Straight answers for Canadian dental practices
Dental privacy, cybersecurity and AI questions
The questions practices actually ask, answered plainly and sourced to the regulators and agencies that publish the guidance. Where something is law, we say so. Where it is guidance or common practice, we say that too.
Privacy and the law
Ontario examples reflect PHIPA and are labelled. Obligations differ elsewhere in Canada.
When does a dental practice have to report a privacy breach in Ontario?
Under Ontario's Personal Health Information Protection Act, a dental practice that is a health information custodian must notify the affected patient at the first reasonable opportunity when personal health information is stolen, lost, or used or disclosed without authority. The Information and Privacy Commissioner must also be notified in prescribed circumstances.
Separately, custodians must give the Commissioner a report of the previous calendar year's breach statistics on or before 1 March each year. A practice in private practice that had no breaches during the year is not required to file that annual report.
Practices outside Ontario are subject to their own provincial health privacy legislation, and federal PIPEDA breach reporting may apply to commercial activity. Confirm your own obligations with qualified counsel.
Source: Information and Privacy Commissioner of Ontario, annual reporting of health privacy breach statistics, setting out the requirement in section 6.4 of O. Reg. 329/04 under PHIPA. ipc.on.ca
Does a dental practice need a privacy officer?
In Ontario, a health information custodian must designate a contact person under section 15 of PHIPA, or take on the role personally. That person facilitates compliance, ensures staff understand their duties, responds to public inquiries and to access and correction requests, and receives complaints.
In a solo practice the dentist is often both custodian and contact person. Larger practices commonly designate the office manager. The title privacy officer is widely used in the profession, but the legal term in Ontario is contact person, and the role need not be held by a health care practitioner.
What matters in practice is that the role is named, that the person knows what it involves, and that they have the authority to act rather than only to escalate.
Source: Information and Privacy Commissioner of Ontario, health privacy rights and custodian obligations under PHIPA. ipc.on.ca
What is the difference between HIPAA and PHIPA for a Canadian dental practice?
HIPAA is United States law and does not apply to a Canadian dental practice. Ontario practices are governed by PHIPA. Other provinces have their own health privacy legislation, and the federal Personal Information Protection and Electronic Documents Act may apply to commercial activity.
This matters more than it sounds. A great deal of dental privacy and security content online is written for HIPAA, so a Canadian practice that follows it can end up meeting requirements that do not apply while missing ones that do. Two common examples: Ontario's annual breach statistics report to the Commissioner has no HIPAA equivalent, and the duties of a PHIPA contact person are not the same as those of a HIPAA privacy official.
If a training programme, policy template or checklist references HIPAA, treat it as a signal that it was not built for your jurisdiction.
What should a dental practice privacy policy include?
In Ontario, PHIPA requires a custodian to have information practices that comply with the Act, and to produce a written public statement describing them. At minimum that statement covers what information is collected, how it is used and disclosed, how it is protected, how a patient can access or correct their record, and how to complain to the practice and to the Commissioner.
Beyond the public statement, the internal policies that actually get used tend to cover access rules and what "need to know" means, retention and secure disposal, consent, breach response, remote and mobile device use, vendor and agent obligations, and acceptable use of AI tools.
A policy that describes a practice you do not follow is worse than no policy, because it establishes a standard you can be measured against.
Source: Information and Privacy Commissioner of Ontario, custodian obligations under PHIPA. ipc.on.ca
Do privacy rules for dental practices differ across Canada?
Yes. Health privacy is primarily provincial. Ontario has PHIPA, Alberta has the Health Information Act, British Columbia and several other provinces have personal information protection legislation, and federal PIPEDA applies where provincial legislation has not been declared substantially similar or where the activity is federally regulated.
The underlying principles are broadly consistent: collect only what you need, obtain consent, safeguard what you hold, be open about your practices, and give people access to their own information. The specifics differ, including breach notification thresholds and reporting deadlines.
