Skip to main content

Does Your Dental Office Website Have to Comply with the ADA?

by Olivia Wann

Your dental practice may be ADA compliant inside the office—but what about your website?

For many dental practices, the website is the first interaction a patient has with the practice. Patients use dental websites to learn about services, find office hours, complete forms, request appointments, make payments, review insurance information, and communicate with the office.

If a patient with a disability cannot effectively access that information or use those online services, your practice may have an accessibility problem.

The ADA Doesn’t Stop at the Front Door

The Americans with Disabilities Act (ADA) is designed to prevent discrimination against individuals with disabilities and to provide equal access to goods and services.

Dental offices are generally considered places of public accommodation under Title III of the ADA. While the ADA was enacted long before most businesses had websites, website accessibility has become an increasingly important issue for businesses that provide services to the public.

For a dental practice, that means ADA compliance should not be limited to the physical office.

Your ADA compliance review should also consider your digital front door: your website and patient portals.

United States v. Springfield Clinic, LLC

In May 2024, the DOJ entered into a Title III settlement with Springfield Clinic, a healthcare provider, after a patient with a vision disability complained that the clinic’s website and web-based patient services were inaccessible to screen-reader users.

The DOJ settlement required the clinic to:

  • Make its websites and web-based services accessible;
  • Address its patient and records-request portals;
  • Follow WCAG 2.1 AA;
  • Adopt a web accessibility policy;
  • Designate a web accessibility coordinator;
  • Train employees;
  • Conduct accessibility testing; and
  • Provide compensation to the complainant.

That’s very relevant to a dental practice because it involves a healthcare provider whose website was connected to patient services.

Although courts have not uniformly agreed on whether every website is independently covered by Title III of the ADA, website accessibility claims continue to be litigated, and the Department of Justice continues to pursue website-accessibility enforcement. For healthcare providers, the issue is particularly significant when a website provides access to patient services

What Could Make a Dental Website Inaccessible?

A website can look attractive and function perfectly for most visitors while still creating barriers for patients with disabilities.

Consider a patient who is blind and uses a screen reader. If your website contains photographs of your office, doctors, or procedures without appropriate alternative text, the patient may not receive the same information as other visitors.

Or consider a patient who cannot use a mouse and relies on keyboard navigation. If the appointment request form or menu cannot be navigated with a keyboard, the patient may be unable to contact your practice or request an appointment.

Common accessibility issues on dental websites may include:

  • Images without appropriate alternative text
  • Videos without captions
  • Poor color contrast
  • Forms that cannot be completed using a keyboard
  • Online appointment systems that are inaccessible
  • Links that do not clearly identify their purpose
  • PDFs that cannot be read by screen readers
  • Pop-ups that cannot be closed using a keyboard
  • Improperly structured headings
  • Inaccessible patient forms
  • Online payment systems that create accessibility barriers
  • Third-party scheduling or communication platforms that are not accessible

What About Your Online Appointment System?

This is particularly important for dental offices.

Many practices allow patients to request or schedule appointments online. If that system is inaccessible to a patient with a disability, the problem may extend beyond the practice’s website itself.

Dental offices should look at the entire patient experience—not simply the homepage.

Ask:

Can a patient with a disability independently:

  • Find your office location?
  • Learn about your services?
  • Find your telephone number?
  • Request an appointment?
  • Complete new-patient forms?
  • Access financial or insurance information?
  • Read important patient instructions?
  • Contact the office electronically?
  • Navigate your website without a mouse?
  • Use your website with a screen reader?

If the answer is no, your practice may need to address accessibility barriers.

Don’t Forget Your PDFs and Patient Forms

Dental practices frequently place documents on their websites, including:

  • New-patient forms
  • Medical history forms
  • Financial policies
  • HIPAA notices
  • Privacy policies
  • Post-operative instructions
  • Patient education materials
  • Insurance information
  • Registration documents

Simply making a PDF available for download does not necessarily make it accessible.

A PDF may need to be properly structured so that assistive technology can interpret the document and present the information to the user.

