DentDock Logo

Security Policy

Last Updated: Apr 25, 2026
Compliance: Healthcare Standards

1 Security Overview

At DentDock, protecting your clinical data is our highest priority. We implement industry-leading security measures to ensure your patient records, financial data, and sensitive information remain secure at all times. Our security framework is designed to meet and exceed healthcare data protection standards.

Commitment: We continuously review and improve our security measures to address emerging threats and maintain the highest level of protection for your data.


2 Data Encryption

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (Transport Layer Security) with 256-bit AES encryption. This ensures that data cannot be intercepted or read during transmission.
  • Encryption at Rest: All data stored in our databases is encrypted using industry-standard encryption algorithms. This includes patient records, financial data, and all sensitive information.
  • Database Encryption: Our databases use transparent data encryption (TDE) to protect data at the storage level, ensuring that even if physical storage media were compromised, the data would remain unreadable without proper encryption keys.
  • Key Management: Encryption keys are managed using secure key management systems with strict access controls and regular rotation policies.

3 Access Control

  • Role-Based Access: DentDock implements a comprehensive role-based access control (RBAC) system. Users can only access data and features relevant to their assigned role (e.g., receptionists can access appointments but not financial reports).
  • Principle of Least Privilege: Each user is granted the minimum level of access necessary to perform their job functions. This reduces the risk of unauthorized data exposure.
  • Session Management: User sessions are automatically terminated after a period of inactivity. Users can view and manage their active sessions from their profile settings.
  • IP Restrictions: Administrators can configure IP-based access restrictions for additional security control.

4 Authentication

  • Multi-Factor Authentication (MFA): We strongly encourage and support MFA for all user accounts. This adds an additional layer of security beyond passwords.
  • Strong Password Requirements: Users are required to create strong passwords with minimum length and complexity requirements. Passwords are hashed using bcrypt with salt before storage.
  • Password Policies: We enforce password expiration policies and prevent password reuse. Users can reset their passwords through secure email-based reset flows.
  • Login Monitoring: We monitor login attempts for suspicious activity and may temporarily lock accounts after multiple failed login attempts.

5 Data Backups

  • Automated Daily Backups: We perform automated daily backups of all clinical data, including patient records, appointments, invoices, and media files.
  • Redundant Storage: Backups are stored in multiple geographically distributed locations to ensure data availability even in the event of a regional disaster.
  • Backup Retention: We maintain multiple backup versions with different retention periods, allowing for point-in-time recovery when needed.
  • Backup Encryption: All backup data is encrypted both in transit and at rest using the same strong encryption standards as our production systems.

Note: While we maintain comprehensive backups, we recommend that clinic administrators also maintain their own local backups for critical business continuity planning.


6 Security Monitoring

  • 24/7 Monitoring: Our infrastructure is monitored 24 hours a day, 7 days a week for security events and anomalies.
  • Intrusion Detection: We employ intrusion detection systems (IDS) and intrusion prevention systems (IPS) to identify and block potential threats in real-time.
  • Log Management: All system activities are logged and retained for security auditing and forensic analysis. Logs are protected and access is strictly controlled.
  • Vulnerability Scanning: We regularly conduct automated vulnerability scans and penetration testing to identify and address potential security weaknesses.

7 Compliance

DentDock is designed to help healthcare providers meet their data protection obligations:

  • HIPAA Alignment: Our security measures are designed to align with HIPAA (Health Insurance Portability and Accountability Act) requirements for protecting protected health information (PHI).
  • GDPR Alignment: We implement privacy and security measures aligned with GDPR (General Data Protection Regulation) requirements for processing personal data.
  • Local Regulations: We adapt our practices to comply with local healthcare data protection regulations in the regions where our customers operate.
  • Customer Responsibility: While we provide secure infrastructure, customers remain responsible for using DentDock in compliance with applicable healthcare regulations in their jurisdiction.

8 Incident Response

  • Incident Response Plan: We maintain a documented incident response plan that outlines procedures for detecting, containing, and responding to security incidents.
  • Breach Notification: In the event of a confirmed data breach that may affect your clinic, we will notify affected customers without undue delay in accordance with applicable legal requirements.
  • Communication: We will provide timely updates about any security incidents that may affect your data, including the nature of the incident, steps taken to address it, and recommendations for affected users.
  • Post-Incident Review: After any security incident, we conduct a thorough review to identify lessons learned and implement improvements to prevent recurrence.

9 User Responsibility

While we implement robust security measures, users also play a critical role in maintaining security:

  • Strong Passwords: Use unique, strong passwords for your DentDock account and never share them with others.
  • Enable MFA: Enable multi-factor authentication if available for your account.
  • Secure Devices: Ensure that devices used to access DentDock are secured with up-to-date antivirus software and operating system patches.
  • Phishing Awareness: Be cautious of phishing attempts. DentDock will never ask for your password via email or unsolicited communication.
  • Report Issues: Immediately report any suspected security incidents or unusual account activity to our support team.

Security Questions?

If you have security concerns or need to report a potential security vulnerability, please contact our security team.

Security Contact

[email protected]

We take security reports seriously and respond promptly