Privacy Policy
Last updated: August 3, 2026
This Privacy Policy describes how Therasoft Dental ("we," "us") collects, uses, and protects information in connection with our website (therasoftdental.com) and our insurance-billing service for dental practices (the "Service"), available at app.therasoftdental.com.
1. Two kinds of information
We handle two very different categories of data, and different rules apply to each:
- Website and account information — information you give us when you contact us or sign up, such as your name, practice name, email address, and billing details for your subscription.
- Protected health information (PHI) — patient demographic, insurance, and treatment information that flows through the Service on behalf of a dental practice: eligibility responses, claims, remittances, and attachments such as radiographs.
2. Our role under HIPAA
When a dental practice uses the Service, the practice is the HIPAA covered entity and Therasoft Dental acts as its business associate. We process PHI only as permitted by the Business Associate Agreement (BAA) we sign with each practice and as required to provide the Service — verifying eligibility, submitting claims, processing remittances, and managing denials. We do not sell PHI, use it for advertising, or use it for any purpose outside the BAA.
3. What we collect through the website
- Information you send us by email (for example, an early-access request to hello@therasoftdental.com).
- Standard server logs: IP address, browser type, pages requested, and timestamps, used for security and capacity monitoring.
This marketing website does not use advertising trackers and does not require cookies to function.
4. What the Service processes
Through the practice's connection to Open Dental and to our clearinghouse, the Service processes patient demographics, insurance coverage details, appointment schedules, completed procedures, claims (including CDT codes and tooth-level detail), electronic remittance advice, denial information, and claim attachments. This processing happens at the direction of the practice under the BAA.
5. How we protect information
- Encryption in transit (TLS) and at rest for all PHI, including attachments.
- Role-based access controls within each practice's account, with audit logging of PHI access and exports.
- Practice API credentials for Open Dental are stored encrypted and are never shared across tenants.
- We do not send PHI over email; notifications direct users into the secure portal.
6. Sharing
We share information only with subprocessors necessary to deliver the Service — such as our clearinghouse for claim, eligibility, and remittance transactions, and our hosting infrastructure — each bound by appropriate agreements, including BAAs where PHI is involved. We may disclose information if required by law.
7. Retention and data return
Claim-related records are retained for the period required by applicable law and the practice's BAA (generally seven years). When a practice ends its subscription, we provide a complete export of its data and then destroy or return PHI in accordance with the BAA.
8. Your choices
Patients seeking access to or correction of their health information should contact their dental practice, which remains the record holder under HIPAA; we support practices in fulfilling those requests. Practice contacts may ask us at any time what account information we hold about them and request corrections or deletion of non-required data.
9. Changes to this policy
If we make material changes to this policy, we will post the updated version here with a new "last updated" date and notify practice administrators through the Service.
10. Contact
Questions about privacy or our HIPAA practices: hello@therasoftdental.com.