Practices are using Lovable, Bolt, and Replit to build online booking, patient intake, and treatment-plan portals fast. None of them sign a Business Associate Agreement. 2025 was the worst year on record for healthcare breaches, and dentistry alone logged 15+ named incidents — including a 15-million-record breach at a dental practice-management vendor.
Free Dental App Scan → Talk to UsBooking widgets, intake forms, and imaging viewers all touch patient data the moment a patient uses them. Here is where AI-built dental apps create HIPAA exposure.
MMG Fusion, a dental practice-management vendor, was breached in December 2020 and 15 million individuals' data hit the dark web — but it never notified its dental clients. OCR only found out via a patient complaint, and it settled with OCR in March 2026. The covered dental practices still owned the patient-notification duty. An AI-built app hosted with no Business Associate Agreement carries this exact risk with zero contract protection.
MMG Fusion's breach was largely just names and appointment dates and times, and OCR still treated it as a full PHI breach. Those same fields sit in nearly every AI-built dental booking widget, typically in a Supabase table with row-level security left off — the exact failure behind Lovable's CVE-2025-48757, which exposed 170+ apps to anyone with the public anon key.
X-rays and CBCT scans in DICOM format embed name, date of birth, SSN, and diagnosis codes in the file itself. Security researchers have found 3,600+ DICOM servers exposed on the open internet, only 0.14% of them using TLS. A vibe-coded "share this x-ray with the specialist" feature can recreate the same exposure in a single afternoon.
Ortho auto-debit and in-house membership plans mean recurring card storage (PCI DSS) tied directly to treatment data (HIPAA) — and 36 states separately regulate dental membership plans as Discount Medical Plan Organizations. AI builders default to storing everything, cards included, in one convenient table.
Attackers have explicitly shifted toward small and mid-size dental offices as softer targets. Westend Dental in Indianapolis had roughly 450 patients at its breached location and still paid to the Indiana AG in January 2025 — for a ransomware attack it concealed for over two years plus PHI disclosed in Google-review replies and x-rays posted to social media.
Replying to a review in a way that even confirms someone is a patient is a HIPAA violation. One dental practice paid a OCR civil monetary penalty for a single Google-review reply; another paid over a Yelp response. An AI-built "auto-respond to reviews" feature can automate this violation at scale.
| What you built | Hidden risk |
|---|---|
| Online booking / scheduling widget | Names + appointment data = PHI, often sitting in a Supabase table with RLS disabled |
| Patient intake / new-patient form | Health-history answers stored in a non-BAA backend is an impermissible disclosure on submission one |
| Treatment-plan / payment-plan portal | Mixes diagnosis + treatment codes with card data — HIPAA and PCI DSS at once |
| Imaging viewer / x-ray share link | DICOM files carry name, DOB, SSN, diagnosis in the file itself |
| Recall / reminder texting | Any marketing content needs prior express written TCPA consent, or it's – per text |
| Review-generation / auto-response tool | Confirming patient status in a public reply is a standalone HIPAA violation |
| DSO multi-location dashboard | One missing auth check exposes every location's data at once |
| Regulation | Triggers when… | Penalty |
|---|---|---|
| HIPAA Privacy / Security / Breach Rules | Any practice transmits PHI electronically (e-claims, billing, booking, online forms) | – per violation category, 2025 tiers |
| OCR Risk Analysis Initiative | Missing or inadequate HIPAA risk analysis — OCR's most-cited deficiency since Oct 2024 | Settlements from + multi-year corrective action plan |
| State record retention laws | Any app storing patient records (CA 7 yrs, TX/IL 10 yrs, FL 5 yrs, longer for minors) | State dental board discipline |
| State breach notification + AG enforcement | Breach of state residents' data, regardless of practice size | Westend Dental: (Indiana AG) |
| PCI DSS | App accepts deposits, membership dues, or payment-plan installments | Processor fines, higher fees, breach liability |
| TCPA | Automated recall, reminder, or marketing texts without consent | per message, if willful |
No. Neither Lovable nor Replit signs a Business Associate Agreement, and Lovable's own privacy policy tells users not to upload HIPAA data. If your app collects appointment requests, intake answers, or x-rays, you need a BAA-backed host and a security review before it handles real patients.
Yes. Regulators have treated a patient's name plus an appointment date and time as protected health information in real enforcement actions, even with no diagnosis attached. If your booking widget stores that data in an unsecured database, you likely have an active HIPAA exposure right now.
MMG Fusion was a dental practice-management vendor breached in 2020 that never notified its dental clients; OCR settled with it in March 2026. It shows that your vendor's failure becomes your legal problem. If your app runs on a platform with no BAA, you carry that exact risk today.
Yes. Confirming that someone is a patient in a public review reply has drawn real OCR penalties, including a civil monetary penalty against one dental practice. An AI-built auto-response tool needs guardrails so it never confirms patient status in a public reply.
If the form collects health-history answers and stores them anywhere other than a HIPAA-compliant, BAA-backed system, yes. Most AI app builders explicitly decline to sign BAAs, which means the moment a real patient submits the form you have an impermissible disclosure.
We check database access controls (row-level security), whether patient data sits behind a BAA, PCI scope on any payment-plan or deposit flow, TCPA consent on recall texts, and whether imaging or document links are guessable or public. You get a plain-English report with fixes ranked by risk.
Get a free, no-obligation scan of your dental app — database access, HIPAA exposure, and PCI scope, in plain English.
Start With a Free Scan →