Compliance problems in dental practices rarely come from owners who do not care. They come from owners who assume someone else handled it: the previous owner, the office manager who left, or the software vendor. Then an employee has a needlestick, a laptop is stolen, or a board inspector shows up, and the question is whether you can produce the written plan, the training records, and the logs.

This chapter covers the federal requirements that apply to nearly every US dental practice, points to the state rules you must layer on top, and turns it all into a calendar and a checklist. It is written for owners and office managers. It is not legal advice, and it cannot cover every state variation. State rules differ significantly; confirm your obligations with your state dental board, your state radiation control program, and a healthcare attorney.

Key takeaways

  • OSHA's bloodborne pathogens standard requires a written exposure control plan reviewed at least annually, hepatitis B vaccination offered at no cost, and training at hire and at least annually.
  • HIPAA requires a documented, accurate security risk analysis. It is the requirement small practices most often skip and the one federal regulators keep citing.
  • Sign a business associate agreement with every vendor that creates, receives, stores, or transmits your patients' health information.
  • CDC recommends spore testing each sterilizer at least weekly and with every load containing an implantable device, and dental unit water at or below 500 CFU/mL.
  • If you place or remove amalgam, EPA's dental effluent rule requires a compliant amalgam separator, specific practices, a one-time compliance report, and three years of records. Separators installed before June 14, 2017 lose their grandfathered status by June 14, 2027.
  • Records retention, x-ray registration, assistant credentials, and many infection control details are set by your state.

Who regulates a dental practice

Several agencies regulate the office, and they do not coordinate with one another.

AgencyWhat it covers in a dental officePrimary source
OSHA (or your state OSHA plan)Employee safety: bloodborne pathogens, hazardous chemicals, exits, fire safety, injury reporting29 CFR 1910, including 1910.1030 and 1910.1200
HHS Office for Civil RightsHIPAA Privacy, Security, and Breach Notification Rules45 CFR Parts 160 and 164
CDCInfection prevention recommendations (not a regulator, but widely adopted by state boards)Summary of Infection Prevention Practices in Dental Settings
EPA and your local wastewater authorityAmalgam separators and dental wastewater40 CFR Part 441
State dental boardLicenses, permits, CE, delegation of duties, infection control rules, patient records, advertisingYour state dental practice act and board rules
State radiation control programX-ray equipment registration, inspections, operator credentialsState radiation regulations
DEA and state pharmacy or controlled substance agencyControlled substance registration, storage, records21 CFR Part 1300 and following; state law
Department of Labor, USCIS, EEOC, state labor agencyWages, overtime, work authorization, discrimination, postersFLSA, Form I-9 rules, federal and state employment law

OSHA: bloodborne pathogens and the exposure control plan

The bloodborne pathogens standard, 29 CFR 1910.1030, is the OSHA rule that matters most in dentistry. It applies to any employer whose employees can reasonably anticipate contact with blood or other potentially infectious materials, which in a dental office includes saliva in dental procedures. If you have employees, it applies to you. More than twenty states run their own OSHA-approved plans covering private employers, and those plans can be stricter than federal OSHA, so check which applies in your state.

The written exposure control plan

You must have a written exposure control plan. At a minimum it needs to:

  • Identify which job classifications have occupational exposure (in most practices, every clinical role and anyone who handles contaminated instruments or laundry).
  • Describe how you comply: engineering controls (sharps containers, safer needle devices), work practice controls, PPE, housekeeping, regulated waste handling, and laundry.
  • Lay out hepatitis B vaccination and post-exposure evaluation procedures.
  • Be reviewed and updated at least annually, and whenever tasks or procedures change.
  • Document, each year, that you considered and implemented appropriate commercially available safer medical devices, such as safety syringes or needle recapping devices.
  • Document that you solicited input from non-managerial employees who do patient care when choosing those controls.

The plan must be accessible to employees. A template is fine as a start, but one that does not match what your team actually does will not hold up.

Hepatitis B vaccination

You must make the hepatitis B vaccination series available, at no cost to the employee, within ten working days of initial assignment to a job with exposure. Employees can decline, but they must sign the declination statement found in the standard's appendix, and they can change their mind later and still receive it at no cost.

