Skip to content
Hipsana

For independent dental practices

HIPAA shouldn’t require a compliance officer
you can’t afford.

Hipsana helps clinicians who run their own practice find the HIPAA gaps that put them at risk, and lays out how to close them. Start with a free Security Scorecard: ten questions, about three minutes, a score and a written review at the end.

Free · about three minutes · a starting point, not a full audit

HIPAA SECURITY SCORECARD · SAMPLE RESULTFree
59out of 100

Some gaps

05086100
Risk analysis in the last 12 monthsBIGGEST GAP
Signed BAAs with all vendors
Two-factor login (2FA)
HIPAA-compliant email
Tested backup and recovery plan
Devices auto-lock with a password
Ten questions on how your practice handles patient data. A score, your biggest gap named, a written review by email. A starting point, not a full audit.Try it yourself

Three things we won’t compromise on.

Plain-language risk findings

We translate the HIPAA Security Rule into the handful of gaps that actually put your practice at risk. The answer comes first, the jargon stays out.

Independent-practice scale

Enterprise security tools are designed for IT departments you don’t have. We focus on what works for a one-to-ten-person practice.

Cited, not invented

Every regulatory claim points back to HHS, OCR, or NIST. We qualify what we can’t verify and tell you where we drew the line.

What one gap has cost

$750,000one missing vendor agreement2016
$111,400a login that outlived the job2018
$1,165,000four ransomware settlements, one shared failure2026

Named cases, documented at HHS. Read the enforcement report ›

From the public record

What a missing risk analysis actually costs

In 2020, a solo physician’s practice settled with HHS for $100,000 and two years of federal monitoring. The trigger wasn’t a hacker or a stolen laptop. OCR found the practice had failed to complete one basic document: the risk analysis the HIPAA Security Rule requires. To OCR, a solo physician and a solo dentist answer to the same baseline. The free Scorecard checks whether that document, and the gaps around it, exist in yours.

Excerpts from the HHS Office for Civil Rights resolution agreement with Steven A. Porter, M.D., P.C., a solo practice, with the cited failure to conduct a risk analysis and the $100,000 settlement highlighted.
Source: U.S. Department of Health and Human Services, Office for Civil Rights. Press release, March 3, 2020 (the practice of Steven A. Porter, M.D.). Highlights added by Hipsana.
Read the report

Dental HIPAA Breach and Enforcement Report (2026)

We read the public HHS breach and enforcement data so you don’t have to: how dental practices actually get breached, and the one failure OCR keeps fining them for.

Start with the free HIPAA Scorecard.

Answer ten yes/no questions about how your practice handles patient data. You’ll get a score out of 100, based on your answers, and a written review of the gaps they point to, plus the option to book a short free risk review and an intro to a specialist if a referral makes sense. About three minutes. It’s a starting point, not a full audit, and it does not replace a full risk analysis.

DA

Written and researched by Dolev Arama, founder

Hipsana is written by its founder, Dolev Arama. He built the Scorecard and writes the reviews behind it. He is not an attorney, and Hipsana is a publisher and referral service, not a law firm or a healthcare provider. And he won’t pretend to be a compliance authority. What he brings instead is one rule he doesn’t break: every regulatory claim is traced to the regulator that made it (HHS, OCR, or NIST). Where a figure comes from breach data or industry research, the source is named, and anything he can’t verify gets labeled, not guessed. That’s the point. You never have to take his word for any of it: the sources are named, and you can open every one yourself. How we research and source ›