Privacy Commitment Statement

At Dental Billing & Consulting Professionals your trust means everything to us. We know that the information you handle—especially patient information—is deeply personal and deserves the highest level of care. That’s why we built our Services with privacy, security, and transparency at its core. We are committed to safeguarding your data, honoring your confidentiality, and supporting your practice with technology that respects the people behind every record. Whether you’re using our apps, exploring our website, or communicating with our team, you can count on us to treat your information responsibly and with the same respect we would want for our own. This Privacy Policy explains how we protect, use, and manage the information entrusted to us.

Dental Billing & Consulting Professionals Privacy Policy

Effective Date: January 1, 2026
Last Revised: January 1, 2026

PLEASE READ THE FOLLOWING CAREFULLY.

This Privacy Policy describes how Dental Billing & Consulting Professionals (“Company,” “We,” “Us,” or “Our”) collects, uses, discloses, and protects information when individuals or organizations interact with Us, including when they:

·       Visit or use Our websites, landing pages, or any online content We operate;

·       Contact Us or communicate with Our team;

·       Use any of Our applications, including:

o   HIPAA Snippa™: PDF Snipping Tool for EOB extraction;

o   EstimatorIQ™: Insurance Verification & Treatment Estimator; and

o   CompliCentral™: HIPAA & OSHA Compliance Platform (powered by Abyde);

(collectively, the “Services”).

This Privacy Policy applies to all Users of the Services, including:

·       Dental and medical practices;

·       Other organizations;

·       Administrators and authorized staff;

·       Individuals who access Our website or interact with Us; and

·       Any entity or person who uses or evaluates the Services.

(collectively,  “Users,” “You,” or “Your”).

By accessing or using the Services, you acknowledge that you have read and understand this Privacy Policy.

1.     Scope of Policy. This Privacy Policy applies to all information We collect or process through the Services, including:

a.      Information collected through Our website, landing pages and all integrated applications;

b.     Information collected from or on behalf of dental or medical practices under Business Associate Agreements (“BAAs”);

c.      Personal information collected from Users when creating or accessing accounts;

d.     Any PHI (Protected Health Information) handled on behalf of covered entities under HIPAA;

e.      Any information You provide when communicating with us, requesting support, or evaluating the Services.

This Privacy Policy does not replace or modify the terms of any applicable BAA. Where a conflict exists between this Privacy Policy and a BAA, the terms of the BAA govern.

Your use of the Applications is also governed by Our Terms of Use. In the event of any conflict between this Privacy Policy and the Terms of Use with respect to non-PHI information relating to the Applications, the Terms of Use will control.

2.     Definitions.

a.      “Applications” refers to HIPAA Snippa™, EstimatorIQ™, and CompliCentral™, each of which is available to purchase and download through the Oral Surgery Suite website.

b.     Business Associate Agreement” or “BAA” means a written agreement required under HIPAA that governs how a Business Associate (such as Our Company) may create, receive, maintain, or transmit PHI on behalf of a Covered Entity (such as a medical or dental practice). A BAA outlines each party’s responsibilities for safeguarding PHI, including permitted uses and disclosures, security safeguards, breach-notification obligations, subcontractor requirements, and other protections mandated by 45 C.F.R. §§164.502(e), 164.504(e), and related HIPAA provisions.

c.      “Covered Entity” means a healthcare provider, health plan, or healthcare clearinghouse that is subject to HIPAA and that transmits health information in electronic form in connection with certain standard transactions. In the context of the Services, the Covered Entity is typically the medical or dental practice that uses Our platform and authorizes us, as its Business Associate, to create, receive, maintain, or transmit PHI on its behalf, as defined under 45 C.F.R. §160.103.

d.     “EOB Data” means information contained in an Explanation of Benefits (EOB) statement issued by a health insurance plan, including details about billed services, amounts paid by the insurer, amounts adjusted or denied, patient responsibility, deductibles, copayments, and other claim-processing outcomes. When EOB Data identifies an individual patient or can reasonably be used to identify an individual, it constitutes PHI under HIPAA.

