Is AI Dental Software HIPAA Compliant? What to Actually Ask Vendors (2026)
Every AI vendor says "HIPAA compliant." Almost none of them explain what that means in practice. Here are the specific questions that separate a real answer from a marketing checkbox.
Quick Answer
Reputable AI dental vendors will all say they're HIPAA compliant, and most of them are telling the truth as far as it goes: encrypted transmission, a signed BAA, and access controls are close to table stakes at this point. The real evaluation happens one level deeper: how is audio handled (stored or discarded), is your PMS chart copied into a separate database or read in place, can you export or delete every record the vendor holds on a patient, and is the BAA included automatically or something you have to negotiate. Ask those four questions of any vendor, dental AI or otherwise, before the compliance conversation is considered closed.
Key Takeaways
- "HIPAA compliant" is not a certification a vendor earns once and displays forever. It's an ongoing set of practices, and the phrase alone tells you almost nothing about what a vendor actually does with your data.
- Every dental AI vendor worth evaluating will say yes when asked if they're HIPAA compliant. The differentiator isn't the yes, it's what happens when you ask the follow-up questions.
- A signed Business Associate Agreement (BAA) is non-negotiable and should be included at no extra cost. If a vendor hesitates, charges extra, or won't put it in writing before a trial, that's the answer.
- Data retention is the question most practices don't ask and most vendors don't volunteer. Whether audio is stored or discarded, and whether your PMS chart is copied into a second database, changes your actual risk exposure more than any compliance badge does.
- There is no independent SOC 2 attestation currently listed on Marea's public security page. If SOC 2 status matters to your evaluation, ask any vendor directly and get it in writing rather than assuming based on general "enterprise-grade security" language.
What "HIPAA Compliant" Actually Means for AI Vendors
HIPAA (the Health Insurance Portability and Accountability Act) sets rules for how protected health information gets handled, stored, and transmitted in the United States. For a software vendor, being "HIPAA compliant" generally means: encrypting data in transit and at rest, maintaining access controls and audit logs, and signing a Business Associate Agreement (BAA) with each covered entity, in this case, your practice, that spells out how PHI will be handled.
What it doesn't mean is that the vendor's product is automatically safe in every sense that matters to a dental practice. HIPAA compliance is a floor, not a ceiling. Two vendors can both be genuinely, accurately HIPAA compliant while handling your data in meaningfully different ways, one storing every call recording indefinitely, the other discarding audio the moment a transcript is generated. Both can say "HIPAA compliant" honestly.
Why Every Vendor Says Yes (And Why That's Not Enough)
Ask any AI scribe, AI receptionist, or practice management vendor whether they're HIPAA compliant, and the answer will be yes. This isn't usually a lie. Basic HIPAA compliance (encryption, a BAA, access logging) has become close to a baseline requirement to sell into healthcare at all, so the vendors still standing in the dental AI market have generally cleared that bar.
The problem is that "yes" answers a question that isn't specific enough to be useful. It tells you the vendor meets a minimum standard, not how they handle the decisions that sit above that minimum: what gets stored, for how long, who can access it, and what your options are if you want to leave. Those are the questions worth spending your evaluation time on, because the "are you HIPAA compliant" question has already been answered by every vendor still in the conversation.
Related read: Which Dental PMS Systems Integrate With AI Software.
The Questions That Actually Separate Vendors
These are the follow-up questions worth asking after a vendor confirms they're HIPAA compliant. The answers are where the real differences show up.
01. Is the Business Associate Agreement included, or an add-on? A BAA should be signed with every customer, automatically, before go-live, at no extra cost. If a vendor treats it as an enterprise-tier upsell or something that requires a separate negotiation, that's worth noting before you sign anything.
02. Is audio stored, or discarded after transcription? For any AI scribe or AI receptionist, ask specifically what happens to the recording once the transcript exists. Vendors that discard audio immediately after processing have a fundamentally smaller amount of sensitive data sitting on a server, and therefore less that could ever be exposed in a breach.
03. Does the tool copy your PMS chart, or read it in place? Some AI tools replicate a copy of your patient records into their own database to work with them. Others connect directly to your PMS and read what they need without copying it elsewhere. A replicated copy is a second location holding protected health information that you're responsible for, whether or not you think about it day to day.
04. Can you export or delete everything the vendor holds on a patient? Ask this directly, and ask how long it takes. A vendor that can produce or delete a patient's full record within hours is telling you something concrete about how their data architecture actually works, not just what their policy document says.
05. Is your data ever used to train models, or shared with third parties? This should be a flat no, in writing. If a vendor's answer involves qualifiers about "anonymized" or "aggregated" data, ask exactly what that means before accepting it as equivalent to "no."
06. Where, specifically, does data live? "The cloud" isn't an answer. Ask which systems retain data, for how long, and whether that's disclosed anywhere in writing you can reference later, not just something a salesperson said on a call.
Related read: The HIPAA question every dentist asks us.
Audio and Data Retention: The Question Most Practices Skip
Of every question on this list, data retention gets asked the least, and it's arguably the one that matters most. It's easy to focus a compliance conversation on encryption and BAAs, because those are binary and easy to confirm. Retention is a spectrum, and vendors describe it in whatever language sounds best.
Two practices can both be working with a "HIPAA-compliant, encrypted, BAA-covered" AI scribe, and one of them has months of stored patient audio sitting on a vendor's servers while the other has none, because the second vendor discards audio the moment a transcript is generated. Both vendors are compliant. Only one of them has meaningfully less to protect, and less that could ever be exposed if something goes wrong.
The same logic applies to your PMS chart. A tool that reads your chart in real time and never copies it holds less risk than one that replicates your patient database into its own system, even if both are encrypted and covered by a BAA.
What "HIPAA Compliant" Claims Typically Cover vs. Leave Out
| Typically covered by "HIPAA compliant" | Often left out, ask directly |
|---|---|
| Data encrypted in transit (TLS) | Whether audio is stored at all, and for how long |
| Data encrypted at rest (AES-256 or similar) | Whether your PMS chart is copied or read in place |
| A Business Associate Agreement exists | Whether the BAA is included automatically or a paid add-on |
| Role-based access controls | How quickly you can export or delete a patient's full record |
| Audit logging of access | Whether data is ever used to train models |
| General "compliant with HIPAA Security and Privacy Rules" language | Independent third-party attestations (e.g., SOC 2), if not listed publicly |
How Marea Approaches This
Marea is built around holding as little patient data as possible, on the reasoning that data that was never stored can't be part of a future breach. A few specifics, all verifiable on Marea's security page:
- Audio is never stored. Calls and operatory recordings are processed in real time and discarded; nothing is written to disk.
- The PMS chart is never replicated. Marea reads and writes directly to the PMS platforms it supports (including Dentrix, Dental EMR, DentiMax, TDO and others) without copying the patient database elsewhere.
- A BAA is signed with every customer before go-live, automatically, at no additional cost.
- Data is encrypted in transit (TLS 1.2+) and at rest (AES-256) for the artifacts Marea does retain: call summaries, generated letters, and form submissions.
- What Marea does retain is exportable and deletable on request, and is never used to train external models or shared with third parties.
Where this stands today: there is no independent SOC 2 attestation currently listed on Marea's public security page. If that specific certification matters to your practice's procurement process, ask directly rather than assuming either way, and treat any vendor's answer the same way, in writing, not verbally.
Have a security review to get through? Book a walkthrough with our team. We'll go line by line through the BAA, data retention, and PMS integration questions your IT or compliance lead is going to ask. Book a Free Demo.
What to Ask Before You Sign
- Get the BAA in writing before your trial starts, not after you've committed.
- Ask specifically whether audio is stored or discarded, and for how long if stored.
- Ask whether your PMS chart is copied into the vendor's own database, or read without being copied.
- Ask how quickly you can get a full export, or a full deletion, of everything held on a given patient.
- Ask directly whether your data is ever used for model training, and get a flat answer, not a qualified one.
- Ask for any independent certifications (SOC 2 or otherwise) in writing rather than assuming from general marketing language.
Frequently Asked Questions
Is AI dental software HIPAA compliant?
Reputable vendors generally are, in the baseline sense: encrypted data, a signed BAA, and access controls. But "HIPAA compliant" doesn't tell you how a vendor handles the decisions above that baseline, whether audio is stored, whether your PMS chart is copied, and how easily you can export or delete your data. Ask those questions directly rather than treating "HIPAA compliant" as the end of the conversation.
What's the difference between being HIPAA compliant and having a BAA?
HIPAA compliance describes a set of practices around handling protected health information. A Business Associate Agreement is the specific legal contract between your practice and a vendor that spells out how that vendor will handle PHI on your behalf. A vendor can claim general compliance without one, which is why asking for the signed BAA directly, in writing, before you commit, matters more than the general claim.
Does storing call audio matter if the vendor says they're HIPAA compliant?
Yes. Stored audio containing patient conversations is protected health information sitting on a server, encrypted or not. A vendor can be fully HIPAA compliant while storing months of recordings, or fully HIPAA compliant while discarding audio immediately after transcription. Both are "compliant." Only one of them has meaningfully less exposure if something ever goes wrong. Ask specifically which model any vendor uses.
Sources & Further Reading
Marea resources
More from the Marea blog
Marea is the clinical documentation platform for dental practices. Marea Documentation writes the note, the letter, and the perio chart. Marea Inbound answers the call and completes intake — on the PMS you already use.