Skip to main content

A $140,000 HIPAA Lesson for Dental Practices: Why Your Right of Access Policies Matter

By Olivia Wann

A recent HHS Office for Civil Rights settlement involving a Pennsylvania dental practice is an important warning for every dental office: HIPAA compliance is about more than protecting patient information—it also requires having the right policies and procedures in place to provide patients timely access to their records.

On October 8, 2026, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a $140,000 settlement with Shen Smiles, P.C., a Pennsylvania dental practice, following an investigation into potential violations of the HIPAA Privacy Rule.

The case serves as a valuable reminder that dental practices need more than a general HIPAA policy sitting in an employee handbook. Practices need specific, written procedures addressing patient access to records, safeguarding protected health information (PHI), and responding appropriately when records are lost, stolen, or otherwise compromised.

What Happened?

OCR began investigating Shen Smiles after receiving a complaint alleging that the practice failed to provide an individual with timely access to her protected health information despite receiving multiple requests.

During the investigation, the practice explained that it could not provide the patient with access to her records because a workforce member had stolen the records from the practice.

That explanation did not resolve the HIPAA concerns.

According to OCR, its investigation determined that the practice had failed to implement appropriate policies and procedures concerning PHI that were designed to comply with the HIPAA Privacy and Breach Notification Rules.

Specifically, OCR determined that the practice did not have appropriate Right of Access policies and procedures and did not reasonably safeguard PHI against intentional or unintentional uses or disclosures that would violate the Privacy Rule.

The result?

A $140,000 payment to OCR.

The HIPAA Right of Access Is a Big Deal

HIPAA gives patients important rights concerning their health information.

Under the HIPAA Privacy Rule’s Right of Access provisions, an individual—or the individual’s personal representative—generally has the right to obtain access to protected health information maintained by a covered entity.

A covered entity generally must provide access within 30 days of receiving the request, although one additional 30-day extension may be available when the applicable requirements are met.

That means a dental office cannot simply put a patient’s records request on the back burner.

A request for records needs to be recognized, processed, tracked, and completed within the required timeframe.

“We Don’t Have the Records” May Not Be Enough

One of the most important lessons from the Shen Smiles case is that a practice’s inability to produce records does not necessarily eliminate its HIPAA obligations.

In this case, the practice indicated that a workforce member had stolen the records.

That situation potentially raises multiple HIPAA compliance issues, including:

  • Were the records properly safeguarded?
  • Did the practice have policies addressing the protection of PHI?
  • Did the practice have procedures for responding to lost or stolen records?
  • Was the incident evaluated under the HIPAA Breach Notification Rule?
  • Did the practice have a written Right of Access procedure?
  • Were patient requests tracked and handled appropriately?
  • Did employees understand their responsibilities regarding PHI?
  • Were appropriate administrative, physical, and technical safeguards in place?

A dental practice needs to be prepared to answer these questions.

Your HIPAA Manual Should Address More Than “Keep Patient Information Private”

Many dental offices have a HIPAA manual, but the existence of a manual does not necessarily mean the practice has adequate HIPAA compliance procedures.

A comprehensive HIPAA program should address the actual processes employees are expected to follow.

For example, your practice should have a clearly defined procedure for handling a patient request for records.

That procedure should identify:

  1. Who receives and processes the request
  2. How the request is documented
  3. How the identity of the requester is verified
  4. What information is included in the request
  5. Where the records are located
  6. How the request deadline is calculated
  7. Who is responsible for fulfilling the request
  8. How the records are securely delivered
  9. How fees are handled when permitted
  10. How the practice documents completion of the request
  11. What happens if the practice cannot locate the records
  12. When an escalation to the Privacy Officer is required

The goal is to create a process that does not depend upon one employee simply remembering what to do.

What About Stolen or Missing Records?

The Shen Smiles case also highlights another important area: PHI must be reasonably safeguarded.

Dental practices should have procedures addressing what happens when protected health information is:

  • Lost
  • Stolen
  • Misplaced
  • Sent to the wrong person
  • Accidentally disclosed
  • Accessed by an unauthorized employee
  • Removed from the office
  • Stored improperly
  • Exposed through an electronic system

Employees should know who to notify immediately when an incident occurs.

A practice should not wait until a patient complains—or until OCR comes knocking—to determine what its response should be.

Your Employees Need to Know the Procedure

HIPAA compliance ultimately comes down to what happens in the dental office every day.

Your employees should understand that a patient’s request for records is not simply an administrative task. It is a federal HIPAA right.

Training should cover:

  • Patient rights under HIPAA
  • Right of Access requirements
  • Identifying a valid records request
  • Verifying the identity of the requester
  • Protecting records during transmission
  • Responding to lost or stolen PHI
  • Reporting suspected privacy incidents
  • Breach response procedures
  • Documentation requirements
  • Who to contact when there is a question

Don’t Wait for an OCR Investigation

The Shen Smiles settlement is the 56th HIPAA Right of Access enforcement action announced by OCR, demonstrating that patient access to medical records continues to be an area of enforcement attention.

For dental practices, the takeaway is straightforward:

Your HIPAA compliance program needs to address both sides of the equation.

You must protect PHI from unauthorized use and disclosure and have procedures that allow patients to exercise their rights under HIPAA.

A policy that says “patients have a right to their records” is not enough.

Your team needs to know exactly what to do when the request comes through the door.

5 HIPAA Policies Every Dental Office Should Review After This Settlement

This settlement is a good reason to pull out your HIPAA manual and review these five policies:

1. Right of Access Policy

Does your practice have a written procedure for receiving, tracking, processing, and completing patient requests for records within HIPAA’s required timeframe?

2. Privacy and Safeguarding of PHI Policy

Does your policy explain how employees must protect paper and electronic PHI from unauthorized access, use, disclosure, loss, or theft?

3. Breach and Incident Response Policy

Does your team know exactly what to do when PHI is lost, stolen, misdirected, or accessed by someone who should not have access?

4. Workforce HIPAA Responsibilities Policy

Are employees clearly told what they are permitted and prohibited from doing with patient information—and how they are expected to report concerns?

5. HIPAA Training and Documentation Policy

Can you demonstrate that employees received appropriate HIPAA training and that the practice maintains documentation of that training?

The Bottom Line

HIPAA compliance is not simply having a binder on a shelf. It is having written policies, trained employees, documented procedures, and safeguards that work when something goes wrong.

The $140,000 Shen Smiles settlement is a reminder that patient access to records is a HIPAA right—and dental practices need to be prepared to honor that right while protecting the information entrusted to them.

Is Your Dental Practice Prepared?

Now is a good time to review your HIPAA program and ask:

If a patient requested a complete copy of their records today, could your team demonstrate exactly how that request would be handled?

And just as importantly:

If patient records were lost or stolen today, would your team know exactly what to do?

If the answer to either question is uncertain, your practice may have a compliance gap that needs attention.

Modern Practice Solutions helps dental practices develop and maintain comprehensive compliance programs, including HIPAA policies, procedures, employee training, privacy and security responsibilities, and documentation designed specifically for the dental environment.

Don’t wait for a complaint or an OCR investigation to discover a weakness in your HIPAA program.

Review your policies. Train your team. Document your procedures. Protect your patients—and your practice.

Author

  • Olivia Wann - Founder - Modern Practice Solutions

    Olivia Wann founded Modern Practice Solutions, LLC in 2000 and later expanded her professional offerings by establishing The Law Office of Olivia Wann & Associates, PLLC in 2012.

    As an attorney, Olivia sets herself apart by prioritizing client education. She demystifies complex legal issues, empowering her clients to make informed decisions.

    View all posts

Olivia Wann

Olivia Wann founded Modern Practice Solutions, LLC in 2000 and later expanded her professional offerings by establishing The Law Office of Olivia Wann & Associates, PLLC in 2012. As an attorney, Olivia sets herself apart by prioritizing client education. She demystifies complex legal issues, empowering her clients to make informed decisions.