Each province's dental regulator adds a further layer on top of privacy legislation, and those expectations vary too.
Cybersecurity
What to have in place, who is accountable, and what to do when something goes wrong.
What cybersecurity controls should a dental practice have as a minimum?
The Canadian Centre for Cyber Security publishes Baseline Cyber Security Controls for Small and Medium Organizations, a voluntary set of controls designed for organizations without dedicated security staff. It is the most useful starting point for a dental practice because it was written for exactly that situation.
The controls most practices need to address first:
- Multi-factor authentication on every account that touches patient information
- Backups that have been tested by restoring from them
- Patching and updates applied on a schedule rather than when convenient
- Employee awareness training, which the baseline treats as a control in its own right
- An incident response plan the team has actually walked through
- Encryption on any device that leaves the building
These are recommended practices, not law. Ontario's PHIPA does impose a legal duty to take steps that are reasonable in the circumstances to protect personal health information, and the baseline is a defensible way to demonstrate what reasonable looks like.
Source: Canadian Centre for Cyber Security, Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089). cyber.gc.ca
Is our IT provider responsible for our compliance?
No. An IT provider can secure systems, but a service contract does not transfer the practice's legal accountability. In Ontario the health information custodian remains responsible for safeguards, staff training, privacy decisions, patient notice, vendor approval and breach response.
Under PHIPA, an IT provider handling personal health information on the practice's behalf is generally an agent of the custodian. Agents carry duties of their own, including notifying the custodian at the first reasonable opportunity of any theft, loss or unauthorized use of personal health information. But the custodian retains ultimate responsibility for what the agent does.
This is not a criticism of IT providers. Policies, training, consent, patient notice and college obligations were never inside the scope of a typical support contract. The gap is structural, and the fix is to name who owns each item rather than to assume.
How often should dental staff complete privacy and security training?
There is no single legislated frequency in Canada. Common practice is training at onboarding and at least annually afterward, with a record of who completed what and when, plus additional training whenever systems, policies or roles change materially.
Two things push practices toward a documented recurring programme rather than a one-off session. The Canadian Centre for Cyber Security includes employee awareness training among its baseline controls, and Canadian cyber insurers commonly ask for evidence of recurring training at renewal.
The record matters as much as the training. A programme you cannot evidence is difficult to rely on at renewal or after an incident.
Source: Canadian Centre for Cyber Security baseline controls. cyber.gc.ca
What should a dental practice do first after a suspected breach?
Contain first, then assess, then notify. Containment means stopping the loss continuing: disconnect an affected device rather than wiping it, disable a compromised account, and preserve logs. Do not delete anything, because you may need it to establish what happened.
Then work out what information was involved and who is affected, and follow your notification obligations. In Ontario that means notifying affected patients at the first reasonable opportunity, and notifying the Commissioner in prescribed circumstances.
Two practical points. Involve your privacy contact person and, where relevant, counsel and your insurer early, because insurers often require notification before you engage a forensics firm. And write down what you did and when, from the first moment. Reconstructing a timeline afterward is far harder than recording it as you go.
This is a general description, not legal advice for a specific incident.
How much should a dental practice spend on cybersecurity?
There is no credible benchmark specific to Canadian dental practices, and anyone quoting a percentage of revenue is guessing. A more useful question is what is unowned rather than what is unspent.
Most practices we assess are not underspending on technology. They are spending on tools while leaving the people and process work undone, which costs comparatively little: naming a contact person, writing policies that match how the practice runs, training the team on a schedule, testing a restore, and reviewing vendors before signature.
Start by establishing what you actually have and who owns it. That usually reveals that the next useful dollar is not a purchase.
AI in dentistry
Scribes, chatbots, imaging tools and vendors, and what Ontario regulators now expect.
Can Ontario dentists use AI scribes with patient information?
There is no prohibition, but Ontario's Information and Privacy Commissioner published guidance in January 2026 setting out what health sector organizations should consider before adopting AI scribes.
