South Carolina PDMP Query and Patient Privacy Laws: A Guide for Independent Dental Groups

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

South Carolina PDMP Query and Patient Privacy Laws: A Guide for Independent Dental Groups

Kevin Henry

Data Privacy

August 19, 2026

8 minutes read
Share this article
South Carolina PDMP Query and Patient Privacy Laws: A Guide for Independent Dental Groups

South Carolina PDMP Requirements for Dental Practices

What the PDMP is and why it matters

South Carolina’s Prescription Drug Monitoring Program (often referred to as SCRIPTS) is a statewide database that tracks dispensing of Schedule II–V medications. For independent dental groups, consistent PDMP use helps you identify overlapping prescriptions, potential misuse, and drug–drug risks before issuing a controlled substance.

Prescription Drug Monitoring Program registration

If you prescribe or may prescribe controlled substances, complete Prescription Drug Monitoring Program registration and maintain an active account for each prescriber. Establish internal controls for creating, revoking, and auditing user and delegate access as roles change.

When to run a South Carolina PDMP query

  • Before prescribing opioids, benzodiazepines, or other Schedule II–V drugs, especially for new patients or when restarting therapy.
  • Periodically during ongoing therapy and whenever clinical “red flags” arise (early refill requests, lost prescriptions, concurrent sedatives, or multiple prescribers).
  • When you suspect diversion, forged prescriptions, or identity misuse.

Document your clinical rationale when you elect not to prescribe after a PDMP review, and note any safety steps you take (shorter supplies, partial fills, or non-opioid alternatives).

Delegation, accountability, and privacy

You may authorize trained staff to run PDMP queries as delegates, but the prescriber remains responsible for how the information is used. Limit PDMP access to patient care and compliance purposes, store results within the record only as needed, and prevent unauthorized printing or exporting.

Charting the PDMP check

  • Date and time of the PDMP query and who performed it.
  • Summary of relevant findings (e.g., “no overlapping opioid fills in 6 months”).
  • How findings informed the prescription decision and patient counseling.
  • Any follow-up actions (care coordination, medication changes, or referrals).

Controlled substance prescribing rules: practical safeguards

  • Perform a focused pain and risk assessment; review medical history, current medications, and allergies.
  • Prescribe the lowest effective dose for the shortest practical duration and avoid dangerous combinations when possible.
  • Discuss risks, benefits, alternatives, and safe storage/disposal; record that counseling in the note.
  • Use informed consent documentation for opioid therapy, including functional goals and discontinuation criteria.

Patient Recordkeeping Requirements

Core expectations

Maintain records that are accurate, legible, and contemporaneous. Each entry should allow another licensed dentist to understand your diagnosis, the services provided, the materials used, and your clinical decision-making—especially when controlled substances are involved.

Medical record retention policies

Adopt written medical record retention policies that meet the longer of state requirements, payer contracts, and HIPAA’s documentation timelines. Set clear rules for adults, minors, inactive records, images, models, and electronic backups, and publish your policy so staff apply it consistently.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Storage, security, and integrity

  • Use secure electronic health record systems with routine encrypted backups and tested disaster recovery.
  • Protect paper records in locked areas with controlled keys, visitor logs, and clean-desk expectations.
  • Keep separate but linkable storage for radiographs, photos, 3D scans, and lab prescriptions to preserve chain of custody.
  • Maintain DEA-required inventories and logs if you store controlled substances onsite.

Patient Record Content

Essential elements to include

  • Patient demographics, emergency contact, and communication preferences.
  • Comprehensive medical and dental history, medications, and patient-reported conditions.
  • Allergies and adverse reactions; baseline vitals when clinically indicated.
  • Examination findings, diagnoses (with diagnostic basis), and differential considerations.
  • Treatment plan, alternatives, risks, benefits, costs discussed, and informed consent documentation.
  • Progress notes for each encounter, materials used, tooth numbers/surfaces, and outcomes.
  • Prescriptions issued or e-prescribed (drug, strength, quantity, directions, refills) and the PDMP check notation.
  • Imaging and lab results with interpretation; referrals, consultations, and interprofessional communications.
  • Sedation/anesthesia records when applicable, including monitoring, medications, and discharge criteria.
  • Patient education, at-home instructions, follow-up plans, and any complications or adverse events.

Special scenarios

  • Minors or patients with guardians: record legal authority for consent and custody status.
  • Interpreter use: note the interpreter’s name, modality, and confirmation of accurate communication.
  • Telehealth or teledentistry: capture modality, locations, identity verification, and limitations of remote assessment.

Patient Record Confidentiality

Patient health information confidentiality

Protect confidentiality by applying the HIPAA “minimum necessary” standard, restricting access based on role, and auditing user activity. Verify identity before discussing or releasing information, and avoid unencrypted email or text unless you use secure, approved methods with appropriate patient acknowledgments.

