Bright LittleDentistry for children

Small print

Privacy

What a dental practice does with your child's information, written so you can actually read it — and a plain statement of what this website itself does, which is nothing.

About this notice

This notice explains how Bright Little Dentistry would collect, use, share and protect information about a child and the adults responsible for them. It sits alongside — and does not replace — the practice's Notice of Privacy Practices under HIPAA, which is the document you would be given at registration and which governs your protected health information.

It is written for parents, guardians and carers, and it covers the practice as a whole: the front desk, the surgeries, the billing team and this website.

What a dental practice collects

A paediatric practice holds four kinds of information, and they are worth separating.

Identifying information

Your child's name, date of birth, address, school where relevant, and the names and contact details of the adults with parental responsibility. Your phone number and email address for appointment reminders, and an emergency contact.

Clinical information

Medical history, allergies, current medicines, the names of any consultants or paediatricians involved in your child's care, notes of every examination and treatment, radiographs and clinical photographs, consent forms, and any care plan we hold — including the sensory and communication plans described on our special needs care page.

Insurance and Medicaid information

Your plan and member details, Ohio Medicaid or CHIP identifiers where they apply, eligibility checks, claims and pre-treatment estimates, and the plan's responses to them.

Payment information

What was charged, what was paid, and by what method. Card details are handled by a payment processor and a practice of this kind does not keep full card numbers in its own records.

Why we hold it

HIPAA describes three ordinary purposes, and nearly everything falls into one of them.

  • Treatment. Examining, diagnosing and treating your child, and coordinating that care with other clinicians — a paediatrician, a cardiologist, an orthodontist, a hospital day-surgery unit.
  • Payment. Checking eligibility, submitting claims and estimates, and collecting what is owed.
  • Health care operations. Running the practice properly: appointment scheduling and reminders, clinical audit, staff training, quality and safety review, and our own legal and accounting obligations.

Anything outside those three — marketing, for instance, or selling information, which we do not do — would need your written authorisation, and you could withdraw that authorisation afterwards.

HIPAA and the Notice of Privacy Practices

A dental practice in the United States is a covered entity under the Health Insurance Portability and Accountability Act. That means your child's records are protected health information, and the practice is required to give you a Notice of Privacy Practices, to obtain your acknowledgement that you received it, and to follow it.

Companies that handle protected health information on the practice's behalf — a records system, a billing service, a secure shredding company — are business associates, and each is bound by a written agreement that holds them to the same standard.

Children's information, and who may see it

Almost every patient here is a minor, so the question of who may access a record comes up constantly. As a general rule the custodial parent or legal guardian is your child's personal representative and may see and request their record, give consent to treatment, and exercise the rights listed below on their behalf.

There are limits to that, and they are worth stating plainly. Where a court order, a custody arrangement or a guardianship document changes who may act for a child, we follow the document — so please give us a copy. And where Ohio law allows a minor to consent to their own care, the parent's automatic right of access to the records of that specific care can be limited. The rules differ by the type of care and by the age and circumstances of the young person; the practice applies them case by case, and would tell you when a limit applies rather than leaving you to guess.

Older teenagers are also entitled to a degree of privacy in the conversation itself. A sixteen-year-old may be asked, in the room, whether they are happy for something to be discussed in front of a parent. That is normal practice and not a sign that anything is wrong.

How long records are kept

Dental records are kept for as long as the law, our insurers and professional guidance require, and for a child that period is measured from adulthood rather than from the date of the appointment — which in practice means a child's record is held for a number of years past their eighteenth birthday. Radiographs, consent forms and clinical photographs are kept with the record.

Billing and accounting records are kept separately, for the period tax and insurance rules require. When a record reaches the end of its retention period it is destroyed securely; paper is cross-shredded and electronic records are deleted from live systems and from backups on their own cycle. Ask us and we will tell you the exact period we apply to your child's record.

Who we share information with

Only where it is needed, and only where the law permits it. In practice that means:

  • Your dental plan or insurer, for eligibility, claims and pre-treatment estimates.
  • Ohio Medicaid and the managed care plan administering it, or CHIP, where your child is covered by them.
  • Other clinicians involved in your child's care — an orthodontist, an oral surgeon, a paediatrician or consultant, a hospital day-surgery unit — where we refer or where we need their advice before treating.
  • Business associates who process records or payments for us, under written agreement.
  • Public authorities, in the narrow circumstances where the law requires or permits it: public health reporting, a suspected-abuse report a clinician is mandated to make, a valid court order or subpoena, or a health-oversight audit.

We do not sell information, we do not share it for advertising, and we do not give it to a school, an employer or a family member who is not your child's personal representative without your authorisation.

Your rights

Under HIPAA you have these rights over your child's protected health information, and you can exercise any of them by asking us in writing.

  • Access. To inspect the record and to be given a copy, electronically if we hold it electronically. A reasonable, cost-based fee may apply to copies.
  • Amendment. To ask us to correct something you believe is wrong or incomplete. If we decline we must tell you why in writing, and you may file a statement of disagreement that stays with the record.
  • An accounting of disclosures. A list of certain disclosures we have made outside treatment, payment and health care operations.
  • To request a restriction on how information is used or shared. We are not obliged to agree to every restriction — but where you pay for an item of care in full yourself, and ask us not to tell your plan about it, we must agree.
  • Confidential communications. To ask us to contact you at a particular number or address, or to leave no message.
  • A paper copy of the Notice of Privacy Practices, at any time, even if you agreed to an electronic one.
  • To complain without any effect on your child's care.

Complaints go first to the practice, using the details below. If you are not satisfied, you may complain to the U.S. Department of Health and Human Services, Office for Civil Rights, which enforces HIPAA and accepts complaints online, by post and by email. Complaints about the conduct of a licensed dentist can also be made to the Ohio State Dental Board. Nobody at this practice may retaliate against you for making either.

This website: cookies, analytics and browser storage

This is the part people usually skim. It is also the shortest, because there is almost nothing here.

  • No analytics. This demonstration site sets no analytics cookies, loads no analytics script, and has no tag manager, heatmap, session recorder or advertising pixel.
  • No cookies at all. Nothing on this site writes a cookie, so there is no cookie banner to dismiss.
  • No third-party requests. The fonts, images, styles and scripts are all served from this site. Nothing is fetched from another company's server while you read.
  • Three keys in your own browser's localStorage. The brand-kit demo stores your chosen colours and typeface under bl:brand:v2 (an earlier build of the same feature used bl:brand:v1), and the children's brushing chart stores its ticks under bl:brush:v1. Both are local to the browser you are reading in. They are never transmitted anywhere, we cannot read them, and clearing your site data removes them.

A real practice's website would usually differ here — most run analytics of some kind, and would say so in this section and offer you a way to refuse it. A real practice's booking form would also transmit what you type, over an encrypted connection, into a system covered by a business associate agreement. This one does not, because there is nothing behind it.

How to contact us about privacy

Questions, requests and complaints about privacy go to the practice directly. A real practice of this size names a privacy contact in its Notice of Privacy Practices rather than appointing a separate data protection officer, and being a US practice treating patients in Ohio it has no EU representative.

Bright Little Dentistry
2140 Kenny Road, Suite 120
Columbus, OH 43221
(614) 555-0142
[email protected]

Because this is a demonstration site, that address, phone number and mailbox are placeholders and reach nobody. Please do not send real information about a real child to them.

Book a visit