HIPAA Training for Oral Surgery Schedulers: Securely Emailing 3D Facial CT Reconstructions to Referring Dentists

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Training for Oral Surgery Schedulers: Securely Emailing 3D Facial CT Reconstructions to Referring Dentists

Kevin Henry

HIPAA

August 21, 2026

7 minutes read
Share this article
HIPAA Training for Oral Surgery Schedulers: Securely Emailing 3D Facial CT Reconstructions to Referring Dentists

HIPAA Compliance for Emailing Patient Information

3D facial CT reconstructions, DICOM studies, and any identifiers you attach to them are Electronic Protected Health Information. When you prepare these files for a referring dentist, treat them as ePHI governed by the HIPAA Privacy and Security Rules. That means safeguarding confidentiality, integrity, and availability at every step.

Your practice must maintain a Written Security Risk Analysis that identifies risks in emailing or sharing imaging, documents the safeguards you use, and maps responsibilities across staff and vendors. Confirm that any email, messaging, or cloud service you rely on signs a Business Associate Agreement and supports encryption, access controls, and audit trails.

Disclosures for treatment are not subject to the Minimum Necessary standard; however, you should still limit what you send to clinically relevant data to reduce risk exposure. Establish clear procedures for verifying recipient identity, labeling messages, and retaining transmission logs for compliance and quality review.

What to include with a CT referral

  • Patient identifiers necessary for matching (name, DOB, MRN/chart ID).
  • Specific study description (e.g., “3D facial CT, date, series”).
  • Brief clinical context or request from the surgeon.
  • Instructions for accessing the files or viewer and who to contact for support.

Secure Email Practices

Whenever possible, use HIPAA-Compliant Data Sharing through a secure portal or Encrypted Messaging instead of standard email attachments. Portals provide stronger Patient Record Access Controls, automatic encryption in transit and at rest, and auditable activity logs.

Step-by-step sending workflow

  1. Verify the recipient: confirm the dentist’s name, practice, and email address using a trusted directory or call-back to the office line on file.
  2. Prepare the data: package only the required series and de-identify any nonessential metadata when feasible.
  3. Choose the channel: prefer a secure portal link with expiration, single-use tokens, and MFA; avoid raw attachments of ePHI in traditional email.
  4. Protect the message: use subject lines without ePHI; include a short cover note and access instructions in the body.
  5. Send the password or code via a separate channel if you use a password-protected archive; ensure strong encryption and unique credentials.
  6. Record the event: save confirmation of delivery, the recipient, and the files sent for your audit log.

Good practices to reduce risk

  • Prefer link-based access over attachments for large DICOM sets and 3D reconstructions.
  • Enable Cloud Storage Security features: encryption at rest, object-level access policies, and geo-redundant backups.
  • Restrict downloads when a view-only workflow suffices, and set automatic link expiration.
  • Document any exceptions and escalate unusual requests to a privacy or security officer.

Breach Notification Requirements

If ePHI is compromised, follow HIPAA’s Breach Notification Rule. Conduct a risk assessment that considers the nature of the data, who received it, whether it was actually viewed, and mitigation taken. If the PHI was encrypted to recognized standards and keys were not compromised, safe harbor may apply.

Notify affected individuals without unreasonable delay and no later than 60 days after discovery. For incidents involving 500 or more individuals in a state or jurisdiction, notify prominent media and the Secretary of HHS within 60 days. For fewer than 500, log the breach and report to HHS annually within the required timeframe.

Immediate actions for schedulers

  • Contain: attempt to recall messages, revoke shared links, or change passwords.
  • Report: escalate to your privacy/security officer at once and complete incident documentation.
  • Assess: collect facts (what, when, to whom) to support the risk assessment.
  • Mitigate: notify unintended recipients to delete data and confirm destruction where possible.

Patient Requests for Unencrypted Email

Patients have a right to receive their records via unencrypted email if they are informed of the risks and still choose that option. Obtain and retain written acknowledgment of their preference, verify the destination address carefully, and note that the Right of Access timelines still apply.

If a patient directs you to send their CT to a third party (such as a referring dentist) using unencrypted email, you may honor the request after risk counseling and documentation. This exception does not obligate you to use insecure methods for routine provider-to-provider exchanges; secure channels remain the default for treatment disclosures.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

How to document

  • Record the patient’s request, the address provided, and that risk counseling occurred.
  • Use a standardized form and store it in the chart for future reference.
  • Apply a consistent subject line convention and avoid placing ePHI in the subject.

