 90 days post-migration; instant rollback available
PMS systems
Vendor migration tools only work within their own ecosystem
Dentrix, Eaglesoft, Open Dental, Curve, Carestream — all covered under one protocol

The verdict: In 847 migrations completed since 2019, Comply has recorded zero data loss incidents. The protocol is the reason — not luck.


Question 02 of 03

"What happens to patient records during the switch?"

The moment records leave a paper chart or a local drive, they enter HIPAA-regulated territory. Most practices don't know what that requires until an auditor explains it — at $50,000 per violation. Here is the difference between a Paper Referral Loop and an Encrypted Digital Handoff.

DimensionPaper Referral Loop
The legacy standard
Encrypted Digital Handoff
The compliance standard
Referral pathway
Paper referral form faxed to specialist; no delivery confirmation
Encrypted HL7 FHIR message with delivery receipt and read timestamp — HIPAA §164.312(e)
Record access
Patient records locked in local server; inaccessible if server fails
Role-based cloud access with MFA; available from any operatory in under 3 seconds
Imaging pipeline
X-rays stored as unencrypted JPEG on workstation C:/ drive
AES-256 encrypted DICOM vault; BAA executed with storage provider on day 1
Breach surface
Fax machines, USB drives, and email attachments — each a reportable breach vector
Zero-trust architecture: every data path encrypted, logged, and anomaly-monitored
Transition window
Paper charts coexist with digital indefinitely; staff maintain both systems
72-hour structured cutover with Comply engineer on-site — no hybrid limbo
Patient notification
No formal notification process; practices unaware of HIPAA notice requirements
Comply drafts and delivers compliant patient notification as part of standard protocol

The citation: HIPAA §164.312(a)(2)(iv) requires encryption of ePHI in transit. A fax line does not satisfy this requirement — regardless of how many years your practice has used it.


Question 03 of 03

"How do we stay compliant during the transition?"

The transition period is the highest-risk window — when two systems coexist and neither is fully governed. The practices that pass audits are the ones that treated compliance as the starting point, not an afterthought. Here is the comparison between a Manual Recall Spreadsheet and an Automated 90-Day Recall Engine.

DimensionManual Recall Spreadsheet
The status quo
Automated 90-Day Recall Engine
The Comply standard
Recall method
Staff manually calls patients from a spreadsheet; 60–70% of calls go unanswered
Automated 90-day sequence: SMS → email → voicemail drop — 34% higher recall rate
Audit trail
No record of recall attempts; untestable if audited for standard-of-care compliance
Every patient touchpoint logged with timestamp, channel, and outcome — audit-ready
Compliance posture
No formal HIPAA risk assessment; practices rely on "we haven't been audited yet"
Comply conducts a full NIST-framework risk assessment before any system goes live
Staff training
One-time training at PMS purchase; no refresher schedule, no documentation
Annual HIPAA training module per staff member; completion certificates auto-generated
BAA coverage
Business Associate Agreements missing or unsigned for cloud vendors used daily
Comply audits and executes BAAs with every vendor in the practice's technology stack
DSO readiness
Each location runs different software; consolidation requires negotiating 30 contracts
Single-platform rollout: Comply standardizes all locations onto one system by target date

The closing argument: After three questions, the only variable still unresolved is when your practice starts. The assessment below takes 45 minutes. The audit you're currently exposed to does not give you a warning.

The Assessment

The only question left is when.

Every day without a compliance assessment is a day the 67% statistic applies to your practice. The assessment is complimentary. The risk of skipping it is not.

Book Your Compliance Assessment

No commitment required. Complimentary for qualifying practices. Your data is protected under our BAA.

What the assessment includes

  • 45-minute technology audit of your current PMS and imaging stack
  • HIPAA risk assessment scored against NIST SP 800-66r2 framework
  • Written findings report with prioritized remediation roadmap
  • BAA gap analysis — every vendor in your stack reviewed
  • Migration feasibility estimate with timeline and zero-downtime plan

Download the HIPAA Technology Checklist

Not ready to book? Get the 47-point checklist practices use to self-audit before an OCR investigator does it for them.

"We were three weeks from an OCR audit when Comply found the BAA gaps. The assessment paid for itself before we even started the migration."

MR

Dr. Marcus Reinholt, DDS

Reinholt & Associates Dental Group — 4 locations, Phoenix AZ