Worksheet · 5 pages
Cyber Insurance Readiness Worksheet for Dental Practices
The exact questions dental-focused cyber insurance applications ask. Work through them before you apply or renew, not during underwriting.
Cyber insurance applications for healthcare and dental practices have gotten noticeably stricter over the last few renewal cycles. What used to be a short self-attested questionnaire is now a detailed technical review, and carriers increasingly verify the answers rather than taking them on faith.
A single no on a question like multi-factor authentication or tested backups can mean an outright denial, a large premium increase, or a policy that excludes the exact scenario most likely to happen to a small practice. Practices are frequently surprised that the gap was not exotic. It was ordinary, and it was on the application the whole time.
This worksheet mirrors the questions carriers actually ask on dental and medical cyber applications. Work through it before you sit down with your broker or open the application portal, and you will walk in with answers instead of guesses.
Multi-factor authentication & access control
The single most common reason a dental cyber application gets flagged. Carriers now ask about MFA by system, not just "do you have it."
Privileged/admin account count:
Systems still missing MFA (if any): list every one, do not summarize
- Is multi-factor authentication enforced on every email account, including the owner and any front-desk shared logins? Owner accounts are the ones most often granted a quiet exception, and they are also the accounts with the most access. Carriers ask about this one specifically.
- Is MFA enforced on your practice management software and any remote access into it (VPN, remote desktop, portal login)? PMS access is the crown jewel for an attacker. A yes here on the email question and a no here is a common and costly gap.
- Is MFA enforced on financial and banking logins, including online banking, payroll, and merchant services? Business email compromise and wire fraud losses are now a bigger claims category than ransomware for small practices. Financial logins get their own question on most applications.
- Do you know how many privileged or administrator-level accounts exist across your systems? Fewer is safer. Applications often ask for a number, and "we are not sure" reads as a control failure even if the true number is small.
- Does every staff member use a business password manager rather than reused or written-down passwords? Not always a required field, but it is a follow-up question on many applications once MFA gaps are found, and it is cheap to fix.
Backup & recovery
Carriers want to know you can recover without paying a ransom. That means a real vendor, a real schedule, and a real, recent test restore.
Backup vendor:
Backup frequency: e.g. continuous, hourly, nightly
Last test restore date:
Offsite copy? (Y/N):
- Are backups automated for every system holding patient data, including cloud platforms like Microsoft 365? Cloud providers are explicit that their own retention is not a backup. Applications increasingly ask this as a separate line item from on-premise backup.
- Is at least one backup copy stored offsite, and is it immutable or kept offline from the production network? Ransomware actively hunts for and encrypts connected backup drives first. A copy that cannot be reached or altered from the network is what carriers are asking about.
- Has a real restore been tested within the last 90 days, with someone confirming the data actually opened? The single most common yes-that-was-actually-a-no on this section. A backup that runs nightly but has never been restored is unverified, and some applications now ask for the date directly.
Endpoint & network protection
The section most likely to reveal an aging piece of equipment or an unsegmented network that nobody has thought about in years.
End-of-life devices/systems still in use (if any): list make/model/OS
- Does every device that touches patient data run managed endpoint detection and response (EDR) or business-grade antivirus? Consumer antivirus with no monitoring is treated differently on modern applications than managed EDR with an alert response. The distinction matters more each renewal.
- Is there a firewall in place with logging enabled, and does anyone review those logs? A firewall that exists but logs nothing, or logs that nobody looks at, often does not satisfy the question as written.
- Is guest wifi fully segmented from the network your practice management software runs on? A patient or vendor on guest wifi should have no network path to clinical or financial systems. This is now a standalone question on most dental applications.
- Is there a documented patch management process, with someone confirming updates actually apply? "Automatic updates are on" and "every machine is current" are different claims. Applications increasingly ask which one you are making.
- Are any devices or servers still running an end-of-life operating system or unsupported hardware? An unsupported OS on the same network as your PMS is one of the fastest ways to get a coverage exclusion or a flat decline. Answer this one honestly.
Email security
Email is still the most common entry point for both ransomware and payment fraud claims, so this section carries real weight on pricing.
Phishing training frequency: e.g. monthly, quarterly, annual
- Is there email filtering or anti-phishing tooling in place beyond the default spam filter? Applications distinguish between the filtering built into your email platform and a dedicated anti-phishing layer. Have the actual product name ready.
- Are DMARC, SPF, and DKIM configured for your domain? These stop your own domain from being spoofed to send fraudulent email as you. Increasingly a named checkbox rather than a general email-security question.
- Do staff receive phishing simulation or security awareness training on a defined schedule? "We talked about it once" is not a schedule. Carriers want a cadence: monthly, quarterly, or annual, with records.
- Is there a verbal callback procedure required before changing any wire, ACH, or vendor payment details received by email? This single control is the one most directly tied to business email compromise claims, which now cost practices more on average than ransomware does.
Incident response & training
How you would respond, and what has already happened, are both part of the underwriting decision, not just the technology in place today.
Designated incident contact (name & phone):
Prior claims or security incidents in the past 3 years: describe or write "none"
MFA everywhere and tested backups are no longer optional add-ons A few renewal cycles ago, these were nice-to-haves that might shave a point off your premium. At most carriers writing dental and medical cyber policies today, they are baseline requirements to bind or renew coverage at all. Treat a gap in either one as something to close before you apply, not something to explain on the application.
- Does a written incident response plan exist, naming who to call first and what to do? At the moment screens are encrypted, nobody improvises well. Carriers want to see this exists on paper, not just that everyone would know what to do.
- Is there a designated incident contact for the practice, reachable outside business hours? A name and a phone number, not "our IT company will figure it out." Some applications ask for this contact by name.
- Do all staff receive annual security awareness training, with dated records kept? Distinct from phishing simulations above. This is general security training and many applications ask about it as a separate line.
Want the printable version?
Get the full worksheet as a free PDF
Everything on this page, formatted to print or save, delivered straight to your inbox. No sales call required.
Download the free PDF