1. Scope of this notice
This notice covers the marketing website, the account application and the client portal operated by Benchside Dental (“Benchside”, “we”, “us”). It describes how we handle information about dental practices that hold accounts with us, the individuals who use those accounts, and the case data those practices send.
It is written for practices in the United States, which is where we supply. It is not a Notice of Privacy Practices: that is a document your practice gives its own patients, and this notice does not replace it.
2. Our role under HIPAA
Your practice is a covered entity. When you send us a prescription, a scan or a patient reference, Benchside acts as your business associate under 45 CFR §160.103. We use and disclose protected health information only to perform the services you have engaged us for, and as our business associate agreement with you permits.
Before we accept PHI we sign a business associate agreement with your practice. Our business associate agreement and our manufacturing partner’s subcontractor agreement are both drafted and are with counsel; ask us for their current status before you send a case. Where the agreement and this notice differ on the handling of PHI, the agreement governs.
We do not sell PHI, do not use it for marketing, and do not use your case data to train machine-learning models.
3. PHI leaves the United States
Benchside does not operate its own bench. Manufacturing is performed by Lumina Dental Laboratory, our exclusive manufacturing partner, at its laboratory in Egypt. To make your case, that laboratory receives what is needed to make it: the prescription, the scan files, the shade and material selections, and the patient reference the case travels under.
HIPAA does not prohibit a business associate from disclosing PHI to a subcontractor outside the United States. It requires the disclosure to be governed. So it is:
- Our manufacturing partner is a subcontractor under 45 CFR §164.308(b)(2), and a subcontractor agreement binding it to the same restrictions and conditions that apply to us — including the duty to report a breach to us — is drafted and with counsel. Ask us for its current status before you send a case. Being our only bench does not change this: Lumina is a separate company, so it is a subcontractor and needs its own agreement.
- Only what is needed to manufacture the case is sent. A chart reference is enough to identify a case; we do not send — because we do not hold — dates of birth, addresses, contact details or payer identifiers.
- The transfer is disclosed here, in clause 6 of the terms of service, on the quality page, on the pouch label in the box, and on the case record in your portal. You should not have to discover it.
If your practice, your state, your payer contracts or your own policies prohibit offshore processing of PHI, we cannot supply you. Tell us before opening an account rather than after. We would rather lose the account than have you breach an obligation you did not know you were breaching.
Three places it is worth checking, because they catch practices out. Some states restrict where patient health information may be stored or handled, and a few prohibit offshore handling outright. Medicaid managed-care contracts in several states carry their own restrictions. And Medicare Advantage plans generally require attestations about offshore subcontractors, which flow down to network providers through their own agreements. Ask us and we will give you what you need to answer any of them — the disclosure, the subcontractor agreement, and a description of the safeguards.
4. What we collect
Practice and account details
What is given in the account application and afterwards: practice name and address, professional licence or state registration details, the names, work email addresses and roles of the team members who need logins, and billing and shipping details.
Case prescriptions
The clinical instruction for each case: restoration type, tooth numbers, material and shade selections, implant system and connection where relevant, occlusal notes, the requested return date, and any free-text notes you add. The prescription is also the regulatory record of the device, so it is retained as part of the device file.
Scan files and case media
Intraoral and desktop scan exports, CBCT data where a guided case requires it, photographs you supply, and any supporting documents uploaded to the case. These are clinical files. Some scanner exports carry embedded metadata written by your own software, so we treat the whole file as PHI regardless of what is inside it.
Where a scanner is connected to us directly, the same files arrive automatically instead of being uploaded by hand. Nothing else about the handling changes.
Where a scanner connection is available, you sign in on the scanner manufacturer’s own page and we never see that password. We ask only to read — we list your recent cases so you can choose one, and we download files only for the scans you choose or send to us. We cannot change anything in your scanner account. The access is stored encrypted, and disconnecting it in your settings destroys our copy of it.
Patient reference data
A chart or patient reference of your own choosing, which is meaningful only inside your own records. Optionally, patient initials, a patient name and the name of the treating dentist, where you choose to supply them.
A patient name is never required to place a case. Where one is supplied it is used for two things and nothing else: it prints on the label inside the pouch, so your front desk can match a delivery to a chart without opening the packaging, and your own team can search on it inside the portal. It is never printed on the outside of a shipment, which carries the case number alone and passes through couriers, customs and mailrooms identifying nobody.
Case activity and platform records
Timestamps and actor identity for every action taken on a case: submission, review decisions, production transitions, file uploads and downloads, messages and dispatch. Plus the ordinary technical records any hosted service keeps — sign-in events, IP address and browser user agent at sign-in, and error logs.
Manufacturing and financial records
Material manufacturer, product and lot numbers, the technicians assigned, quality-control photographs, the documentation issued with the case, and the invoice lines the case produced. These exist because device regulation and accounting law require them.
5. What we deliberately do not collect
We do not ask for dates of birth, home addresses, patient contact details, Social Security or other national identifiers, insurance or payer identifiers, or medical history beyond what the restoration requires. A laboratory does not need them to make a restoration, and data that is never collected cannot be breached, subpoenaed or mishandled.