Every document you add to your website should be considered part of your accessibility program.

What Are the WCAG Guidelines?

The Web Content Accessibility Guidelines (WCAG) are commonly used as a technical framework for improving website accessibility.

WCAG focuses on four basic principles. Website content should be:

Perceivable – Patients should be able to perceive the information being presented.

Operable – Patients should be able to navigate and interact with the website.

Understandable – Information and navigation should be clear and understandable.

Robust – The website should work with a variety of browsers, technologies, and assistive devices.

WCAG can be a valuable resource for dental practices working with their website developers to improve accessibility.

However, simply stating that a website is “WCAG compliant” does not necessarily eliminate every potential legal concern. Dental practices should consider their specific circumstances and applicable legal requirements.

Don’t Rely Solely on an Accessibility Widget

Some dental practices have added accessibility widgets or overlays to their websites believing that this automatically makes the website ADA compliant.

It isn’t that simple.

An accessibility tool may provide useful features, but it should not be viewed as a substitute for addressing accessibility problems in the underlying website.

A better approach is to identify potential barriers, correct them, and establish a process for maintaining accessibility as the website changes.

Dental Websites Change Constantly

Website accessibility should not be treated as a “one and done” project.

Dental practices routinely add new:

  • Doctors and staff
  • Services
  • Blog posts
  • Photos
  • Videos
  • Patient forms
  • Online scheduling features
  • Payment systems
  • Patient education materials
  • Third-party applications

Any of these changes can potentially create a new accessibility barrier.

For that reason, website accessibility should be incorporated into your practice’s ongoing compliance efforts.

What Should Your Dental Practice Do?

Consider adding website accessibility to your practice compliance checklist.

1. Have Your Website Evaluated

Work with someone knowledgeable about website accessibility to identify potential barriers.

Automated scanning tools can be helpful, but automated testing alone may not identify every accessibility problem.

2. Review Your Patient-Facing Technology

Don’t stop with your homepage.

Review your:

  • Online scheduling system
  • Patient forms
  • Payment portal
  • Patient portal
  • Contact forms
  • PDFs
  • Videos
  • Chat features
  • Third-party applications

3. Correct Identified Problems

Prioritize and address accessibility barriers rather than simply documenting them.

Your website developer should be involved in correcting technical issues.

4. Develop an Accessibility Policy

Consider creating a written website accessibility policy explaining your practice’s commitment to providing accessible digital information and services.

5. Provide a Way to Report Accessibility Problems

Patients should have a clear way to contact your practice if they encounter difficulty accessing information or services online.

Your practice should have a process for responding to those concerns.

6. Train the Appropriate Team Members

The people responsible for updating your website should understand basic accessibility principles.

Something as simple as uploading an image without appropriate alternative text can create an accessibility issue.

ADA Compliance Is Part of the Patient Experience

For dental practices, accessibility isn’t simply a legal issue. It is also about providing patients with equal access to healthcare information and services.

Your website is your digital front door.

Just as you want your physical office to be accessible to patients with disabilities, you should consider whether your online presence provides meaningful access as well.

Don’t wait until a complaint or demand letter brings website accessibility to your attention.

Take a proactive approach. Review your website, identify potential barriers, correct them, and make accessibility part of your dental practice’s ongoing compliance program.

Is Your Dental Practice’s Website Accessible?

If your practice has never evaluated its website for accessibility, now is a good time to put it on your compliance checklist.

A comprehensive compliance program should look beyond the four walls of the dental office—and that includes the technology your patients use to interact with your practice.

Your patients deserve access to your practice—both inside the office and online.

E-Assist Data Breach – Take Action Now!

By Olivia Wann

eAssist Dental Solutions has been the target of a ransomware attack claimed by the DireWolf threat actor group although full details and the extent of the data breach is yet under investigation.

eAssist is one of the largest third-party dental insurance billing companies in the country.  As of date, the breach is an unconfirmed claim.  However, what we do know is that DireWolf published a listing naming eAssist Dental Solutions.  Neither eAssist or majority interest owner, Henry Schein, has issued a statement yet.

