Most general liability and property policies for dental practices do not cover cyberattacks. If a hacker accesses patient records or locks your systems with ransomware, you need a separate cyber insurance policy to be covered.
A patient calls your front desk. They saw their personal information for sale online. Your office didn’t even know it had been breached. By the time you figure out what happened, you’re already behind on notifying patients, dealing with state reporting requirements, and explaining to your team why the scheduling system is frozen.
This isn’t a rare scenario anymore. Dental practices sit on exactly the kind of data cybercriminals want: full names, dates of birth, insurance details, Social Security numbers, and protected health information. Add in payment processing and you’ve got a target that’s smaller than a hospital system but just as valuable to attackers, and often less protected.
The Coverage Gap
Here’s where the confusion usually starts. Practice owners assume that because they carry general liability or a business owner’s policy, they’re covered if something goes wrong digitally. They’re not.
A standard property policy is built to cover physical loss, like a fire or a stolen laptop. It typically excludes the financial fallout of a data breach entirely. General liability covers bodily injury and property damage claims from third parties, not the cost of notifying 4,000 patients that their records were exposed.
That gap is exactly where practices get caught. The breach happens; the practice goes looking for coverage and finds out the policy they’ve paid into for years was never built to respond to this kind of event.
What Cyber Insurance Actually Covers
A dedicated cyber policy is built around the specific costs that come with a breach or attack, which tend to add up fast:
-
Ransomware payments and negotiation. If your systems get locked down, a cyber policy can cover the ransom itself along with professional negotiators who handle it for you.
-
Patient notification costs. Most states require you to notify affected individuals within a specific window. That includes mailing costs, call center support, and sometimes credit monitoring for patients.
-
Legal and regulatory costs. HIPAA violations tied to a breach can trigger investigations and fines. A cyber policy typically covers legal defense and regulatory penalties.
-
Business interruption. If your systems are down for days while you recover, you’re still paying staff and rent with no patients coming through the door. Business interruption coverage helps close that gap.
-
Forensic investigation. Figuring out what was actually accessed and proving it to regulators, requires a digital forensics team. That’s a covered expense too.
A Real Example
Dr. Tarasha Pearson’s practice experienced exactly this kind of attack. What started as a routine day turned into a scramble to understand what had been accessed, who needed to be notified, and how to keep the practice running while systems were down. Having cyber coverage in place meant the practice had a clear next step instead of an open-ended crisis. Without it, every one of those costs would have come straight out of the practice’s pocket.
Common Questions
How much does cyber insurance cost for a dental practice? Cost depends on practice size, patient volume, and existing security measures, but for most single-location dental practices it’s a modest addition to an existing insurance package, especially compared to the average cost of a breach.
Is being HIPAA compliant the same as being insured? No. HIPAA compliance is about how you handle and protect patient data. Cyber insurance is about what happens financially after something goes wrong despite your compliance efforts. You need both, and one doesn’t substitute for the other.
Does my malpractice policy cover data breaches? Almost never. Malpractice coverage is built around clinical and professional liability, not cybersecurity incidents.
What’s the first thing I should do if I think my practice was breached? Contact your insurance broker immediately, even before you’ve confirmed the full scope. Many cyber policies include access to a response team that can guide your next steps from the start.
Where to Go From Here
If you’re not sure what your current policy actually covers when it comes to a cyberattack, that’s worth a quick conversation. We can walk through your existing coverage and show you exactly where the gaps are, no pressure, just clarity on what you’re protected against.
