AI Governance for Dental Practices and Dental Groups

A documented governance position for practices, implant and orthodontic clinics and multi-site groups using AI in imaging, notes, transcription, patient communication or admin workflows.

What you are buying: for a fixed £5,500 + VAT, in four working days, a board-ready evidence pack that answers one question with evidence: what AI is in use across your practice, what patient data it touches, and how that use is governed. The pack is what you put in front of your DPO, a CQC inspector, your MDO, your insurer or your board when the question lands.

A dental practice or group can be running AI in several places at once without a line about it in the practice records: detection features inside the imaging software, an associate drafting notes in ChatGPT, transcription on referral letters, and patient recall managed by a marketing platform.

The tools are not the problem. The problem is the day someone asks which of them touch patient data and nobody can answer.

Evidence guides: AI in Dental Practices evidence guide · AI Evidence Pack Checklist for Private Clinics

Why a documented governance position matters in dentistry

  1. 1. CQC-regulated dental activities are subject to inspection

    Dental practices providing regulated activities are required to register with and be inspected by CQC under the Health and Social Care Act 2008. CQC's key questions include whether a service is safe and well-led. Where AI affects clinical records, care workflows, data processing or human oversight of clinical output, the practice needs a documented position it can show an inspector. There is no dental-specific AI guidance equivalent to CQC GP Mythbuster 109, which is GP-specific. The Fundamental Standards apply to dental regardless, and AI governance is within scope of what an inspector can ask about.

  2. 2. GDC professional standards require the clinician to own the clinical record

    The GDC Standards for the Dental Team place responsibility for patient records with the treating clinician. Where AI supports radiographic interpretation, treatment planning or note generation, the clinician remains accountable for what enters the record and what is relied on clinically. That review step needs to be written down, not assumed. A practice that cannot evidence the review cannot show the standard has been met.

  3. 3. Dental AI processes significant volumes of special category health data

    Radiographs, intraoral scans, clinical photographs, orthodontic records, treatment plans and correspondence are all special category health data under UK GDPR. Where AI processes any of them, a DPIA is likely required or strongly indicated. That determination is the practice's DPO's to make, and screening should come before live use, not after.

  4. 4. AI imaging tools may require medical device review

    Where AI software meets the MHRA's definition of a medical device or software as a medical device, specific regulatory obligations may apply to the supplier and the deploying practice. AI dental imaging tools used for caries detection, bone level analysis or radiograph interpretation sit in this territory. ELSA AI flags where SaMD review may be warranted and what supplier evidence should be requested; it does not make the classification decision.

  5. 5. The indemnity position needs to be confirmed

    The consistent theme across medical defence organisation guidance is that the clinician remains responsible for the accuracy of the clinical record, including where the first draft was AI-generated, and that AI use outside organisational approval and governance may carry personal risk. The current position should be confirmed with your own MDO or indemnity organisation.

The typical governance position we find

In dental practices and dental groups, the recurring pattern is an evidence gap rather than a single failure.

Common findings include:

  • AI imaging tools are in use, but the practice holds no supplier evidence: no data processing agreement, sub-processor list, hosting information or retention terms.
  • ChatGPT and Microsoft Copilot are in use for drafting referral letters, clinical notes or patient communications, with no documented patient-data boundary.
  • Transcription is live on referral letters or consultation notes without DPIA screening.
  • Patient transparency wording is missing, inconsistent or untested across clinicians and reception staff.
  • Marketing automation uses patient contact data with no documented boundary between marketing and clinical records.
  • There is no approved, conditional and prohibited use position that all staff have seen in writing.
  • Incident reporting does not cover AI-related record errors, clinically incorrect or invented content, imaging misinterpretation or unintended disclosure.
  • Multi-site groups have no single inventory: what is in use at one site is unknown at another.

None of this is a legal conclusion. It means there is an evidence gap. That gap becomes urgent when a DPO, insurer, MDO, CQC inspector, board member or patient asks how AI use is controlled.

Common triggers for engaging ELSA AI

  • A DPO asking whether patient images, records or special category data reach AI tools.
  • CQC inspection scheduled or anticipated.
  • An AI imaging or note-generation tool under consideration, in pilot or recently adopted.
  • An insurer or indemnity renewal questionnaire including AI questions.
  • A practice manager or principal discovering informal ChatGPT or Copilot use.
  • A patient asking whether AI was used in their images, notes or correspondence.
  • A complaint, incident or subject access request involving AI-generated content.
  • A group board or investor seeking a practice-level AI exposure view.

