Most dental practices do not fail compliance because they decided not to comply. They fail because the exposure control plan was last reviewed by an office manager who left two years ago, the risk analysis was done once at startup, and nobody knows when the x-ray registration expires. A calendar fixes almost all of that. This one distributes the recurring federal and state obligations across the year so that no month is overwhelming and nothing goes three years without attention.

How to use this template

  • Print it in January, write real names in the owner column, and post it where the office manager works.
  • Move tasks to fit your own renewal dates. The point is that every task has a month, not that it has this month.
  • Put each row into a shared calendar with a reminder two to four weeks ahead. Paper is the record; the calendar is the prompt.
  • State rules vary and are often stricter than federal ones. Confirm your obligations with your state dental board, state OSHA plan, and state radiation control program before relying on this list.
  • File the completed calendar in your compliance binder. It is evidence that your program is being run, not just written.

Program header

FieldEntry
Practice name 
Calendar year 
Owner or managing doctor 
Infection control coordinator 
HIPAA privacy official 
HIPAA security official 
Federal OSHA or state plan? Which agency 
State dental board contact 
IT vendor and phone 
Healthcare attorney and phone 

Ongoing tasks (not tied to a month)

FrequencyTaskOwnerWhere recorded
Every loadMechanical monitoring logged; internal chemical indicator in every package  
DailyAir removal test on pre-vacuum sterilizers; waterline flushing; eyewash flush  
WeeklySpore test each sterilizer; verify data backups completed  
MonthlyWaterline testing per manufacturer; amalgam separator inspection per manual; fire extinguisher visual check; records audit for gaps  
At hireBloodborne pathogens and HazCom training; HIPAA training; hepatitis B vaccine offered within 10 working days; I-9 completed; license verified  
When it happensExposure incident evaluation; breach risk assessment; new vendor BAA; new chemical added to inventory and SDS  

January

TaskOwnerDate doneNotes
Report prior-year breaches affecting fewer than 500 individuals to HHS (due within 60 days of year end)   
Update the hazardous chemical inventory and refresh the SDS set   
Confirm required federal and state labor posters are current   
Set the year's training dates and put them on the schedule   

February

TaskOwnerDate doneNotes
Review the vendor register; confirm a signed BAA for every vendor that touches PHI   
Audit user accounts in practice software, imaging, email, and remote access; remove former employees   
Confirm multifactor authentication on email, remote access, and cloud software   
Review the Notice of Privacy Practices with counsel if it has not been reviewed recently   

March

TaskOwnerDate doneNotes
Update the HIPAA security risk analysis and the risk management plan   
Refresh the ePHI inventory: servers, workstations, cloud apps, imaging, backups, phones   
Confirm encryption on laptops, backup drives, and any portable media   
Assign and date each remediation item from the risk analysis   

April

TaskOwnerDate doneNotes
Annual review and update of the written exposure control plan   
Document the safer medical device evaluation, with input from non-managerial clinical staff   
Confirm the post-exposure evaluation arrangement with your occupational health clinic   
Review sharps containers, PPE stock, and regulated waste handling   

May

TaskOwnerDate doneNotes
Annual bloodborne pathogens training (interactive, with someone knowledgeable available for questions)   
Hazard communication refresher, including any new label formats or chemicals   
Record attendees, date, content summary, and trainer (keep 3 years)   
Confirm hepatitis B vaccination status or signed declination for every exposed employee   

June

TaskOwnerDate doneNotes
HIPAA workforce refresher training; document attendance   
Review the patient right of access workflow and response times (generally 30 days, one 30-day extension with notice)   
Run a phishing awareness refresher with the team   
Verify the breach log is current, even if empty   

July

TaskOwnerDate doneNotes
Run the CDC infection prevention checklist as a self-audit; document gaps and fixes   
Review the sterilization logs for the year to date; look for missing weeks   
Review the waterline protocol and test results; confirm the boil-water advisory plan is written   
Confirm the failed spore test protocol is posted at each sterilizer   

August

TaskOwnerDate doneNotes
Check x-ray equipment registration status and inspection due dates with your state radiation program   
Verify radiography credentials or training for every staff member who exposes radiographs   
Review amalgam separator status, maintenance records, and container replacement schedule   
Confirm separators installed before June 14, 2017 have a replacement plan ahead of June 14, 2027   

September

TaskOwnerDate doneNotes
Perform a full backup restore test, not just a log review; document the result   
Review the emergency action and fire prevention plan; walk the exits   
Fire extinguisher professional service; eyewash station inspection   
Medical emergency drill; check emergency kit, oxygen, and AED expirations   

October

TaskOwnerDate doneNotes
List every license, permit, and registration with its expiration date for the coming year   
Check CE progress for each provider, including any state-mandated topics   
Verify CPR or BLS certification dates for all required staff   
Check DEA registration (3-year cycle) and any state controlled substance registration   

November

TaskOwnerDate doneNotes
Audit I-9 files; confirm they are stored separately from personnel files and on the current form edition   
Review personnel files, handbook acknowledgments, and job descriptions   
Review exempt and nonexempt classifications and overtime practices with counsel or your payroll provider   
Purge records that are past retention under your written policy; document what was destroyed   