e.      “HIPAA” means the Health Insurance Portability and Accountability Act of 1996, together with its implementing regulations, including the Privacy Rule, Security Rule, Breach Notification Rule, Enforcement Rule, and related amendments under the Health Information Technology for Economic and Clinical Health (HITECH) Act. HIPAA governs the privacy, security, and permitted uses and disclosures of PHI, and establishes the obligations of Covered Entities and their Business Associates under 45 C.F.R. Parts 160 and 164.

f.      “HITECH” means the Health Information Technology for Economic and Clinical Health Act of 2009, which strengthens HIPAA’s privacy and security requirements, expands obligations for business associates, and establishes federal breach-notification standards for unsecured Protected Health Information.

g.     “MFA” (Multi-Factor Authentication) means a security process that requires Users to verify their identity using two or more independent authentication factors—such as a password, a code sent to a mobile device, or an authentication app—before accessing the Services. MFA helps protect User accounts and PHI by adding an additional layer of security beyond traditional username and password credentials.

h.     “NPI” (National Provider Identifier) means the unique 10-digit identification number assigned to healthcare providers and healthcare organizations in the United States by the Centers for Medicare & Medicaid Services (CMS). NPIs are used for administrative and billing purposes, including claim submission, insurance verification, and authentication within HIPAA-regulated systems. While an NPI is not PHI, it is considered professional or organizational identifying information and may be collected as part of a Practice’s account setup or use of the Services.

i.       “OSHA” means the Occupational Safety and Health Administration and its applicable regulations governing workplace health and safety for healthcare providers, including training, documentation, and compliance obligations that may be supported through the Services.

j.       “PDF” (Portable Document Format) means a widely used digital file format that preserves the layout, text, tables, images, and structure of documents in a consistent manner across different devices and software. In the context of the Services, PDFs commonly include Explanation of Benefits (EOBs), remittance summaries, insurance correspondence, scanned or faxed records, and other billing-related documents used by medical or dental practices. PDFs can contain PHI when they include identifiable patient billing or insurance information. The Services may process, extract, or convert information from PDFs as part of normal billing, verification, and compliance workflows.

k.     “Personal Information” means information that identifies, relates to, describes, or can reasonably be linked to an individual person or organizational User, excluding PHI. Personal Information includes names, email addresses, phone numbers, job titles, and other contact information; login credentials and authentication information; account profile and billing information; IP addresses, device identifiers, and other technical or analytics data; and any communications or other information collected through the Services that does not meet HIPAA’s definition of Protected Health Information.

l.       “PHI” (Protected Health Information) means any information that relates to an individual's past, present, or future physical or mental health or condition; the provision of healthcare to that individual; or the past, present, or future payment for the provision of healthcare--when that information identifies the individual or could reasonably be used to identify the individual. PHI includes (but is not limited to): patient names, dates of birth, insurance information, policy numbers, claim or EOB data, medical or dental treatment information, diagnosis or procedure codes, eligibility and coverage data, and any uploaded files that contain identifiable health information, this definition reflects HIPAA’s meaning under 45 C.F.R. §160.103.

m.   “Practice” means the medical or dental practice, healthcare provider entity, or other Covered Entity that enters into a Business Associate Agreement (BAA) with us, along with its administrators, workforce members, and other authorized Users who access or use the Services on its behalf.

n.     “Services” means all integrated applications HIPAA Snippa™, EstimatorIQ™, and CompliCentral™, Our website, landing pages, customer-support channels, and any other online products or services that We operate or make available.

3.     HIPAA / HITECH Compliance Statement. We are committed to maintaining the security and confidentiality of PHI in accordance with HIPAA, HITECH, and all implementing regulations. When We receive or process PHI on behalf of a Covered Entity, We act as its Business Associate and implement administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of PHI processed through the Services. These safeguards include:

a.      BAAs – We enter into BAAs with all Covered Entity clients outlining Our permitted uses, disclosures, and responsibilities with respect to PHI.

b.     Access Controls & MFA – All user accounts require individualized login credentials and multi-factor authentication.

c.      Encryption – PHI is encrypted in transit and, where applicable, at rest within Our secure Azure cloud environment.

d.     Minimum Necessary Standard – We limit the PHI We access, use, or disclose to the minimum amount necessary to perform the Services.

e.      Secure Development & Architecture – The Services are designed to support HIPAA/HITECH compliance, including access logging, audit controls, and data-integrity safeguards.

f.      Breach Notification – In the event of a breach of unsecured PHI, We will provide prompt notification to affected Covered Entities in accordance with HIPAA/HITECH requirements.

g.     Vendor Management – Any third-party vendors with access to PHI (such as pVerify for EstimatorIQ™) are required to maintain HIPAA-compliant safeguards and, where applicable, execute appropriate BAAs.

