August 19th, 2026
Cyber Liability Insurance for Dental Practices: What Carriers Actually Ask
Industry Research — Dental Cybersecurity
Cyber insurance is one of those subjects every practice owner nods along to and almost nobody reads closely.
Two carriers will insure the same dental practice against the same ransomware attack. Travelers hands the applicant a separate signed form that breaks multi-factor authentication into four different systems, down to who can log into the backup console, and asks the signer to confirm the person who runs their IT helped answer it. TDIC, one of the best-known dental-endorsed carriers in the country, publishes an application of five yes/no questions that never mentions multi-factor authentication at all. Same risk, same industry, completely different bar.
That gap matters because cyber liability insurance for a dental practice is priced and issued off that application, a document that rarely gets a close read. Answering its questions accurately is what keeps the policy from being challenged later. Answering them quickly and from memory is how a practice ends up holding coverage a carrier can try to unwind after a breach.
We are an IT company, not an insurance agency. We do not sell policies and we do not get paid when you buy one. We end up involved because the security questions on these forms are questions about the environment, and that is the part a practice cannot answer without its IT provider. So we went and read the applications themselves rather than the articles about them. What follows is what carriers are asking, and where those questions get hard for a dental practice to answer honestly.
The Application and the Policy Do Different Jobs
Most coverage explainers stop at what a policy pays for. That part is easy to find anywhere: breach response, forensics, data restoration, business interruption, ransomware and extortion, third-party liability.
Two other questions get far less attention, and they are separate. What has to be true about your practice for a carrier to issue coverage in the first place, and what the policy itself grants, limits and excludes once issued. The application governs the first. The policy form governs the second. Getting the application right does not guarantee any particular claim gets paid, because exclusions, conditions, sublimits and retentions all live in the policy. What an accurate application does is keep the contract itself from being challenged.
Both are documents you sign, and both deserve reading. Start with what the application itself says it is for. On a Travelers CyberRisk application, the language above the signature line reads:
"The undersigned Authorized Representative represents that to the best of his or her knowledge and belief, and after reasonable inquiry, the statements provided in response to this Application are true and complete, and, except in NC, may be relied upon by Travelers as the basis for providing insurance."
Read the phrase "after reasonable inquiry" again. It is doing real work. It means the carrier is not asking what you believe about your network. It is asking what you have checked.
Then read what the policy can do with those answers afterward. The National Association of Insurance Commissioners, the standards body for state insurance regulators, put it plainly in the exclusions section of its 2023 report on the cybersecurity insurance market, which is the most recent edition to walk through common exclusions in this detail:
"Failure to maintain security measures is another common exclusion to cyber insurance policies. An insurance policy’s terms may require an insured to maintain appropriate procedures and controls to protect against cyberattacks. For example, insurers may require an insured to use two-factor authentication and patch its computer systems in an acceptable timeframe."
So the controls can matter twice, through two different mechanisms. Once as representations when you attest to them to obtain the policy, and separately as policy conditions where a carrier has written maintenance of those controls into the coverage form. Those are not the same instrument and not every carrier uses both.
The Questions Carriers Actually Ask
Below are real questions from real applications, quoted from the forms themselves.
1. Multi-factor authentication, broken into four separate systems
This is the question that catches dental practices, because "we have MFA" is almost never a single fact. Travelers uses a standalone multi-factor authentication form that an applicant signs separately from the application, currently published as the Multi-Factor Authentication Supplement, form CYB-14306 Rev. 03-23. It asks whether MFA is required for email and for remote network access, and then it asks this:
"In addition to remote access, multi-factor authentication is required for the following, including such access provided to 3rd party service providers: a. All internal and remote admin access to directory services (active directory, LDAP, etc.). b. All internal and remote admin access to network backup environments. c. All internal and remote admin access to network infrastructure (firewalls, routers, switches, etc.). d. All internal and remote admin access to the organization’s endpoints/servers."
Item b is the one worth stopping on. A practice can have MFA on Microsoft 365, on the VPN, and on the PMS, and still have a backup console that an administrator reaches with a username and a password. For a multi-location group the same gap usually appears at the seams, on the management tools and remote-access accounts that were set up per location and never brought under one standard. Travelers explains on the same form why it cares: requiring MFA on administrative access "can prevent an intruder from gaining the level of access necessary to successfully deploy ransomware across the network."
These forms also get revised. The edition filed as an exhibit in the 2022 case discussed below, CYB-14306 Ed. 05-21, was titled an Attestation and told applicants outright that the listed controls "are the minimum controls that must be in place in order to be eligible for a Cyber policy." The current Rev. 03-23 is titled a Supplement and does not carry that sentence. The four-part question above appears in both.
2. Whether you consulted the person who runs your security
The last item on that same Travelers form is not a technical question at all:
"The signer of this form has done so with the assistance of the person in charge of IT security."
A practice owner who signs that after filling the form out alone has made a representation about process, not just about technology. The Ed. 05-21 edition said it outright, instructing outsourced practices to complete the form with their managed security provider, and for a practice whose IT is outsourced the current question amounts to the same thing.
If you take one operational thing from this article, take this: do not answer a cyber application without your IT provider in the room. The form is explicitly asking you to confirm that you did not.
3. Backups, with conditions attached
Carriers have moved well past "do you back up your data." A Corvus Smart Cyber application asks applicants to select which of the following apply, and the list is a decent audit in its own right: backup servers segmented from the rest of the network, a copy of backups kept offline or air-gapped, cloud based backups, backup servers not joined to a Windows domain, immutable backups, unique credentials for backup servers and user accounts, MFA required for access to backups, and multiple copies stored in two or more geographical locations.
A CRC Group cyber application goes further and puts a clock on it, asking whether the backup solution is kept in a cloud service protected by MFA, has been tested in the last six months, and can be used to restore essential network functions within three days of a widespread malware or ransomware attack.
Notice that every one of those is verifiable. A backup that has never been restored cannot honestly be described as one that can restore your practice in three days.
For a group, this question has a second edge. One application covers every location, so the honest answer is set by your weakest site. A DSO with immutable, MFA-protected backups at eighteen practices and a legacy setup at the nineteenth is answering for the nineteenth.
4. HIPAA compliance, as a yes/no with a warranty attached
This is where dentistry differs from a general small business, and it deserves more thought than it usually gets.
The Travelers CyberRisk application asks, at question 4, whether the applicant is "a Healthcare Provider, Business Associate, or Covered Entity under HIPAA," and if yes, follows immediately with four words: "is the Applicant HIPAA compliant?" A CRC Group application asks whether you deal with protected health information as defined by HIPAA, and if so, whether you have procedures and audit practices in place to ensure compliance under the rules and regulations of HIPAA, including encryption of electronically transmitted records.
Practically every dental practice that bills electronically answers yes to the first half. The second half is then a single yes/no covering the entire Security Rule.
"Are you HIPAA compliant?" feels like a question with an obvious answer. It is not. HIPAA compliance is not a status you hold, it is a set of documented practices, and the anchor of it is a Security Risk Analysis. HHS requires the risk analysis be conducted and reviewed periodically, and deliberately does not prescribe a single frequency, since the right cadence depends on the size of the practice and how much has changed. Annual review is what we recommend and what most auditors expect to see, but the more useful question before you answer a carrier is simpler: can you produce the document at all, and does it reflect the systems you are running today? If nobody in the practice can find one, that is the answer to the insurance question too.
We wrote a separate 20-item IT audit for dental practices that covers what a defensible security posture looks like control by control. This article is about what happens when you tell an insurance carrier you have one.
5. Patching, with a specific window
CRC Group’s application asks whether you regularly monitor security vulnerabilities and appropriately patch and upgrade systems and applications, and then narrows it: do you apply security patches within 30 days of release?
That is a question about whether someone is actually managing your environment on a schedule. It is very hard to answer honestly in a practice where patching happens when a workstation gets slow.
6. Endpoint detection, by product name
Applications increasingly ask you to name the tool. Corvus asks applicants to list the product and vendor for their endpoint protection. CRC asks whether you use an endpoint detection and response tool with centralized monitoring and logging of all endpoint activity across the enterprise, and if yes, to provide the name of the EDR provider.
Antivirus and EDR are not the same product category, and a carrier asking for a vendor name is asking a question a practice cannot answer vaguely.
7. Incident response, security training, and prior incidents
Beazley’s small-business cyber application asks how often you conduct interactive social engineering training, offering never or not regularly, annually, or twice or more per year. It asks whether you have an incident response plan for network intrusions and malware incidents. It asks whether you regularly back up business critical data, with at least monthly, or at least weekly or daily, as the options.
Prior-incident questions appear on nearly every form. They matter because a practice that had an incident, handled it quietly, and then answers "no" has created exactly the kind of discrepancy that surfaces during a claim investigation. If you are unsure whether something in your history counts, the pattern across the largest breaches in dentistry is that the reportable event is often discovered well after the intrusion itself.
The Same Control, Five Different Questions
Laid side by side, the forms disagree about almost everything except that they want a signature. This is the comparison we could not find anywhere else.
| Control area | Travelers CyberRisk (CYB-14102 Ed. 01-19) plus MFA Supplement CYB-14306 Rev. 03-23 | Corvus Smart Cyber (Version 3.2, September 2024) | CRC Group cyber application | Beazley small business (F00863, 042023 ed.) | TDIC Cyber Suite (CYB9016-0320AS) |
|---|---|---|---|---|---|
| Multi-factor authentication | Separate signed supplement. Email and remote access, then four admin surfaces: directory services, backup environments, network infrastructure, endpoints and servers | Four parts: remote access, internal privileged accounts, webmail and mailbox apps, all critical applications | Four parts: remote access including RDP, web-based email, privileged and administrator accounts, internal and external access to cloud backups | Two questions: remote access to the network including VPN, and web-based email | Not asked |
| Backups | One line item within a controls list | Eight options to select, including offline or air-gapped copies, immutable backups, unique credentials, MFA on backups, and copies in two or more locations | Frequency, plus a combined test: cloud service protected by MFA, tested in the last six months, restores essential functions within three days. Also asks about 3-2-1 procedures | Frequency (at least monthly, or at least weekly or daily), plus whether a cloud backup is a syncing service | Not asked |
| Endpoint detection and response | Anti-virus asked. EDR not asked by name | Product and vendor name requested | Asks for EDR with centralized monitoring and logging across the enterprise, and the provider name | Vendor name requested separately for EPP, EDR and MDR | Not asked |
| Patching window | Process, whether it is automated, and whether critical patches are installed within 30 days | Not asked | Monitoring and patching, then a 30-day window for security patches | Whether you or an outsourced provider actively manage and install critical patches on internet-facing systems. No window given | Not asked |
| HIPAA | Asks whether you are a healthcare provider, business associate or covered entity, then asks in four words whether you are HIPAA compliant | Not asked | Asks whether you handle PHI, then whether you have procedures and audit practices to ensure compliance, including encryption of transmitted records | Not asked | Not asked |
| Incident response plan | Asks for both a disaster recovery or continuity plan and an incident response plan, whether they are tested, and expected restore time | Asks for a business continuity or disaster recovery plan and whether it was tested in the last 12 months | Asks for a tested business continuity or disaster recovery program, though not an incident response plan by name | Asks whether you have an incident response plan for network intrusions and malware incidents | Not asked |
| Prior incidents | Asked | Three questions: any incident in the past three years, knowledge of any circumstance likely to give rise to a claim, and any unscheduled outage over six hours in three years | Asked | Asked | Asked, limited to a breach of personal information in the last 12 months |
| Security awareness training | Asked | Asks whether all employees get security or phishing training at least annually | Asked | Asks how often, with never or not regularly, annually, or twice or more per year | Not asked |
| Duty to report changes after signing | Explicit on the MFA Supplement, which has the applicant agree to notify Travelers of any material changes to the information provided | Not stated on the form we read | Limited to the window between submission and the requested effective date | Limited to changes between the application date and the effective date, with a duty to immediately notify the insurer | Explicit and ongoing: notify of any change "before and after a policy is issued" |
Read down the TDIC column and then across any other row. That is the whole argument of this article in one view. Read across the multi-factor authentication row instead and you get the more useful version: four carriers all ask about MFA and no two of them ask about the same set of systems, so "we answered the MFA question last year" does not tell you what you will be asked this year.
One caution on the empty cells. "Not asked" means the control does not appear on the published application we read. It does not mean the carrier does not care about it, does not ask in a broker conversation, and it certainly does not mean the control is optional for your practice.
What the Dental-Endorsed Carrier Asks Instead
The four columns to the left of TDIC in that table are all general-market carriers. Dental-endorsed programs underwrite differently, and the TDIC column is worth reading on its own rather than only as the empty end of a comparison.
The Dentists Insurance Company, TDIC, is one of the best-known dental-endorsed carriers in the country, and to its credit it publishes its Cyber Suite Liability application openly, which is what makes this comparison possible at all. Most carriers do not.
The published form, CYB9016-0320AS, carries five yes/no questions, and how many you answer depends on the limit you want. They ask whether you have suffered a breach of personal information in the last 12 months, whether you conduct background screens for prospective employees, whether you have a posted document retention and destruction policy, whether you maintain regularly updated computer security measures such as a firewall, secured wireless connectivity and virus protection, and whether physical records are maintained in a secure environment with limited access.
The tiering is the part worth noticing. The form offers $50,000 with a $1,000 deductible, $100,000 with a $1,000 deductible, and $250,000 with a $2,500 deductible, and it directs an applicant requesting the $50,000 limit straight to the authorization block without answering any of the five. Questions 1 through 3 apply at $100,000, and all five at $250,000. Underwriting depth scales with the limit requested rather than with the risk being insured.
Multi-factor authentication is not among the questions on this form. Neither is anything about backups, which all four general-market forms in the table above ask about, nor patching, which three of them ask about, nor endpoint detection, which three ask about by name. Two honest caveats: this is the application TDIC publishes, and we cannot tell you what a broker asks in conversation or what a renewal or supplemental form might add. It is also a March 2020 edition, while the Travelers form above is a 2023 revision. Underwriting with fewer questions is a legitimate business decision, and for a single-location practice that wants coverage without a technical review, it is often exactly the appeal.
Now read what sits at the top of that same form. This kind of language is conventional across the market rather than unique to TDIC, which is precisely why it is worth quoting once:
"You warrant and represent that the following statements are yours and that you know the statements to be true. You know and intend that we will rely on the truth of the information you have provided in deciding to issue a policy to you, and that providing any materially false information in this application is grounds for us to deny you insurance or rescind any policy we issue if the false information was material to our underwriting decision."
And further down: "IF A POLICY IS ISSUED, THIS APPLICATION WILL BECOME PART OF THE POLICY."
That is the part worth understanding. A short application is not a lenient one. It is a smaller set of statements you are still warranting, and each one covers more ground. Question 4, the one asking whether you maintain "regularly updated computer security measures," is a single checkbox covering a subject that other carriers break into a dozen or more questions. An office running an unsupported operating system has to think carefully about what answering it "yes" commits to.
The narrow point is this: how many questions a carrier asks tells you about that carrier’s underwriting, not about your practice. A light application does not mean light obligations, and it certainly does not mean you are secure. It means the detailed verification did not happen at the application stage, so it has to happen somewhere else. Your ransomware exposure does not change with the length of the form, and neither does your obligation under the Breach Notification Rule.
Rescission, and What One Real Dispute Looked Like
There is a real case here, and it is worth getting exactly right, because a lot of what is written about it overstates what happened.
In July 2022, Travelers filed suit in the U.S. District Court for the Central District of Illinois against International Control Services, a manufacturer, seeking to rescind a CyberRisk Tech policy after a ransomware event. Travelers alleged that ICS had made incorrect statements in applying for the policy about its use of multi-factor authentication.
What happened next is the part that gets misreported. There was no trial and no ruling on whether the misrepresentation legally voided coverage. Travelers filed an agreed motion, and on August 30, 2022, the court entered an order recording that both parties "stipulate and agree to the entry of an order rescinding the insurance policy in question and declaring it void from its inception." The court’s own order describes the misrepresentation as something "Travelers asserts," not something the court found. The policy was rescinded and the case was dismissed with prejudice, with each party bearing its own costs. In its complaint, Travelers had stated it was tendering back to ICS all amounts paid as premium, which is the ordinary mechanic of rescission: the carrier returns the money and the coverage is treated as though it never existed.
So nobody should write that a court has ruled that a bad MFA answer voids your policy. That has not been decided. What the record does show is something more useful to a practice owner: faced with a rescission claim over an application answer, the policyholder consented to giving up the entire policy roughly two months after the suit was filed, following a ransomware attack. What it does show is how quickly an application answer can put an entire policy in play.
It also illustrates a distinction worth keeping straight:
Claim denial means the carrier refuses to pay for one particular loss, usually because of an exclusion or a condition. You still have a policy.
Rescission means the policy is treated as though it never existed. Not this claim, every claim, past and future. In the ICS matter the parties stipulated that no coverage would be available "for past, present, and future claims, suits, loss, costs, or expenses of any kind whatsoever."
An application answer is one of the things that can open the second door. Whether it does in any given case depends on the policy language, the materiality of the answer and the law of your state, which is exactly why the accuracy of the form is worth more attention than it usually gets.
Worth knowing: state law limits how far this can go, and the limits differ by state. TDIC’s own application carries state-specific amendments, and in Arizona and Nevada the form states that application statements "shall be deemed to be representations and not warranties." Read your state’s amendment on the form itself and ask your broker how it is applied. Nothing here is legal advice.
The Market Context Behind the Tighter Questions
None of this is carriers being difficult for its own sake. The economics moved.
The NAIC’s most recent report on the cybersecurity insurance market, covering 2024 data, found the U.S. cyber insurance market recorded its first ever reduction in direct written premium, with approximately $9.14 billion written in 2024, a 7% decrease from $9.84 billion in 2023. Over the same period, the number of claims rose almost 40%, with nearly 50,000 reported.
Premium down, claims up. That is the backdrop against which applications have moved from asking whether you have a firewall to asking who can reach your backup console. The same NAIC report notes that companies investing in cybersecurity controls is "looked upon favorably by underwriters."
For a dental practice, the specific exposure behind those numbers is worth stating plainly. HHS Office for Civil Rights publishes on its breach portal that it "investigates all breaches of protected health information (PHI) and Part 2 records that affect 500 or more individuals." The threshold counts individuals affected by the breach, not records on file, so a small incident stays a small incident. But the events that put dental practices in the news are the ones that reach the whole database: ransomware on a practice management server, or a compromise at a shared vendor. Once an incident reaches an established practice’s patient list, clearing 500 is not a high bar, and a multi-location group clears it many times over.
Under the HIPAA Breach Notification Rule, notification to affected individuals must go out "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach," and for breaches involving 500 or more individuals, HHS must be notified contemporaneously with those individuals. Smaller breaches are logged and reported annually instead.
So the incidents that hurt most bring a regulatory investigation and a 60-day clock at the same moment you are trying to get operatories running again. The coverage question and the compliance question are not separate projects.
What to Verify Before You Sign the Application
Run these before the form goes back to your broker, not after.
Get the actual questions in advance and answer them with your IT provider
Ask your broker to send the application and any multi-factor authentication form before the renewal meeting. Then go through it with whoever runs your security. This is not optional diligence, it is what the Travelers form asks you to certify you did.
Enumerate every system MFA is supposed to cover
Not "do we have MFA" but: email, remote network access, directory services, the backup environment, firewalls and network gear, servers and endpoints, and any third-party administrative access. Your IT provider should be able to answer that list system by system. If the answer to any of them is "I think so," that is the finding.
Multi-location groups should run that list per location until they can prove it is identical everywhere. That is the practical case for standardization: it is what makes one accurate answer possible instead of nineteen separate ones.
Produce the Security Risk Analysis before you answer the HIPAA question
Find the document, check its date, and check whether it describes the systems you actually run now. If nobody can produce one, or the one you have predates your current PMS or your last two locations, you have learned something more important than an insurance answer. Medix runs a formal Security Risk Analysis for practices and groups that have never had one.
Restore from a backup before you attest that you can
Not a successful backup log. An actual restore, with someone opening a patient record out of it. Carrier questions increasingly specify a test window and a recovery time, and both are claims you should be able to demonstrate rather than estimate.
Ask whether the limit is per claim or aggregate, and what carries a sublimit
A $250,000 aggregate and a $250,000 per-claim limit are very different products. Ask specifically about notification costs, ransom payment mechanics, and funds transfer fraud, which is commonly excluded or sublimited and is a real exposure for any practice that pays vendors by bank transfer.
Tell your carrier when the environment changes
Reporting duties differ by form, and the difference is worth knowing before you assume one exists. TDIC and Travelers both carry continuing duties: TDIC asks to be notified of any change in the information "before and after a policy is issued," and the Travelers MFA Supplement has the applicant agree to notify Travelers of any material changes to the information provided. The CRC Group form is narrower, limiting the duty to "the time between submission of this application and the requested date for coverage to be effective." So on some of these forms the obligation ends when the policy incepts and on others it runs for the life of the policy. Read yours rather than assuming there is a continuing duty, or assuming there is not. Migrating your PMS, adding locations, changing IT providers, or opening remote access for a billing contractor can all change what you attested. Whether a given change is material enough to report is a question for your broker, but a DSO acquiring practices should assume the question comes up several times a year, which is one more reason IT due diligence before closing pays for itself.
One Thing an Insurance Broker Told Us in 2019
The first version of this article was built around a conversation with Josh Ehlen, then Vice President at Reynolds and Reynolds Inc., a Des Moines insurance agency that became part of USI Insurance Services in 2021. One thing he said has aged better than anything else in that piece:
"Cyber Liability coverage forms vary greatly depending on the carrier, which is why it is critically important to hire an insurance professional that only works with Cyber Liability carriers that offer the broadest coverage forms."
Everything above is evidence for that. Five yes/no questions at one carrier and a signed four-part attestation at another, with limits, sublimits and exclusions varying just as widely underneath. A broker who works in this line every day is worth more than a good rate, because the rate is the part that is easy to compare.
Where This Leaves a Practice Owner
Cyber liability insurance is not a substitute for a security program. It is priced on one, and increasingly it is conditioned on one.
The uncomfortable version: if your practice cannot pass the application honestly, buying the policy does not fix the problem, it converts a technology problem into a coverage problem. You now have a document with your signature on it describing an environment you do not have, and that discrepancy surfaces at the exact moment you can least afford it.
The constructive version is that these applications are a free control checklist written by people with money on the line. Travelers, Corvus, CRC and Beazley have each published what they think matters. A questionnaire is not an audit, and answering it well is not proof that any control is correctly implemented, but a practice that can answer every question accurately and produce evidence behind each answer has done most of the work that makes ransomware hard to pull off. The policy handles what is left.
Our founder Tom Terronez says something about acquisitions that applies cleanly here: IT diligence is not a checkbox, it is risk pricing. An underwriter is doing what a buyer does, pricing your risk from what can be verified. The difference is that the underwriter is asking you to price it yourself, in writing, before anything has gone wrong.
If you are filling out one of these and you get to the MFA section and are not certain of the answer, that uncertainty is the actual finding. We are happy to walk through the form with you the way these forms contemplate, whether or not you ever become a client.
Dental Cyber Insurance Application Questions
Who should actually fill out a dental practice’s cyber insurance application?
The owner or an officer has to sign it, since carriers generally require an executive signature. But the security questions should be answered by whoever administers the systems, and at least one carrier makes that explicit: question 4 of the Travelers Multi-Factor Authentication Supplement (CYB-14306 Rev. 03-23) asks the signer to confirm the form was completed "with the assistance of the person in charge of IT security." The signature and the answers do not have to come from the same person, and on the technical questions they usually should not.
What is the difference between a cyber claim being denied and a policy being rescinded?
Denial refuses one specific loss, usually under an exclusion or an unmet condition, and you still have a policy for everything else. Rescission unwinds the contract entirely and treats it as though it never existed, which removes coverage for past, present and future claims at once. The premium is typically returned. Denial usually turns on what happened during the incident, while rescission usually turns on what you said on the application.
Can a dental practice answer yes to the HIPAA compliance question on a cyber application?
Only if it can produce the documentation behind it. HIPAA compliance is not a certification anyone issues you, it is a set of documented practices anchored by a Security Risk Analysis that HHS expects to be conducted and reviewed periodically. On the Travelers CyberRisk application the whole subject is compressed into one follow-up question, "is the Applicant HIPAA compliant?", which makes it easy to answer quickly and hard to answer carefully. The test to apply before checking that box is whether you could hand an investigator a current risk analysis, your workforce training records, and your signed Business Associate Agreements. If any of those cannot be produced, the honest answer needs a conversation with your broker rather than a checkmark.
Is a small dental practice too small for the 500-individual threshold to matter?
No, though the threshold works differently than most people assume. It counts individuals affected by a breach, not records on file, so a laptop exposing twelve patients is a twelve-person breach at a practice of any size. What matters is that the incidents which actually hit dental practices are rarely small ones. Ransomware on a practice management server or a compromise at a shared vendor reaches the whole patient database at once, and at that point an established practice is well past 500. Practice size changes the size of the loss, not whether the regulatory machinery starts.
What should a DSO check before signing one cyber application for every location?
A group applying as a single insured is making one representation about every practice it owns, so the accurate answer is set by the least-standardized location rather than the average one. Before signing, confirm that MFA coverage, backup configuration, endpoint tooling and patching cadence are genuinely identical across sites, and confirm who is answering for practices acquired since the last renewal.
Does buying cyber insurance reduce a practice’s ransomware risk?
No, and the distinction matters more than it sounds. A policy transfers financial consequences after an incident, it does not prevent one. The controls the application asks about are what reduce the likelihood, which is why a practice that can answer every question accurately is in a genuinely better position than one that simply holds a policy.
Posted in Dental Cybersecurity