Most healthcare websites worry about HIPAA. Most child-focused websites worry about COPPA. Pediatric dental practices need to address both-and the overlap creates complexity that general compliance guides miss.
HIPAA's scope on your website: For a HIPAA-regulated practice, website data becomes PHI when individually identifiable health information is created, received, maintained, or transmitted by the covered entity or a business associate. That can include appointment requests mentioning symptoms, new patient forms asking about medical history, or contact messages describing a child's dental concerns. HIPAA safeguards apply to ePHI, and a BAA is required when a vendor creates, receives, maintains, or transmits PHI on the practice's behalf.
COPPA's scope on your website: COPPA applies when a site or service is directed to children under 13 or the operator has actual knowledge that it collects their personal information. Child-completed forms, contests, or gamified features can create that exposure; merely making a parent-facing practice site welcoming to families does not by itself establish COPPA coverage.
Where they intersect: A child-completed pre-appointment questionnaire can implicate both frameworks when each framework's scope is met: the practice handles PHI in its regulated role, and the site is child-directed or the operator has actual knowledge that it is collecting the child's personal information. The compliance approach must then satisfy both sets of requirements.
This content is educational and does not constitute legal advice. Consult with a healthcare compliance attorney and your state dental board for guidance specific to your practice.