2026 · Dental Practices · 47-control checklist

Cyber Insurance Requirements for Dental Practices

A dental practice is a small business that is also a HIPAA-covered entity, and that combination is exactly what makes it a favored ransomware target. Practice-management platforms (Dentrix, Eaglesoft, Open Dental) and on-premise imaging servers hold PHI, payment data, and scheduling for the whole patient base — often on a single server in a back office maintained by a part-time IT vendor. Attackers know these offices rarely have a security team, and that a clinic locked out of its imaging and scheduling will feel intense pressure to pay.

47 controls mapped to what underwriters verify · one-time purchase · instant download

Why cyber insurance is different for dental practices

The risks underwriters price for your vertical

A dental practice is a small business that is also a HIPAA-covered entity, and that combination is exactly what makes it a favored ransomware target. Practice-management platforms (Dentrix, Eaglesoft, Open Dental) and on-premise imaging servers hold PHI, payment data, and scheduling for the whole patient base — often on a single server in a back office maintained by a part-time IT vendor. Attackers know these offices rarely have a security team, and that a clinic locked out of its imaging and scheduling will feel intense pressure to pay.

The regulatory driver is the same HIPAA Security Rule that governs hospitals: a dental office must perform a risk analysis, implement access controls and audit logging, and address encryption of electronic PHI. The HHS Office for Civil Rights does enforce against small practices, and dental service organizations have appeared in breach reporting. Underwriters know the compliance bar is identical even though the IT maturity usually is not — so they probe hard on the few controls that actually stop a dental-office ransomware event.

Two patterns dominate dental claims: ransomware that encrypts the practice-management and imaging servers, and breaches that originate through the practice’s IT vendor or a shared DSO network. That is why carriers weight tested air-gapped backups (can you restore the imaging server without paying?), MFA on remote access (how does your IT vendor connect?), and controlled, logged vendor access far more heavily than generic policies. A practice that can show a recent successful backup restore and MFA-gated vendor access is a fundamentally different risk than the typical default-configured office.

What’s driving the requirements

The regulatory and contractual pressures underwriters expect dental practices to have already accounted for.

  • HIPAA Security Rule safeguards for electronic PHI in practice-management and imaging systems
  • HIPAA Breach Notification Rule reporting obligations for patient records
  • Business Associate Agreement obligations for IT vendors and dental service organizations (DSOs)
  • Payment Card Industry (PCI) obligations where the office processes card payments

Priority controls

The 7 controls insurers weight most for dental practices

Drawn verbatim from the 47-control Cyber Insurance Prep Checklist — with why each one matters specifically for your vertical.

  • CI-31CRITICALBackups

    Keep at least one air-gapped or append-only backup.

    Dental claims are dominated by ransomware on the imaging/practice-management server; one air-gapped backup is what lets an office restore instead of paying.

  • CI-07CRITICALBackups

    Test backup restoration at least once in the last 12 months.

    Many offices have backups that have never been restored; carriers specifically ask whether a restore of the practice-management database was tested.

  • CI-32CRITICALVendor Access

    Limit third-party vendor remote access to approved windows, with MFA.

    The most common breach path is the IT vendor’s remote connection — controlled, MFA-gated, time-boxed vendor access is the single biggest lever for a dental office.

  • CI-02CRITICALMFA

    Require MFA for all remote access — VPN, RDP, and SSH.

    Remote support tools left open without MFA are how attackers reach a back-office server; carriers treat unprotected remote access as a top dental gap.

  • CI-36CRITICALData

    Encrypt sensitive customer data at rest (PII, PHI, payment card).

    Patient records and imaging are PHI that must be encrypted at rest to satisfy HIPAA and avoid an underwriting decline.

  • CI-09HIGHEndpoint

    Deploy Endpoint Detection & Response (EDR) on all endpoints.

    EDR on the front-desk and clinical PCs catches ransomware before it reaches the server — practices without it look like the uninsurable default.

  • CI-19HIGHNetwork

    Do not expose Remote Desktop Protocol (RDP) directly to the internet.

    Exposed RDP to the practice server is a classic dental ransomware entry point and a frequent disqualifier on applications.

These are 7 of the 47 controls. The full checklist covers all of them — required, premium-affecting, and disqualifying — with verification and remediation steps.

Get dental practices insurance-ready

Most popular

Cyber Insurance Prep Checklist

$47one-time
  • All 47 controls underwriters verify
  • Verify & fix steps for each control
  • Required vs. premium-affecting vs. disqualifying
Get the checklist ›

Best value

Complete Compliance Bundle

$497one-time
  • Every checklist & hardening pack
  • Cyber insurance, M365, AWS, Azure, SOC 2, PCI
  • The full library at one price
Get the bundle ›

Free

Cyber Insurance Readiness Score

$02 minutes
  • 14 plain-English questions
  • Instant 0–100 score & gap list
  • No login, no email gate
Take the free assessment ›

By purchasing you agree to our Terms. Digital products are non-refundable once accessed. A checklist supports your application; it does not guarantee an underwriting decision.

Dental Practices cyber insurance — FAQ

Why are dental practices targeted by ransomware so often?

Dental offices hold valuable PHI and payment data, depend completely on practice-management and imaging servers to operate, and rarely have dedicated security staff. That mix — high-value data, total operational dependence, low defenses — is precisely the profile attackers and, in turn, underwriters focus on.

Our IT company handles everything. Isn’t that enough for insurance?

Carriers actually scrutinize vendor access more, not less, because the IT vendor’s remote connection is the most common breach path into a small office. Underwriters want to see that vendor access is MFA-protected, time-limited, and logged — and that you, not just the vendor, can confirm a backup was successfully restored.

Do small dental offices really get fined under HIPAA?

HHS OCR enforces against practices of all sizes, and breaches of patient records must be reported regardless of office size. The Security Rule safeguards — risk analysis, encryption, access controls — apply to a two-chair practice the same as a hospital, which is why the underwriting questions look similar.