Guaranteed Expert Consultation Within 1 Hour. Click Here!

Guaranteed Expert Consultation Within 1 Hour. Click Here!

FDA Establishment Registration, 21 CFR 820 Quality System Records, Medical Device Tracking and HIPAA Business Associate Duties: Compliance for US Dental Lab Software

This article is part of our series on Custom Dental Lab Case Management Software Development for US Dental Laboratories: Building a Digital Impression, Milling and Case-Tracking Platform

Introduction: A Dental Lab Is a Device Manufacturer, and the Software Is Inside the Quality System

A US dental laboratory making crowns, bridges, dentures, or aligners is manufacturing medical devices. A case management platform that holds the production and quality records is not adjacent to that regulatory obligation. It sits inside it.

A US dental laboratory making crowns, bridges, dentures, or aligners is manufacturing medical devices. A case management platform that holds the production and quality records is not adjacent to that regulatory obligation. It sits inside it.

Dental lab software compliance requirements span four surfaces:

  • FDA establishment registration and the limits of the custom device provision
  • Quality-system records under the current Part 820 and QMSR framework
  • What device tracking and traceability actually require
  • HIPAA business associate duties

State registration and disclosure obligations layer on top of all four.

This is educational and strategic content, not legal or regulatory advice. Confirm your obligations with FDA regulatory counsel and a qualified quality-systems consultant.

Compliance is the regulatory layer of the full custom dental lab case management software development guide. Which of these obligations become concrete product features is mapped in Dental Lab Software Features: The 2026 Feature Checklist. The platform holding these records is where custom software development treating quality-system requirements as product inputs earns its place. The dentist portal and case communication layer depend equally on web application development built around compliant data handling.

FDA Establishment Registration and the Limits of the Custom Device Provision

The custom device provision under section 520(b) of the FD&C Act, reflected in 21 CFR 812.3(b), is the reason most dental restorations do not go through premarket clearance. It is important to state what it does and does not do. It exempts qualifying custom devices from premarket approval or clearance and from performance standards. It is not a blanket exemption from FDA oversight, and it does not automatically resolve registration and listing.

Whether a specific laboratory must register its establishment and list devices depends on what it manufactures and its role in the supply chain. It also depends on whether it produces devices for other laboratories, whether it imports or exports, and current FDA policy. This is a determination to reach with regulatory counsel, not one to assume in either direction. The wrong assumption is expensive in both directions.

Aligner manufacturing sits in materially different regulatory territory from crown and bridge work. Aligner treatment-planning software may itself be regulated. Any laboratory moving into aligners should treat that as a separate regulatory assessment rather than an extension of its existing position. FDA regulatory counsel is required before making that move.

21 CFR Part 820 and the QMSR Transition: What Changed in February 2026

The quality-system framework US device manufacturers work under has changed. FDA’s Quality Management System Regulation amends 21 CFR Part 820 to incorporate ISO 13485:2016 by reference, with a compliance date of February 2, 2026. A laboratory scoping software in 2026 should be building to the current framework rather than to the language of the previous Quality System Regulation.

For a laboratory, the practical effect is less a change of substance than a change of structure and vocabulary. The underlying expectations around documented processes, records, control of production, traceability, and corrective action persist. The organizing framework and terminology now follow ISO 13485.

Why this matters for a software project: requirements documents, record definitions, and validation plans written against the old framing will need reworking. Any vendor proposing a Part 820 compliance module built on pre-2026 assumptions is selling something dated.

The design consequence worth stating plainly: the platform does not make a laboratory compliant. It holds the records and enforces the process steps that the laboratory’s quality system defines. Vendors who claim to deliver compliance rather than to support it should be treated with caution.

Confirm the current state of the rule and any FDA transition guidance before publication.

The Records the Platform Has to Carry

Device History and Production Records

For each case, the platform must record what was made, to which specification, and from which materials and lots. It must also record by whom, on which equipment, through which process steps, and the inspection or QC results before release. These records are captured at the point of work through station scanning and material logging rather than reconstructed afterwards. Reconstruction is both expensive and unconvincing to an auditor. Capturing at the point of work means capturing in the technician’s hand, so custom mobile app development built around station scanning and lot entry is what decides whether the device history record fills itself or gets typed up at the end of the week.

Material and Lot Traceability

Blanks, pucks, alloys, ceramics, resins, and implant components must be tracked by lot with expiry, from receipt through to the specific unit they went into. Lot traceability is also what makes a supplier issue containable. When a lot is questioned, the laboratory needs to know which cases it reached and act on that answer quickly.

Nonconformance, Complaints, and Corrective Action

The platform must provide a defined path for handling nonconforming product with disposition and structured complaint intake from practices. Investigation records and corrective action with effectiveness follow-up complete the requirement. Adverse event reporting obligations should be assessed with counsel. The reporting path must be built into the complaint workflow rather than left to individual judgment at the time an event occurs.

Device Tracking, Traceability, and UDI: What Actually Applies

“Medical device tracking” has a specific regulatory meaning that is often used loosely in dental laboratory discussions. The distinction is worth making clearly before scoping a platform around the wrong requirement.

Tracking under 21 CFR Part 821 is an obligation FDA imposes on specific devices through a tracking order. It applies typically to devices whose failure would have serious adverse health consequences, or to implants and life-sustaining devices used outside a facility. It is not a general obligation that attaches to everything a laboratory makes. Dental restorations are generally not in that category. Verify applicability for your specific product mix with regulatory counsel rather than assuming either way.

What does bind a laboratory is traceability within the quality system: the ability to connect a finished device back to its materials, processes, equipment, and personnel. The device history record delivers that. This is the traceability that matters operationally and that the platform must support.

UDI is a third distinct requirement. Custom devices have exceptions from UDI labeling requirements. Confirm applicability for the products in question with counsel before treating UDI as either a firm obligation or a dismissed one.

HIPAA Business Associate Duties and Where PHI Actually Lives

Dental laboratories handle protected health information routinely, and it is spread wider than most owners expect. Patient names appear on prescriptions and case pans. Intraoral scans and photographs, radiographs and CBCT studies, communication threads with the practice, and shipping labels are all potentially PHI.

Whether a specific laboratory is formally a business associate depends on the services it performs and its arrangement with the practice. Many practices require a BAA as a matter of policy regardless. The practical position is to build the platform to BAA-level expectations from the start, regardless of where the formal determination lands.

In software terms: access control by role, encryption in transit and at rest across both database and file storage, and audit logging of who viewed or exported what. Minimum-necessary access means a milling technician does not need the patient’s full record. Secure disposal and a breach-response capability that can establish scope quickly complete the technical control set.

HHS OCR published proposed HIPAA Security Rule updates in January 2025. Verify their current status before publication and before finalizing the security architecture.

State Registration and Origin and Material Disclosure Laws

Alongside federal obligations, several states require dental laboratories to register with a state authority and require disclosure of materials used and the point of origin where work is manufactured. Requirements vary by state. Verify for each state the laboratory operates in or ships into rather than working from a national assumption.

The software consequence: material and origin data must be captured per case and reproduced on the documentation that accompanies the restoration, including for outsourced and offshore work.

One clarification worth including because it is widely confused: Certified Dental Technician and Certified Dental Laboratory credentials, known as CDT and CDL, are voluntary industry credentials, not government licensure. They signal competence. They are not a substitute for whatever state registration applies in a given jurisdiction.

Software Validation: Your Platform Becomes Part of the Quality System

Software used as part of production or the quality system must be validated for its intended use. That obligation is carried in 21 CFR 820.70(i) and reflected in the equivalent ISO 13485:2016 requirement under the current QMSR framework. A custom case management platform that routes production, holds device history records, and controls release is precisely that software.

What validation means practically: a validation plan tied to intended use, documented protocols and test evidence, records retained, and a defined process for revalidating after changes. Every meaningful release carries a validation consideration, which makes this an ongoing operating obligation rather than a one-time gate. Budget it, schedule it, and decide who owns it after launch before development starts.

Validation cost and ownership are among the first questions to put to any consultant before funding a build, covered in The Five Questions US Dental Laboratory Owners Should Ask a Technology Consultant.

Final Thoughts

Laboratories that scope software against the obligations that actually apply build platforms that produce audit evidence as a by-product of daily work. Those obligations are the current QMSR quality-system framework, an honest registration determination, real traceability rather than assumed device tracking, HIPAA-grade controls on the PHI they already hold, and validation as an ongoing commitment. Confirm your specific obligations with FDA regulatory counsel and a qualified quality-systems consultant. This is educational content, not legal or regulatory advice.

If you are scoping a platform that will hold your quality records, establishing your registration position, your record set under the current QMSR framework, and your HIPAA control requirements before architecture is fixed is the step that keeps compliance from becoming a rebuild. Validation scope must be part of that same conversation. Learn more about digital transformation solutions from a leading AI software company in the United States.

Explore more categories