Should you just wait and see what happens if you were a customer of eAssist?  What should you do?

The Office for Civil Rights (OCR) publishes HIPAA breaches that are currently under investigation at U.S. Department of Health & Human Services – Office for Civil Rights.  eAssist does not yet appear as of the date of this article.

Take action now!  Suggested steps include:

In compliance with HIPAA, maintain a security-incident procedure and documentation:

  • Date you became aware of the reports
  • Where you learned about the alleged incident
  • Your relationship with eAssist
  • Your current BAA with eAssist
  • What types of PHI eAssist receives
  • What systems/accounts eAssist can access
  • Communications with eAssist
  • Your investigation and mitigation steps – see provided checklist

Review your BAA with eAssist.  HIPAA requires a business associate to report security incident sand breaches to the covered entity, and the BAA may impose more specific reporting requirements. 

Specifically look for the following information on the BAA:

  • Security incident notification
  • Breach notification
  • Time limits for notification
  • Cooperation with investigations
  • Access to forensic information
  • Data return/destruction
  • Subcontractor requirements
  • Indemnification
  • Cybersecurity requirements
  • Termination rights

Don’t assume that because eAssist handles the breach, the dental practice has no responsibility.

Contact eAssist in writing and inquire:

___  Has eAssist experienced a cybersecurity incident?

___  Is the September 2026 ransomware claim legitimate?

___  When was the incident discovered?

___  When did the unauthorized access allegedly occur?

___  What systems were accessed?

___  Was the practice’s data involved?

___  Was ePHI involved?

___  What categories of PHI were potentially accessed?

___  How many patients may be affected?

___  Was data exfiltrated?

  • Was ransomware deployed?
  • Has law enforcement been notified?
  • Has eAssist engaged an independent forensic firm?
  • Has eAssist notified its cyber-insurance carrier?
  • Has eAssist notified HHS/OCR?
  • When will affected customers receive a formal breach report?
  • What containment and remediation measures have been implemented?

Discuss with your IT/cybersecurity team what eAssist had access to that relates to your data base:

What does eAssist have access to?

For example:

  • Practice management system
  • EHR
  • Patient demographics
  • Insurance information
  • Claims
  • Payment information
  • Account balances
  • Treatment information
  • Social Security numbers, if applicable
  • Driver’s license information, if applicable
  • Banking information
  • Provider credentials
  • Patient portals
  • Remote-access accounts

Then determine whether eAssist has ongoing access.

If unnecessary access exists, restrict it.

HHS emphasizes access controls, audit controls, encryption, incident response, and risk analysis as important Security Rule safeguards

Review your audit logs.

Ask your IT vendor to review:

  • eAssist user activity
  • Remote logins
  • Failed login attempts
  • Privileged-account activity
  • Downloads/export activity
  • Unusual after-hours activity
  • Bulk patient-record access
  • Changes to banking/payment information
  • Changes to user permissions

Preserve the logs. Don’t simply delete or overwrite them.

Update your HIPAA Security Risk Analysis.

This is especially important given OCR’s current emphasis on risk analysis.

Your risk analysis should now address the risk associated with your third-party billing/business-associate relationship with eAssist.

Document:

Threat: Cyberattack against business associate handling practice ePHI

Vulnerability: Reliance upon external vendor’s cybersecurity controls

Potential impact: Unauthorized access, disclosure, alteration, destruction, or unavailability of ePHI

Existing controls: BAA, encryption, access controls, MFA, audit logging, vendor due diligence

Additional mitigation: Written incident inquiry, access review, enhanced monitoring, contingency planning, vendor reassessment

HHS specifically states that covered entities and business associates must conduct risk analyses addressing threats and vulnerabilities to the confidentiality, integrity and availability of ePHI.

Can you Afford to Pay a $552,250 Settlement for HIPAA Violations? 

by Olivia Wann, JD

Another ransomware enforcement action sends a clear message to health care providers: A HIPAA risk analysis must be accurate, thorough, and capable of identifying the organization’s actual cybersecurity risks.