What you get for £5,500, in four working days

The Clinical AI Exposure Diagnostic™, scoped to a dental setting, produces a board-ready governance pack. It establishes:

  • which AI tools are in use across clinical, imaging, admin, marketing and support functions, including declared and shadow AI;
  • whether dental images, notes, correspondence, patient identifiers or special category data are being processed, and at what level of sensitivity;
  • whether use is approved, conditional, tolerated, shadow or unknown, and whether any tools are running on personal devices or free-tier accounts;
  • whether DPIA screening, privacy notice, data processing agreement and vendor evidence are in place, and where gaps exist;
  • whether AI imaging or clinical decision-support tools require SaMD review, and what supplier evidence should be requested;
  • whether patients are informed consistently and have a clear route to raise concerns or decline use;
  • whether staff have a documented and approved AI use position;
  • whether MDO, PMI or insurer disclosure needs review;
  • what should be done in the next 30 days.

You receive nine deliverables in one pack

  • Board Findings Report
  • One-page RAG Exposure Map
  • AI Tool and Use Case Inventory
  • DPIA Readiness and Patient Data Exposure Note
  • Vendor Data Position and Evidence Tracker
  • Ambient Scribe Assessment Sheet, where applicable
  • MDO, PMI and Insurer Disclosure Readiness Note
  • 30-Day Priority Action Plan
  • Source and Guidance Mapping Appendix

Where a deliverable does not apply to your practice, it is recorded as not applicable with the reason stated, so the pack stands as a complete evidence record.

Fee and timeline

Fixed fee: £5,500 + VAT. Delivered within four working days from the start of delivery.

This standard fixed fee covers a single-site dental practice of up to 60 staff, in a single clinical specialty, with no NHS contract or NHS data-sharing arrangement in scope. Multi-site groups and practices with mixed specialties are scoped individually at intake.

Where an ambient scribe, AI transcription or consultation note-generation tool is in use, in trial or planned, the engagement routes to the Clinical AI Exposure Diagnostic™ with Ambient Scribe Assessment at £8,500 + VAT, delivered in six working days.

A separate six-working-day engagement. The ambient scribe assessment runs through the full evidence pack, not as a standalone addition.

View pricing details

No platform subscription. No retainer required to start.

For practices that want to convert the Diagnostic into a board-adopted governance baseline, the Clinical AI Safe Usage Launchpad™ follows over four to six weeks. For practices that want their governance evidence kept current as tools, staff use, vendor terms and regulatory expectations change, the AI Exposure Sentinel™ retainer is available at £950 per month, £2,850 per quarter in advance, or £10,500 per year prepaid, + VAT. Annual prepaid is preferred.

What ELSA AI does not do

ELSA AI provides advisory governance support only. We do not:

  • determine legal compliance with UK GDPR, the Data Protection Act 2018 or any other legislation;
  • provide CQC, GDC, ICO or MHRA approval, certification or sign-off;
  • complete or sign a DPIA;
  • determine insurer coverage, underwriting or MDO indemnity support;
  • approve AI tools or certify a vendor's position;
  • make medical device or SaMD classification decisions;
  • replace the practice's DPO, legal adviser, clinical lead, principal dentist or accountable officers.

Final legal, data protection, clinical safety, regulatory, insurer and MDO decisions remain with the practice's own accountable officers and advisers. Where useful, ELSA AI structures evidence so it can be reviewed, adopted and signed off by those advisers. We say what we found, what it means and what to do about it. You decide, and you adopt.

Founder-delivered

Engagements are led by Faisal Ali, AAISM, CISM, CRISC, Founder and Principal Consultant of ELSA AI. Faisal brings more than two decades in cybersecurity, information risk and governance across healthcare, financial services and national infrastructure.

Senior-led. No junior delegation. No template-and-invoice model.

Get a documented AI governance position before the next question lands.

Find out whether your practice or group has meaningful AI governance exposure in 20 minutes.

Advisory governance support only. Not legal advice; CQC, GDC, ICO or MHRA approval; insurer coverage advice; MDO indemnity advice; a completed or signed DPIA; or medical device or SaMD classification. CQC and GDC standards are referenced as governance-standard signals; they do not constitute, and are not a substitute for, the practice's own legal, regulatory or clinical safety review.