Guide · Dental offices

AI receptionist for dental offices: privacy rules and vendor questions

Short answer

Yes, a dental office can use an AI receptionist for booking, reminders and common questions, but the vendor handles patient information on the practice’s behalf, so the contract matters as much as the software. In the United States, a vendor that creates, receives, maintains or transmits protected health information for a covered dental practice is a business associate under HIPAA and must sign a business associate agreement with the terms set out in 45 CFR 164.504(e). In Canada, the practice stays responsible for information it sends to a vendor and must protect it by contract under PIPEDA, unless a provincial law applies instead: Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia have health information laws recognized as substantially similar, and Quebec clinics fall under a health information act that requires specific contract clauses and a public register of technology products. This guide explains which rule applies where, what to put in the contract, how to keep the receptionist away from clinical data, and twelve questions to ask any vendor. It is general information, not legal advice.

The short answer: which rule applies to your practice

The first question is not “is this tool compliant?” but “which law governs the patient information it will touch?”. The answer depends on where the practice is and how it is organized. A vendor badge does not settle it: your practice remains responsible under every regime below.

Where the practice isMain rule for patient informationWhat it means for an AI receptionist
United States, practice that is a HIPAA covered entityHIPAA Privacy RuleThe vendor is a business associate if it handles protected health information for you; a business associate agreement is required (45 CFR 164.504(e)).
Canada, most provinces and the territoriesPIPEDAYou stay accountable for information sent to the vendor and must ensure comparable protection by contract (Schedule 1, principle 4.1.3).
Ontario, New Brunswick, Newfoundland and Labrador, Nova ScotiaProvincial health information law, recognized by the federal Privacy Commissioner as substantially similar to PIPEDACheck the provincial act and regulator; PIPEDA can still apply to information that crosses provincial or national borders.
Alberta, British ColumbiaProvincial private-sector privacy law (and provincial health law where it applies)Check with the provincial privacy commissioner which act covers your practice.
Quebec, clinic where dentists practise on their own accountAct respecting health and social services information (CQLR c. R-22.1)Written vendor contract with the clauses of s. 77, and the tool listed in the clinic’s public technology register (s. 107).

Summary by ZeniTech from 45 CFR 160.103 and 164.504 (eCFR), PIPEDA Schedule 1, the Office of the Privacy Commissioner of Canada’s page on provincial laws, and CQLR c. R-22.1, read on October 2, 2026. Not legal advice.

Is a booking request health information?

Often, yes. Under HIPAA, individually identifiable health information includes demographic information collected from an individual that is created or received by a health care provider and relates to the provision of health care to that individual, when it identifies the person or could reasonably be used to identify them (45 CFR 160.103). A name and phone number attached to “new patient, cleaning, Thursday 4 pm” at a dental practice fits that description.

Quebec’s act says the same thing in its own words: a name, date of birth or contact details become health and social services information when attached to health information or collected to register or take charge of the person (s. 2). And the clinic is still considered to hold the information when it entrusts its storage to a third party (s. 5).

Practical consequence: treat every conversation the receptionist has with a patient as patient information, not as marketing data.

What a HIPAA business associate agreement must contain

A vendor that creates, receives, maintains or transmits protected health information on behalf of a covered entity, other than as a member of its workforce, is a business associate (45 CFR 160.103). The contract with it must, among other things (45 CFR 164.504(e)):

Summary of 45 CFR 164.504(e)(2) read on eCFR on October 2, 2026. Not legal advice.

In Canada: accountability stays with the practice

PIPEDA’s first principle makes an organization responsible for personal information in its possession or custody, including information transferred to a third party for processing, and requires it to use contractual or other means to provide a comparable level of protection while the third party processes it (Schedule 1, principle 4.1.3).

The Office of the Privacy Commissioner explains that PIPEDA does not prohibit transferring information to an organization in another jurisdiction for processing, that the transferring organization remains accountable, and that a contract cannot override the laws of a foreign jurisdiction. Ask where each subprocessor stores and processes the data, and tell patients in your privacy notice.

Where a provincial law applies instead, the same logic generally holds: the practice chooses the vendor, writes the contract and answers to its regulator. In Quebec, the health information act goes further and voids a vendor contract that lacks the clauses of section 77.

Keep the receptionist away from clinical data

The simplest privacy measure is to give the AI receptionist less to protect. Scheduling needs very little.

InformationDoes the receptionist need it?Where it should stay
Name, phone, emailYes, to book and confirmReceptionist and CRM, with a retention period
Date of birth, new or existing patientOften, to find or open the fileAs little as your intake sheet requires
Type of appointment (exam, cleaning, emergency)Yes, to pick the right slotShort, closed choice; no free-text symptoms
Insurance yes or noSometimes, to tell the patient what to bringNo policy numbers in chat
Symptoms, medical history, medicationsNoYour practice software, collected by your team
Charts, X-rays, treatment plansNoYour practice software

Grid by ZeniTech to illustrate data minimization; adapt it with your privacy officer.

Twelve questions to ask any AI receptionist vendor

Reminder and recall texts

Canada: under CASL, a message that solely confirms a transaction the patient already agreed to, such as a booked appointment, does not need consent (s. 6(6)(b)). A patient who bought a service from the practice in the past two years has an existing business relationship with it, which gives implied consent for recall reminders (s. 10(10)(a)). Every commercial message must identify the practice and include an unsubscribe mechanism (s. 6(2)).

United States: the FCC treats text messages as calls under the Telephone Consumer Protection Act. Ask for the patient’s agreement to receive texts when they book and confirm federal and state rules with counsel.

In both countries, keep texts neutral: the practice name and the appointment time, never the reason for the visit.

What ZeniTech does, and what it does not claim

Luna is ZeniTech’s AI receptionist for dental clinics. According to her page, she answers the phone with an AI voice and replies to texts and website messages, books into the slots your clinic defines, sends confirmations and reminders, fills cancellations from the waitlist and sends recall reminders. She never gives medical advice or a diagnosis; clinical questions go to your team, and anyone in danger is directed to 911 or the local emergency number. Clinical records stay in your practice management software, every conversation can be reviewed, and your data is never used to train a third party’s model.

ZeniTech does not claim HIPAA, PHIPA or any other compliance or certification. Before you sign, we put in writing what Luna stores and where it goes, so your privacy officer or advisor can decide whether it fits your obligations. Pricing is a one-time setup, then a monthly plan; the full price list is on zenitech.dev/en/pricing.

Features from zenitech.dev/en/ai-agents/dental-clinics, read on October 2, 2026. Prices are published on zenitech.dev/en/pricing.

Frequently asked questions

Can a dental office use an AI receptionist under HIPAA?

Yes, if the vendor is treated as what it is. A vendor that creates, receives, maintains or transmits protected health information for a covered dental practice is a business associate, and HIPAA requires a written business associate agreement that limits use and disclosure, requires safeguards and breach reporting, binds subcontractors and covers return or destruction of the data. Ask for it before sharing any patient data.

Does an AI receptionist vendor need to sign a BAA?

If it handles protected health information on behalf of a covered practice, yes: it meets the definition of a business associate in 45 CFR 160.103. That usually includes call recordings, transcripts and booking details. The agreement must also flow down to its subcontractors, such as the telephony and language model providers it uses.

What privacy law applies to a dental clinic’s AI receptionist in Canada?

It depends on the province. PIPEDA applies in most provinces and the territories. Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia have health information laws recognized as substantially similar for personal health information; Alberta, British Columbia and Quebec have their own private-sector laws, and Quebec clinics of professionals fall under its health and social services information act. In every case, the practice remains responsible for what the vendor does with the data.

Is the name and phone number of a patient who books an appointment health information?

Often, yes. Under HIPAA, demographic information received by a health care provider and related to the provision of care is individually identifiable health information when it identifies the person. Quebec’s act says a name or contact details become health information when attached to health information or collected to take charge of the person. Treat booking conversations as patient information.

What should a dental AI receptionist never collect?

Anything scheduling does not need: symptoms in free text, medical history, medications, insurance policy numbers, charts or X-rays. Those stay in your practice software and are collected by your team. A receptionist that asks closed questions (new patient, type of appointment, preferred slot) has much less to protect.

Can patient conversations be processed outside Canada?

PIPEDA does not prohibit it, but the practice stays accountable and must ensure comparable protection by contract, and the Privacy Commissioner notes a contract cannot override foreign law. Quebec’s health information act is stricter: before a vendor contract that sends information outside Quebec, the clinic needs a privacy impact assessment showing adequate protection (s. 78). Ask every vendor where each subcontractor stores and processes the data.

Are appointment reminder texts legal?

Generally yes. In Canada, CASL does not require consent for a message that only confirms an appointment the patient agreed to, and a purchase in the past two years gives implied consent for recall reminders; each commercial message needs the practice’s identification and an unsubscribe option. In the United States, texts are calls under the TCPA, so collect the patient’s agreement to texts when they book. General information, not legal advice.

Is ZeniTech’s AI receptionist HIPAA or PHIPA compliant?

ZeniTech does not claim HIPAA, PHIPA or any other compliance or certification. Luna handles scheduling and general questions, clinical records stay in your practice software, every conversation can be reviewed and your data is never used to train a third party’s model. Before you sign, we put in writing what Luna stores and where it goes, and your privacy officer decides.

Related

Free consultation

Get a fixed price for your project in 30 minutes.

We look at what the project has to achieve, tell you what it costs, and tell you when you do not need it.

Book a call →+1 581-748-7017

Sources