HIPAA, GDPR & DPDP for dental WhatsApp
A practical compliance brief for dental clinics in the US, EU, UK and India using WhatsApp for patient communication — what's encrypted, what's your responsibility and how LandinChat covers the rest.
- SOC 2 aligned
- BAA + DPA on request
- Role-based access
- Audit logs
Key things to know
BAA + DPA on request
US HIPAA BAA and EU GDPR DPA on file before you process any PHI.
Role-based access
Receptionists, hygienists, dentists and managers see only what their role permits.
Audit log
Every PHI view, edit and message export is logged with user, IP and timestamp.
Template-only outbound
Business-initiated messages must use Meta-approved templates — protects against rogue blasts.
People also ask
Q.Is WhatsApp HIPAA compliant for dental practices?
WhatsApp Business API is end-to-end encrypted, but HIPAA compliance is your operational responsibility. LandinChat is SOC 2 aligned, signs a BAA on request, and ships HIPAA-aware workflows — role-based access, audit logs, PHI access controls and approved-template-only outbound.
Q.What about GDPR for clinics in the EU/UK?
LandinChat is GDPR-compliant — data residency in the EU on request, lawful-basis tracking per patient, DSAR export, right-to-erasure tooling and DPA on file.
Q.What about DPDP for clinics in India?
Fully supported — consent capture, purpose limitation, retention controls and data-fiduciary obligations are built into the patient timeline.
Q.Can I send X-rays and treatment plans on WhatsApp?
Yes — over the verified patient thread. The Official WhatsApp Business API encrypts attachments end-to-end; LandinChat adds OTP-gated opens for high-sensitivity files.
Q.What happens if a staff member leaves the clinic?
Role-based access lets you revoke that user instantly. Their chat history stays auditable but they lose access to PHI from the moment they're deactivated.
Q.Do you store WhatsApp messages?
We store the operational metadata required to deliver reminders, run workflows and provide an audit log. Message content storage and retention follow your configured policy — including auto-delete schedules.
WhatsApp encryption is necessary but not sufficient
End-to-end encryption protects PHI in transit. Compliance requires more: access controls, audit logs, consented templates, retention policy and a BAA / DPA with your vendor. Most clinics fail an audit on access logs and template approvals, not encryption.
LandinChat ships every operational control your auditor will ask for. Below is the exact map.
Built for serious growth teams
BAA + DPA on request
US HIPAA BAA and EU GDPR DPA on file before you process any PHI.
Role-based access
Receptionists, hygienists, dentists and managers see only what their role permits.
Audit log
Every PHI view, edit and message export is logged with user, IP and timestamp.
Template-only outbound
Business-initiated messages must use Meta-approved templates — protects against rogue blasts.
Data residency
EU residency for European clinics; US residency on request for healthcare workloads.
Retention controls
Set message and PHI retention by category — auto-delete or auto-archive per policy.
Get live in days, not months
- 1
Sign the BAA / DPA
Request from your CSM — usually back within 24 business hours.
- 2
Map roles to access
Apply the dental role matrix (Receptionist, Hygienist, Dentist, Manager) in one click.
- 3
Configure retention
Set per-category retention windows — clinical vs marketing vs operational.
- 4
Run the compliance audit
Export the audit-log + access matrix for your annual review.
What teams ship with this
US dental DSO
BAA, HIPAA-aware workflows, US residency option.
EU/UK dental group
DPA, GDPR DSAR + erasure, EU data residency.
India multi-branch
DPDP-ready consent capture, purpose limitation and retention controls.
Frequently asked questions
Related guides & pages
Compliance-ready out of the box
LandinChat ships every control your dental auditor asks for. BAA and DPA on file, audit-logs on by default.