Communications Policy

Dental Gallery

102 W. El Dorado Blvd., Suite C1
Friendswood, Texas 77546
281-990-8448
info@dentalgalleryfriendswood.com

Effective Date: June 2026

This Communications Policy governs all aspects of how Dental Gallery communicates with patients, prospective patients, legal representatives, third-party entities involved in patient care, business associates, and individuals interacting with Dental Gallery through any communication channel.

The purpose of this Policy is to ensure that every communication sent or received by Dental Gallery complies with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the HIPAA Privacy, Security, and Breach Notification Rules (45 C.F.R. Parts 160 and 164), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), the Texas Medical Records Privacy Act (Texas Health and Safety Code Chapter 181), the Texas Health and Safety Code §181.154 governing electronic disclosures, the Texas Health and Safety Code §521.053 regarding breach notifications, the Texas Identity Theft Enforcement and Protection Act (Texas Business and Commerce Code §521.001 et seq.), the rules of the Texas State Board of Dental Examiners (“TSBDE”), including 22 Texas Administrative Code §§108.1–108.8, the Telephone Consumer Protection Act (“TCPA”), 47 U.S.C. §227 and 47 C.F.R. §64.1200, the CAN-SPAM Act (15 U.S.C. §§7701–7713), and all other applicable state and federal laws regulating healthcare communications. When Texas law offers greater protection or imposes stricter requirements than federal law, Dental Gallery follows Texas law.

Dental Gallery uses multiple communication channels including in-person discussions, telephone calls, voicemail messages, SMS text messaging, encrypted email, unencrypted email, secure patient portals, online scheduling platforms, electronic health record messaging systems, postal mail, facsimile transmissions, automated reminder systems, and digital messaging systems operated by business associates under HIPAA-compliant Business Associate Agreements. This Policy applies to all communications generated or received by the practice, regardless of medium, format, technology, or device used.

Protected health information communicated by any method is governed by the HIPAA Privacy Rule and HIPAA Security Rule. Electronic protected health information transmitted through digital systems is subject to the administrative, technical, and physical safeguard requirements of 45 C.F.R. §§164.308, 164.310, and 164.312. Dental Gallery maintains safeguards including encrypted communications where appropriate, access controls, role-based permissions, authentication measures, software security, audit logs, system monitoring tools, firewalls, intrusion detection systems, business associate oversight, and workforce training ensuring that protected health information is not improperly accessed, used, or disclosed through any communication channel.

Employees shall not discuss protected health information in public areas where unauthorized persons could overhear, including hallways, waiting rooms, or front desk areas.

Telephone Communications

Dental Gallery uses telephone communications for scheduling, coordination of care, treatment follow-up, insurance and billing discussions, and administrative matters. By providing a telephone number to Dental Gallery, you consent to receive live calls and voicemail messages at that number for treatment, payment, and healthcare operations, subject to your right to request restrictions or alternative confidential communications.

Before disclosing any protected health information by phone, the identity and authority of the caller must be verified using established verification protocols. Voicemail messages may be left at a telephone number provided by the patient when reasonably necessary to support treatment, payment, or healthcare operations as defined in 45 C.F.R. §164.506. All voicemail messages contain only the information reasonably necessary for the communication.

Patients may request that voicemail not be used or may request alternative means of communication. Dental Gallery will honor reasonable requests for confidential communication methods under 45 C.F.R. §164.522(b).

Contact Information and General Communications

Dental Gallery may use contact information you provide to communicate with you for treatment, payment, healthcare operations, scheduling, billing, and other practice-related purposes, as permitted by applicable law and consistent with your communication preferences.

Where applicable law requires separate consent or authorization for a particular communication method, purpose, or disclosure, Dental Gallery will obtain that consent or authorization separately.

You are responsible for ensuring that the contact information you provide belongs to you or that you are authorized to receive communications through that number, address, account, or device. Dental Gallery is not responsible for disclosures resulting from access by authorized or unauthorized users of your phone, email account, mailbox, fax machine, device, or communication account.

Email Communications

Dental Gallery uses both encrypted and unencrypted emails. By providing an email address to Dental Gallery, you consent to receive email communications at that address for treatment, payment, and healthcare operations, subject to your right to request alternative or more confidential methods.

Encrypted email is used when required by HIPAA, Texas privacy law, or when the content of the communication contains sensitive or clinically significant protected health information.

Email communications may be used when a patient initiates communication using an unencrypted method or consents to receive unencrypted email despite the inherent risks. These risks include potential interception, unauthorized access by individuals with access to the email account or device, mis-delivery, and inadvertent disclosure. By communicating through unencrypted email, the patient acknowledges and accepts these risks.

Dental Gallery may still choose to transmit certain information only through encrypted channels when legally required or when necessary to safeguard protected health information. Even encrypted email carries residual risks (including misdelivery, compromised accounts, and technology vulnerabilities), although encryption reduces risk compared to unencrypted email.

SMS Text Messaging

Dental Gallery uses SMS text messaging to provide appointment reminders, scheduling confirmations, recall notices, incomplete treatment notices, administrative updates, and other operational communications that support treatment, payment, or healthcare operations. Text messages may be generated manually or through automated systems.

Under the Telephone Consumer Protection Act, 47 U.S.C. §227, automated text messages may only be sent after the patient provides express consent. Dental Gallery may send text messages to a mobile number provided by you when permitted by applicable law and within the scope of any consent applicable to the communication. Dental Gallery will obtain separate consent where required.

Standard message and data rates may apply. Dental Gallery includes instructions for revoking consent, typically by replying STOP to any text message. SMS text messaging is not encrypted and may expose protected health information to risks inherent in mobile messaging platforms.

Due to such risks, Dental Gallery limits the content of text messages and may require encrypted channels for information involving diagnoses or sensitive clinical details.

Secure Patient Portals and Messaging

Dental Gallery may use a secure patient portals and encrypted messaging systems that comply with HIPAA and Texas privacy law. By enrolling in or using a secure patient portal or secure messaging system provided by Dental Gallery, you consent to receive electronic communications through that system, and you agree to maintain the confidentiality of your access credentials.

These systems use SSL/TLS encryption and automated, multi-factor authentication when available, user credential control, secure hosting environments, and audit logs to ensure that protected health information is stored and transmitted securely.

Communications conducted through these systems become part of the patient’s dental record and are managed in accordance with Texas Health and Safety Code §181.102 and TSBDE Rule 22 TAC §108.8. Patients are responsible for maintaining the confidentiality of usernames, passwords, and device security.

Postal Mail

Dental Gallery also communicates by postal mail. By providing a mailing address to Dental Gallery, you consent to receive mailed communications at that address for treatment, payment, and healthcare operations, subject to any reasonable request for confidential communications.

Postal mail may be used to transmit patient statements, billing notices, receipts, treatment plans, legal correspondence, medical necessity documentation, clinical summaries, and other administrative or healthcare-related communications. Dental Gallery uses sealed envelopes for all mailed documents.

When warranted, such as when transmitting sensitive information or responding to records requests, Dental Gallery may use certified mail or other trackable delivery methods to ensure proper delivery and documentation.

Facsimile Transmissions

Dental Gallery uses facsimile transmissions (“fax”) to communicate with insurance companies, dental specialists, medical providers, laboratories, pharmacies, legal offices, and other authorized entities involved in treatment, payment, or healthcare operations.

If you provide a facsimile number for receiving information, you consent to Dental Gallery sending fax communications to that number, and you are responsible for ensuring the fax destination is secure.

Fax communications are transmitted only to verified fax numbers. Each fax includes a confidentiality notice informing unintended recipients of their obligations under HIPAA and Texas law. Dental Gallery staff confirm fax numbers and use cover sheets to limit risk of unauthorized disclosure.

Dental Gallery documents fax transmissions when necessary to satisfy regulatory requirements or to confirm the release of records. Fax numbers must be verified both before sending and after transmission to confirm receipt by the intended party.

Communications with Healthcare Providers and Other Entities

Dental Gallery may communicate with other healthcare providers, insurance payors, dental laboratories, pharmacies, hospitals, urgent care centers, emergency departments, and any healthcare entity involved in treatment, payment, or healthcare operations.

These communications may include electronic disclosures permitted under Texas Health and Safety Code §181.154, including certain disclosures to covered entities for treatment, payment, or healthcare operations, and other disclosures authorized or required by law.

Such communications may involve referrals, diagnostic imaging, prescriptions, specialist consultations, eligibility verification, coordination of benefits, and care continuity arrangements. Dental Gallery verifies the identity and authority of the receiving entity before disclosing protected health information.

Business Associates and Subcontractors

Dental Gallery communicates with business associates and subcontractors who provide services such as secure messaging platforms, cloud storage, practice management software, telephone systems, SMS delivery systems, email platforms, IT support, billing companies, collection agencies, audit services, and third-party administrators.

Dental Gallery enters into Business Associate Agreements with vendors and service providers when required by HIPAA. Business Associate Agreements require the business associate and any subcontractor to safeguard protected health information, restrict access to authorized personnel, notify Dental Gallery of security incidents, and comply with all applicable federal and Texas requirements.

Dental Gallery conducts due diligence and oversight to ensure that business associates implement proper security measures.

Electronic communications, including email and text messaging, must not be used for emergencies. Dental Gallery cannot guarantee immediate response to electronic communications.

Disclosures to Unauthorized Third Parties

Dental Gallery does not disclose protected health information to unauthorized third parties, including employers, schools, private individuals, attorneys, marketing companies, or unrelated entities, unless the patient provides a HIPAA-compliant authorization under 45 C.F.R. §164.508 or unless the disclosure is required by law.

