Voice perio charting software introduces a specific HIPAA consideration that practices often overlook: when a hygienist speaks patient probing depths, bleeding points, and recession measurements aloud and that audio is captured and processed by a cloud-based AI system, patient-identifiable health data is leaving the practice’s local network and entering a third-party platform. That pathway requires the same HIPAA compliance infrastructure as any other Business Associate relationship, and most practices that deploy voice perio charting do not have it properly documented before the first patient appointment.
Ekim IT Solutions is the dental-exclusive IT provider that builds HIPAA compliance documentation for voice perio charting deployments at dental practices across Maine, New England, Tampa Bay, and nationally.
A dental practice that deploys Bola AI, Avora, or any cloud-based voice perio charting platform without a signed Business Associate Agreement is operating a HIPAA-covered Business Associate relationship without the required legal documentation from the moment the first patient’s data passes through the system.
Under HIPAA, a Business Associate is any entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. A voice perio charting platform that receives a hygienist’s spoken probing depth callouts, processes them through cloud-based AI, and returns structured data to the practice management system is receiving and transmitting PHI on the practice’s behalf. That makes the voice perio software vendor a Business Associate regardless of how long the data is retained or how it is anonymized internally.
Check off each voice perio platform your practice has a signed BAA in place for.
Bola AI: BAA executed and confirmed before any Dentrix, Eaglesoft, or Open Dental practice goes live with its voice perio feature
Avora: BAA executed as part of its enterprise dental deployment process, confirmed before deployment in any practice
VoiceWorks by Florida Probe: BAA executed and confirmed before the system processes any patient charting data
Most voice perio charting platforms process audio through cloud-based AI before returning structured data to the practice management system. The audio itself may or may not be retained by the vendor after processing depending on the platform and the BAA terms. Ekim IT Solutions reviews the BAA language for each voice perio platform to confirm what data is retained, for how long, and under what conditions it can be accessed or deleted. This information is documented in the practice’s Security Risk Assessment as part of the Business Associate relationship entry for the voice perio vendor.
Adding a voice perio charting platform to a dental practice is a material change to the practice’s technology environment that requires the Security Risk Assessment to be updated. The updated assessment should identify the voice perio vendor as a Business Associate, document the data flow from the operatory microphone through the cloud AI and into the PMS, confirm the BAA is in place, and note the encryption status of the data transmission pathway. Ekim IT Solutions updates the Security Risk Assessment for every practice we support when a voice perio platform is added.
Ekim IT Solutions builds HIPAA compliance documentation for voice perio charting deployments at dental practices across Maine, New England, Tampa Bay, and nationally. We make sure that pathway is properly documented before your next patient appointment, not after an audit.