Record-Keeping Requirements for New Dental Practices

Learn the essential record-keeping rules for new dental practices: what to keep, how long, and practical steps to stay compliant in 2026.
Starting a dental practice means taking on significant compliance responsibilities, and record keeping sits at the center. Federal and state regulations, along with HIPAA and OSHA, dictate what you must document, how you store it, and for how long. This guide outlines the core requirements and gives you concrete steps to implement a compliant system this week.
Why Record Keeping Matters for Dental Practices
Dental practices face audits from the IRS, state dental boards, HIPAA investigators, and OSHA. Missing or incomplete records can lead to fines, license suspension, or legal liability. For example, HIPAA violations can cost $100 to $50,000 per violation, with a maximum of $1.5 million per year. OSHA record-keeping violations can add $13,000 to $70,000 per citation. Proper records protect you and your patients.
Core Record Types and Retention Periods
Here are the essential records you must maintain and the minimum retention periods as of 2026. State laws may require longer, so always check with your state dental board.
| Record Type | Minimum Retention | Notes |
|---|---|---|
| Patient treatment records | 7 years after last treatment, or age of majority plus 3 years (whichever is longer) | Includes x-rays, charts, treatment plans, and consent forms |
| Financial records (ledgers, invoices) | 7 years | For tax and audit purposes |
| HIPAA authorizations and disclosures | 6 years from creation or last effective date | Keep logs of any disclosures |
| OSHA injury/illness logs (OSHA 300) | 5 years | Must be updated within 7 days of an incident |
| Employee records (I-9, payroll) | 3 years for I-9, 4 years for payroll | Check state variations |
| Business licenses and permits | While active, plus 3 years | Renewals and proof of compliance |
| X-rays and diagnostic images | Same as patient records | Store in a secure digital format |
HIPAA Compliance: Privacy and Security Rules
HIPAA requires you to protect patient health information (PHI). For record keeping, this means:
- Privacy Rule: You must have written policies for using and disclosing PHI. Document every disclosure outside of treatment, payment, or operations.
- Security Rule: You must implement safeguards for electronic PHI (ePHI). This includes access controls, encryption, and audit logs.
- Breach Notification: If a breach occurs, you must document it and notify affected patients, HHS, and sometimes the media.
Practical Steps for HIPAA Compliance
- Conduct a risk assessment within 90 days of opening. Use a template from HHS or a consultant.
- Create a Notice of Privacy Practices and give it to every patient.
- Implement a secure EHR system with role-based access and automatic audit trails.
- Train all staff on HIPAA policies and document the training.
- Sign business associate agreements with any vendor that handles PHI (e.g., billing, cloud storage).
OSHA Requirements for Dental Offices
OSHA’s Bloodborne Pathogens Standard applies to all dental practices. You must keep records of:
- Exposure control plan: Review and update annually.
- Training records: For each employee, include date, content, and trainer name. Keep for 3 years.
- Hepatitis B vaccination declinations: Signed forms for employees who decline the vaccine.
- Sharps injury log: Record every needlestick or sharps injury, including the device and circumstances.
OSHA Record-Keeping Steps
- Post OSHA 300A summary from February 1 to April 30 each year.
- Maintain an OSHA 300 log if you have 10 or more employees, but even smaller practices must keep injury records if required by state plan.
- Store training records for at least 3 years.
State Dental Board Requirements
Every state has its own rules for patient records, radiographs, and treatment documentation. Common requirements include:
- Radiographs: Must be of diagnostic quality and retained for the same period as patient records.
- Treatment plans: Must be documented and signed by the patient or guardian.
- Referrals: Document all referrals and follow-up.
Check your state dental board’s website for specific retention tables. For example, Texas requires 10 years for adult records, while California requires 7 years. Some states require lifelong retention for minors.
Digital vs. Paper Records: What You Need to Know
Digital records are now the norm, but they come with their own rules.
- EHR systems: Must be HIPAA-compliant, with encryption and backup. Popular options like Dentrix, Eaglesoft, or Open Dental cost $300-$500 per month for a single provider, plus setup fees.
- Backup: You must have a backup strategy. Use the 3-2-1 rule: 3 copies, 2 different media, 1 offsite. Cloud backups cost $50-$150 per month.
- Scanning paper records: If you convert paper to digital, ensure the scans are legible and indexed. Keep the originals for at least the retention period if required by state law.
- Disposal: When records are no longer needed, shred paper and wipe digital media. Keep a log of destruction.
Practical Steps to Implement This Week
- Create a record retention policy that lists all record types and retention periods. Use a template from your state dental association.
- Set up a secure EHR system if you haven’t already. Schedule a demo with at least two vendors.
- Develop a HIPAA compliance binder with policies, training logs, and risk assessment.
- Draft an OSHA exposure control plan and schedule staff training.
- Designate a records custodian who is responsible for maintaining and disposing of records.
- Back up your data immediately. Use an encrypted cloud service and test restoration.
FAQ
How long do I need to keep patient x-rays?
Keep x-rays for the same period as patient records: typically 7 years after last treatment, or age of majority plus 3 years, whichever is longer. Some states require longer, so check your state board.
Can I store patient records digitally only?
Yes, if your EHR system is HIPAA-compliant and you have backups. You must also ensure you can produce records in a readable format if requested. Some states require original paper records for certain types, so verify.
What happens if I don’t keep proper records?
You risk fines, license discipline, and legal liability. For example, HIPAA fines can reach $50,000 per violation, and OSHA citations can be $13,000 or more. In worst cases, you could lose your license.
Do I need a dedicated server for my EHR?
No. Cloud-based EHRs are common and often more secure than on-site servers. They cost $300-$500 per month and include backups, but you must have a business associate agreement.
The Bottom Line
Record keeping is not optional. Start with a clear retention policy, invest in a HIPAA-compliant EHR, and train your staff. Use the steps above to build a system that keeps you compliant and protects your practice. If you’re unsure about state specifics, consult a dental attorney or your state association. The time you invest now will save you from costly penalties later.