Secure Platforms for Sharing Patient Records

Purpose-built platforms reduce friction and improve compliance when sending 3D facial CT reconstructions. Look for end-to-end encryption, robust Patient Record Access Controls, strong Cloud Storage Security, and full audit logging to prove who accessed what and when.

Evaluation checklist

  • Business Associate Agreement availability and clear data processing terms.
  • Encryption in transit and at rest, key management, and link expiration controls.
  • Granular roles/permissions, MFA, IP or domain restrictions, and session timeouts.
  • Bulk upload of DICOM, embedded or web-based viewing, and download controls.
  • Comprehensive audit trails, immutable logs, and exportable reports.

Features of Secure.Dentist

Secure.Dentist provides dental teams with tools for HIPAA-Compliant Data Sharing designed around referral workflows. It focuses on fast, secure exchanges of imaging and documents between oral surgery practices and general or specialty dentists.

  • Encrypted Messaging and file transfer with automatic encryption in transit and at rest.
  • Large-file handling for DICOM sets and 3D reconstructions without email size limits.
  • Time-limited, access-controlled links with optional passwords and MFA.
  • Patient Record Access Controls, role-based permissions, and practice-level user management.
  • Audit trails that record sends, opens, downloads, and revocations.
  • Dental-specific address book and referral tracking to reduce misdirected messages.
  • Business Associate Agreement support and administrative policy controls.

Features of eDossea

eDossea streamlines the exchange of dental records by centralizing uploads and secure sharing in a single portal. It helps schedulers move 3D facial CT data to referring dentists with fewer steps and fewer errors.

  • Secure, link-based sharing that avoids raw email attachments and supports large studies.
  • Configurable expiration, download permissions, and view-only options.
  • Practice directories and contact management to verify recipients before sending.
  • Comprehensive logging for compliance and referral-status visibility.
  • Cloud Storage Security with encryption at rest and data redundancy.
  • BAA availability and admin controls for user provisioning and offboarding.

Features of PostDICOM

PostDICOM offers a cloud PACS with a web-based DICOM viewer suitable for facial CT studies. Referring dentists can review multiplanar 3D reconstructions in the browser without installing local software.

  • Advanced viewing (MPR, MIP, volume rendering) for detailed 3D assessment.
  • Secure sharing via expiring links, optional passwords, and recipient-specific permissions.
  • Encryption in transit and at rest, plus fine-grained Patient Record Access Controls.
  • Audit logs for each access event and exportable reports for investigations.
  • Anonymization tools when de-identification is requested for training or consultation.
  • Business Associate Agreement support and administrative policy settings.

Conclusion

For HIPAA training that sticks, standardize a secure workflow: verify recipients, use encrypted portals with strong access controls, log every transmission, and prepare for breaches with clear playbooks. Empower schedulers to honor informed patient requests while making secure, auditable sharing the default for 3D facial CT reconstructions.

FAQs

What are the key HIPAA requirements for emailing patient information?

Protect ePHI with encryption in transit and at rest, maintain a Written Security Risk Analysis, use vendors that sign BAAs, verify recipients, and keep audit logs. Apply the Minimum Necessary principle where applicable, train staff regularly, and follow the Breach Notification Rule if something goes wrong.

How can oral surgery schedulers verify email addresses securely?

Confirm the address using a trusted directory or the practice’s published phone number, perform a call-back to the office, and send a non-ePHI test message when first establishing contact. Maintain an approved contact list, require dual review for new recipients, and use platforms with built-in directories and access controls.

What should be done in case of a patient information breach?

Immediately contain the incident (revoke links, reset credentials), escalate internally, and complete a documented risk assessment. Notify affected individuals within required timelines, report to HHS as applicable, preserve logs, and implement mitigation steps such as recipient attestations of deletion and targeted staff retraining.

How do HIPAA-compliant platforms improve data security?

They centralize HIPAA-Compliant Data Sharing with encryption, Cloud Storage Security, and Patient Record Access Controls, while generating tamper-evident audit trails. Role-based permissions, MFA, link expiration, and BAAs reduce misdelivery risk and simplify proof of compliance during audits or investigations.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles