Dental practice back office at night with a wall of monitors showing an incident dashboard and a stack of printed patient notification letters on the desk

The most quoted number about dental data breaches is nine years old, and the page serving it does not show you a date.

Ask what the cost of a data breach for a dental practice actually is and you will get a confident answer within seconds. One dental IT vendor puts the average ransomware incident at a single practice at roughly $85,000. Around $380 for every patient record. Multiply that second number by your patient count and you have a budget. It is a clean, satisfying calculation, and most of it falls apart the moment you go looking for the source.

That $380 per record figure, sitting at the top of the search results for this question, traces to a study published in 2017. The research behind it still gets published every year, and the current edition contains no such number anywhere. It also warns, in its own FAQ, against using its per-record figure to size breaches far outside the range it studied.

Every figure below is traced to the organization that produced it, with the size of business it describes stated plainly. That caveat is what separates a number you can use from a number that just sounds authoritative. The good news is that a much closer figure does exist, drawn from companies far nearer a practice’s size than IBM’s sample. Almost nobody quotes it.

Why the Numbers in Circulation Do Not Hold Up

The claim is that a healthcare record costs $380 when it is breached, against a $225 average across U.S. companies. It appears on the page currently ranking first for this question, on a competitor page dated March 2019, and elsewhere as $408, the healthcare figure from the 2018 edition, and as $200. Four different per-record figures, all presented as current, on one page of search results.

The first page names its source honestly: “a 2017 study sponsored by IBM Security and conducted by Ponemon Institute.” That is the problem rather than the defense. The study is nine years old, and no date is shown to a reader anywhere on the page. Nothing signals that the figure predates most of the software now running in their office.

IBM still publishes this research annually. We downloaded the 2026 Cost of a Data Breach Report and read it. Neither $225 nor $380 appears anywhere in it, and there is no healthcare-specific per-record figure at all. The only per-record numbers in the current edition are organized by data type rather than industry, including $192 for customer personal information, $188 for employee personal information, $196 for intellectual property.

Then there is the arithmetic itself. IBM’s FAQ is explicit about the limits of its per-record number: “It’s not consistent with this research to use the overall cost per record as a basis for calculating the cost of single or multiple breaches totaling millions of records,” because every breach in the study involved between 2,590 and 115,380 records. A per-record average is a byproduct of that sample, not a price list, and multiplying your patient count by it borrows a precision the source never claimed.

None of this is anyone behaving badly. But a figure arriving without a date and without a named source is not something you can budget from.

What the Credible Sources Say, and Who They Are Describing

Real figures exist. Most of them, though, describe organizations many times larger than a dental practice, and that caveat is usually gone by the time the number reaches a dental blog.

Here are the data breach cost figures by source, and the population each one actually measures.

Data breach cost figures by source, and the population each one measures
SourceHeadline figureWhat it measuresWho it actually describes
NetDiligence 2026, smallest revenue band$141,000 average incidentReported cyber insurance claims, 2021 to 20253,872 claims from companies under $50 million in revenue. The closest published band to a practice
Coalition 2026 Cyber Claims$269,000 average ransomware claimReported claims, full-year 2025A cyber insurer’s paid claims. Coalition notes firms above $100 million in revenue claim five times as often as smaller ones
Coalition 2026 Cyber Claims$116,000 average claim, all typesAll cyber claim typesSame book, all business sizes. Severity fell 19 percent year over year
Sophos Healthcare 2025$1.02 million mean recoveryRecovery only, excluding ransom292 healthcare respondents, all at organizations with 100 to 5,000 employees
Sophos Healthcare 2025$150,000 median ransom paidRansom actually paid, down from $1.47 millionSame. Only 36 percent paid at all
IBM 2026$6.64 million healthcare averageTotal breach cost, all categories602 organizations worldwide. Healthcare means “hospitals and clinics” and was about 2 percent of the sample. Breaches ran 2,590 to 115,380 records

That last column is the argument. IBM’s healthcare category is hospitals and clinics, and the smallest breach in the entire study involved 2,590 records. Sophos surveyed only organizations with at least 100 employees. A five-person practice is in neither population, so neither headline figure was ever measuring anything like it.

IBM is unusually direct about this. The report states that the study “drew upon a representative, nonstatistical sample of global entities” and that “statistical inferences, margins of error and confidence intervals can’t be applied to this data.” That is a research team telling you not to scale $6.64 million down to your office.

Which leaves the figure almost nobody quotes. The NetDiligence Cyber Claims Study, now in its sixteenth year, analyzes 10,309 claims and reports incident cost by revenue band. In the smallest band, 3,872 claims of $1,000 or more average $141,000 per incident across companies of any industry under $50 million in revenue, a band that still reaches far above a dental practice. It is not a dental figure, but it comes from real insurance claims in the smallest revenue band NetDiligence reports. It is the most honest single anchor available, and it sits roughly 47 times below the IBM number everyone cites.

The Coalition figures are worth keeping alongside it for a different reason. They come from an insurer’s own claims data rather than survey estimates, so they reflect reported losses rather than what a respondent recalls. Coalition’s $269,000 figure is its average ransomware claim across every business size it insures. Separately, it reports that its average loss across all claims for firms above $100 million in revenue, $268,000, is the highest of any revenue band. Read the ransomware figure as a cross-sector number rather than a small-business one.

The Cost Lines a Dental Practice Actually Pays

An aggregate is still the wrong tool for planning, because a breach does not arrive as one bill. It arrives as separate costs landing over several months, which is exactly why practices underestimate it. I made this point about the hidden IT costs that erode margins, and it applies here too. These costs survive because every one of them is too small to escalate.

Diagram showing five separate cost sources, lost production, notification, forensics, legal and staff time, converging into one invoice

NetDiligence breaks its crisis-services costs into components for that same under-$50-million band, which gives us the first defensible view of the individual lines at something near practice scale.

Average cyber-claim crisis-services costs, companies under $50 million in revenue (NetDiligence 2026).
Cost lineAverage (NetDiligence Table 4)What drives it
Notification$56,000Number of people you must write to
Forensics$36,000How many systems were touched, and whether you have logs
Legal guidance$18,000Breach counsel, regulatory response
Credit monitoring$4,000Take-up rate among notified patients
Total crisis services$88,000Not the sum of the lines above. The lines cannot share a denominator, since together they exceed the total

One thing to understand before using those numbers, because it is the kind of detail that quietly produces wrong budgets. The lines above do not add up to the total, and they are not supposed to. They cannot share a denominator, since together they exceed the total, and the likeliest reason is that each averages only the claims that incurred that cost. Not every breach needs forensics, and not every breach triggers notification. Adding the four named lines would give you $114,000 for a total that NetDiligence itself reports as $88,000, which is why the total is the better benchmark and the components are there to tell you where the money goes.

NetDiligence also reports a catch-all line for other costs, averaging $82,000 among the claims that carried it, which is one more reason the lines cannot be summed.

These are averages drawn from the 3,872 claims in that band, from a sample NetDiligence itself describes as a “convenience” sample rather than a statistical one. Treat them as the shape of the bill, not a quote. What they do establish is which lines are capable of getting large. Notification carries the highest average of the four, which surprises most practices who assume forensics dominates, though the differing denominators mean this is not a strict ranking of what any one breach will cost. Note also what is absent from the list entirely: the ransom.

1. Lost production: what a day of downtime costs

This is the cost you can size precisely, because the inputs are yours.

The American Dental Association’s Health Policy Institute publishes what you need. In its Survey of Dental Practice results for 2025, solo general practitioners reported gross billings of $529 per practice hour at the median and $621 at the average.

A full eight-hour day is therefore somewhere between about $4,200 and $5,000 in billings, which is production rather than profit. A week down is near $21,000. Two weeks is near $42,000. We checked the average against ADA’s separate billings and hours tables and the two paths agree within about one percent. Dividing median billings by hours gives a higher figure, about $575, so ADA’s reported $529 median is the conservative basis and $4,200 the conservative end.

Two honest caveats. Some of that production is deferred rather than destroyed, because a crown postponed ten days is usually still a crown. What does not come back is the hygiene column, the cancelled new patient exams, and the schedule you could not rebuild because it lived in the encrypted database. Run the math with your own collections and you will have a better number than any article can give you.

2. Notification: what it actually costs to notify patients

Once a breach involves unsecured patient data, notification runs on a regulatory deadline, subject to the rule’s risk assessment and its narrow exceptions.

Under 45 CFR Part 164, Subpart D, you must notify affected individuals “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach,” by first-class mail to each person’s last known address, or by email where the patient has agreed to electronic notice. Two further rules sit above that, and neither works the way most summaries suggest. Notifying HHS is not optional at any size: the rule says a covered entity must notify the Secretary following discovery of a breach, full stop. What the 500 figure changes is timing. At 500 or more affected individuals you notify HHS at the same time you notify patients. Below 500 you log it and report within 60 days of the year end. Media notice is a separate duty again, owed only where a breach involves “more than 500 residents” of a single state or jurisdiction, so under the federal rule a 600-person breach spread across three states may trigger no media notice at all, although state breach laws can add their own duties.

When HHS wrote the rule, it published its own cost model. In the 2013 HIPAA Omnibus Final Rule, the government estimated “$0.06 for paper and envelope and $0.45 for a first class stamp, totaling $0.51 per letter,” plus about “$32.75 per breach” in combined labor for composing and preparing the notice.

Fifty-one cents a letter. Against NetDiligence’s $56,000 average notification line from actual claims. Postage has nearly doubled since that model, to 82 cents, but that does not begin to explain the gap. HHS’s model did price more than envelopes, including a toll-free line for substitute notice and hours of investigation per breach, and still averaged about $763 per covered entity that had to respond to a breach. NetDiligence does not itemize its notification line, but the work around the letters is where that money goes: assembling and verifying the address list, mailing at volume, and a staffed call center rather than a phone number. Legal guidance and credit monitoring are separate lines on top of it. When a practice budgets for notification by imagining envelopes, this is the gap it falls into.

Our breakdown of dental data breach notification requirements covers what each notice has to contain and the clock it runs on.

3. Forensics: what an investigation costs and what drives it up

Someone has to determine what happened, what left the building, and whether the environment is clean. It is specialized work, usually assigned from your carrier’s approved panel, and it averages $36,000 at the smallest company band.

What drives that number up is how many systems the attacker touched and whether you have logging that answers the question quickly. What drives it up fastest is someone wiping a machine before the forensics team arrives. That destroys the evidence needed to answer the one question governing everything downstream, which is whether patient data was accessed or taken. Our data breach response plan for dental practices covers the call order that prevents it.

4. Ransom payments: how much, and how often practices pay

This is the line everyone anchors on, and the evidence says they should not.

Coalition reports that initial ransom demands rose 47 percent year over year in 2025, and that a record 86 percent of businesses refused to pay. Sophos found that 36 percent of healthcare providers paid, down from 61 percent in 2022, and that among organizations of 100 to 5,000 employees the median payment fell to $150,000 from $1.47 million, the lowest of any sector it surveyed.

Coalition reads rising demands alongside record refusals as a sign of better backups and response planning, though that is its interpretation across every sector it insures. The measurable signal is simpler: fewer organizations are paying. Whether you pay is a decision for your carrier and your counsel, made in advance rather than on the morning of the incident, and a practice with isolated, tested backups has an option that does not depend on a decryption key.

One number worth sitting with from the same Sophos research: backups were used to restore data in only 51 percent of healthcare incidents, down from 72 percent. Sophos suggests that may reflect falling confidence in backup resilience. Whatever the cause, nearly half of the organizations hit did not restore from backups.

5. Staff time: the cost nobody invoices you for

Nobody bills you for this and it is real money.

The front desk rebuilds a schedule by hand and calls every patient on it. The office manager becomes the incident coordinator on top of a full-time job. Insurance verification goes manual for weeks. Someone fields calls from patients who received a notification letter.

You can at least put a scale on it. ADA reports an average hourly wage of $25.10 for full-time dental assistants and $48.80 for full-time hygienists in 2025. If two people each absorb twenty extra hours a week for three weeks, that is 120 hours, or about $3,000 of base wages at the assistant rate before any overtime premium. Treat that as an illustration of the scale rather than a published average, because the hours are assumed and the real figure depends on who does the work and whether it lands as overtime or displaces something else. Across a group, the part that resists centralizing is schedule reconstruction, because the people who know each schedule are standing in each building.

6. Patient attrition: why no one can give you a number

Some patients leave after a breach notification. Anyone who hands you a percentage is guessing, and we are not going to add another guess to the pile.

What we would say is that dentistry runs on recall and referral more than most of healthcare, so the loss surfaces slowly, in a hygiene column that does not refill and referrals that quietly stop. It does not appear as a line item in the month of the incident, which is exactly why it is missing from every breach cost estimate including this one. NetDiligence excludes it too, along with in-house administrative time.

The Cost of a Data Breach for a Dental Practice: Two Worked Examples

Here is the arithmetic assembled from the figures established above. These illustrate a method rather than predict your outcome, and every line says where it came from.

A solo general practice, one week down

Illustrative cost lines for one practice, one week down. These do NOT add to a total: three of the five lines carry no dollar figure.
Cost lineFigure (not additive)Basis
Lost production, 5 daysAbout $21,000ADA median of $529 per practice hour, 8-hour days
Crisis services$88,000 averageNetDiligence, companies under $50M revenue
RansomMost do not pay86 percent refused, per Coalition 2026
Staff time and manual workflowWeeks of labor, unbilledExcluded from the claims data by NetDiligence’s own definition
Patient attritionUnquantifiedNo credible published figure exists

Read that as two quantified benchmarks and three unpriced lines rather than a total. Production is yours to calculate exactly. Crisis services is a real average from real claims, though drawn from companies that reach considerably larger than a practice. Ransom, staff time and patient attrition carry no published average at practice scale, which is precisely why a single confident total for “what a dental breach costs” should make you suspicious. No published source supports the $85,000 single-practice figure that one vendor quotes and that AI assistants repeat. We could not find the research behind it, and any single total has to fill those three blanks with estimates.

A five-location group, same event

For a group the arithmetic does not multiply cleanly, and the reasons matter more than the number.

Production loss does scale roughly with locations, so five practices down for five days sits near $106,000 on the same median figure. ADA’s sample is private solo practices rather than DSO-owned locations, so treat that as a floor for multi-provider sites. That part does multiply. The notification line does not, and it is the one that changes the shape of the bill.

Notification scales with affected individuals across the whole organization rather than per office, and that is where the two bills diverge. Both owe individual notice and both owe HHS a report. But a solo practice whose incident touches a few hundred records reports to HHS on the annual cycle and owes no media notice, while a group sharing one identity system can put thousands of records in scope from a single intrusion, which moves the HHS report to the same time as the patient letters and can pull in media notice in any state where more than 500 residents are affected. Same incident, same rules, and a materially heavier notification line, against an average of $56,000 in the claims data. The group is not paying five times the solo bill. It is paying a different bill.

Media notice then works differently again, counted per state rather than per organization, so a group operating across several states may cross the federal threshold without crossing the media one in any single jurisdiction. And the incident rarely starts at your strongest site: it is usually the practice acquired last quarter, still running the setup it came with. Our walkthrough of how a ransomware attack unfolds hour by hour covers why shared architecture turns one incident into an organization-wide event, and our guide to IT diligence in dental acquisitions covers finding it before you buy it.

What This Means for What You Spend

The reason the inflated numbers are worth correcting is not pedantry. A wrong number produces a wrong decision in both directions.

Quote a practice owner $85,000 and it lands as an article about somebody else. Quote them $6.64 million and it stops being a business decision at all, because nothing they could reasonably spend would move a figure that size. Both produce the same outcome, which is no decision.

The honest version is more useful. The most directly calculable cost is production, which you can work out from your own collections in about two minutes. The response costs land near $88,000 on average in NetDiligence’s smallest revenue band. And the controls that change the outcome are ordinary and knowable: backups that are isolated and actually restore-tested, multifactor authentication everywhere including the office you just bought, and a written answer to who gets called first. We publish what we see across the practices we monitor in our dental cybersecurity data report, which is the same discipline applied to our own numbers. Almost none of what determines your recovery is decided during the incident. It is decided months earlier, on a quiet day.

