FROM THE BENCH
Consent Metadata for Case Studies: What Labs Should Capture Before You Publish
Case studies are how a lab proves the work, but the consent layer underneath them is what keeps that proof defensible. Here is the metadata structure we capture on every published Dani Dental case, the fields that matter for HIPAA, and how dentists submitting cases for publica...
Every case study published on a dental lab site is two things at once. It is a marketing artifact. It is also a patient record being shown outside the clinical context where it was created. Most labs treat the first part seriously and the second part casually. That gap is where compliance problems get written.
This post walks through the consent metadata structure we capture at Dani Dental before a case appears anywhere public, why each field exists, and what dentists submitting cases for publication should look for from their lab partner. If you refer cases to a lab and that lab publishes work, the authorization trail attaches to your practice too. Worth knowing what it looks like.
Why consent metadata is a structured field, not a checkbox
Most lab websites that show case photography rely on a single yes-or-no in a CRM somewhere: patient signed a release, case is cleared. That works until somebody asks which release, signed when, covering what use, witnessed by whom, and revocable under what conditions. At that point the single checkbox is not a record. It is a guess.
HIPAA's authorization requirements under 45 CFR 164.508 are explicit about what a valid marketing authorization must contain. Six core elements: a specific description of the information to be used, the names of the persons authorized to make the disclosure, the names of those who will receive it, a description of each purpose, an expiration date or event, and the patient's signature with date. Miss one and the authorization is not valid. The penalty tier for a non-compliant disclosure starts around 100 dollars per violation and runs to 50,000 dollars per violation for willful neglect, with annual caps near 1.9 million dollars per identical violation category.
That is the floor. Most labs and most referring practices want more than the floor. They want a structured record that survives a turnover in marketing staff, a change in lab ownership, or a patient who five years later asks the case to be taken down.
The metadata fields we capture on every published case
Here is the structure we use on case work that appears on the Dani Dental site or in CE material. Treat it as a template, not a prescription. Your practice attorney and your lab's compliance lead should review it against your state law (California, Texas, and New York layer additional requirements on top of HIPAA).
Identity and authorization fields
- Authorization ID(internal reference, links to the signed document)
- Patient initials only(never full name on the public-facing record)
- Signing date
- Expiration date or expiration event(we default to 7 years from signing, or earlier on written revocation)
- Witness signature and date(we require one even when state law does not)
- Authorized uses(specific list: website case gallery, printed CE material, conference presentation slides, podcast visual, social media). Each use is a separate checkbox on the authorization form, not a blanket yes.
- Authorized recipients(Dani Dental, named CE partners if applicable, conference organizer if applicable)
Clinical and image fields
- Referring clinician name and license number
- Practice name and city, state
- Procedure type(single-unit crown, three-unit bridge, full-arch implant prosthetic, etc.)
- Material specification(lithium disilicate, monolithic zirconia, hybrid PMMA, etc.)
- Identifiable features flag(does the photo show recognizable anatomy beyond teeth: tattoo, scar, distinctive lip shape, jewelry). If yes, photographer is required to reframe or the case is flagged for additional written consent on the identifiable feature specifically.
- Image capture date
- Technician of record(the named bench tech on the case, for the named-accountability voice we use across the site)
Revocation and audit fields
- Revocation method(written request to a named compliance contact)
- Revocation response SLA(we commit to take-down within 5 business days of written request, with confirmation back to the patient and the referring practice)
- Last audit date(we review the consent file annually)
- Storage location(signed authorization stored in encrypted document management, retained 7 years past expiration per HIPAA retention guidance)
That is 17 fields. Sounds heavy. In practice it adds about 8 minutes to the case-publication workflow, and it means that when a question comes up two years later, the answer is in a structured record instead of a search through email.
What referring dentists should ask their lab
If your cases end up in a lab's marketing material, the chain of authorization runs through your practice. A few questions worth asking any lab partner before you let them publish your work:
- Show me a sample authorization form. Does it list the six HIPAA-required elements? Does it specify each use separately?
- What is your take-down SLA when a patient revokes consent? Get it in writing.
- Do you redact identifiable features beyond intraoral anatomy? Tattoos, jewelry, distinctive lip shape: these are reasonable concerns for cases involving anterior smile photography.
- Who is your compliance contact and what is their direct line? (Same logic as the named-technician model. If there is no named person, there is no accountability.)
- How long do you retain authorization records? HIPAA says 6 years minimum from creation or last effective date; we default to 7 years past expiration, which gives a margin.
If a lab cannot answer those questions, the case work they publish is exposure. Yours and theirs.
The internal workflow that makes the metadata real
Metadata fields on a form do not enforce themselves. The workflow has to. Our internal rule is that no case appears on the public site until the consent record passes a two-person review: the technician of record confirms the clinical fields and the named patient initials match the case file, and the compliance contact confirms the authorization document is signed, dated, witnessed, and covers the specific use being requested.
If either review fails, the case goes back to the referring practice for a corrected authorization or it does not get published. We have killed published-case candidates over missing witness signatures and over photography that captured an identifiable tattoo we had not flagged at intake. That is not a process failure. That is the process working.
What this looks like from the dentist's side
For a referring practice, the practical version is short. When a case comes in that you think would be worth publishing as a study (a high-esthetic anterior result, a complex full-arch rehabilitation, a difficult shade match that went right), bring the consent question up at the same visit you brought up the case. Use a marketing-specific authorization form, not a general clinical release. List each use the patient is agreeing to. Witness it. Send the signed document to the lab with the case.
The lab should be doing the rest of the metadata capture on their side, but they cannot do it without a valid authorization on the referring end. The whole structure depends on that first signature being real, specific, and revocable.
Case studies are how labs and practices prove the work to the next dentist and the next patient. The consent metadata behind them is what makes that proof something you can stand behind seven years later when somebody asks the question.
GO DEEPER
The full procedure, start to finish
This post is one decision inside a larger workflow. Read the procedure pillar for the complete picture: indications, materials, turnaround, and how we build it.
KEEP READING
More from the bench
REQUEST A DOCTOR KIT
Want this on your own case?
Request a Doctor Kit and put a real case in our hands. We mail RX pads, a shade guide, and pre-paid shipping for your first three cases. No call, no contract.