If a practice includes such data anyway — in a free-text note, an embedded file name or a photograph — we ask that it be removed. Where we notice it, we will say so.
6. Why we hold it
- To manufacture and deliver the restorations you prescribe, which is the performance of our contract with you and the service you engaged us for as your business associate.
- To meet obligations under the device rules that apply to a custom-made dental device — device records, traceability, labelling, complaint handling and reporting.
- To operate the portal: authentication, permissions, notifications, and the audit trail that makes the case timeline trustworthy.
- To handle warranty and remake claims, which depends on being able to show what was received, what was decided and what was made.
- To invoice, to keep the accounting records the law requires, and to prevent fraud and misuse of accounts.
7. How it is stored and secured
Case files move over TLS and are stored encrypted at rest. Access is scoped to the practice that owns the case: no other account on the platform can list, open or download it, and that boundary is enforced in the data layer rather than by hiding buttons in the interface.
Internally, access is limited to the people who need it to do the work — the technicians assigned, the review desk, dispatch and administration — and access is logged. The timeline you see on a case is drawn from that audit record rather than being a summary written alongside it, so it cannot flatter us.
Each team member has their own credentials. Shared logins defeat the audit trail and we do not support them.
Where a scanner or practice system is connected to us directly, every submission is authenticated before it is used. A delivery agent on your own computer signs each request with a secret held by your practice, and it is rejected if the signature, the timestamp or the payload does not match. An order notified to us by a scanner service is not accepted as delivered: we read it back from that service over our own authenticated connection, and act only on what it returns. Work reaches your account only through a connection made for your practice. Scans are added to an existing case only when exactly one open case carries their patient reference, and a case is opened from a scanner order only when its prescription has a single clear reading — anything less certain waits for a person rather than being placed by guesswork.
8. How long we keep it
Design files and scans are retained so that a restoration can be remade from the original data rather than from a fresh appointment. Device records — the prescription, the materials and lots, the QC photographs and the documentation issued — are retained for seven years from dispatch, which covers the periods commonly required of a dental laboratory and of a practice’s own records. Financial records are retained for the periods tax and accounting law require.
You can ask us to delete the source scan files for a case at any time. We will do so and keep the audit record of the case without them — the history of what was made, when, and from what materials remains; the mesh does not.
Account records are retained while the account is open and for the period afterwards required by tax and accounting law. You may request an export of your case history at any time, before or after closing the account.
9. Who else touches it
A small number of third parties are needed to run the service. Each is bound by contract, processes data only on our instructions, and is limited to what its function requires. We will not disclose PHI to any of them without a written agreement carrying the same obligations we owe you.
- Lumina Dental Laboratory — manufacturing. Receives the prescription, the scans and the case reference. Located in Egypt; see section 3.
- Cloud hosting and database — the portal and its data, hosted in the United States.
- Object storage — scan files and case media.
- Transactional email — notifications and account messages. Case notifications name the case number, never a patient.
- Express couriers — dispatch and delivery details only. The outside of a shipment carries the case number and never a patient name.
- Payment and accounting providers — billing data only, never clinical data.
The current list of named providers, with their locations and functions, is available on request from support@benchsidedental.com. We will tell account holders before adding a subcontractor that will handle PHI.
We disclose information to anyone else only where the law requires it, and where we are permitted to tell you that we have, we will.
10. Your rights, and your patients’
Account users can see and correct much of their own data directly in the portal, and can ask us to correct or delete the rest.
Requests about a patient must come through the prescribing practice. As a business associate we do not respond to patients directly. We hold only a reference that you chose, so you are the only party that can connect a case to a person — and the only party positioned to verify who is asking. Where a patient exercises a right of access, amendment, restriction or accounting of disclosures with you, we will give you what you need to answer, promptly and without charge.
Practices and individuals in states with their own consumer privacy laws may have additional rights. Where information is PHI held by a business associate, those laws generally leave it to HIPAA — but if you believe a state right applies, write to us and we will deal with it rather than argue about which statute governs.
11. Cookies and analytics
The website and the portal set only the cookies required to run: a session cookie to keep you signed in, and security cookies to protect against cross-site request forgery. These are strictly necessary and cannot be turned off without breaking sign-in.
We do not run third-party advertising or tracking, and there is no analytics pixel on the portal. If that changes, this section will be updated before the change is made, not after.
12. Changes to this notice
We will update this page when what we do changes. Material changes affecting how case data or PHI is handled will be notified to account holders by email rather than by quietly amending the page and moving the date.
13. Contact
Questions about this notice, requests about data, the current subcontractor list, or the status of our business associate agreement: support@benchsidedental.com. Case and clinical enquiries: cases@benchsidedental.com. Case desk hours: Case desk open Sunday 18:00 – Friday 13:00 Eastern.
If you believe we have mishandled protected health information, write to us first — we would rather know. You may also complain to the US Department of Health and Human Services, Office for Civil Rights, and we will not retaliate for it.
Benchside Dental is a sole proprietorship established in Quebec, Canada, and supplies dental practices in the United States. Full legal and contact details of the proprietor are available on request.