On July 29, 2026, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with OSF HealthCare System and its affiliated covered entities, marking OCR’s 21st ransomware enforcement action. OSF agreed to pay $552,250 and comply with a corrective action plan that will be monitored by OCR for two years.

The case arose from a 2021 ransomware attack involving the Nephilim ransomware variant. OSF discovered evidence of ransomware on April 23, 2021. During its investigation, OSF determined that threat actors had stolen the protected health information (PHI) of 53,907 individuals.

What Did OCR Find?

OCR’s investigation identified several areas of concern under the HIPAA Privacy, Security, and Breach Notification Rules.

According to the Resolution Agreement, OCR determined that OSF:

  • Failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to its electronic protected health information (ePHI);
  • Impermissibly disclosed the PHI of 53,907 individuals as a result of the stolen data;
  • Failed to provide timely notification to affected individuals; and
  • Failed to provide timely notification to the HHS Secretary regarding the breach affecting more than 500 individuals.

The settlement itself does not constitute an admission of liability by OSF. The parties entered into the agreement to resolve the OCR investigation.

The Corrective Action Plan Is Particularly Important

For health care organizations, the corrective action plan may be more instructive than the settlement amount.

OSF must conduct an accurate and thorough risk analysis addressing security threats and vulnerabilities involving its ePHI. The analysis must incorporate electronic equipment, data systems, programs, applications, off-site data storage, and other technology that creates, receives, maintains, or transmits ePHI.

OSF must also develop and implement an enterprise-wide risk management plan addressing the risks and vulnerabilities identified through its risk analysis. The plan must include processes and timelines for implementing, evaluating, and revising remediation activities.

The corrective action plan goes beyond simply completing a risk assessment and putting it in a file. OSF is required to conduct annual assessments during the two-year compliance period and report its compliance to OCR.

Workforce Compliance Is Also Under the Microscope

Another significant component of the corrective action plan involves workforce compliance.

If OSF determines that a workforce member failed to comply with its existing Privacy, Security, or Breach Notification policies and procedures, OSF must investigate the matter and, when appropriate, report the event to OCR. The report must describe the event, the policies involved, and the corrective and preventive measures taken—including appropriate sanctions when warranted.

OSF must also submit annual reports to OCR that include an attestation regarding completion of required HIPAA training by its workforce.

What Does This Mean for Dental Practices?

While OSF is a large health care system, the lesson is highly relevant to dental practices of every size.

OCR’s ransomware enforcement actions demonstrate that cybersecurity compliance is not limited to having antivirus software, firewalls, backups, or a written HIPAA policy. A practice must be able to demonstrate that it has identified its actual risks to ePHI and has taken reasonable steps to address those risks.

For a dental practice, that risk analysis should consider the technology and systems actually used by the practice, including:

  • Practice management and electronic health record systems;
  • Cloud-based software and storage;
  • Email systems;
  • Patient portals;
  • Computers, laptops, and mobile devices;
  • Backup systems;
  • Dental imaging and radiography systems;
  • Remote access;
  • Third-party vendors and business associates;
  • Cybersecurity protections and vulnerabilities;
  • Workforce access to ePHI; and
  • Emerging technologies, including artificial intelligence (AI) tools.

A generic HIPAA risk assessment that does not accurately reflect the practice’s current technology, vendors, workflows, and vulnerabilities may not be enough.

The Takeaway

The OSF settlement is another reminder that HIPAA compliance must be an ongoing process—not a binder on a shelf.

A strong HIPAA Security Rule compliance program should include a current and thorough risk analysis, a documented risk management plan, appropriate policies and procedures, workforce training, vendor oversight, incident response procedures, and documentation demonstrating that identified risks are actually being addressed.

OCR’s ransomware enforcement actions continue to reinforce one important point:

If your practice cannot identify its cybersecurity risks, it cannot effectively manage them. And if you cannot demonstrate your compliance efforts, you may have difficulty defending your program when OCR comes knocking.

