Newsroom

Cyber Liability

Ransomware and Patient Records: Why Small Dental Offices Are Targets

Dentistry Insured by Emery & Webb, Inc. · 7/28/2026

A dental practice holds exactly what a criminal wants: names, dates of birth, Social Security numbers, insurance identifiers, treatment history, and payment cards, all in a practice management system that must be running for the office to see patients. Small offices are not overlooked. They are selected, because a practice with no dedicated IT staff is likely to pay quickly to reopen tomorrow's schedule. How the loss actually unfolds The encryption is the visible part. The expensive part is everything after it. A practice that cannot open charts cancels a day or a week of production. Then, because protected health information was involved, HIPAA breach notification obligations begin: forensic investigation to determine what was accessed, written notice to every affected patient, credit monitoring, notification to the Department of Health and Human Services, and — above 500 affected individuals — notice to prominent media in the state. Regulatory inquiry can follow. So can a patient class action. The ransom itself is frequently the smallest line item on the claim. What a real dental cyber policy has to include Many practices believe they have cyber coverage because a business owners policy carries a small endorsement, often $25,000 or $50,000 of data coverage. That is a rounding error against a breach involving a few thousand patient records. A serviceable policy needs: - Breach response and forensics, with an assigned breach coach who is on the phone the same day - Notification and credit monitoring costs for the full patient population, not a sublimit that covers a fraction of it - Business interruption and extra expense, including dependent business interruption if your practice management software is cloud-hosted and the outage is at the vendor - Data restoration, including rebuilding records and digital imaging - Cyber extortion, with the carrier's negotiation resources - Regulatory defense and fines where insurable - Social engineering and funds transfer fraud, which is how the wire for the new CBCT machine goes to the wrong account Read the sublimits. A $1,000,000 policy with a $50,000 social engineering sublimit and a $100,000 ransomware sublimit is not a $1,000,000 policy for the losses you are most likely to have. What carriers now expect before they quote Underwriting has tightened. Expect the application to ask whether you have multifactor authentication on email and remote access, offline or immutable backups that are tested, endpoint detection, and staff phishing training. Answering yes materially improves pricing, and answering yes inaccurately can jeopardize the claim. Multifactor authentication on email is now close to a condition of coverage and is the single highest-value control a small practice can implement this week. Five things worth doing regardless of coverage 1. Turn on multifactor authentication for email and any remote desktop access. 2. Keep one backup offline or immutable, and actually restore from it once to prove it works. 3. Verify wire and vendor bank-change requests by phone using a number you already had, never one in the email. 4. Remove administrator rights from day-to-day staff logins. 5. Confirm in writing what your practice management vendor is and is not responsible for after an incident. Cyber is one of the coverages we most often find underpowered when we review a dental practice's existing program. Send us your current declarations page and we will map the sublimits against the exposure your patient record count actually creates.