Most dental practices do not fail compliance because they decided not to comply. They fail because the exposure control plan was last reviewed by an office manager who left two years ago, the risk analysis was done once at startup, and nobody knows when the x-ray registration expires. A calendar fixes almost all of that. This one distributes the recurring federal and state obligations across the year so that no month is overwhelming and nothing goes three years without attention.
How to use this template
- Print it in January, write real names in the owner column, and post it where the office manager works.
- Move tasks to fit your own renewal dates. The point is that every task has a month, not that it has this month.
- Put each row into a shared calendar with a reminder two to four weeks ahead. Paper is the record; the calendar is the prompt.
- State rules vary and are often stricter than federal ones. Confirm your obligations with your state dental board, state OSHA plan, and state radiation control program before relying on this list.
- File the completed calendar in your compliance binder. It is evidence that your program is being run, not just written.
Program header
| Field | Entry |
|---|---|
| Practice name | |
| Calendar year | |
| Owner or managing doctor | |
| Infection control coordinator | |
| HIPAA privacy official | |
| HIPAA security official | |
| Federal OSHA or state plan? Which agency | |
| State dental board contact | |
| IT vendor and phone | |
| Healthcare attorney and phone |
Ongoing tasks (not tied to a month)
| Frequency | Task | Owner | Where recorded |
|---|---|---|---|
| Every load | Mechanical monitoring logged; internal chemical indicator in every package | ||
| Daily | Air removal test on pre-vacuum sterilizers; waterline flushing; eyewash flush | ||
| Weekly | Spore test each sterilizer; verify data backups completed | ||
| Monthly | Waterline testing per manufacturer; amalgam separator inspection per manual; fire extinguisher visual check; records audit for gaps | ||
| At hire | Bloodborne pathogens and HazCom training; HIPAA training; hepatitis B vaccine offered within 10 working days; I-9 completed; license verified | ||
| When it happens | Exposure incident evaluation; breach risk assessment; new vendor BAA; new chemical added to inventory and SDS |
January
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Report prior-year breaches affecting fewer than 500 individuals to HHS (due within 60 days of year end) | |||
| Update the hazardous chemical inventory and refresh the SDS set | |||
| Confirm required federal and state labor posters are current | |||
| Set the year's training dates and put them on the schedule |
February
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Review the vendor register; confirm a signed BAA for every vendor that touches PHI | |||
| Audit user accounts in practice software, imaging, email, and remote access; remove former employees | |||
| Confirm multifactor authentication on email, remote access, and cloud software | |||
| Review the Notice of Privacy Practices with counsel if it has not been reviewed recently |
March
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Update the HIPAA security risk analysis and the risk management plan | |||
| Refresh the ePHI inventory: servers, workstations, cloud apps, imaging, backups, phones | |||
| Confirm encryption on laptops, backup drives, and any portable media | |||
| Assign and date each remediation item from the risk analysis |
April
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Annual review and update of the written exposure control plan | |||
| Document the safer medical device evaluation, with input from non-managerial clinical staff | |||
| Confirm the post-exposure evaluation arrangement with your occupational health clinic | |||
| Review sharps containers, PPE stock, and regulated waste handling |
May
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Annual bloodborne pathogens training (interactive, with someone knowledgeable available for questions) | |||
| Hazard communication refresher, including any new label formats or chemicals | |||
| Record attendees, date, content summary, and trainer (keep 3 years) | |||
| Confirm hepatitis B vaccination status or signed declination for every exposed employee |
June
| Task | Owner | Date done | Notes |
|---|---|---|---|
| HIPAA workforce refresher training; document attendance | |||
| Review the patient right of access workflow and response times (generally 30 days, one 30-day extension with notice) | |||
| Run a phishing awareness refresher with the team | |||
| Verify the breach log is current, even if empty |
July
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Run the CDC infection prevention checklist as a self-audit; document gaps and fixes | |||
| Review the sterilization logs for the year to date; look for missing weeks | |||
| Review the waterline protocol and test results; confirm the boil-water advisory plan is written | |||
| Confirm the failed spore test protocol is posted at each sterilizer |
August
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Check x-ray equipment registration status and inspection due dates with your state radiation program | |||
| Verify radiography credentials or training for every staff member who exposes radiographs | |||
| Review amalgam separator status, maintenance records, and container replacement schedule | |||
| Confirm separators installed before June 14, 2017 have a replacement plan ahead of June 14, 2027 |
September
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Perform a full backup restore test, not just a log review; document the result | |||
| Review the emergency action and fire prevention plan; walk the exits | |||
| Fire extinguisher professional service; eyewash station inspection | |||
| Medical emergency drill; check emergency kit, oxygen, and AED expirations |
October
| Task | Owner | Date done | Notes |
|---|---|---|---|
| List every license, permit, and registration with its expiration date for the coming year | |||
| Check CE progress for each provider, including any state-mandated topics | |||
| Verify CPR or BLS certification dates for all required staff | |||
| Check DEA registration (3-year cycle) and any state controlled substance registration |
November
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Audit I-9 files; confirm they are stored separately from personnel files and on the current form edition | |||
| Review personnel files, handbook acknowledgments, and job descriptions | |||
| Review exempt and nonexempt classifications and overtime practices with counsel or your payroll provider | |||
| Purge records that are past retention under your written policy; document what was destroyed |
December
| Task | Owner | Date done | Notes |
|---|---|---|---|
| Review infection control, OSHA, and HIPAA policies for needed updates | |||
| Confirm the compliance binder is complete and each item can be found in minutes | |||
| Check for new state board rules or state law changes effective January 1 | |||
| Build next year's calendar and assign owners |
Renewal and expiration tracker
| Item | Number | Holder | Expires | Renewed on |
|---|---|---|---|---|
| Dental license, doctor 1 | ||||
| Dental license, doctor 2 | ||||
| Hygienist license(s) | ||||
| Assistant registration or expanded function permit | ||||
| Radiography credentials | ||||
| Sedation or anesthesia permit | ||||
| DEA registration | ||||
| State controlled substance registration | ||||
| X-ray unit registrations | ||||
| Business or facility license | ||||
| Malpractice policy | ||||
| Workers' compensation policy | ||||
| Property, liability, and cyber policies | ||||
| CPR or BLS cards |
Sign-off
| Field | Entry |
|---|---|
| Year-end review completed by | |
| Date | |
| Items carried into next year | |
| Owner signature |
State rules vary, and they are often stricter than federal rules. More than twenty states run their own OSHA-approved plans covering private employers. State boards set infection control details, record retention, assistant credentials, and continuing education requirements. Radiation programs set x-ray registration and inspection intervals. Some localities add their own amalgam rules. Use this calendar as a framework and confirm the specifics with your state board, state agencies, and a healthcare attorney.
How to run the calendar
Set it up once a year, in January, in a single sitting. Print the sheet, write the owner for each month's block, then enter each row into a shared calendar with a reminder two to four weeks before the month it falls in. The reminder is what makes the task happen. The paper sheet is what proves it happened, because it holds the date and the initials.
Do not try to do all of this yourself if you are the owner. Most of it belongs to the office manager or the infection control coordinator, with the owner doing the sign-off and the items that require the owner's own records. The value of the calendar for an owner is that it converts a vague sense of unease into a one-page status check: which rows have dates in them and which do not.
The ongoing tasks table at the top is deliberately separate from the months. Spore tests, waterline treatment, backup verification, and load monitoring are not annual events, and they should be running on the sterilization monitoring log and maintenance log. They appear here only so the annual review can confirm they are still happening.
Why the months land where they do
January carries the year-end HIPAA breach reporting deadline, since breaches affecting fewer than 500 people are reported to HHS within 60 days after the end of the calendar year. It is also the natural month for the chemical inventory and poster check.
March holds the security risk analysis because it is the single most-cited HIPAA failure and deserves its own month with nothing competing for attention. HHS does not set a fixed interval for updating it, but many practices refresh it annually, and it must be updated when things change: new software, a move, a breach, or a change of ownership.
April and May pair the exposure control plan review with the annual bloodborne pathogens training, because the plan review feeds the training content. The standard requires the plan to be reviewed and updated at least annually, and training at initial assignment and at least annually after that.
September is the backup restore test, which should be an actual restore. A backup log that says "success" every night is not evidence that the data is recoverable. Practices find out otherwise during a ransomware incident, when it is too late. See ransomware in dental practices.
October gathers licensing so you have a full quarter of runway before January renewals. November handles employment records while the year is still open, and December is the policy review and next-year setup.
What good looks like
Good looks like a sheet where every month has dates written in, including the boring rows. It looks like a renewal tracker that is filled in completely, so that nobody is surprised by a DEA registration or an x-ray registration lapsing. It looks like at least one month where the notes column says something happened: a gap found in the sterilization log, a vendor with no BAA, three inactive user accounts that were still enabled.
A practice running this well can answer an inspector's question with a document rather than a story. Ask for the exposure control plan and its current-year review, and someone produces it in two minutes. Ask when the last HIPAA training was, and there is a sign-in sheet with a date. That is the entire bar, and it is reachable.
The other marker of a healthy program is that responsibility is written down. Assign each area to a named person, put the recurring tasks on the calendar, and audit yourself once a year before someone else does it for you.
Common mistakes
Treating a template plan as a real plan. A generic exposure control plan that does not describe your actual job classifications, your actual devices, and your actual procedures will not hold up. Edit it to match reality, and document the employee input on safer devices.
Doing the risk analysis once. A risk analysis performed at startup and never touched is the most common HIPAA finding in small practices. It needs to be accurate, thorough, and current, with a management plan that says what you will do about what you found, by when, and who owns it.
Assuming a vendor's BAA covers everything. Keep a vendor register. Any company that creates, receives, maintains, or transmits PHI on your behalf needs a signed BAA before you share anything. Consumer-grade email, texting, and file sharing tools that will not sign one are telling you not to use them for patient information.
Forgetting the compliance items that come with equipment and ownership changes. Buying a practice or a piece of equipment moves x-ray registrations and triggers a new one-time amalgam separator compliance report to your control authority within 90 days of the transfer. Add both to any acquisition checklist.
Letting the calendar become the whole program. The calendar tracks recurring work. It does not replace written policies, training records, or the logs themselves. Read the compliance chapter for the full picture of what belongs in the binder.
Related ChairsideSource resources
- Compliance: OSHA, HIPAA, infection control, and more
- HIPAA security checklist for dental practices
- What happens during an OSHA inspection of a dental office
- Course lesson: being inspection ready
- Dental records retention: how long to keep what
This template is educational and is not legal advice. Federal requirements summarized here can change, and state requirements vary and are often stricter. Confirm your obligations with your state dental board, state agencies, and a healthcare attorney.
This guide is educational content and does not constitute legal, financial, tax, or clinical advice. Laws and regulations vary by state and change over time. Consult your own dental-specific attorney, CPA, and state dental board before acting.