Updated 25.02.2025

In developing these technical and organizational measures, Dentsply Sirona has taken into consideration the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons and on basis of company-wide regulations.  These measures ensure an appropriate level of security, as detailed below.

 

Note that most of the Customer Personal Data is processed through the SureSmile Software.  Personal data processed outside the Software is generally limited to identifiers, manufacturing specifications, and/or order tracking.

Table of Contents

1. Confidentiality 

1.1 Physical Access Control

The purpose of the physical access control in place is to prevent unauthorized access to facilities where personal data is processed.

The following security measures are in place at facilities where Customer Personal Data is processed:

  • Exterior surveillance by video;
  • Securing of the factory premises by plant security;
  • Access to premises is given either through personalized, electronic company ID card or registration at reception/plant security; 
  • Visitors register at the reception/plant security and are then picked up and accompanied by their Dentsply Sirona host for the entirety of their visit;
  • Access rights to certain buildings/rooms/times are granted individually according to the assignment of tasks;
  • Sensitive areas and safety zones are secured by electronic access control systems; and
  • IT rooms are secured by video surveillance and intrusion detection systems.

Note that the SureSmile Software itself is hosted by Amazon Web Services, which provides similar physical security measures.

1.2 Electronic Access Control

The purpose of the electronic access control is to prevent unauthorized access to systems that process personal data.

The following security measures are implemented by the SureSmile Software::

  • Access to all patient data is controlled by an authentication and authorization system built into the Software;
  • User authentication uses explicit and unique usernames and passwords;
  • Strict password conventions, including complexity requirements, are applied;
  • Multi-factor authentication is required for administrative access to the Software;
  • User passwords are stored in salted and hashed format (using PBKDF2);
  • User passwords are used as the base of a key chain that ultimately controls access to all encrypted information;
  • All practice and patient data is encrypted at rest using a 256-bit AES symmetric key.
  • All traffic, between local clients and the SureSmile servers and between internal system endpoints, uses the HTTPS protocol and is TLS 1.2 encrypted; and
  • Additional cyber security measures used to protect personal data from unauthorized access include:
    • Multiple firewall layers including security groups, web application firewalls (AWS WAF), and application load balancers (ALB);
    • Virtual Private Cloud (VPC) to isolate systems; and
    • A combination of intrusion detection systems.

Note that the SureSmile Software includes tools such as role-based access controls and user activity logging to help practices manage their own users.

 

1.3  Internal Access Control

The purpose of internal access control is to ensure that persons who use systems where personal data is stored only have access the parts of the system they need for the fulfillment of their duties.

The following security measures are in place::

  • Access to Customer Personal Data is granted based on business need for access to Customer Personal Data;
  • User access rights, including administrator level access, and changes to access rights are requested through a formal process and approved by management;
  • Access is removed promptly when the user is terminated, leaves the company, goes on extended leave (maternity/paternity, medical, etc.), or otherwise no longer needs the access;
  • System access rights are regularly reviewed by system owners; and
  • System access is logged.

1.4  Isolation Control

The purpose of the isolation control is to ensure that data collected for different purposes can be processed separately.

The following provisions are implemented by the SureSmile Software:

  • Separation of practices and their data:
    • All Patient data is nested within a practice and can be only accessed in the SureSmile application within the corresponding practice;
    • No other resources (URI’s) are allowed to directly access Patient data without first accessing a practice;
    • A distinct 2048-bit customer generated key pair for each practice is used to enable patient and practice data encryption (This ensures separation of practices as the encryption key for one practice can’t be used to decrypt personal data of another practice); and
    • All database queries are automatically scoped and limited to a single practice.
  • Separation of production systems from development and test systems; and
  • Separation of organizational units. 

1.5  Pseudonymisation

The purpose of pseudonymisation is to protect the personal data by ensuring that the personal data cannot be associated with a specific data subject without the assistance of additional information. 

Provisions related to pseudonymisation include:

  • Outside the SureSmile Software the 3D models and manufacturing orders are generally identified by a unique practice and patient ID, or by an order number rather than patient name;
  • Instructions to business partners (dentists, dental laboratories, etc.) to provide health data to us exclusively in an anonymized or pseudonymized way;
  • Pseudonymisation is considered when applying "Privacy-by-Design" and "Privacy-by-Default" to internally developed systems; and
  • Internal instructions to anonymize/pseudonymize health data whenever deemed appropriate.

2.  Integrity

2.1  Data Transfer Control

The purpose of the data transfer control is to ensure that personal data cannot be read, copied, changed or deleted in an unauthorized way during an electronic transfer, physical transportation or storage on a data storage medium.

The following provisions are implemented::

            All practice and Patient data is encrypted at rest; 

  •  All traffic, between local clients and the SureSmile servers and between internal system endpoints, uses the HTTPS protocol and is TLS 1.2 encrypted;
  • Patient data is temporarily transferred to Dentsply Sirona locations in the USA, Mexico, and Costa Rica for manufacturing and processing purposes.  The data is only transferred temporarily and is not permanently stored at these locations.  Both the transfer and the local storage are encrypted.  After processing, the data is promptly deleted;
  • Patient data is permanently stored in the respective region of the customer.  Data generated in Europe, for example, is permanently stored in the AWS region in Ireland; and
  • A combination of cyber security measures is used to protect the data from unauthorized access:
    • Multiple firewall layers: including security groups, web application firewalls (AWS WAF), and application load balancers (ALB);
    • Virtual Private Cloud (VPC) to isolate systems; and
    • A combination of intrusion detection systems.

 

2.2 Data Entry Control

The purpose of the data entry control is to verify retroactively whether and by whom personal data was entered, changed, or deleted from a data processing system..

The SureSmile Software logs system access and change history. These logs are available to the practices, as they enter, modify, and delete personal data most frequently.  The SureSmile team can assist as necessary.

3.  Availability and Resilience 

3.1 Availability Control

The purpose of the availability control is to ensure that personal data is protected against accidental destruction or loss. 

The following security measures are implemented by the SureSmile team, using functionality available from Amazon Web Services, the cloud hosting provider for the SureSmile system:

  • Constant backup of databases, files and systems;
  • Redundancy of all critical systems including servers, and databases;
  • Redundancy of the data centers;
  • Multiple firewall layers including security groups, web application firewalls (AWS WAF), and application load balancers (ALB);
  • Use of virus protection and intrusion detection systems; and
  • Critical event monitoring and reporting. 

3.2 Rapid Recovery 

The purpose of the rapid recovery control is to ensure that in case of disruption, the stored data will be made available again as soon as possible.

The following security measures are implemented by the SureSmile team, some of which use functionality available from Amazon Web Services, the cloud hosting provider for the SureSmile system:

  • Controlled escalation path within the SureSmile and Dentsply Sirona team, defining responsibilities and actions to be taken;
  • Reinforced availability of systems through redundancy of all critical systems including servers, and databases; and
  • Backup/restore processes. 

4. Procedures for Regular Testing, Assessment and Evaluation

4.1  Data Protection Management

The purpose of data protection management is to ensure that appropriate technical and organizational measures have been identified and implemented.

Dentsply Sirona has a centralized data protection organization, which defines goals, duties, competencies and responsibilities regarding data privacy:

  • Data protection organization, consisting of the Global Data Protection Officer, the global Privacy Office, Local Data Protection Directors and locally supporting Data Privacy Coordinators;
  • Global Data Protection, Data Breach, and Retention Policies;
  • Global Data Protection Guidelines, covering company standards regarding procedures on specific questions related to data protection requirements, such as how to handle sensitive personal data, subject access rights, data privacy impact assessments (DPIAs) etc.; and 
  • Regular data protection trainings of our employees.
 

4.2  Incident Response Management

The purpose of incident response management is to ensure that cybersecurity incidents are identified and responded to appropriately.

Technical and organizational measures related to incident management include:

  • Dedicated Cloud and Security Operations team;
  • Automated anomaly detection and alerting;
  • Regular reviews of cybersecurity logs and systems;
  • Formal incident response process which includes containment, eradication, restoration, investigation, deadline monitoring, and incident reporting; and
  • Recurring pen tests to detect vulnerabilities.

 

4.3 Data Protection by Design and Default

The purpose of this section is to ensure that the security of personal data is considered and is the default configuration when developing new products and services. 

Data Protection by Design and by Default is achieved through the following measures:

  • Assessment of all projects and products to ensure personal data is protected appropriately; and
  • Execution of data privacy impact assessments for high risk processing activities.

 

4.4 Engaging Third Parties

The purpose of this section is to ensure that personal data, which is processed by third parties, will not be processed without clear and unambiguous contractual arrangements. 

To achieve this purpose, the following organizational measures are implemented:

  • A well-defined third-party selection process that includes appropriate vetting;
  • Contract with each vendor;
  • Clear contract design, including requirements that the vendor destroy, delete or return personal data upon completion or termination of the contract; and
  • Use of specific agreements as required (for example, Business Associate Agreements (HIPAA) and Standard Contractual Clauses (GDPR).