4.     Information We Collect. We collect information in the following categories:

a.      PHI Processed Through the Apps. Depending on how the Practice uses the Services, We may collect or process:

                                          i.     Patient names;

                                        ii.     Dates of birth;

                                      iii.     Policy numbers and insurance information;

                                      iv.     EOB data extracted via HIPAA Snippa™;

                                        v.     Coverage, eligibility, and estimation data generated via EstimatorIQ™;

                                      vi.     HIPAA/OSHA compliance information handled via CompliCentral™;

                                     vii.      Any uploaded documents, PDFs, or files containing PHI.

App-Specific Notes

                                          i.          HIPAA Snippa™ currently processes PHI without storing it. Planned future updates may allow optional PHI storage within that Application.

                                        ii.          EstimatorIQ™ processes PHI and may store data related to eligibility, verification, and estimates.

                                      iii.          CompliCentral™ processes PHI and compliance-related information via Abyde’s integrated tools.

PHI is processed solely on behalf of the Practice for permitted purposes under HIPAA and the applicable BAA.

b.     Personal Information (Non-PHI). We may collect or process:

                                          i.     User account information (name, email, role, password/MFA settings);

                                        ii.      Practice information (practice name, address, NPI, contact details);

                                      iii.     Billing and subscription information (via accept.blue / Integrity Merchant Solutions);

                                       iv.     Log-in activity, IP address, device/browser type;

                                         v.     Website usage analytics and feature interaction data;

                                       vi.     Support requests and communications.

c.      Information Collected Automatically (Website & Landing Page Analytics). When You visit or interact with Our websites, landing pages or Applications, We may automatically collect certain technical information through cookies, analytics tools, and similar technologies. This may include:

                                          i.     IP address, device type, operating system, and browser details;

                                        ii.      Pages viewed, links clicked, scrolling behavior, search terms, and timestamps;

                                      iii.     Website or Landing Page performance and diagnostic data;

                                       iv.     Referring pages and navigation paths.

We may share this information with Squarespace, Our website hosting and analytics provider, to analyze traffic patterns and improve website performance. Squarespace processes this information in accordance with its own policies. This automatically collected information does NOT include PHI.

d.     Information Submitted Through Webforms (Contact or Support Forms). When You submit information to Us through a contact form, support form, or any other webform on Our website or landing pages, We collect the information You choose to provide so We can respond to Your inquiry. This may include Your name, email address, practice information, and the content of Your message. We do not sell information submitted through webforms. We may share this information with Our service providers only as needed to operate the website, process Your submission, or respond to Your request. Squarespace, Our website hosting provider, may process this information solely as needed to provide website services to Us and does so in accordance with its own privacy policies. Webform submissions are not used for advertising or marketing unless You explicitly opt in to such communications.

5.     How We Use Information. We use PHI and Personal Information for the following purposes:

a.      To Provide and Support the Services. We may use information to deliver, operate, and support the functionality of the Services, including:

                                          i.     Extracting and exporting EOB data;

                                        ii.      Conducting insurance verification and estimates;

                                      iii.     Managing HIPAA/OSHA compliance workflows;

                                       iv.     Maintaining secure access, authentication, and MFA;

                                        v.     Generating reports, logs, or documentation used by the Practice.

b.     To Maintain Security. We may use information to protect the Services and User accounts, including:

                                          i.     Access controls;

                                        ii.      Audit logs (if applicable; will be updated once finalized);

                                      iii.     Encryption;

                                      iv.     Monitoring for unauthorized access.

c.      To Manage Accounts and Billing. We may use information to administer User accounts and process payments, including:

                                          i.     Subscription processing;

                                        ii.      Application bundling and pricing management;

                                      iii.     Payment processing through accept.blue.

d.     To Improve the Services. We may use information to maintain, develop, and enhance the Services, including:

                                          i.     Troubleshooting and diagnostics;

                                        ii.      Feature development;

                                      iii.     Performance optimization.

e.      To Comply with Applicable Law. We may use PHI and Personal Information as necessary to comply with federal, state, and local legal or regulatory requirements, including:

                                          i.     Implementing and maintaining required HIPAA, HITECH and OSHA compliance measures;

                                        ii.      Fulfilling state and federal data breach-notification requirements;

                                      iii.     Processing internal requests related to subpoenas, court orders, investigations, or other lawful requests (with any disclosures made only as permitted under Section 6(c)).

f.      We do NOT use PHI for marketing or advertising.

6.     How We Disclose Information. We disclose PHI only as permitted by HIPAA and the applicable BAA, including:

a.      To the Practice. All PHI is accessible solely to the Practice and its authorized users.

b.     Subcontractors and Vendors. Only where permitted by HIPAA and pursuant to a written BAA or subcontractor agreement:

                                          i.     pVerify for insurance verification (EstimatorIQ™);

                                        ii.      Azure for cloud hosting (all Applications);

                                      iii.     Abyde for CompliCentral™ compliance tools;

                                      iv.     accept.blue / Integrity Merchant Solutions for payment processing.

We do NOT disclose PHI to advertisers or data brokers.

c.      Legal Requirements. We may disclose PHI or Personal Information only when required by applicable law and only to the extent permitted by HIPAA, including disclosures:

                                          i.     In response to subpoenas, court orders, warrants, or other lawful judicial or administrative requests;

                                        ii.     To government agencies conducting authorized audits, investigations, or oversight activities;

                                      iii.     As otherwise required by federal, state, or local law, and only after following HIPAA’s minimum-necessary and verification requirements.

7.     How We Protect & Secure Information. We maintain administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of PHI and Personal Information processed through the Services. These measures include, without limitation:

a.      Azure-hosted secure environments with encryption in transit and, where applicable, at rest;

b.     Multi-factor authentication and individualized access credentials;

c.      Role-based access controls within each Application;

d.     Secure development lifecycle practices, including code review and vulnerability management;

e.      Logging, monitoring, and activity tracking to detect and investigate potential security incidents;

f.      Vendor and subcontractor oversight, including HIPAA-compliant agreements where required; and

g.     Data minimization and least-privilege access standards.

While We implement safeguards consistent with HIPAA, HITECH, and applicable industry standards, no method of data transmission or storage is 100% secure. We cannot guarantee absolute security, but We take reasonable and appropriate measures to reduce risks and protect the information We handle.

8.     Data Retention. We retain information collected through the Services in accordance with HIPAA, HITECH, applicable state and federal law, industry standards, and Our contractual obligations. Because the Services include the integrated Applications, Our website, landing pages, support channels, and business operations, retention practices vary by data type:

a.      PHI. We retain PHI only as permitted under HIPAA and the applicable Business Associate Agreement (“BAA”). PHI may be retained for:

                                          i.     The duration necessary to provide the Services to the Practice;

                                        ii.      Any longer period required by the BAA or applicable law; or

                                      iii.     As otherwise directed in writing by the Practice.

We do not retain PHI beyond these parameters.

b.     Personal Information (non-PHI). We retain personal information such as User account data, profile information, practice information, and security credentials for as long as:

                                          i.     The User’s account remains active;

                                        ii.      Necessary to provide the Services; or

                                      iii.     Required under Our contractual or legal obligations.

c.      Website & Analytics Data. Information collected automatically through Our website (e.g., IP addresses, device/browser details, pages visited, clicks, searches, or analytics data) is retained for the period necessary to operate, secure, and improve the website and to understand usage trends. We may retain aggregated or anonymized analytics data for longer periods.

d.     Communications & Support Records. Emails, support tickets, contact form submissions, and other communications with Us may be retained to:

                                          i.     Respond to inquiries;

                                        ii.      Maintain internal records;

                                      iii.     Improve customer service;

                                      iv.     Comply with legal or audit requirements.

e.      Billing, Payment, and Transaction Records (Non-PHI). We retain invoices, subscription records, payment confirmations, and other commercial billing information generated through the Services. This information does NOT include patient billing data or PHI. These records are retained as required by applicable tax, accounting, and financial-recordkeeping laws.

f.      Deletion Requests. Practices may request deletion of PHI or account data consistent with HIPAA, the BAA, and applicable law. Non-PHI Personal Information may be deleted upon verified request, subject to legal obligations, fraud-prevention requirements, and operational needs necessary to maintain the integrity and security of the Services.