Post-exposure evaluation

After a needlestick or other exposure incident, the employee is entitled to a prompt, confidential medical evaluation and follow-up at no cost, including documentation of how the exposure happened and source individual testing where consent and law allow. Arrange this in advance with an occupational health clinic and post the steps where clinical staff will see them.

Training and records

  • Training is required at initial assignment and at least annually after that (within one year of the prior training), and again when changes affect exposure. It must be interactive: the trainee must be able to ask questions of someone knowledgeable. A video with no one available to answer questions does not meet the standard.
  • Training records (dates, content summary, trainer, attendees) must be kept for three years.
  • Employee medical records related to exposure, including vaccination status, must be kept confidential and retained for the duration of employment plus thirty years.

Injury logs and reporting

Offices of dentists are on OSHA's list of industries partially exempt from routine injury and illness recordkeeping (the OSHA 300 log), and employers with ten or fewer employees are also generally exempt. Because the standard's sharps injury log requirement applies to employers who must keep the 300 log, many dental practices are not strictly required to keep one. Many keep a sharps injury log anyway, because it documents exposure incidents cleanly and supports the annual safer device review. State plans may differ. Every employer, exempt or not, must report a work-related fatality to OSHA within eight hours and an in-patient hospitalization, amputation, or loss of an eye within 24 hours.

OSHA: hazard communication and the rest of the list

The hazard communication standard, 29 CFR 1910.1200, covers the chemicals in your office: disinfectants, sterilants, etchants, bonding agents, impression materials, and so on. Employers who use hazardous chemicals must have:

  • A written hazard communication program describing how labels, safety data sheets, and training are handled.
  • A list of hazardous chemicals present in the workplace.
  • Safety data sheets (SDS) for each, readily accessible to employees during every shift. Electronic access is acceptable if it is reliable and employees know how to use it.
  • Labels on containers, including secondary containers such as spray bottles you refill.
  • Training at initial assignment and whenever a new chemical hazard is introduced.

The 2024 HazCom update. OSHA amended the hazard communication standard in 2024 to align more closely with the current version of the Globally Harmonized System. Under the current text, employers must update workplace labeling, their written program, and training as needed by November 20, 2026 for single substances and by May 19, 2028 for mixtures, after manufacturers update their labels and safety data sheets. These dates have been adjusted before, so confirm them on osha.gov. In practice: swap in new SDS versions as suppliers issue them and refresh training on new label elements.

Other OSHA items that apply to most offices

Display the federal "Job Safety and Health: It's the Law" poster (or your state plan's version). Keep exit routes clear and maintain an emergency action and fire prevention plan suited to your size. Inspect any portable fire extinguishers you provide, and provide eyewash facilities where employees handle corrosive chemicals. Radiation and regulated medical waste are also covered, largely through state programs.

HIPAA in practice, not just on paper

If your practice transmits health information electronically in standard transactions (electronic insurance claims count), you are a HIPAA covered entity subject to three rules enforced by the HHS Office for Civil Rights (OCR).

The Privacy Rule

  • Notice of Privacy Practices. Give it to new patients, make a good faith effort to get written acknowledgment, post it in the office, and post it on your website. If your NPP has not been reviewed recently, have counsel check it: HHS required certain updates by February 16, 2026 related to substance use disorder records, and the reproductive health provisions from a 2024 rule were vacated by a federal court in 2025.
  • A designated privacy official and written policies.
  • Minimum necessary. Staff should access and share only what their job requires.
  • Patient right of access. Patients may request copies of their records, and you generally must respond within 30 days, with one 30-day extension allowed if you notify the patient. Fees must be reasonable and cost-based. OCR has pursued dental practices specifically on this point; in September 2022 it announced settlements with three dental practices under its right of access enforcement initiative.
  • Workforce training within a reasonable time after hire and after material policy changes, with documentation.

The Security Rule and the risk analysis

The Security Rule governs electronic protected health information (ePHI) in your software, imaging, email, backups, and devices. Its foundation is the risk analysis: an accurate and thorough assessment of risks to the confidentiality, integrity, and availability of that information, followed by a risk management plan that addresses what you found.

A usable risk analysis for a small practice:

  1. Inventories where ePHI lives: servers, workstations, cloud software, imaging devices, backup drives, phones, email, texting and review platforms.
  2. Identifies realistic threats (ransomware, phishing, stolen devices, failed backups, former employees with active logins) and vulnerabilities (outdated operating systems, shared passwords, no multifactor authentication, unencrypted laptops).
  3. Rates likelihood and impact, assigns a risk level, and records what you will do about each risk, by when, and who owns it.
  4. Is updated when things change: new software, a move, a breach, a change of ownership. HHS does not set a fixed interval, but many practices refresh it annually.

HHS and the Office of the National Coordinator offer a free Security Risk Assessment Tool designed for small and medium providers. OCR's enforcement announcements repeatedly cite failure to conduct an accurate risk analysis, and OCR runs a dedicated Risk Analysis Initiative. A January 2025 proposal would substantially tighten the Security Rule; as of mid-2026 it had not been finalized, and HHS's regulatory agenda listed July 2027 as the target for final action. Build to the current rule, and treat the proposal's themes (multifactor authentication, encryption, asset inventories, tested backups) as good practice anyway.

Ransomware is a HIPAA event. Under HHS guidance, a ransomware attack that encrypts patient data is presumed to be a breach unless you can demonstrate a low probability that the information was compromised. Offline, tested backups are the difference between a bad week and a practice-threatening event (see the Open Dental backups module).

The Breach Notification Rule

A breach of unsecured protected health information triggers notification duties:

  • Affected individuals: without unreasonable delay and no later than 60 days after discovery.
  • HHS: for breaches affecting 500 or more people, within 60 days of discovery. For fewer than 500, you may log them and report to HHS within 60 days after the end of the calendar year.
  • Media: for breaches affecting more than 500 residents of a state or jurisdiction.

An impermissible use or disclosure is presumed to be a breach unless a documented risk assessment covering four factors (the nature of the information, who received it, whether it was actually viewed or acquired, and how far the risk was mitigated) shows a low probability of compromise. Information properly encrypted under HHS guidance is not "unsecured," which is the best argument for encrypting every laptop and backup drive. Many states have their own breach notification laws with different timelines, so involve counsel immediately.

Business associate agreements

A business associate is a person or company that creates, receives, maintains, or transmits PHI on your behalf. You need a signed business associate agreement (BAA) with each one before sharing PHI. HHS publishes sample BAA provisions. Typical dental business associates include:

  • Cloud practice management and imaging software vendors, and your IT support company
  • Patient communication platforms (reminders, texting, reviews, online forms)
  • Outsourced billing, insurance verification, and collections services
  • Email and cloud storage providers used for PHI
  • Shredding and records storage companies
  • Answering services and outsourced call centers
  • Consultants, CPAs, or attorneys who access patient-level data

Keep a vendor register. List every vendor, whether it touches PHI, whether a BAA is signed, and where the signed copy is. Review it annually. Consumer-grade email, texting, and file-sharing tools often will not sign a BAA, which is your signal not to use them for patient information.

Infection control: CDC guidance and your documentation

CDC's Summary of Infection Prevention Practices in Dental Settings: Basic Expectations for Safe Care condenses CDC's 2003 dental infection control guidelines into a practical set of expectations, with a companion checklist for self-assessment. CDC is not a regulator, but many state boards incorporate CDC guidance into their rules or use it as the standard of care during inspections and complaint investigations. Among the administrative expectations: designate at least one person trained in infection prevention to coordinate the program, maintain written policies, and train personnel at hire, at least annually, and when new procedures or equipment are introduced.