If you want the specific version of that list, our dental office cybersecurity checklist organizes each control by the artifact you would produce for an underwriter, a regulator, or a buyer. If you are sizing coverage, our breakdown of cyber liability insurance for dental practices covers what policies pay for and the conditions that void them.

Dental Data Breach Cost Questions

What is the average cost of a data breach in the healthcare industry?

IBM’s 2026 Cost of a Data Breach Report puts it at $6.64 million, down 10.5 percent from $7.42 million the year before, and healthcare has been the most expensive industry for 13 consecutive years. It was also the only industry whose costs fell this year. The caveat is the population: IBM defines healthcare as “hospitals and clinics,” the study covered 602 organizations worldwide, and the breaches examined ranged from 2,590 to 115,380 records. It is not a dental practice figure, and IBM states that statistical inferences cannot be applied to the data. For something nearer practice scale, NetDiligence reports an average incident cost of $141,000 for companies under $50 million in revenue.

Why do data breach cost estimates vary so much?

Three reasons, all checkable. First, the figures measure different things: a total incident cost, a recovery cost excluding ransom, and a paid insurance claim are three different numbers, and they get quoted interchangeably. Second, they describe different sized organizations, from hospital systems down to companies under $50 million in revenue, and the population is usually dropped when the number is repeated. Third, several widely circulated figures are simply old, including a per-record cost from a 2017 study that still appears on pages carrying no date. When comparing two sources, check which of those three is causing the gap before deciding either one is wrong.

Is ransomware covered by insurance?

Generally yes, under a cyber liability policy, which typically covers forensics, breach counsel, notification, credit monitoring, business interruption and in some cases the ransom itself. The conditions are where practices get caught. Many policies require you to use the carrier’s approved response vendors and to report within a tight window, so acting alone before the carrier is involved can jeopardize the claim. Coverage can also be challenged where the application misstated security controls such as multifactor authentication.

Should a dental practice pay the ransom?

That decision belongs to your carrier and your legal counsel, not to the morning of the incident, and in practice it is often not yours to make alone: many policies require the carrier’s approved vendors and can be jeopardized by acting first. Beyond the economics, paying does not resolve whether patient data was compromised, and it does not remove the notification obligations that follow if it was. It also does not resolve the question OCR will ask, which is whether you can produce a risk analysis. Practices that assume a payment closes the incident tend to discover the compliance work is still ahead of them, and the deadline started running at discovery rather than at recovery.

What actually drives the notification bill after a breach?

Not postage. The work that costs money is establishing who must be notified, which is why a practice that cannot say what the attacker accessed pays more than one that can. Building a verified address list from a patient database that has not been cleaned in years is billable work, and returned letters create follow-up work. Then the notice itself needs legal review, because its required contents are set by regulation, and the call volume it generates has to go somewhere other than your front desk. A practice with current logging, a clean patient roster, and a written response plan spends less on this line than one without, and that difference is decided long before the incident.

How much does a data breach cost a small dental practice?

There is no single credible figure, and any article giving you one has estimated the parts nobody publishes. What you can establish is this. Lost production you calculate yourself, at about $4,200 for a full day using the median solo general practice billing rate, or about $5,000 using the average. Crisis-services costs averaged $88,000 across cyber claims at companies under $50 million in revenue, the smallest band in that study, which still reaches well above a practice. Ransom, staff time and patient attrition carry no published average at practice scale. So a practice losing a week is looking at a five-figure production loss, plus a response bill that the nearest published benchmark puts in the tens of thousands, plus three lines nobody can size for you in advance.

Does a small dental practice face the same risk as a large group?

The mechanics are the same and the arithmetic is not. A solo practice has a blast radius of one building and a notification list of one patient base. A group sharing identity systems and network connections between locations can lose every site at once, and its notification count is calculated across the whole organization rather than per office. That is why the same incident is a hard week for a single practice and an organization-wide event with a valuation tail for a group.

Posted in Dental Cybersecurity

Filter By: