Security & compliance

HIPAA business associate: our security model and BAA process

Dental Revenue Desk signs a business associate agreement before any PHI access is provisioned. Access is scoped to the practice management system modules verification requires, protected by MFA, and attributable to named individual accounts. Dental Revenue Desk discloses its access geography in writing: the delivery team works remotely from Pakistan during US business hours.

Published July 21, 2026

BAA before access — the order of operations

Dental Revenue Desk signs a business associate agreement before any PHI access is provisioned. There is no trial look at your schedule. Eventhe pilot of 10 completed verifications sits behind that gate: it starts only after the agreement and the Business Associate Agreement are signed.

HHS'sSummary of the HIPAA Security Rule sets that order: "Before permitting a business associate to create, receive, maintain, or transmit ePHI, a regulated entity must have in place a contract or other written arrangement." Under HITECH a business associate is alsodirectly liable for Security Rule compliance, breach notification, and minimum-necessary limits — so Dental Revenue Desk answers to OCR, not only to your practice. Seewhere the BAA sits in onboarding.

  1. Agreement + BAA signed. Before anything else happens.
  2. Access provisioned. Your administrator creates named, scoped accounts in your PMS.
  3. Verification begins. Only now does the team touch PHI.

Access controls: who can see what

Dental Revenue Desk asks for the minimum necessary: named individual accounts, created and owned by your administrator, scoped to the PMS modules verification work actually touches — eligibility, coverage tables, benefit notes, and supporting documents. Shared or administrator credentials are not requested, and nothing beyond what the work requires is.

Inside your system, the Dental Revenue Desk team verifies coverage,writes back the full benefits breakdown, and flags the exception in the exception report — nothing more. Seethe verification work these controls protect, and how write-back reaches your practice management system.

Diagram of the Dental Revenue Desk access model: a signed BAA gates provisioning, then named team-member accounts with MFA reach only the practice management system modules verification requires, with every session recorded in audit logs

Device, training, and audit controls

These are Dental Revenue Desk's published commitments as of July 2026, confirmed in writing in your BAA and vendor questionnaire — not third-party attestations. Treat them as a floor:NIST SP 800-66r2 notes that covered entities are "permitted to require more of their business associates" in the BAA. Seethe claims policy behind every statement on this page.

Security controls that Dental Revenue Desk publishes, and what each commits to
ControlWhat it commits
BAA before accessDental Revenue Desk's policy is that no PHI access is provisioned before the agreement and the business associate agreement are signed — the pilot of 10 completed verifications included.
Minimum-necessary accessAccess is scoped to the PMS modules verification requires, provisioned by your administrator.
Multi-factor authenticationMFA is required on the accounts used to reach practice systems.
Named accounts + audit logsDental Revenue Desk's policy is named individual accounts only; shared or administrator credentials are not requested. Sessions and completed work are logged.
Session timeoutAccounts used to reach practice systems are subject to session timeout, so an unattended session does not stay open.
Device policyA written device policy governs the machines used for verification work.
TrainingTeam members complete privacy and security training.
Subcontractor policyAny subcontractor handling PHI on Dental Revenue Desk's behalf signs a business associate agreement on the same terms as the practice's own.
Breach procedureA written procedure defines escalation and containment; the notification obligation is set in the BAA signed with Dental Revenue Desk.
Access revocationYour administrator can revoke access at any time, no notice required, and access is deprovisioned when a team member leaves or the engagement ends.
Data return and destructionAt termination, PHI held for your practice is returned or destroyed, with no copies retained.
Access geographyDental Revenue Desk's delivery team works remotely from Pakistan during US business hours, disclosed in writing during your review.

Dental Revenue Desk calls these commitments, not certifications: HIPAA compliance is an ongoing obligation, and Dental Revenue Desk claims no attestation it does not hold.

Access geography

Where the team works — disclosed, not buried

Dental Revenue Desk's delivery team is remote and based in Pakistan, working US business hours. Every control in the Dental Revenue Desk controls table — the business associate agreement, minimum-necessary access, MFA, named individual accounts, audit logs — applies to every team member regardless of where they sit.

OCR, on ePHI heldoutside the United States, cautions that "outsourcing storage or other services for ePHI overseas may increase the risks and vulnerabilities to the information or present special considerations with respect to enforceability of privacy and security protections over the data." Dental Revenue Desk discloses its access geography so that risk is one your reviewer weighs rather than discovers. State law and your PMS vendor's agreement may add restrictions of their own; Dental Revenue Desk gives no legal advice and expects your reviewer to check both.