The complete OSF HealthCare System Resolution Agreement and Corrective Action Plan is available from HHS OCR. Read the OSF Resolution Agreement and Corrective Action Plan

Source: U.S. Department of Health and Human Services, Office for Civil Rights, July 29, 2026.

The Power of a Handshake: Why Human Connection Still Matters in Dentistry

By Olivia Wann

In a world filled with emails, text messages, video meetings, and social media, there is one simple gesture that continues to leave a lasting impression—a handshake.

Recently I was travelling to the Association of Dental Safety annual conference. A large group of us made reservations at a nearby restaurant.  The waitress was running frantically attending to everyone’s request. She went the extra mile assuring that everyone was taken care of in her seating area. On leaving, I extended my hand to shake hers. Initially she appeared shocked. “Why is this businesswoman shaking my hand?” she probably thought. And then her face glowed with a large smile as I thanked her for working hard to make our dinner amazing. I treated her with the same level of respect as I would another professional.

I always shake the hand of my Uber driver and thank them for getting me to my destination safely. One of the drivers remarked that he deals with people from all over the world, but not many that took the time to shake his hand.

Do you introduce yourself to your new patient?  Does it include a handshake?

During the COVID-19 pandemic, handshakes virtually disappeared. We became accustomed to waving from a distance, bumping elbows, or avoiding physical contact altogether. While those precautions served an important purpose during a public health crisis, many people never returned to one of the oldest forms of greeting.

Perhaps it’s time we did.

A firm handshake accompanied by eye contact and a genuine smile communicates something technology never can. It says, “I’m happy to meet you. You have my full attention.” It establishes trust, confidence, and respect in just a few seconds.

Whether you are welcoming a new patient, interviewing a job candidate, or introducing yourself at a networking event with other dental professionals, personal interaction matters. People may forget what was said during a conversation, but they often remember how they felt. A warm greeting can make someone feel valued before a single word is spoken.

The dental and legal professions are built on relationships. Clients and patients are often experiencing uncertainty or stress. They want to know they are more than a file, a chart, or a case number. A handshake—when appropriate—helps bridge that gap and reminds people they are interacting with another human being who genuinely cares.

Of course, good hand hygiene remains important.  Most dental offices have hand sanitizer located throughout the dental office.  We are all well versed in how to wash our hands properly.  I have hand sanitizer in my office, in my purse and in my car. These simple precautions allow us to enjoy the benefits of personal connection while remaining mindful of health and safety.

As our society becomes increasingly digital and artificial intelligence handles more routine tasks, authentic human interaction becomes even more valuable. No software can replace empathy, kindness, or the confidence conveyed through a sincere greeting.

So the next time you meet someone, don’t underestimate the impact of extending your hand. That brief moment of connection may be the beginning of a trusted relationship, a lifelong client, a meaningful friendship, or simply someone’s brighter day.

Sometimes the most powerful communication requires no words at all.

Should a Teenage Minor Bring a Younger Sibling to the Dentist Without a Parent or Legal Guardian?

By Olivia Wann

It is not uncommon for busy families to ask an older teenage child to bring a younger sibling to a dental appointment. While this may seem like a practical solution, dental practices should carefully consider the legal and ethical implications before treating a minor patient without a parent or legal guardian present.

In general, a minor cannot provide legal consent for another minor’s dental treatment. Parents and legal guardians have the legal authority to make healthcare decisions for their children unless a specific law provides otherwise. An older sibling—even one who is 16 or 17 years old—is typically not authorized to consent to examinations, radiographs, restorative treatment, extractions, or other dental procedures on behalf of a younger sibling.

Unless the older sibling has been appointed as the younger child’s legal guardian or has another legally recognized authority to make healthcare decisions, the dental practice should not rely on the teenager’s permission to proceed with treatment.

What About Routine Hygiene Appointments?

Even for what appears to be a routine preventive visit, unexpected findings may require additional treatment or decisions. During an examination, the dentist may discover:

  • Dental decay requiring restorative treatment
  • A fractured tooth
  • An abscess or infection
  • The need for radiographs beyond those anticipated
  • An orthodontic concern
  • An urgent condition requiring immediate care

Without an authorized decision-maker available, the practice may have to postpone recommended treatment or obtain parental authorization before proceeding.