Disclosures to individuals involved in the patient’s care, such as family members or caregivers, are made only in accordance with 45 C.F.R. §164.510 or when authorized by the patient.

Dental Gallery may communicate limited information to confirm appointments or coordinate scheduling, provided that only the minimum necessary information is disclosed.

Governmental Communications

Dental Gallery may communicate with governmental entities including the Texas State Board of Dental Examiners, the Texas Department of State Health Services, the Texas Health and Human Services Commission, and federal agencies when required for regulatory compliance, investigations, audits, or reporting obligations.

Disclosures to the Texas State Board of Dental Examiners are permitted under the Dental Practice Act and TSBDE Rules. Disclosures to the Secretary of the Department of Health and Human Services must be made upon request to determine compliance with HIPAA or its implementing regulations. Disclosures required by law do not require patient authorization.

Legally Required Notices

Dental Gallery may communicate electronically or in writing to provide legally required notices, including breach notifications under the federal Breach Notification Rule, 45 C.F.R. §§164.400–414, and Texas Business & Commerce Code §521.053.

In the event of a breach involving at least 250 Texas residents, Dental Gallery will also notify the Texas Attorney General as mandated by Texas law. Notifications will include a description of the breach, types of information involved, steps taken to mitigate harm, measures implemented to prevent recurrence, and instructions for protecting against potential misuse of information.

Communication Preferences and Restrictions

Patients have the right to request restrictions on how Dental Gallery communicates with them, including requests for confidential communications through alternative methods such as encrypted email, postal mail, telephone contact at specific numbers, or other reasonable accommodations.

Dental Gallery will accommodate reasonable requests that do not conflict with legal requirements or impede necessary healthcare operations.

Patients also have the right to request that no voicemail messages be left or that text messaging be discontinued. Requests for restrictions are governed by 45 C.F.R. §164.522.

Patients may update their contact preferences at any time. Dental Gallery maintains documentation of communication preferences in the patient’s record and implements system settings to enforce these preferences.

Dental Gallery encourages patients to notify the office promptly if contact information changes, including telephone numbers, email addresses, or mailing addresses.

Security

Dental Gallery maintains administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of information communicated through any channel.

These safeguards include encrypted communication mechanisms where appropriate, authentication protocols, user access controls, automatic logoff features, device security standards, firewall protections, intrusion detection systems, audit logging of access and disclosures, and workforce training consistent with the HIPAA Security Rule and Texas Medical Records Privacy Act.

Dental Gallery enforces strict role-based access to minimize unauthorized use or disclosure of information. All employees and workforce members receive training regarding permissible communications, disclosure limitations, identity verification procedures, and protocols for handling sensitive, confidential, or legally protected information.

Communication Channel Security

Dental Gallery may limit or decline the use of a specific communication channel if it determines that the channel presents an unacceptable security risk or does not comply with legal obligations under HIPAA or Texas law.

For example, Dental Gallery may refuse to communicate sensitive clinical information through unencrypted email or SMS messaging. Dental Gallery may require the use of encrypted platforms or secure portals for certain communications, particularly those involving diagnoses, treatment plans, imaging, insurance details, or other protected health information that mandates additional safeguards.

Breach Notification

If Dental Gallery discovers or reasonably suspects a breach of unsecured protected health information that occurred through any communication method, Dental Gallery will conduct a risk assessment consistent with 45 C.F.R. §164.402 to determine whether the incident constitutes a breach.

If a breach is confirmed, Dental Gallery will issue notifications as required under the federal Breach Notification Rule and Texas Business & Commerce Code §521.053.

Notifications will be provided to the patient, the Department of Health and Human Services when required, and the Texas Attorney General when the incident involves at least 250 Texas residents.

Notifications will be issued “as soon as practicable,” but not later than the deadlines established by federal and Texas law.

Complaints

Patients have the right to communicate complaints or concerns regarding Dental Gallery’s communication and privacy practices. Complaints may be submitted to the Dental Gallery privacy, or compliance officer.

Additional information regarding patient rights, regulatory contacts, records requests, and complaint procedures is available in Dental Gallery’s Notice of Privacy Practices and applicable Texas patient notices.

Dental Gallery will not retaliate against any individual who files a complaint in good faith.

Changes to This Policy

This Communications Policy does not create contractual rights beyond those provided by federal and state privacy laws. Dental Gallery may update or revise this Policy at any time to reflect changes in technology, regulatory requirements, operational procedures, or best practices.

Any updates will be incorporated into the most recent version of this Policy, which will be made available upon request. The current version of this Policy will be made available upon request and through Dental Gallery’s applicable patient communication channels.

All questions regarding this Communications Policy, including requests for alternative communication methods, revocation of SMS or email consent, clarification of electronic disclosure practices, or concerns about communication security, should be directed to the Dental Gallery privacy or compliance officer using the contact information provided at the beginning of this document.