...

Ekim IT Solutions

Blog / Illinois Dental Practice Data Privacy: PIPA and HIPAA
All Dental

Illinois Dental Practice Data Privacy: PIPA and HIPAA

Ekim IT Solutions guide to Illinois PIPA and HIPAA compliance for dental practices

Illinois dental privacy should be managed as one coordinated security program, not two unrelated compliance checklists.

HIPAA protects electronic protected health information, while the Illinois Personal Information Protection Act addresses personal information, reasonable security, and breach notification.

The overlap matters because Illinois PIPA recognizes compliant HIPAA and HITECH entities for its reasonable-security requirement, while Illinois still adds its own breach-notification step when Section 50 applies.

One program, different legal duties An Illinois dental practice should build privacy and security around HIPAA, then understand the Illinois PIPA rules that attach to that framework.

The page identifies PIPA Section 50 as the key Illinois detail for HIPAA-covered dental practices. If a breach must be reported to the HHS Secretary, Illinois adds an Attorney General notification requirement that should already exist in the incident-response plan.

Not sure your PIPA and security documentation would hold up? Find out in 15 minutes if we are the right fit.
Schedule a Discovery Call →
What Illinois PIPA requires

Reasonable security should show up in risk management, access control, backup, and vendor handling

The article says PIPA Section 45 requires organizations that maintain records containing Illinois personal information to implement and maintain reasonable security measures against unauthorized access, acquisition, destruction, use, modification, or disclosure.

Risk + AccessRisk Analysis + MFA + Role-Based Access

Maintain a current HIPAA Security Risk Analysis, use risk management based on identified vulnerabilities, and apply MFA and role-appropriate access controls.

OperationsBackups + Remote Access + Auditability

Monitor and test backups and recovery, maintain secure remote access, and preserve evidence that access and security controls are operating as intended.

VendorsBAAs + Contracts + Accountability

Track vendors, business associate agreements, and contracts involving personal information so access and security obligations stay documented.

Illinois-specific detail: include the Illinois Attorney General notification step in the breach-response checklist when PIPA Section 50 applies.
How HIPAA and PIPA fit together for dental practices

HIPAA can satisfy the reasonable-security baseline while Illinois still keeps its own breach-notification requirement

The page explains that PIPA Section 50 deems a HIPAA-covered entity or business associate compliant with PIPA when it is subject to and compliant with HIPAA and HITECH privacy and security standards.

Shared Security ProgramHIPAA Risk Management + Technical Safeguards

Reasonable and appropriate administrative, physical, and technical safeguards still need to be implemented in the actual network, workstations, cloud systems, accounts, backups, and vendor relationships.

Illinois AdditionSection 50 Notice Path

If a breach must be reported to the HHS Secretary, the page says the Illinois Attorney General must also be notified within five business days after the Secretary notification.

The practical model is coordinated rather than duplicated: one operating security program, with separate legal duties understood where Illinois adds them.
A policy binder is not enough

The practice should be able to prove risk management, breach readiness, and vendor accountability in the actual environment

The article moves beyond policy language and focuses on what a dental practice and its IT provider should be able to document and show.

Risk ProgramSecurity Controls in Production

MFA and unique user accounts, endpoint protection and patch management, secure firewall and wireless design, encryption and secure transmission where appropriate, audit logging, access reviews, tested backup and recovery, and secure remote access.

Breach ReadinessPre-Built Technical + Legal Paths

Preserve evidence, support HHS analysis, maintain the Illinois notification step, coordinate patient communication, and keep recovery from competing with the legal response during an incident.

Vendor AccountabilityInventory + Contracts + Offboarding

Track vendors, agreement requirements, access reviews, account offboarding, and where patient and personal information flows through PMS platforms, imaging vendors, backup providers, email, communications tools, billing vendors, and IT providers.

The page’s proof standard is practical: show how the PMS, imaging environment, networks, endpoints, cloud identities, backups, and remote access are protected and how those controls are documented.

Turn Illinois Privacy Rules Into Operational Proof

A privacy program is stronger when the practice can show what is actually running, documented, tested, and ready. Tap each requirement to see the HIPAA and Illinois PIPA context alongside the evidence it takes to prove it.