Release records with a valid, HIPAA-compliant authorization, or without authorization only for treatment, payment, and health care operations, and for specific legal exceptions (such as certain public health or law enforcement requirements). For subpoenas and court orders, confirm scope and authenticity and document your response steps.

Patient rights

  • Right of access to inspect or obtain copies within HIPAA timelines, using reasonable, cost-based fees.
  • Right to request amendments; when you deny an amendment, include a written explanation and the patient’s statement of disagreement if provided.
  • Right to an accounting of certain disclosures outside routine treatment, payment, and operations.

HIPAA Compliance for Dental Practices

Administrative safeguards

  • Designate a privacy and security officer, complete an enterprise-wide risk analysis, and implement risk management plans.
  • Maintain written policies and procedures, Business Associate Agreements, and sanction policies for violations.
  • Conduct initial and periodic workforce training; document attendance and competency.

Physical safeguards

  • Secure facilities, server rooms, and records storage; manage keys and badges; use privacy screens and locked shredding bins.
  • Control device movement and disposal with certified media destruction.

Technical safeguards and HIPAA privacy safeguards

  • Unique user IDs, strong authentication (preferably MFA), automatic logoff, and role-based access.
  • Encryption in transit and at rest for EHR, backups, and portable media; maintain audit logs and alerts.
  • Secure e-prescribing of controlled substances (EPCS) with identity proofing and two-factor authentication.

Breach readiness

  • Incident response playbooks, timely investigation, documentation of findings, and breach notifications consistent with federal and state law.
  • Regular tabletop exercises to test detection, decision-making, and patient communication.

Documentation and Reporting Obligations

What to document—every time

  • PDMP queries and how they influenced care decisions.
  • Risk–benefit discussions and patient education for controlled substances.
  • Informed consent documentation for invasive procedures, sedation, and opioid therapy.
  • Inventory, receipt, and dispensing logs if you store or administer controlled substances.
  • Equipment checks for emergency kits, oxygen, and monitoring devices.

What to report—and to whom

  • Significant theft or loss of controlled substances to appropriate authorities without delay, and document the investigation and remediation.
  • Privacy or security incidents through your internal reporting channel; escalate potential breaches for legal review and, if required, notify affected individuals and regulators.
  • Suspected fraud, diversion, or forged prescriptions according to your compliance policy and payer contracts.

Role-based training essentials

  • PDMP workflows, including delegate rules, documentation standards, and red-flag identification.
  • HIPAA privacy and security fundamentals, phishing awareness, and clean-desk practices.
  • Records management, release-of-information processing, and verification of identity.
  • Clinical protocols for controlled substance prescribing, post-op instructions, and adverse event reporting.
  • EPCS operations, device security, and responding to system outages.

Accountability and oversight

  • Assign a compliance lead, run periodic chart audits, and monitor PDMP utilization reports.
  • Use checklists for new-hire onboarding, access provisioning, and termination to prevent orphaned accounts.
  • Refresh competencies annually and when laws, technology, or roles change.

Conclusion

Independent dental groups in South Carolina protect patients and reduce risk by pairing consistent PDMP use with strong recordkeeping, clear medical record retention policies, and robust HIPAA safeguards. Build disciplined documentation habits, train your team, and audit performance so your controlled substance prescribing rules and patient health information confidentiality remain defensible and compliant.

FAQs

What are the PDMP query requirements for dentists in South Carolina?

You should register for the state Prescription Drug Monitoring Program, run a South Carolina PDMP query before prescribing opioids or other controlled substances when clinically appropriate, and recheck periodically during ongoing therapy or when red flags appear. You may delegate queries to trained staff, but you must document the check in the record and base prescribing decisions on the findings.

How must dental patient records be maintained for privacy compliance?

Maintain complete, timely, and legible records that support diagnosis, treatment, and billing; secure them with administrative, physical, and technical HIPAA privacy safeguards; apply the minimum necessary standard; and follow a written retention policy that satisfies state law, HIPAA documentation timelines, and payer requirements. Use access controls, encryption, audit logs, and secure release-of-information workflows.

Obtain a HIPAA-compliant written authorization for most disclosures to third parties. You may disclose without authorization for treatment, payment, and health care operations and for specific legal exceptions. Verify identity before releasing records, disclose only the minimum necessary, and document each legal patient information disclosure in your ROI log.

What HIPAA measures must independent dental groups implement?

Perform a risk analysis, maintain written policies and Business Associate Agreements, train your workforce, and enforce role-based access, encryption, multi-factor authentication, automatic logoff, and audit logging. Prepare for incidents with an investigation and breach-notification plan, and regularly test backups and disaster recovery to ensure continuity and data integrity.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles