David Nowak.
Home/Decision brief · Dental & medical practice
Decision brief

Can a dentist use AI safely?

8 min read · Sep 2026 · Every tool linked to its full review · Not legal advice
Straight answer

Yes — for the front desk, not the chair. Reminders, reviews, insurance questions drafted for your approval, and a phone agent that answers after hours all work today.

Nothing with a patient's name attached goes into a general chatbot. That includes "just checking why Maria Lopez missed her appointment" typed into a free chatbot.

The hard line

One line you can't cross

Health data is governed by HIPAA — the federal law that protects patient information. If information can identify a patient, it is protected: name, phone number, appointment history, x-ray notes, payment records.

Run that through a tool that isn't covered by a business associate agreement — the contract that makes a vendor legally responsible for protecting patient data — and it's a federal problem, not a settings problem. Penalties run into the five figures per violation, and "we didn't know" doesn't soften it.

The line — for the whole team

If it has a patient's name on it, it doesn't go in the general chatbot. De-identify first — "a patient with a cracked molar" — or use a tool built for clinics.

This one habit — de-identify before you paste — puts most of what AI is good at back in reach without touching a compliance line.

Safe to start

What's safe to start with

Four uses that carry real payoff and no patient-data exposure. Each links to the vetted review that covers it.

Answering the phone
After hours and during procedures — bookings, directions, "do you take my insurance." An AI phone agent trained on your website, handing off to your front desk for anything clinical.
Rosie · Goodcall
Read the warning below before patient calls
Drafting patient-facing text
Recall emails, social posts, your newsletter. A general chatbot, with de-identified context and your final edit.
ChatGPT · Claude
free tier is enough to start
Admin and forms
Supply lists, staffing checklists, front-desk procedures, marketing copy. A general chatbot; nothing patient-specific required.
Review replies
Responding to Google reviews without violating the reviewer's privacy. Template replies, personalized from the review's public text only.

The phone-agent warning: a phone agent will hear patients say their names, insurance details, and symptoms out loud — that can make it patient data. Rosie publishes no HIPAA statement anywhere, and Goodcall markets to healthcare but shows no confirmed independent security certification in its public record.

If calls will carry patient details, you need documented compliance: Retell signs a HIPAA agreement self-serve at no extra cost, and Bland includes HIPAA in its standard rate. For a non-clinical line — directions, hours, marketing — the cheaper tools are fine.

Never

What never goes in a public tool

Never

Anything with a name attached — appointment lists, recall lists, "Maria's balance is $480."

Never

X-ray and chart notes, even without the name — images and treatment descriptions are identifiable once combined with anything else.

Never

Insurance and payment details — claim numbers, subscriber IDs, card data.

Never

Referral letters describing a patient's case — the case history is the identifier.

The test that survives training a new front-desk hire on day one: would you post this on the waiting-room wall? Same rule for the chatbot.

Before you sign

The five-minute vendor check

Run any vendor through these before money moves. A good vendor answers plainly. A deflecting one tells you what you need to know.

  1. Will you sign a business associate agreement? If the tool touches anything a patient could identify, this is the whole ballgame — a privacy-policy promise is not a BAA. Retell and Bland hand it over without a tier fight; if a salesperson hedges, walk.
  2. Where are call recordings and transcripts stored, and for how long? "We keep everything for training" is a different universe from "30 days, then gone." You want a number.
  3. Is your staff able to listen to our calls? Some platforms review audio; you want to know who and when.
  4. What happens to recordings if we cancel? Do you delete everything on cancellation, in writing?
  5. Which of your own vendors touch our data? The phone agent is a stack — speech recognition, the language model, the voice, the phone carrier. Each is a company. A serious vendor names them; a vague answer is your answer.
If it goes wrong

If something goes wrong

AI doesn't need to be perfect in a practice — it needs to fail quietly and get caught. Three steps, in order:

Step 01

Stop using the tool for patient-related work the same day. Don't debug it with live patient data.

Step 02

Write down what went where: which tool, what information, roughly how much, how long ago. You'll need this record, and reconstructing it later is misery.

Step 03

Tell the people affected and loop in your malpractice carrier or attorney — HIPAA breach rules have timelines, and the call costs you nothing.

This is general information, not legal advice. Your carrier's breach line exists for this call — that's what you pay it for.

Your call

The honest trade-off

Most businesses can pick any tool on price and convenience. Yours can't quite: the compliance question arrives earlier, and the cheapest option on the phone is the one most likely to fail it. The pattern that works: keep patient data out of general tools entirely, use HIPAA-covered platforms for anything clinical, and lean on free chatbots for the de-identified work — drafting, admin, marketing.

The upside is real and it doesn't require a project: a phone agent answering after hours costs $79–299 a month in this category, and a hyphen of missed calls is worth more than a year of it.

The 30-second takeaway

Yes to AI for reminders, drafts, reviews, and the phone — no to patient identities in general tools. De-identify what you paste, demand a business associate agreement from anything that hears patient calls, and start with one task for two weeks.

I'm David. I build AI that keeps your data yours.

David Nowak

Twenty years building software for businesses like yours — cloud tools when they fit, your own machines when the data demands it. Fixed fee projects starting at $500, or a standing second opinion on your AI and software decisions from $300 a month.

Book a session

Bring one real problem. You leave with a plan — whether we work together or not.

Prefer writing first? Enable JavaScript to see the email

"Most companies are selling you fear and complexity. He cuts through the bullshit and just fixes things. That's what partnership looks like."
Jim · Owner, media production company · more testimonials