Tap a requirement to expand it

RequirementRisk Management: Current Risk Analysis
+
HIPAA + Illinois ContextShared Baseline

PIPA recognizes compliant HIPAA and HITECH entities for its reasonable-security requirement.

EvidenceRisk Analysis + Remediation Record

A current risk analysis, documented vulnerabilities, assigned remediation, and evidence that changes were implemented.

RequirementIdentity + Access: MFA + Access Reviews
+
HIPAA + Illinois ContextAdministrative + Technical Safeguards

HIPAA safeguards and Illinois reasonable-security expectations meet in the day-to-day control environment.

EvidenceUser List + MFA + Access History

Named users, current permissions, MFA status where supported, access-review records, and offboarding evidence.

RequirementBackup + Recovery: Tested Restore Capability
+
HIPAA + Illinois ContextOperational Resilience

The article includes tested backup and recovery among the controls a practice should be able to document.

EvidenceBackup Status + Restore Test

Monitoring history, recovery-test records, restore results, and documentation of what systems and data can be recovered.

RequirementVendor Accountability: BAAs + Contracts
+
HIPAA + Illinois ContextBusiness Associates + PIPA Contracts

Contracts involving disclosure of Illinois personal information must also require reasonable security measures.

EvidenceVendor Inventory + Agreements + Offboarding

Current vendor list, BAAs where applicable, security terms, vendor access records, and proof that access is removed when relationships end.

RequirementBreach Response: Preserve + Contain
+
HIPAA + Illinois ContextIllinois Section 50: Separate State Notification Step

If the breach requires HHS Secretary notification, the article says the Illinois Attorney General must also be notified within five business days after that federal notification.

EvidenceIncident Log + Notification Checklist

Preserved logs, affected-system record, containment notes, recovery documentation, HHS analysis, and the Illinois Attorney General step already built into the response plan.

Important distinction

The technical team should preserve evidence, isolate affected systems, and document recovery. The practice’s legal and privacy advisors determine the notification obligations based on the facts and applicable law.

The program becomes defensible when requirements can be matched to real evidence. HIPAA and PIPA may overlap, but the practice still needs to show that its risk management, access controls, backups, vendor relationships, and incident-response steps exist in the actual dental environment and are documented before an incident occurs.

Frequently Asked Questions

The Illinois Personal Information Protection Act, or PIPA, is a state law addressing the protection of certain personal information and notification following qualifying security breaches. Section 45 requires data collectors that own, license, maintain, or store covered personal information about Illinois residents to implement and maintain reasonable security measures. Section 50 provides specific treatment for HIPAA covered entities and business associates that are subject to and in compliance with HIPAA and HITECH privacy and security standards.
Illinois PIPA Section 50 says a HIPAA covered entity or business associate that is subject to and in compliance with HIPAA and HITECH privacy and security standards is deemed compliant with PIPA. That deemed-compliance provision is conditioned on the entity also notifying the Illinois Attorney General when it is required to report a breach to the HHS Secretary. A dental practice should therefore maintain its HIPAA and HITECH compliance program while also accounting for this Illinois-specific breach-reporting requirement.
When a HIPAA covered entity or business associate is required to notify the HHS Secretary of a breach under HITECH, Illinois PIPA Section 50 requires it to notify the Illinois Attorney General within five business days after notifying the Secretary. The timing of the HHS report itself depends on the applicable HIPAA breach-notification rules, including the number of individuals affected. The practice should coordinate reportability and notification decisions with its privacy or compliance leadership and qualified legal counsel.
An Illinois dental practice should build its technical safeguards around its HIPAA risk analysis, systems, data, and actual threats rather than rely on a one-size-fits-all checklist. A practical baseline can include MFA where supported and appropriate, unique and role-appropriate user access, secure administrative and remote access, endpoint protection, vulnerability and patch management, secure network configuration, appropriate encryption, security monitoring and auditability, monitored and tested backups, documented vendor access, and incident-response and recovery procedures.
Know whether your HIPAA compliance actually satisfies Illinois PIPA, plus the Attorney General notification requirement?

Ekim IT Solutions serves dental practices across Illinois and nationally. We make sure your HIPAA and HITECH compliance actually satisfies PIPA’s Section 50 provision, and that the additional Attorney General notification step is covered when it applies.

Compliance built for both HIPAA and Illinois PIPA.
Get an Illinois data privacy compliance review →