9.     Rights of Practices and Users. We respect the rights of Practices and individual Users regarding the information processed through the Services. Because We act as a Business Associate when handling PHI, certain rights must be exercised through the Practice rather than directly with Us.

a.      HIPAA Rights (Access, Amendment, Accounting of Disclosures). For any information that qualifies as PHI, Users must direct requests for access, correction, amendment, or accounting of disclosures to the applicable Practice (Covered Entity). We will support the Practice in fulfilling these requests as required under the applicable BAA.

b.     Rights Regarding Personal Information (Non-PHI). Depending on Your state of residence or applicable privacy law, You may have rights to:

                                          i.     Access or obtain a copy of Your Personal Information;

                                        ii.      Request correction or updates to inaccurate Personal Information;

                                      iii.     Request deletion of Personal Information We maintain (not including PHI processed under HIPAA);

                                       iv.     Request information about how We collect, use, or disclose Your Personal Information.

These rights do not apply to PHI, which is governed exclusively by HIPAA.

c.      How to Submit a Request. Users may submit rights requests by contacting Us at: privacy@dentalbillingconsulting.com. We may need to verify Your identity before processing Your request.

d.     Response Timeframes. We will respond to verifiable requests within the time period required by applicable law (typically 30–45 days) and may extend this period where permitted.

e.      Right to Appeal (Non-PHI Requests). If We deny Your request regarding Personal Information, You may appeal the decision by emailing privacy@dentalbillingconsulting.com. We will review and respond to appeals within the timeframe required by applicable law.

f.      Limitations. We may deny a request if:

                                          i.     It applies to PHI (which must be handled through the Practice);

                                        ii.     It would violate HIPAA or another legal/regulatory obligation;

                                      iii.     Compliance would adversely affect the security or integrity of the Services;

                                       iv.     The request is unverified.

10.  Privacy of Minors. The Services are not directed to or intended for use by individuals under 18, and minors are not permitted to create accounts or directly access the Services. However, the Services may process PHI or Personal Information of minor patients on behalf of a Covered Entity. It is the responsibility of the Covered Entity to ensure that all required parental or guardian authorizations are obtained before submitting a minor’s information to the Services. We process minors’ PHI only as permitted by HIPAA and the applicable Business Associate Agreement.

11.  Domestic Use Only. The Services are intended for use within the United States. If Users access the Services from outside the United States, they do so at their own risk and are responsible for compliance with local laws.

12.  Business Transfers & Successor Entities. If Our business is involved in a merger, acquisition, financing, asset sale, corporate restructuring, or similar event, We may transfer the information We hold (including User accounts) to the new owner or successor. Any such entity will be required to honor this Privacy Policy or maintain privacy protections that are materially similar. If PHI is transferred, it will only be done in compliance with applicable BAAs and HIPAA. You acknowledge that such transfers may occur and that any successor entity may continue to process Your information as described in this Privacy Policy.

13.  Changes to this Privacy Policy. We may update this Privacy Policy periodically to reflect changes in Our Services, legal requirements, or Our privacy and security practices.

a.      Changes Affecting PHI or HIPAA-Related Practices. Any material changes to how We handle, use, store, or protect PHI—or changes affecting the functionality of the Applications that process PHI—will be communicated directly to affected Practices. Where required by HIPAA, such changes will be incorporated into an updated Business Associate Agreement (“BAA”) or provided through formal written notice to the Practice.

b.     Changes Affecting the Applications. If We make material changes to the Applications, or features that affect how Users interact with the Services, we will notify Practices through in-Application notices, email, or other appropriate means.

c.      Changes Affecting Non-PHI Personal Information. For material changes related to Our collection, use, or disclosure of Personal Information that does NOT involve PHI, We will post an updated Privacy Policy on Our website and update the “Last Updated” date. We may also provide supplemental notice through email or in-Application notifications when appropriate.

d.     Effective Date. Unless otherwise required by law or specified in the notice, changes to this Privacy Policy become effective upon posting.

14.  Contact Information. For questions about this Privacy Policy or Our privacy practices, please contact Us at privacy@dentalbillingconsulting.com.