It addresses lawful authority to collect and use personal health information, patient notice and consent, accuracy and human review of AI-generated notes, vendor contracts and where data is stored and processed, and retention and disposal. The Commissioner also published a companion checklist for organizations working through an adoption decision.
The point that matters most for a dental practice: the custodian remains accountable for the record regardless of which tool produced it. An AI-generated note that goes into the chart without human review is still your note.
Source: Information and Privacy Commissioner of Ontario, AI Scribes: Key Considerations for the Health Sector, 28 January 2026. Guidance, not law, and Ontario-specific. ipc.on.ca
What does the RCDSO require when a dental practice uses AI?
The Royal College of Dental Surgeons of Ontario issued guidance on artificial intelligence in dentistry, effective 18 September 2025. It sets out that dentists remain accountable for patient care and for documentation, should inform patients where AI directly affects their care, should document that use, and are advised to seek continuing education on the responsible and ethical use of AI.
It is guidance rather than a standard of practice, and it applies to Ontario dentists. Other provincial regulators are at different stages on this, so confirm your own college's position.
Read alongside the IPC's AI scribes guidance, the practical implication is consistent: AI can be used, but the accountability does not move.
Source: Royal College of Dental Surgeons of Ontario, Artificial Intelligence in Dentistry, effective 18 September 2025. rcdso.org
Is ChatGPT safe to use in a dental office?
It depends entirely on what you put into it. General-purpose AI tools are fine for work involving no patient information: drafting a job posting, rewriting a recall message template, summarizing a public document.
They should not be used with personal health information unless the practice has confirmed where the data is stored and processed, whether inputs are used to train the model, what the vendor agreement actually commits to, and that the use is authorized under applicable privacy legislation. Consumer accounts typically fail at least one of those tests.
The realistic risk is not a dentist deliberately pasting a chart into a chatbot. It is a team member pasting a patient email to get help with the wording, with no idea that is a disclosure. That is why an acceptable use policy, a named approver, and five minutes of team training do more than a ban nobody follows.
What should a dental practice look for in an AI vendor?
Ask these before signing, and get the answers in writing:
- Where is our data stored and processed, and does it leave Canada?
- Is our data used to train your models, and can we opt out?
- What happens to our data if we cancel, and how quickly is it deleted?
- Who at your company can access personal health information, and under what controls?
- Will you sign an agreement that reflects our obligations as a health information custodian?
- How do you notify us of a security incident, and within what timeframe?
- What accuracy testing has this been through in a dental context specifically?
- How will you tell us when your terms or your model change?
That last one matters more than people expect. AI vendors change terms and models between renewals, so a tool you assessed eighteen months ago may not be the tool you are using now.
Do we have to tell patients we are using AI?
In Ontario, RCDSO guidance effective September 2025 sets the expectation that dentists inform patients where AI directly affects their care, and document that use.
Separately, PHIPA requires custodians to be open about their information practices. A practice using AI tools that process personal health information should reflect that in its written public statement of information practices, not only in a conversation at the chair.
Requirements outside Ontario depend on the provincial regulator and the applicable privacy legislation. Where the position is unsettled, telling patients is the safer and more defensible choice.
Sources: RCDSO AI guidance, effective 18 September 2025; IPC Ontario on custodian obligations under PHIPA.
Choosing training and providers
What to look for, and what to ask before you commit.
How do I choose cybersecurity awareness training for a dental team?
Five questions separate training that will hold up from training that will not:
- Is it built on Canadian law? A great deal of dental security training is United States content with local terms substituted. Check whether it references HIPAA.
- Does it cover the whole team? Most breaches involve a decision at the front desk, not in the operatory. Dentist-only training leaves the exposure where it is.
- Does it issue per-learner certificates? You will be asked for evidence at an insurance renewal or after an incident, and a group attendance note is weak evidence.
- Does it cover AI? Anything written before 2025 predates AI arriving in dental workflow.
