Flag of the United States
United States

Health Insurance Portability and Accountability Act of 1996

Pub. L. 104-191, as amended by the HITECH Act; 45 CFR Parts 160 and 164

How MolarPlus safeguards protected health information for dental practices in the United States.

Applies to
United States
Regulator
U.S. Department of Health and Human Services, Office for Civil Rights
The clinic is the
Covered Entity
MolarPlus is the
Business Associate
Data is hosted in
Asia Pacific (Mumbai) region, India
Last reviewed
September 2026

1.Scope

MolarPlus is operated by Upclick Labs (OPC) Pvt. Ltd. (“MolarPlus”, “we”). This statement describes the administrative, physical and technical safeguards MolarPlus applies to protected health information (“PHI”) that dental practices in the United States create, receive, maintain or transmit through the MolarPlus clinic management service. It refers to the Privacy, Security and Breach Notification Rules at 45 CFR Parts 160 and 164.

2.Roles

A dental practice that transmits health information electronically in connection with a standard transaction, such as a claim, is a covered entity. A service provider that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate under 45 CFR 160.103. MolarPlus acts in that capacity for the practices that use it.

3.Security Rule safeguards

The table below sets the standards of the Security Rule against the measures MolarPlus has in place for electronic PHI.

§ 164.308(a)(4)
Information access management: policies for authorizing access to electronic PHI.
The practice owner grants each staff member access section by section. Users see only what their role permits.
§ 164.308(a)(7)
Contingency plan: data backup, disaster recovery and emergency mode operation.
Automated daily database backups, with point-in-time recovery across 7 days. The practice can also export a complete archive of its data at any time.
§ 164.310
Physical safeguards: facility access controls and device and media controls.
Electronic PHI is hosted in Amazon Web Services data centers, whose physical security AWS maintains under its shared responsibility model. Storage volumes are encrypted.
§ 164.312(a)
Access control: unique user identification and encryption of electronic PHI.
Every user signs in with an individual account. Data is encrypted at rest with AES-256.
§ 164.312(b)
Audit controls: record and examine activity in systems that contain electronic PHI.
An activity log records actions taken in the practice account, available to the owner for review and export.
§ 164.312(c)
Integrity: protect electronic PHI from improper alteration or destruction.
Role permissions restrict who may alter records, and database backups allow recovery of data that is altered or destroyed.
§ 164.312(d)
Person or entity authentication.
Passwords are stored only as bcrypt hashes, sign-in is verified with one-time codes, and repeated attempts are rate limited.
§ 164.312(e)
Transmission security: guard against unauthorized access to PHI in transit.
Every connection between users and MolarPlus is encrypted with TLS.

4.Safeguards in detail

Encryption at rest
Patient and clinic records are held in a managed PostgreSQL database on Amazon RDS, encrypted at rest with AES-256. The storage volumes of the application servers are encrypted in the same way.
Encryption in transit
Every connection between a browser or the MolarPlus mobile app and the MolarPlus service is encrypted with TLS.
Network isolation
The production database accepts no connections from the public internet. It can be reached only from the MolarPlus application servers.
Role-based access
The clinic owner decides, section by section, what each staff member can see and do. Staff are given access to the information their work requires and nothing more.
Authentication
Every user signs in with an individual account. Passwords are stored only as bcrypt hashes, sign-in and sign-up are verified with one-time codes, and repeated attempts are rate limited.
Audit trail
Actions taken within a clinic account are recorded in an activity log, which the clinic owner can review and export.
Private document links
Documents, prescriptions and reports are kept in private object storage and are opened only through signed links that expire shortly after they are issued.
Backups and recovery
The database is backed up automatically every day, with point-in-time recovery available across a rolling seven-day window.
Portability
A clinic owner can download a complete archive of the clinic’s data at any time and export patient records as a spreadsheet, without contacting MolarPlus.

5.Privacy Rule support

§ 164.502(a)
Permitted uses and disclosures of PHI; prohibition on the sale of PHI.
MolarPlus uses PHI only to provide the service to the practice. MolarPlus does not sell PHI.
§ 164.502(b)
Minimum necessary: limit PHI to the minimum necessary for the purpose.
Role-based permissions let the practice limit each staff member to the information their work requires.
§ 164.524
Right of access: individuals may obtain a copy of their PHI.
The practice can export a patient’s complete record and provide it to the patient.
§ 164.526
Right to amend: individuals may request amendment of their PHI.
Authorized staff amend records directly, and changes are recorded in the activity log.

6.Breach notification

Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery. MolarPlus will notify an affected practice without unreasonable delay. To the extent possible, MolarPlus will identify each individual affected and provide the other information the practice needs to notify individuals, the Secretary of Health and Human Services and, where required, the media.

7.Data location and providers

PHI is stored on Amazon Web Services in the Asia Pacific (Mumbai) region, India. The HIPAA Rules do not prohibit the storage of PHI outside the United States. The service providers MolarPlus uses are listed in the register of sub-processors.

Optional features pass limited PHI to those providers: WhatsApp and SMS reminders send a patient’s name, telephone number and the message content to the messaging provider, and AI-assisted note drafting sends the content a clinician submits. Each practice should decide whether to enable these features in light of its own obligations under the HIPAA Rules.

8.Business Associate Agreements

A practice that requires a Business Associate Agreement should contact MolarPlus at support@molarplus.com before entering PHI into the service.

9.Contact

Questions about this statement or about the security of the service may be sent to:

Privacy and security contact
Grievance Officer, MolarPlus
Telephone: +91 9594078777
Sky Loft, opposite Golf Course, Shastrinagar, Yerawada, Pune, Maharashtra 411006, India

© 2026 MolarPlus Powered by Upclick labs (OPC) Pvt. ltd.