Last updated: May 21, 2026
This page summarizes how Clear Care Dental Group protects your protected health information ("PHI") under the Health Insurance Portability and Accountability Act (HIPAA) and the regulations issued under it.
Plain-English version: we treat anything in your dental record like the sensitive medical information it is. We encrypt it, lock down who can see it, audit access, train every employee, and never share it without your authorization unless the law requires us to.
What counts as PHI
PHI is any information about your health, healthcare, or healthcare payment that can be tied back to you. In Clear Care Dental's case, this includes:
- Your dental records, appointments, claims, and treatment history
- X-rays you upload for our Second Opinion feature
- Insurance and billing details
- Notes from interactions with our concierge team, including transcripts of calls with Ali (our AI voice receptionist)
How we use and disclose PHI
HIPAA permits certain uses without your separate authorization, including:
- Treatment — sharing PHI with the dentist or specialist you choose
- Payment — verifying coverage and processing payments to providers
- Healthcare operations — quality improvement, member support, fraud detection, system administration
- Required by law — court orders, regulatory audits, public health reporting
Any use beyond these requires your written authorization, which you can revoke at any time.
How we secure PHI
- Encryption — TLS 1.2+ in transit; AES-256 at rest
- Access controls — role-based access, multi-factor authentication, least-privilege principles, password rotation
- Audit logs — every PHI access is logged with user, timestamp, and reason
- Network security — production systems behind firewalls; penetration tested regularly
- Employee training — all staff complete HIPAA training annually
- Business Associates — every vendor that touches PHI (Supabase, AWS, ElevenLabs, etc.) signs a HIPAA Business Associate Agreement
- Physical security — our infrastructure providers' data centers meet SOC 2, ISO 27001, and HIPAA standards
Breach notification
In the unlikely event of a breach of unsecured PHI, we will notify affected members without unreasonable delay and no later than 60 days after discovery, as required by HIPAA. We will also notify the Department of Health and Human Services and, where applicable, prominent media outlets and state regulators.
Your rights under HIPAA
You have the right to:
- Inspect and copy your PHI we maintain
- Request corrections to PHI you believe is inaccurate
- Request restrictions on how we use or disclose your PHI
- Receive an accounting of disclosures we have made
- Request confidential communications through specific channels
- File a complaint if you believe your rights have been violated, with us or directly with the U.S. Department of Health and Human Services
To exercise any of these rights, contact our Privacy Officer at support@clearcaredentalgroup.com. We respond within 30 days.
Privacy Officer
Our designated HIPAA Privacy Officer oversees compliance and handles privacy concerns. Contact: support@clearcaredentalgroup.com · (800) 630-0760
Clear Care Dental Group · 8395 NE 2nd Avenue · Miami, FL 33138
For dental providers
If you are a network dentist or staff at an in-network practice, you receive PHI from Clear Care Dental subject to the HIPAA Business Associate Agreement on file. Report any suspected breach to support@clearcaredentalgroup.com within 24 hours.
Heads up: this HIPAA notice is the operating draft. Before launch we will have it reviewed by counsel and (where applicable) registered with HHS as our Notice of Privacy Practices. Until then, treat it as a good-faith description of our practices, not a final legal agreement.