- Is it independently verifiable? Where your regulator accredits continuing education, check the registry rather than the vendor's own claim.
If a provider cannot answer all five quickly, that itself is informative.
How do I choose privacy training for a dental practice?
The same five questions apply, with one addition specific to privacy: does the training reflect your province's legislation, or does it treat Canada as one jurisdiction? Health privacy is provincial. Training that never distinguishes PHIPA from Alberta's Health Information Act is not training on your obligations.
Also look at who teaches it. Privacy training built by a security vendor tends to be strong on technical controls and thin on consent, access requests, retention and the duties of a contact person, which is where most day-to-day privacy work actually sits.
Finally, ask whether the training comes with anything you can use afterward. Understanding an obligation and having a policy that satisfies it are different problems.
What is RCDSO Category 1 continuing education, and does it matter for privacy and security courses?
Category 1 is the Royal College of Dental Surgeons of Ontario's designation for continuing education that has been approved through a sponsoring organization and carries points toward Quality Assurance Program requirements. Approval is granted for the course as delivered, is held by the sponsoring organization, and expires on a set date.
It matters for two reasons. It means the course has been through an approval process rather than only being marketed as accredited. And it is independently checkable: the RCDSO publishes a Category 1 course registry you can search by presenter or sponsor.
Do check the registry rather than the claim. Approvals expire, and a course that was approved three years ago may not be current.
How do I vet an IT provider for a dental practice?
Ask what is in scope and, more importantly, what is not. The useful conversation is about the boundary rather than the service list:
- Which of these do you own and which do we: patching, backups, restore testing, account provisioning and removal, multi-factor enforcement, endpoint protection, log retention?
- When did you last test a restore of our data, and can we see the report?
- How quickly do you notify us of a security incident, and in what form?
- Will you sign an agreement acknowledging that you act as our agent in respect of personal health information?
- Who at your company can access our systems and our patient data, and how is that logged?
- What happens on offboarding: how fast is a departing employee's access removed?
A good provider will answer these readily and will tell you plainly where their scope ends. That last part is the most valuable answer in the conversation, because it tells you what your practice needs to own.
Insurance
Requirements are set by carriers, not by legislation, and they change. Confirm specifics with your broker.
What does cyber insurance require from a dental practice?
Requirements are set by each carrier rather than by legislation, and Canadian underwriting has tightened considerably. Questionnaires that were once a page are now detailed controls surveys.
The controls that come up most often on Canadian applications and renewals:
- Multi-factor authentication on email, remote access and administrator accounts
- Endpoint protection across all devices
- Backups that have been restore-tested, with a dated report
- A documented and rehearsed incident response plan
- Recurring, documented security awareness training
- Patching and email authentication
One thing worth understanding clearly: your answers on that form are attestations. If a control was available but not enforced when an incident occurred, that discrepancy can affect the claim. Answer accurately, and close the gaps before you sign rather than after.
Requirements vary by carrier, broker and year. Treat the above as the shape of the conversation, not as your policy's terms.
Do we need documented staff training for a cyber insurance renewal?
In most cases yes, and increasingly the question is not whether you train but whether you can prove it. Canadian renewal forms commonly ask about security awareness training, and the practical difference between a good answer and a weak one is documentation.
What tends to satisfy an underwriter: per-learner records showing who completed what and when, a recurring schedule rather than a one-off session, onboarding training for new hires, and certificates you can produce without reconstructing anything.
What tends not to: a note that the team watched a video at a staff meeting two years ago.
Confirm what your specific carrier requires with your broker, since terms differ and change year to year.
No questions match that search. Try a broader term, or clear the filters to see everything.
Not sure where your practice stands?
The Myla SAFE Score™ gives you a first read on privacy, cybersecurity and AI safety in about ten minutes. Free, and no sales call required.
Get your SAFE Score™ Or read about the Myla SAFE™ Framework, the four-stage method behind these answers.