Book a call

Privacy · Cybersecurity · AI Safety

The Myla SAFE Framework

Dentistry needed its own framework. SAFE™ shows a dental practice what good actually looks like across privacy, cybersecurity and AI safety, then gives it four stages to get there.

In short

SAFE™ stands for See the risk, Assign responsibility, Formalize protections, and Enforce and evolve.

The same four stages are applied to privacy, cybersecurity and AI safety, so a practice knows what to do, who is doing it, and in what order. It does not replace your obligations under privacy law. It organizes the guidance you already have into a sequence you can actually work through.

The four stages of the Myla SAFE™ Framework

A safe practice isn't something you buy. It's something you build.

Not a patchwork of fixes bought one at a time. A process, built for dentistry, that covers your systems, your people and the way you work.

S. See the risk

Build an accurate picture of where patient information lives, which systems and vendors touch it, and where the practice is genuinely exposed.

Do we actually know?

A. Assign responsibility

Give every obligation a named person, with the authority to act and a clear boundary around what they decide alone.

Who owns this?

F. Formalize protections

Turn decisions into written policies, agreements, technical safeguards and procedures the team can follow under pressure.

Is it written down?

E. Enforce and evolve

Put protections into daily operation, train the team, watch whether they hold, correct what fails, and adapt as things change.

Is it still true?

Where the SAFE™ Framework starts

The SAFE™ Framework starts by showing you what good looks like

You cannot notice a missing policy, an untrained team member or an unapproved AI tool if nobody has ever laid out the complete picture.

A well-protected dental practice is strong in three places at once. Systems. People. Processes. Most practices are reasonably strong in the first column and thin in the other two, and almost nobody has seen all three set out together.

Systems

Usually your IT provider

  • Multi-factor authentication on every account that touches patient information
  • Backups tested by restoring from them, not just configured
  • Encryption on any device that leaves the building
  • A current inventory of every system and vendor holding patient data
  • Approved AI tools only, with the unapproved ones found first

People

Nobody, unless it is assigned

  • A named privacy officer with real authority, not an informal role
  • Every team member trained on a schedule, with a record of who and when
  • New hires onboarded into a defined standard rather than an oral tradition
  • Clear rules for what "need to know" means at the front desk
  • Someone named who approves an AI tool before it touches a patient record

Processes

Nobody, unless it is assigned

  • Written policies that match how the practice actually runs
  • Consent language and retention rules kept current
  • A breach response procedure the team has walked through at least once
  • Vendor agreements reviewed before signature, and again when terms change
  • A scheduled review with the owner, so accountability is exercised

Your IT provider works in the first column. The second and third were never in the contract. That is not a failure on their part. It is a category of work nobody in the building was ever assigned.

Why the SAFE™ Framework exists

Dentistry is a specialized industry. Generic advice isn't enough.

Enterprise frameworks assume a security team, a compliance department and a budget line. Small business guidance ignores health privacy law and says nothing about a college. Neither describes a dental practice, where the custodian is a named person who is personally accountable, the team is five to fifteen people who all handle patient information, and AI arrived through imaging and note-taking before anyone wrote a policy about it.

Privacy, cybersecurity and AI safety are also not three separate problems any more. An AI note-taking tool is an AI decision, a privacy decision, a vendor decision and a security decision in the same moment. Handled in three separate conversations, it gets three partial answers and no owner. SAFE™ runs one method across all three so nothing lands in the space between them.

Getting this right takes more than software. It takes guidance from people who have sat in dental operatories, read the college guidance, and know how privacy law, insurance requirements and daily workflow actually collide.

In practice

How the SAFE™ Framework simplifies patient trust, practice data and compliance

Four stages, applied the same way every time. Together they cover the trust patients place in you, the data the practice runs on, the obligations you carry, and the defences that keep attackers out.

S

See the risk

The problem it solves

Practices routinely discover risk during an incident rather than before one. Inventory is the stage most often skipped, because it is the least satisfying thing to buy.

What it looks like

  • Listing every system that holds or transmits patient information, including the ones nobody thinks of: the scheduling text service, the shared inbox, the imaging vendor's cloud portal, the laptop that goes home.
  • Identifying every AI tool in use, including tools a team member adopted without approval.
  • Naming which vendors have access to personal health information, and on what terms.
  • Recording what the practice already does well, so the next stage does not start from zero.

How it connects. Nothing downstream is reliable without this. You cannot assign an owner to a risk you have not identified, and you cannot protect a system you did not know existed.

A

Assign responsibility

The problem it solves

This is where most practices actually fail. Not through negligence, but through reasonable assumption. The owner assumes the office manager has it. The office manager assumes the IT provider has it. The IT provider assumes it was outside scope. The obligation sits in the space between three people who each believed it was covered.

What it looks like

  • A named privacy officer with defined authority, not an informal role that landed on whoever was willing.
  • A written split of what the IT provider owns, what the practice owns, and what neither has claimed. The third list is usually the longest.
  • One named person who approves an AI tool before it touches patient information.
  • A decision, made in advance, about who is called first when something goes wrong.

How it connects. Ownership is what turns the picture from stage one into work that will actually happen. A protection with no name beside it will be maintained by nobody.

F

Formalize protections

The problem it solves

Practices frequently do the right thing informally and cannot demonstrate it. When a regulator, an insurer or a patient asks how patient information is handled, an intention is not an answer. Documentation is also increasingly a condition of cyber insurance rather than a nicety.

What it looks like

  • Privacy policies, consent language and retention rules that match how the practice actually operates, not a template from another jurisdiction.
  • Multi-factor authentication and backups that have been tested by restoring from them, not merely configured.
  • An acceptable use policy for AI, with vendor agreements and a requirement for human review of AI output before it enters a record.
  • A breach response procedure the team has walked through at least once, before they need it.

How it connects. This stage converts ownership into evidence. It is also the stage most commonly done first and alone, which is why so many practices own protections they cannot explain or prove.

E

Enforce and evolve

The problem it solves

A policy nobody was trained on is a document, not a protection. This is where governance either becomes real or quietly stops being true: the backup that has not been restored in two years, the AI vendor that changed its terms, the team member who joined after the training.

What it looks like

  • Onboarding and recurring training, with a record of who completed what and when.
  • Restoring from backup on a schedule, rather than assuming.
  • Re-reviewing AI vendors and their terms, because AI tools change underneath you between renewals.
  • Acting when something is missed: correcting it, recording it, and adjusting the process so it does not recur.
  • A scheduled review with the practice owner, so accountability is exercised rather than delegated.

How it connects. This stage feeds back into stage one. Each review produces a new picture of the risk, and the cycle runs again. SAFE™ is meant to be operated, not completed.

What SAFE™ is not. It is not a certification, an accreditation, a software product or a government-approved methodology. It does not guarantee compliance, prevent every incident, or substitute for legal advice, and it does not move a regulated professional's accountability onto Myla or onto an IT provider. It is a professional method for organizing work the practice remains responsible for.

How it connects

How the SAFE™ Framework connects privacy, cybersecurity and AI safety

This is the part practices tell us changes how they think. Twelve questions, each with a yes or no answer, replacing three parallel projects.

The four SAFE™ stages applied across privacy, cybersecurity and AI safety
The four stages PrivacyPatient information CybersecuritySystems and access AI safetyTools and outputs

S. See the risk

Know what patient information you hold, where it lives, and who it is shared with.

Find where systems, devices, backups and vendor connections are exposed.

Find every AI tool in use, including the ones nobody approved.

A. Assign responsibility

Name your privacy officer and define what they decide without escalating.

Set out what the IT provider owns, what the practice owns, and what neither has claimed.

Name who approves an AI tool before it touches patient information.

F. Formalize protections

Consent language, retention rules, and a breach procedure the team has practised.

Multi-factor authentication, tested backups, and scheduled training.

Acceptable use policy, vendor agreements, and human review of AI output.

E. Enforce and evolve

Retrain, and revisit consent and retention as services and guidance change.

Restore from backup on a schedule. Rehearse the response plan.

Re-review vendors, terms and output quality as tools change.

A practice should be able to read this grid and know, without a consultant in the room, which squares are handled and which are not.

What changes

What changes once a practice runs the SAFE™ Framework

  • Your whole team knows what to do. Skills and confidence at every level, from the front desk to the operatory to the owner's office. Nobody is guessing, and nobody is quietly hoping someone else has it.
  • Your privacy officer knows exactly what the role requires. Not a title someone inherited, but a defined job with defined authority and a clear line for when to escalate.
  • You can vet an IT provider, a software vendor or an AI tool properly. Real questions, asked before the contract, instead of trusting that the sales answer was the whole answer.
  • Safe data handling stops being a judgement call. Everyone knows what may be shared, with whom, and through which channel, so the right decision is also the easy one.
  • You are meaningfully harder to attack. The controls that stop most ransomware and phishing are in place, someone owns each of them, and they are checked rather than assumed.
  • You have a recovery plan that has actually been tested. One the team has walked through, not one that gets read for the first time in the middle of an emergency.
  • You can show your work. Documentation you can put in front of a regulator, an insurer at renewal, or a patient who asks how their information is handled.
  • Every technology decision runs the same way. New software, a new hire, an AI tool, a vendor renewal. Same four questions, every time.

Put plainly: your practice knows what it is doing.

None of that is achieved by the framework on its own. SAFE™ creates the structure through which the work gets understood, assigned, done and improved. The practice still does the work.

What the numbers show

Why dentistry needed the SAFE™ Framework

Here are the numbers.

47%

Among Canadian businesses without cyber security employees, the most commonly reported reason was that they use consultants or contractors to monitor cyber security.

Statistics Canada, Impact of cybercrime on Canadian businesses, 2023, released 21 October 2024. Covers enterprises with 10 or more employees.4

22%

of Canadian businesses provided formal cyber security training to their non-IT employees in 2023. Just over one in four (26%) had written cyber security policies in place.

Statistics Canada, Impact of cybercrime on Canadian businesses, 2023.4

4.4%

of assessed dental practices had formal cybersecurity awareness training for their team. Against a national benchmark of 22%, dental practices sit far behind Canadian business generally.

Myla's own assessment data, 453 Canadian dental practices, 2014–2025.5

7.4%

of assessed practices had a documented AI governance policy, at a time when 43.3% of U.S. dentists report using AI for at least one task.

Myla's own assessment data, n=203.5 AI usage figure: American Dental Association Health Policy Institute, U.S. data.6

In Canada, the most commonly cited barrier to adopting AI in dentistry is not cost and not scepticism. It is a lack of education and training.7 That is a solvable problem, and it is the one SAFE™ was built to solve.

Who uses it

Who uses the SAFE™ Framework, and how

Most gaps are not technical. They sit in the space between people who each assumed someone else had it covered.

The owner or principal dentist

You hold the accountability whether or not you chose the software. SAFE™ gives you one view of where the practice stands, so you are approving decisions rather than discovering them.

The office manager or privacy officer

You are usually the person holding the policies, the consent forms and the team's habits together. SAFE™ turns that into a defined role with defined authority instead of an informal one.

The IT provider

In-house or outsourced. SAFE™ makes explicit which controls you own and which the practice owns, which removes ambiguity that both sides currently absorb.

The wider team

Front desk, hygiene, assisting. They handle patient information every day and make most of the small decisions that matter. SAFE™ gives them a standard rather than a judgement call.

From learning to doing

Putting the SAFE™ Framework into practice

Knowing what to do is the first half. The Myla Field Guides cover privacy, cybersecurity and AI safety as three companion volumes, with more than fifty implementation resources: templates and checklists, policies and procedures, team training materials, risk and compliance tools, and technical protection guides.

Included with select
Myla consulting programs.

These Field Guides and resources help your team put SAFE™ into practice with confidence.

Myla Privacy, Cybersecurity and AI Safety Field Guides for dental practices
50+ implementation resourcesto help keep your practice safe
Templates & checklists
Policies & procedures
Team training resources
Risk & compliance tools
Tech & data protection guides

Three field guides, more than fifty implementation resources.

Templates and checklists, policies and procedures, team training resources, risk and compliance tools, and tech and data protection guides.

What's your SAFE Score™?

Take the assessment to see how your practice measures up across privacy, cybersecurity and AI safety.

Get your SAFE Score™
Anne Genge, founder and CEO of Myla Training Corp.

Who built it

Who built the SAFE™ Framework

Anne Genge has worked with dental practices for more than thirty years. In that time she has watched capable teams, acting in good faith, be handed frameworks written for organizations twenty times their size and told to work it out. SAFE™ is what she built to hand them instead.

  • Certified Information Privacy Professional / Canada (CIPP/C), International Association of Privacy Professionals
  • Certified HIPAA Compliance Security Professional (CHCSP) and Certified HIPAA Security Risk Assessment Specialist (CHSRAS)
  • Certificate in AI and Law, Queen's University
  • Certificate in AI in Health Care, Harvard Medical School
  • Executive education instructor, Schulich School of Business, York University
  • Five current RCDSO Category 1 courses, all sponsored by the Ontario Dental Association
  • More than 50,000 healthcare professionals educated across North America
  • Two-time Global InfoSec Award winner for healthcare cybersecurity education
  • Founder and CEO, Myla Training Corp. Co-owner, Alexio Corporation

Where to begin

Start using the SAFE™ Framework

Nobody expects a practice to do this alone, or all at once. There are four ways in, and most start at the first.

Start here

SAFE Score™

A first taste of where your practice might stand right now across privacy, cybersecurity and AI safety. Free, about ten minutes.

Get your SAFE Score™

Then

Deep-dive assessment

The full picture, done properly, with a prioritized plan for your practice rather than a general one.

Ask about an assessment →

For leaders

Leadership training

For owners, managers and privacy officers, the people who carry the accountability and make the decisions.

See the programme →

For everyone

Team training and tools

Privacy, cybersecurity and AI safety courses for every person who touches patient information, plus the Field Guides and templates.

See the courses →

Learn More. Worry Less. Stay Safe.™

Common questions

Myla SAFE™ Framework: common questions

Looking for answers on privacy law, AI scribes, cyber insurance or choosing training? Those are in the dental privacy, cybersecurity and AI questions library.

What is the Myla SAFE™ Framework?

A four-stage method that helps dental practices manage privacy, cybersecurity and AI safety as one connected responsibility. The stages are See the risk, Assign responsibility, Formalize protections, and Enforce and evolve, and each is applied across all three areas. It was developed by Anne Genge of Myla Training Corp. for Canadian dental practices.

Who is SAFE™ designed for?

Practice owners and principal dentists, office managers and privacy officers, IT providers supporting dental clients, and the wider clinical and administrative team. Each has a distinct part, which is exactly why assigning responsibility is its own stage rather than an assumption.

Is SAFE™ a compliance standard?

No. It is a professional method for organizing privacy, security and AI governance work. It is not a certification, an accreditation, a legal standard or a government-approved methodology, and completing it does not establish that a practice is compliant with any law.

Does using an IT provider make our practice secure and compliant?

No. An IT provider can secure infrastructure, but the obligations attached to patient information stay with the practice. Governance, staff training, privacy decisions, patient disclosure, vendor approval and professional accountability are not transferred by a service contract. Making that boundary explicit is one of the main things SAFE™ does.

How does SAFE™ address AI?

AI is treated as one of the three domains, not as a footnote. In practice that means finding every AI tool in use including unapproved ones, naming who approves a tool before it touches patient information, putting an acceptable use policy and vendor agreements in place with human review of AI output, and re-reviewing tools as they change. Ontario's Information and Privacy Commissioner and the Royal College of Dental Surgeons of Ontario have both published expectations in this area.12 For evaluating a specific tool, see the Dental AI Risk Framework.

Can the framework be used outside Ontario?

Yes. The four stages are jurisdiction-neutral. The obligations they help you meet are not. Privacy legislation differs across Canada, and the Ontario examples on this page reflect PHIPA and RCDSO guidance specifically. Practices elsewhere should confirm how their own provincial legislation and dental regulator apply.

How is SAFE™ different from a cybersecurity checklist?

A checklist tells you what to have. It does not tell you who owns it, whether anyone was trained on it, whether it still works, or what to do when it fails. SAFE™ is a sequence with ownership and follow-through built in, and it covers privacy and AI alongside security rather than security alone.

What are our reporting obligations in Ontario?

Under Ontario's Personal Health Information Protection Act, health information custodians must notify the Information and Privacy Commissioner at the first reasonable opportunity in prescribed circumstances, and must also provide the Commissioner with an annual report of the previous year's breach statistics on or before 1 March. A custodian in private practice that had no breaches during the year is not required to file that annual report.8 Obligations elsewhere in Canada differ.

Where should a dental practice begin?

With stage one. The SAFE Score™ assessment takes about ten minutes and produces a picture of where the practice actually stands. Everything after that is easier to prioritize once that picture exists.

References

  1. Information and Privacy Commissioner of Ontario, AI Scribes: Key Considerations for the Health Sector, 28 January 2026. Regulatory guidance, Ontario. ipc.on.ca
  2. Royal College of Dental Surgeons of Ontario, Artificial Intelligence in Dentistry, guidance effective 18 September 2025. Regulatory guidance, Ontario. rcdso.org
  3. Canadian Centre for Cyber Security, Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089). Voluntary recommended practice, Canada. cyber.gc.ca
  4. Statistics Canada, Impact of cybercrime on Canadian businesses, 2023, The Daily, released 21 October 2024. Target population: enterprises with 10 or more employees. statcan.gc.ca
  5. Myla / Alexio practice assessment data. 453 Canadian dental practices assessed 2014–2025; AI governance findings drawn from the 203 practices assessed after AI governance measures were introduced. Myla's own data. Full methodology to appear in the forthcoming Canadian Dental Cybersecurity and Resilience Trend Report.
  6. American Dental Association Health Policy Institute, Dentists' AI Usage and Attitudes, 2026. Survey of U.S. dentists in private practice. Industry evidence, United States. ada.org
  7. Oral Health Data Driven Dentistry survey, conducted by Bramm Research, 15 October to 13 November 2025. 164 completed responses from practising Canadian dentists and specialists; margin of error ±7.6 percentage points, 19 times out of 20. Industry evidence, Canada. oralhealthgroup.com
  8. Information and Privacy Commissioner of Ontario, Annual Reporting of Health Privacy Breach Statistics to the Commissioner, setting out the requirement in section 6.4 of O. Reg. 329/04 under the Personal Health Information Protection Act, 2004. Law, Ontario. ipc.on.ca
  9. Canadian Centre for Cyber Security, Ransomware Threat Outlook 2025–2027. Government threat assessment, Canada. cyber.gc.ca
  10. National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, 26 February 2024, and AI Risk Management Framework (AI 100-1), 26 January 2023. Voluntary standards, international. csrc.nist.gov · nist.gov

Myla SAFE™ Framework and SAFE Score™ are trademarks of Myla Training Corp. myla® is a registered trademark of Myla Training Corp. Learn More. Worry Less. Stay Safe.™

© 2026 Myla Training Corp. All rights reserved. This page is provided for educational purposes and is not legal advice. Privacy obligations differ by province. Practices should confirm how their applicable provincial legislation and dental regulator apply to their circumstances. Sources referenced on this page are listed above and distinguish law, regulatory guidance, voluntary standards and Myla's own assessment data.