2.3 Record Alteration Prohibitions, Electronic Health Records, and Breach Notification

Key Takeaways

  • Intentionally falsifying or altering a dental record is a crime under California Penal Code § 471.5 and constitutes unprofessional conduct under Business and Professions Code § 1950.5(q), subjecting the licensee to criminal prosecution and board discipline.
  • Legitimate record corrections require strict procedural compliance: paper charts require a single strike-through with date, initials, and reason, while Electronic Health Records (EHR) require time-stamped, immutable addenda without deleting original data.
  • Health and Safety Code § 1280.15 requires a licensed clinic, health facility, home health agency, or hospice to report unlawful or unauthorized access to a patient's medical information to the California Department of Public Health within 15 business days of detection; private practices instead report under Civil Code § 1798.82 and the federal HIPAA Breach Notification Rule.
Last updated: September 2026

2.3 Record Alteration Prohibitions, Electronic Health Records, and Breach Notification

Maintaining the integrity and veracity of dental records is both a legal mandate and a foundational ethical duty in dental hygiene practice. Falsifying, backdating, or improperly altering clinical entries destroys professional credibility, constitutes criminal conduct under California law, and subjects the licensee to immediate disciplinary sanctions by the Dental Hygiene Board of California (DHBC). As modern dental practices transition to Electronic Health Records (EHR), dental hygienists must master lawful correction protocols, technical cybersecurity safeguards under HIPAA, and California's rigorous statutory breach notification mandates.

Legal Prohibitions Against Record Alteration and Falsification

Under California law, clinical documentation must reflect an unvarnished, contemporaneous account of patient care:

  • Criminal Penalties Under California Penal Code § 471.5: It is a misdemeanor crime for any person to alter, modify, or falsify any medical or dental record with fraudulent intent. A licensee convicted under this section faces criminal fines, county jail imprisonment, and mandatory reporting to state licensing authorities.
  • Unprofessional Conduct Under Business and Professions Code § 1950.5(q): The intentional alteration, falsification, or backdating of patient records, treatment plans, or billing claims constitutes unprofessional conduct. The DHBC possesses statutory authority to suspend, revoke, or place on probation the license of any dental hygienist who engages in fraudulent record tampering.
  • Impact in Malpractice Litigation: In civil liability lawsuits, evidence that clinical records were altered, erased, or supplemented after an adverse event creates an evidentiary presumption of fraud or consciousness of guilt. In many cases, intentional record alteration voids malpractice insurance indemnification, exposing the clinician to personal liability for punitive damages.

Compliant Correction Protocols for Clinical Records

Clinical documentation errors inevitably happen, but they must be rectified using transparent, legally accepted methods.

Paper Record Correction Standards

When an error is made in a physical paper chart:

  1. Single Strike-Through: Draw a single, clean horizontal line through the erroneous text. The original, incorrect entry must remain completely legible to anyone reviewing the chart.
  2. Never Obliterate or Conceal: Licensees are strictly prohibited from using liquid correction fluid ("white-out"), opaque corrective tape, erasers, chemical ink removers, or black marker scribbles. Erasing entries or covering text with correction fluid triggers immediate suspicion of fraudulent concealment.
  3. Never Remove Pages: Chart pages must never be torn out, shredded, discarded, or rewritten.
  4. Sign, Date, and Explain: Immediately adjacent to the strike-through, record the correct clinical information, the current date, the clinician's initials, and professional license number. If the reason for the correction is not obvious, include a brief explanatory note (e.g., "Error: documented tooth #14; intended tooth #15").

Electronic Health Records (EHR) and Addendum Mechanisms

Modern practice management and electronic charting software (such as Dentrix, Eaglesoft, Open Dental, or Curve Dental) must comply with federal and state audit trail mandates:

  • Immutable Audit Trails: EHR systems automatically log every keystroke, view, edit, print command, and deletion. Attempting to overwrite or delete a signed electronic progress note is impossible without generating a permanent audit trail entry showing the author, terminal IP address, date, and exact timestamp.
  • Locked Clinical Notes: Once a progress note is electronically finalized and signed, the software locks the entry against further direct editing.
  • Compliant Addenda: To correct an error or add omitted information in an EHR, the clinician must create a formal electronic addendum or amendment. The EHR system automatically appends the addendum to the original note, displays the precise date and time of the modification, records the practitioner's identity and DHBC license number, and preserves the untouched original entry for inspection.

Electronic Dental Records and the HIPAA Security Rule

The HIPAA Security Rule (45 CFR Part 164, Subpart C) establishes national standards for safeguarding Electronic Protected Health Information (ePHI). Dental practices must implement three tiers of safeguards:

  1. Administrative Safeguards: Formal security policies and protocols, including appointing a privacy/security officer, conducting periodic security risk assessments, establishing employee access authorization hierarchies, and providing mandatory annual workforce training on password management, phishing recognition, and security incident reporting.
  2. Physical Safeguards: Physical measures protecting electronic equipment and facility premises. Practices must install operatory terminal screens away from patient view or apply polarized privacy filters. Server rooms and backup drives must be physically locked, and portable storage devices (laptops, USB drives) must be strictly inventoried and wiped before decommissioning.
  3. Technical Safeguards: Automated technical controls governing software access:
    • Unique User Credentials: Every dental hygienist must log in with individual credentials; sharing office passwords or group logins is strictly illegal.
    • Automatic Logoff: Operatory computer workstations must be configured to automatically lock or log off after a specified period of inactivity (e.g., 3 to 5 minutes).
    • Encryption: ePHI must be encrypted using National Institute of Standards and Technology (NIST) advanced encryption standards (AES-256) both at rest (stored databases, cloud storage, local drives) and in transit (TLS 1.3 for electronic insurance submissions, secure email).

California Breach Notification Requirements

Two different California statutes apply, and they reach different entities. Civil Code § 1798.82 applies broadly to any person or business — including a private dental practice — that owns or licenses computerized personal information about a California resident. Health and Safety Code § 1280.15 is narrower: it applies to a clinic, health facility, home health agency, or hospice licensed under Health and Safety Code §§ 1204, 1250, 1725, or 1745. A conventional private dental or dental hygiene office is generally not a § 1280.15 licensed facility, but an RDHAP practicing inside a licensed primary care clinic, or a hygienist employed by a skilled nursing facility, may be:

  • Definition of a Breach: A breach is defined as the unauthorized acquisition, access, use, or disclosure of unencrypted medical information that compromises the security, confidentiality, or integrity of the patient's data.
  • Safe Harbor for Encrypted Data: If electronic patient information is fully encrypted in compliance with NIST standards and the encryption key was not compromised, the incident generally does not trigger statutory breach notification mandates.
  • Notification Timelines:
    • California Department of Public Health (CDPH) — licensed facilities only: Under Health and Safety Code § 1280.15, a licensed clinic, health facility, home health agency, or hospice that detects unlawful or unauthorized access to, or use or disclosure of, a patient's medical information must report the incident to CDPH no later than 15 business days after detection.
    • Affected Individuals — licensed facilities: Under § 1280.15 the facility must also notify the affected patient or the patient's representative within the same 15 business day window.
    • Affected Individuals — everyone else: Civil Code § 1798.82 requires disclosure "in the most expedient time possible and without unreasonable delay," rather than on a fixed day count. A private dental practice that suffers a breach of unencrypted computerized personal information is governed by that standard, and separately by the federal HIPAA Breach Notification Rule (45 CFR §§ 164.400–414), which requires individual notice without unreasonable delay and in no case later than 60 calendar days after discovery.
    • California Attorney General: If a single breach incident affects more than 500 California residents, the provider must electronically submit a copy of the breach notification letter to the California Attorney General.
  • Penalties for Late Reporting: For entities covered by Health and Safety Code § 1280.15, CDPH may assess an administrative penalty of $100 for each day the report is late beyond the 15-business-day deadline, subject to the statutory maximums in that section. Federal HIPAA civil money penalties and California Civil Code § 56.36 administrative fines may apply in parallel to the same incident.
Dimension / Record TypeCompliant Paper Chart PracticeIllegal Paper TamperingCompliant Electronic (EHR) PracticeProhibited Electronic Tampering
Correcting an EntrySingle horizontal strike-through, correct entry adjacentApplying correction fluid, erasing, or blacking out textGenerating a time-stamped electronic addendumAttempting database overwrite or administrative deletion
Clinician AuthenticationHandwritten signature/initials and license numberForged signatures or omitting license credentialsUnique authenticated login and electronic signatureSharing login credentials or signing under another clinician
Audit CapabilitiesVisual inspection of original legible strike-throughTorn out, discarded, or rewritten progress pagesImmutable automated audit logs tracking all accessDisabling system audit trails or modifying system clock
Data Security SafeguardsLocked physical chart cabinets and restricted chart accessLeaving paper charts unattended in public waiting roomsNIST AES-256 encryption and auto-lockout timersStoring unencrypted patient files on unprotected thumb drives
Test Your Knowledge

A registered dental hygienist realizes they documented '3 mg' instead of '3 cartridges' of local anesthetic in a paper chart note from earlier in the day. What is the legally mandated method for correcting this error in California?

A
B
C
D
Test Your Knowledge

A licensed community clinic discovers that an unencrypted portable hard drive containing patient records was stolen. Under California Health and Safety Code § 1280.15, within what timeframe must the clinic report the breach to the California Department of Public Health?

A
B
C
D
Test Your Knowledge

Under California Penal Code § 471.5 and Business and Professions Code § 1950.5(q), an intentional fraudulent alteration or falsification of a patient's dental records is classified as which of the following?

A
B
C
D