Breach response

Dental Revenue Desk maintains a written breach-response procedure covering escalation, containment, and reporting. HHS'sBreach Notification Rule sets the floor: a business associate "must provide notice to the covered entity without unreasonable delay and no later than 60 days from the discovery of the breach." Sixty days is an outer limit, not a target; Dental Revenue Desk's own notification commitment is written into the BAA you sign.

No PHI through website forms. Dental Revenue Desk collects no patient information through this website; its forms take practice and workflow details only.

An eligibility response does not guarantee payment.CMSstates that "an eligibility response from a health plan does not guarantee that the health plan will reimburse the provider for health services when a claim is submitted." A Dental Revenue Desk breakdown reflects what the carrier reports; final adjudication rests with the payer.

Ending the engagement: access revocation, data return and destruction

Your administrator provisions access, so your administrator ends it: Dental Revenue Desk accounts can be disabled in your PMS at any time, with no notice owed. Dental Revenue Desk also requests deprovisioning when a team member leaves your account and when the engagement ends, so revocation never waits on you noticing.

What happens to the data is a BAA term, not a policy Dental Revenue Desk can revise later. HHS's sample business associate agreement provisions — sample language, "not required for compliance with the HIPAA Rules" in HHS's words — put it this way: at termination the business associate returns or destroys all protected health information and "shall retain no copies of the protected health information." That is the commitment Dental Revenue Desk signs. The commercial half of leaving — notice, the final invoice, and the last day Dental Revenue Desk works your schedule — sits in your agreement, alongside the published pricing; Dental Revenue Desk has not published a fixed cancellation notice period as of July 2026.

What to ask any verification vendor

A verification vendor is a business associate touching PHI daily. Get these answered in writing — by Dental Revenue Desk or by anyone else:

  • Will you sign a BAA before any access is provisioned — including trials and pilots?
  • Who exactly will access our system: named individuals, or shared logins?
  • What modules do you need, and will you accept access scoped to only those?
  • Is MFA required on every account that reaches our system?
  • Where is the team physically located, and is that disclosed in writing?
  • Will you identify every subcontractor or offshore staff member who handles our PHI, and are they bound by the same agreement?
  • What device policy governs the machines used for our data?
  • What privacy and security training does the team complete?
  • What is the breach procedure, and where are notification obligations documented?
  • How is access revoked when a team member leaves or the engagement ends?
  • What happens to our patient data when the engagement ends — returned, destroyed, or retained?
  • Do you carry cyber liability coverage, and will you name the limits in writing?

Dental Revenue Desk answers these in writing as part of your vendor review.Request the BAA process →

Frequently asked questions

Do you sign a BAA before accessing our system?

Dental Revenue Desk signs a business associate agreement before any PHI access is provisioned. The pilot of 10 completed verifications is no exception: it begins only after the agreement and the BAA are signed.

Where is your verification team located?

Dental Revenue Desk's delivery team works remotely from Pakistan during US business hours. Dental Revenue Desk discloses that access geography in writing during your vendor review, and every control it publishes applies to every team member regardless of location.

Who provisions access to our practice management system?

Your administrator does. Dental Revenue Desk requests named individual accounts scoped to the minimum modules verification requires, and your administrator can revoke that access at any time.

Can we see who accessed our system and when?

Dental Revenue Desk works under named individual accounts, so every session is attributable in your own audit logs. Dental Revenue Desk records every completed verification in the completion log your practice can review.

Should we send patient details through your website to get started?

Dental Revenue Desk collects no patient information through this website; its forms take practice and workflow details only. PHI is exchanged only after the business associate agreement is signed and access is provisioned in your own system.

What happens to our patient data when the engagement ends?

Dental Revenue Desk returns or destroys the protected health information it holds for your practice at termination and retains no copies — the wording HHS uses in its sample business associate agreement provisions. Your administrator revokes system access; the cancellation notice period is set in the agreement Dental Revenue Desk sends before the pilot, and Dental Revenue Desk has not published a fixed notice period as of July 2026.

Are you HIPAA certified?

Dental Revenue Desk is not HIPAA certified, and no vendor is. HHS states there is no standard or implementation specification requiring a covered entity to certify Security Rule compliance, and that HHS does not endorse or recognize private certifications. Dental Revenue Desk publishes a signed business associate agreement and a named control set instead of a badge.

Bring your compliance reviewer to the call

A 20-minute workflow review covers the BAA process, the access model for your system, and the published controls — in writing for your vendor file if you need it. No commitment, no patient information.