December

TaskOwnerDate doneNotes
Review infection control, OSHA, and HIPAA policies for needed updates   
Confirm the compliance binder is complete and each item can be found in minutes   
Check for new state board rules or state law changes effective January 1   
Build next year's calendar and assign owners   

Renewal and expiration tracker

ItemNumberHolderExpiresRenewed on
Dental license, doctor 1    
Dental license, doctor 2    
Hygienist license(s)    
Assistant registration or expanded function permit    
Radiography credentials    
Sedation or anesthesia permit    
DEA registration    
State controlled substance registration    
X-ray unit registrations    
Business or facility license    
Malpractice policy    
Workers' compensation policy    
Property, liability, and cyber policies    
CPR or BLS cards    

Sign-off

FieldEntry
Year-end review completed by 
Date 
Items carried into next year 
Owner signature 

State rules vary, and they are often stricter than federal rules. More than twenty states run their own OSHA-approved plans covering private employers. State boards set infection control details, record retention, assistant credentials, and continuing education requirements. Radiation programs set x-ray registration and inspection intervals. Some localities add their own amalgam rules. Use this calendar as a framework and confirm the specifics with your state board, state agencies, and a healthcare attorney.

How to run the calendar

Set it up once a year, in January, in a single sitting. Print the sheet, write the owner for each month's block, then enter each row into a shared calendar with a reminder two to four weeks before the month it falls in. The reminder is what makes the task happen. The paper sheet is what proves it happened, because it holds the date and the initials.

Do not try to do all of this yourself if you are the owner. Most of it belongs to the office manager or the infection control coordinator, with the owner doing the sign-off and the items that require the owner's own records. The value of the calendar for an owner is that it converts a vague sense of unease into a one-page status check: which rows have dates in them and which do not.

The ongoing tasks table at the top is deliberately separate from the months. Spore tests, waterline treatment, backup verification, and load monitoring are not annual events, and they should be running on the sterilization monitoring log and maintenance log. They appear here only so the annual review can confirm they are still happening.

Why the months land where they do

January carries the year-end HIPAA breach reporting deadline, since breaches affecting fewer than 500 people are reported to HHS within 60 days after the end of the calendar year. It is also the natural month for the chemical inventory and poster check.

March holds the security risk analysis because it is the single most-cited HIPAA failure and deserves its own month with nothing competing for attention. HHS does not set a fixed interval for updating it, but many practices refresh it annually, and it must be updated when things change: new software, a move, a breach, or a change of ownership.

April and May pair the exposure control plan review with the annual bloodborne pathogens training, because the plan review feeds the training content. The standard requires the plan to be reviewed and updated at least annually, and training at initial assignment and at least annually after that.

September is the backup restore test, which should be an actual restore. A backup log that says "success" every night is not evidence that the data is recoverable. Practices find out otherwise during a ransomware incident, when it is too late. See ransomware in dental practices.

October gathers licensing so you have a full quarter of runway before January renewals. November handles employment records while the year is still open, and December is the policy review and next-year setup.

What good looks like

Good looks like a sheet where every month has dates written in, including the boring rows. It looks like a renewal tracker that is filled in completely, so that nobody is surprised by a DEA registration or an x-ray registration lapsing. It looks like at least one month where the notes column says something happened: a gap found in the sterilization log, a vendor with no BAA, three inactive user accounts that were still enabled.

A practice running this well can answer an inspector's question with a document rather than a story. Ask for the exposure control plan and its current-year review, and someone produces it in two minutes. Ask when the last HIPAA training was, and there is a sign-in sheet with a date. That is the entire bar, and it is reachable.

The other marker of a healthy program is that responsibility is written down. Assign each area to a named person, put the recurring tasks on the calendar, and audit yourself once a year before someone else does it for you.

Common mistakes

Treating a template plan as a real plan. A generic exposure control plan that does not describe your actual job classifications, your actual devices, and your actual procedures will not hold up. Edit it to match reality, and document the employee input on safer devices.

Doing the risk analysis once. A risk analysis performed at startup and never touched is the most common HIPAA finding in small practices. It needs to be accurate, thorough, and current, with a management plan that says what you will do about what you found, by when, and who owns it.

Assuming a vendor's BAA covers everything. Keep a vendor register. Any company that creates, receives, maintains, or transmits PHI on your behalf needs a signed BAA before you share anything. Consumer-grade email, texting, and file sharing tools that will not sign one are telling you not to use them for patient information.

Forgetting the compliance items that come with equipment and ownership changes. Buying a practice or a piece of equipment moves x-ray registrations and triggers a new one-time amalgam separator compliance report to your control authority within 90 days of the transfer. Add both to any acquisition checklist.

Letting the calendar become the whole program. The calendar tracks recurring work. It does not replace written policies, training records, or the logs themselves. Read the compliance chapter for the full picture of what belongs in the binder.

This template is educational and is not legal advice. Federal requirements summarized here can change, and state requirements vary and are often stricter. Confirm your obligations with your state dental board, state agencies, and a healthcare attorney.

This guide is educational content and does not constitute legal, financial, tax, or clinical advice. Laws and regulations vary by state and change over time. Consult your own dental-specific attorney, CPA, and state dental board before acting.