Many dental practices ask parents to complete written authorization forms allowing another adult, such as a grandparent, babysitter, or family friend, to accompany a child to an appointment. These forms may authorize the office to communicate with that adult and, depending on state law and the language of the authorization, permit consent for limited routine care.

However, simply sending a younger child with an older teenage sibling is different. A signed note from a parent may not be sufficient to authorize a minor sibling to make healthcare decisions. Dental offices should consult state law and legal counsel regarding what types of delegation are legally recognized.

Emergencies Present Additional Challenges

Suppose a child experiences a medical emergency, allergic reaction, or other unexpected complication during the visit. Having a parent or legal guardian readily available is important to discuss treatment options, provide medical history, and authorize necessary care if time permits.

Best Practice for Dental Offices

To reduce legal risk and protect patients, dental practices should consider implementing a written policy that addresses who may accompany a minor patient and who is authorized to consent to treatment. The policy should include procedures for:

  • Verifying the identity of the parent or legal guardian.
  • Obtaining appropriate consent before treatment.
  • Documenting telephone consent when permitted by law and office policy.
  • Identifying situations in which treatment should be postponed until a parent or legal guardian is available.
  • Training staff on the office’s consent procedures.

When a parent cannot attend an appointment, it is often preferable to have another authorized adult accompany the child rather than an older teenage sibling.

The Bottom Line

While allowing an older sibling to bring a younger child to the dentist may be convenient, convenience should never outweigh proper consent procedures. Every dental office should have clear policies that comply with applicable state law and protect both the patient and the practice.

When in doubt, obtain consent from the parent or legal guardian before providing treatment. A few extra minutes spent confirming authorization can help avoid misunderstandings, reduce liability, and ensure that the child’s best interests remain the primary focus of care.

Disclaimer: This article is intended for educational purposes only and is not legal advice. Dental practices should consult legal counsel regarding state-specific laws governing consent for the treatment of minors.

Why Every Dental Practice Needs an Artificial Intelligence Policy

by Olivia Wann

Artificial intelligence (AI) is rapidly transforming the health care landscape. Dental professionals are increasingly using AI-powered tools to assist with administrative tasks, patient communications, clinical documentation, treatment planning, marketing, and operational efficiency. While these technologies offer significant benefits, they also introduce new privacy, security, compliance, and ethical risks that many dental practices have not yet fully addressed.

Continue reading

Why Should Instruments Remain Packaged Until Point of Use?

By Olivia Wann

In every dental practice, infection prevention depends on more than running instruments through a sterilizer. Proper handling after sterilization is equally important. Once instruments have been sterilized and sealed in approved sterilization pouches, they should remain packaged until the exact moment they are needed for patient treatment. Opening pouches ahead of time defeats an important layer of protection and increases the risk of contamination.

Continue reading

Safety Squints?

by Caitlin Denison, BS, RDH, CHPC

When many of us think of eye protection, we think of safety glasses worn by nail-gun-wielding construction workers, or the goggles worn by chemical-mixing scientists. What our imagination often fails to offer up are images of a hygienist whose prophy angle is spraying polish about, or the dentist using a high-speed drill to excavate-and possibly fling- decay, or even the dental assistant peering into the mouth of a patient whose salivary glands threaten to spray without notice (see the recent TikTok phenomenon of ‘gleeking’.)

Continue reading

Ten Reasons to Choose a Lawyer Familiar with Dentistry to Draft Your Buy-Sell Agreement

by Olivia Wann

Thirty-four percent of dentist owners plan to retire within six years according to Dental Post’s 2025 Dental Salary Survey Report. If you are interested in selling a practice or buying a practice, there are important legal considerations. Selecting a lawyer who understands the many facets of dentistry to prepare or review a buy-sell agreement is to the dentist’s advantage.  Here’s my top ten reasons why:

Continue reading