Sterilization monitoring

CDC's sterilization monitoring guidance calls for three layers:

TypeWhat it checksCDC-recommended frequency
MechanicalTime, temperature, and pressure shown on gauges, displays, or printoutsEvery load, documented
ChemicalWhether conditions inside the package reached key parametersAn internal indicator in every package; an external indicator too if the internal one is not visible
Biological (spore test)Whether the cycle killed highly resistant sporesAt least weekly for each sterilizer, and every load containing an implantable device

When a spore test fails, CDC's protocol is roughly: take the sterilizer out of service, review loading and operating procedures, retest promptly, and quarantine and recall implantable items. If the repeat test passes, the sterilizer can return to service. If it fails again, the sterilizer stays out of service until it is inspected or repaired and passes spore tests in three consecutive cycles, and items processed since the last negative test should be recalled and reprocessed to the extent possible. Several states write weekly spore testing and specific log retention into their own rules, so your state may set the floor. For equipment considerations, see tabletop sterilizers compared and warning signs in a used autoclave.

Dental unit waterlines

CDC's waterline guidance says water used for routine dental treatment should meet the EPA drinking water standard for heterotrophic bacteria: 500 CFU/mL or less. Untreated units cannot reliably meet that. The practical requirements:

  • Use a waterline treatment product or system and follow the equipment and product manufacturers' instructions exactly.
  • Test water quality as the manufacturer recommends, using in-office test kits or a laboratory. Log the date, unit, result, and any action.
  • If a test exceeds 500 CFU/mL, treat per the manufacturer's instructions and retest.
  • Use sterile water or sterile saline, delivered through a device designed for it, as a coolant or irrigant for surgical procedures.
  • Have a written plan for boil-water advisories.

This is not a paperwork exercise: CDC has documented Mycobacterium abscessus infections in children at pediatric dental clinics linked to contaminated waterlines.

Amalgam separators and the EPA dental effluent rule

EPA's dental office effluent guidelines, 40 CFR Part 441, promulgated in 2017, apply to dental offices that discharge to a public sewer system. The key provisions:

  • Who is covered: offices that place or remove amalgam. Exempt: practices limited exclusively to oral pathology, oral and maxillofacial radiology, oral and maxillofacial surgery, orthodontics, periodontics, or prosthodontics; mobile units; and offices that do not place amalgam and remove it only in limited emergency or unplanned circumstances (which must still file a certification).
  • Deadlines: existing sources (discharging before July 14, 2017) had to comply by July 14, 2020 and file a one-time compliance report by October 12, 2020. New sources must comply from the first discharge and file within 90 days.
  • Change of ownership: a new owner must submit a new one-time compliance report to the control authority (usually your local wastewater utility) within 90 days after the transfer. Add this to every acquisition closing checklist.
  • Separator standard: at least 95% removal efficiency, compliant with ISO 11143 or the specified ANSI/ADA standard. Separators installed before June 14, 2017 satisfy the rule only until they are replaced or until June 14, 2027, whichever comes first. If yours is that old, confirm its status with your vendor and control authority now.
  • Maintenance: inspect per the manufacturer's manual; repair or replace a malfunctioning separator within 10 business days of discovering the problem.
  • Best management practices: no discharge of waste amalgam to the sewer, and no cleaning of waterlines, chairside traps, or vacuum lines with oxidizing or acidic cleaners with a pH below 6 or above 8.
  • Records, kept at least three years: inspection dates and results, container replacements, amalgam pickup and disposal records, repairs, and the current operating manual.

Some states and localities have their own, sometimes stricter, amalgam rules. See EPA's dental effluent guidelines page for the reporting form.

State board, radiation safety, and controlled substances

Your state dental board

The board regulates licensure and much of what happens in the operatory. Owners should track, for themselves and every licensed or credentialed employee: license renewal dates and continuing education requirements (including any mandated topics such as infection control or opioid prescribing), CPR or BLS certification if required, anesthesia and sedation permits, dental assistant registration or expanded function permits, and the rules on what each role may legally do. Verify every license at hire through the board's online lookup (see the hiring chapter) and recheck at renewal.

Radiation safety

Dental x-ray equipment is typically registered with a state radiation control program, which sets inspection intervals, shielding and posting rules, and record requirements. Many states also require dental assistants to hold a radiography certificate or complete approved training before exposing radiographs. When you buy, move, or sell x-ray equipment, registration and sometimes shielding review follow the equipment. See dental x-ray registration and inspections for detail, and the panoramic buying guide if you are adding a unit.

Controlled substances

If you prescribe or store controlled substances, you need a DEA registration (renewed every three years) and, in many states, a state controlled substance registration. DEA-registered practitioners were required to complete a one-time eight hours of training on substance use disorders, affirmed at the first registration or renewal on or after June 27, 2023, with some recent graduates deemed compliant through their dental school curriculum. Most states also require checking the prescription drug monitoring program before prescribing certain drugs. If you keep controlled substances on site, inventory, storage, and recordkeeping rules apply. If you use nitrous oxide, see nitrous oxide equipment and compliance basics.

Records retention: how long to keep what

Retention periods come from different laws, and state rules for patient records vary widely (some count from the last visit, some set longer periods for minors). Where federal and state rules differ, the longer period generally governs. Confirm with your state board and attorney.

RecordMinimum retentionSource
Patient dental records, including radiographsSet by state law; variesState dental practice act or health records law
HIPAA policies, risk analyses, training records, BAAs, breach assessments6 years from creation or last effective date, whichever is later45 CFR 164.316 and 164.530
Bloodborne pathogens training records3 years29 CFR 1910.1030
Employee exposure and vaccination medical recordsDuration of employment plus 30 years29 CFR 1910.1030 and 1910.1020
Amalgam separator inspection, maintenance, and disposal records3 years40 CFR 441
Sterilization monitoring logsSet by state or local rulesState board rules; CDC defers to state and local requirements
Form I-93 years after hire or 1 year after employment ends, whichever is laterUSCIS
Payroll records3 years; timecards and wage computation records 2 yearsFLSA, per DOL Fact Sheet 21

Employment law basics every owner owns

Employment law gets its own track (Team and Hiring), but these belong on every compliance list.

  • Form I-9: the employee completes Section 1 by the first day of work, and you complete Section 2, examining acceptable documents, within three business days. Use the current edition from USCIS and store forms separately from personnel files.
  • New hire reporting: federal law requires reporting new hires to your state's directory within 20 days of hire; some states require it sooner.
  • Wage and hour: most dental assistants and front office staff are nonexempt and must receive overtime at one and a half times their regular rate for hours over 40 in a workweek. Being paid a salary does not by itself make someone exempt; the duties and salary tests control. After a federal court vacated the 2024 overtime rule, the federal salary threshold for the white collar exemptions reverted to $684 a week, but several states set higher thresholds and their own overtime rules.
  • Compensable time: mandatory staff meetings, morning huddles, required training such as annual OSHA and HIPAA sessions, and short rest breaks generally count as paid work time. Bona fide meal periods in which the employee is fully relieved of duty generally do not. Several states mandate meal and rest breaks.
  • Worker classification: a temp hygienist placed through an agency is different from a hygienist you pay directly as a "contractor." Misclassification creates tax and wage liability.
  • Anti-discrimination: many federal laws (Title VII, the ADA, the Pregnant Workers Fairness Act) apply at 15 employees, the ADEA at 20, and FMLA at 50. State laws often apply to much smaller employers, and some states require harassment prevention training.
  • Posters and insurance: required federal and state posters, and workers' compensation coverage as your state requires.

Before disciplining or terminating anyone, read When It Isn't Working and talk to an employment attorney in your state.

Annual compliance calendar

This sample calendar spreads the work across the year so nothing piles up in December. Adjust it to your license renewal cycles and state requirements.

TimingTaskOwner (example)
Every loadMechanical monitoring logged; chemical indicators checkedSterilization lead
WeeklySpore test each sterilizer; log result. Verify backups completed.Infection control coordinator; office manager
Monthly or per manufacturerWaterline treatment and testing; amalgam separator inspection per manual; eyewash checkClinical lead
JanuaryUpdate the chemical inventory and SDS set. Report the prior year's breaches affecting fewer than 500 people to HHS within 60 days of year-end.Office manager; privacy official
FebruaryReview vendor register and BAAs. Review user access in practice software and remove former employees.Privacy and security official
MarchUpdate the HIPAA security risk analysis and risk management plan.Security official with IT
AprilAnnual exposure control plan review, including the safer device evaluation with input from clinical staff.Infection control coordinator
MayAnnual bloodborne pathogens training (or on each employee's anniversary) and hazard communication refresher.Trainer; office manager
JuneHIPAA workforce refresher training; review the Notice of Privacy Practices.Privacy official
JulyRun the CDC infection prevention checklist as a self-audit; fix gaps.Infection control coordinator
AugustCheck x-ray registration, inspection due dates, and operator credentials.Owner
SeptemberTest the backup restore. Review the emergency action plan and fire extinguishers.Office manager with IT
OctoberCheck license, permit, DEA, CPR, and CE deadlines for the coming year for every provider and credentialed employee.Office manager
NovemberReview posters, I-9 file, and personnel records; purge records past retention per policy.Office manager
DecemberReview the infection control and HIPAA policies for changes; set next year's calendar.Owner and office manager

The compliance binder checklist

Physical binder or shared drive, an inspector or buyer should be able to find each item in minutes.

OSHA

  • Written exposure control plan, with the current year's review and safer device evaluation
  • Hepatitis B vaccination records and signed declinations (kept confidential)
  • Post-exposure procedure and designated evaluating clinic
  • Bloodborne pathogens training records for the past three years
  • Sharps injury log or exposure incident records
  • Written hazard communication program, chemical inventory, and SDS access
  • Emergency action and fire prevention plan; extinguisher and eyewash checks

HIPAA

  • Designated privacy and security officials, in writing
  • Privacy and security policies and procedures
  • Current Notice of Privacy Practices and acknowledgment process
  • Security risk analysis and risk management plan, with dates
  • Vendor register with signed business associate agreements
  • Workforce training records and signed confidentiality acknowledgments
  • Breach risk assessments and breach log
  • Backup and disaster recovery plan, with the last restore test date

Infection control

  • Written infection prevention policies and named coordinator
  • Sterilization logs: mechanical, chemical, and weekly spore test results
  • Failed spore test protocol and any corrective action records
  • Waterline treatment protocol and test results
  • Most recent CDC checklist self-assessment
  • Equipment maintenance records for sterilizers and ultrasonic cleaners

Environmental, radiation, and licensing

  • Amalgam separator one-time compliance report and three years of inspection and disposal records
  • Regulated medical waste manifests or pickup records
  • X-ray registrations, inspection reports, and operator credentials
  • Copies of all licenses, permits, DEA and state registrations, with expiration dates
  • CE and CPR records for providers and credentialed staff

Employment

  • I-9 forms, stored separately from personnel files
  • Required federal and state posters
  • Employee handbook with signed acknowledgments
  • Workers' compensation policy
  • Payroll and timekeeping records per retention rules

Making compliance stick

Practices that do this well assign each area to a named person, put recurring tasks on a calendar with reminders, and audit themselves once a year, sometimes with an outside consultant, before a regulator does. Build these responsibilities into your office manual and systems so they survive staff turnover.

If you are buying a practice, request the seller's compliance binder during due diligence. Gaps are rarely deal killers, but they tell you what your first ninety days will involve.

What's next

With finances and compliance under control, the last piece of the Operations track is growth. Chapter 7: Marketing and Patient Acquisition covers Google Business Profile, ethical review generation (and responding to reviews without violating HIPAA), websites, local SEO, paid ads, and tracking what works. Or go back to Chapter 5: Financial Management.

This chapter is educational and is not legal advice. Federal requirements are summarized from OSHA, HHS, CDC, EPA, DEA, USCIS, and DOL sources as of September 2026 and can change. State requirements vary and are often stricter. Confirm your obligations with your state dental board, state agencies, and a healthcare attorney.

This guide is educational content and does not constitute legal, financial, tax, or clinical advice. Laws and regulations vary by state and change over time. Consult your own dental-specific attorney, CPA, and state dental board before acting.