Introduction
A practical assessment for protecting patient data

A dental office cybersecurity assessment checklist for practice owners helps turn a broad concern into a repeatable process: identify where electronic protected health information (ePHI) exists, test whether safeguards work, and assign specific fixes to named people and vendors.
A checklist is not a substitute for a HIPAA security risk analysis. It is the working tool that helps a practice perform, document, and maintain that analysis. I recommend treating it as an operational record, not a one-time compliance form.
What the assessment should accomplish
A useful assessment should help you answer four direct questions:
• Where is ePHI stored, received, maintained, or transmitted?
• What could expose, alter, encrypt, or destroy that information?
• Which existing safeguards reduce the risk, and are they actually working?
• Who owns each remaining risk, what will remediation cost, and when will it be completed?
The HHS OCR summary of the HIPAA Security Rule explains that covered entities must use administrative, physical, and technical safeguards, perform risk analysis, and retain required documentation. A dental assessment should address all of those areas.
Key Takeaways
The controls that deserve immediate attention
| Priority area | What to verify | Why it matters |
|---|---|---|
| Identity and access | Unique accounts, MFA, role-based access, timely offboarding | Limits account takeover and unauthorized viewing of ePHI |
| Ransomware recovery | Protected backups, documented recovery steps, tested restores | Keeps the practice from discovering too late that backups cannot be restored |
| Vendor oversight | BAAs, responsibilities, escalation contacts, security evidence | Clarifies who protects systems managed outside the office |
| Device security | Patching, endpoint protection, encryption, imaging-device exceptions | Reduces exposure from workstations, servers, and connected clinical technology |
| Staff readiness | Phishing training, reporting process, periodic testing | Addresses a common entry point for email fraud and malware |
The owner-level rule: evidence, ownership, deadlines
I suggest adding four fields to every checklist item:
| Field | What to record | Example |
|---|---|---|
| Control owner | Person or vendor accountable | Office manager or managed IT provider |
| Evidence | Proof the control exists and was checked | MFA policy screenshot, restore-test report, signed BAA |
| Status | Current state | Complete, partial, not started, not applicable |
| Due date | Date the gap will be resolved | September 30, 2026 |
A control marked “complete” without proof is difficult to defend during an insurance review, security incident, or HIPAA inquiry.
Table of Contents
Assessment and remediation sections
- Scope the systems, vendors, and patient-data flows.
- Review the cybersecurity checklist by control area.
- Score and prioritize risks.
- Test ransomware recovery and incident response.
- Maintain the assessment throughout the year.
Questions addressed in the FAQ
The FAQ covers assessment frequency, ePHI systems, vendor questions, ransomware readiness, imaging security, access control, remediation planning, and post-incident actions.
TL;DR Summary
The short version
Start by mapping every location ePHI touches, including practice management software, imaging, email, patient portals, claims tools, backups, mobile devices, and vendor-hosted platforms. Then evaluate access, encryption, patching, backup restoration, logging, training, physical safeguards, and vendor responsibilities.
The decision that matters most
Do not prioritize only by convenience. Address risks with the highest likely impact on patient care, ePHI confidentiality, downtime, and legal obligations first. A failed backup restore, shared administrator account, exposed remote access tool, or missing BAA can deserve more attention than minor workstation cleanup.
1. Define the Scope Before Checking Controls
Map ePHI from intake through retention
Begin with a patient-data flow map. An asset inventory tells you what exists; a data-flow map shows where information travels and where it may be exposed.
| Workflow stage | Common dental systems | Assessment question |
|---|---|---|
| Intake and scheduling | Online forms, scheduling system, patient portal | Does ePHI enter through encrypted, approved channels? |
| Clinical documentation | Practice management software, charting workstations | Who can view, edit, export, or delete records? |
| Imaging | X-ray sensors, imaging workstations, image archives | Is the imaging environment patched, segmented, and supported? |
| Billing and claims | Clearinghouse, billing platform, payment tools | Which vendors receive ePHI, and is a BAA required? |
| Communications | Email, texting platform, portal, fax service | Are transmission methods approved and configured securely? |
| Backup and retention | Local backup, cloud backup, archived records | Can retained records be restored within the practice’s recovery target? |
For example, a patient may submit a web form, receive a portal invitation, have X-rays taken on an imaging workstation, and generate a claim through a clearinghouse. Each handoff creates a separate security and vendor-review point.
Separate practice-owned and vendor-managed responsibilities
A common assessment failure is assuming an outside provider “handles security” without documenting exactly what that means. Create an ownership boundary for every in-scope system.
| System or control | Practice responsibility | Vendor responsibility | Evidence to retain |
|---|---|---|---|
| Practice management platform | Approve users and roles | Secure hosted application, if contracted | Access review and vendor security documentation |
| Managed firewall | Approve security standards and budget | Configure, monitor, update, and alert | Monitoring report and change records |
| Cloud backup | Define recovery priorities | Protect backup platform and support restores | Restore-test results and service agreement |
| Imaging equipment | Maintain approved workflows | Advise on supported updates and configurations | Support status and exception record |
| Billing service | Limit shared exports and access | Secure service operations | BAA, access list, incident contact |
The HHS OCR Security Rule guidance material supports including vendor risk, access controls, audit controls, incident procedures, and transmission security in the assessment.
Include physical and after-hours access paths
Cybersecurity is not only about screens and passwords. Check who can enter server closets, use unattended workstations, access paper-to-digital scanning areas, or take devices offsite.
For emergency access, avoid a shared “just in case” administrator password. A better approach is a documented emergency-access process with a named approver, time-limited access where technically possible, and a required review afterward. The right design depends on the software and practice size, but the principle remains the same: urgent access should be traceable and should not silently bypass least privilege.
2. Dental Office Cybersecurity Assessment Checklist
Identity, access, and account lifecycle
Use the following checklist for every employee, contractor, and vendor account with access to systems containing ePHI.
• Confirm every user has an individual account. Do not use shared logins for front desk, clinical, billing, or administrator work.
• Require MFA for remote access, cloud email, portals, backup administration, and other systems that support it.
• Review permissions by role. A hygienist, scheduler, treatment coordinator, biller, and IT administrator should not automatically receive the same access.
• Document the new-hire process, including manager approval, initial access level, and security training.
• Document role-change procedures so elevated rights are removed when duties change.
• Disable terminated-user accounts promptly and review mailbox forwarding, remote access, shared credentials, and mobile-device access.
• Review privileged accounts separately. Administrator access should be limited, named, and monitored.
| Access finding | Recommended response | When an exception may be reasonable |
|---|---|---|
| Shared front-desk login | Replace it with individual accounts and role-based permissions | Only if a legacy product cannot support unique IDs, with documented compensating safeguards and replacement planning |
| MFA absent for remote access | Enable MFA before allowing offsite connections | If a legacy system cannot support it, restrict access through a secured gateway and set a modernization deadline |
| Former employee account active | Disable immediately and investigate recent activity | No routine exception should apply |
| Broad administrator rights | Reduce privileges and use separate admin accounts | Temporary vendor access may be approved, time-limited, and logged |
Devices, networks, and imaging systems
Inventory and assess every endpoint that can access, store, or transmit ePHI:
• Desktop computers and laptops
• Servers and network-attached storage
• Firewalls, switches, wireless access points, and remote-access tools
• Tablets, smartphones, and removable media
• Imaging workstations, sensors, scanners, cameras, and image archives
• Printers and multifunction devices that scan to email or network folders
• Patient kiosks, tablets, and guest wireless networks
For imaging systems, do not apply routine patching without confirming vendor compatibility. Some legacy clinical devices may depend on older operating systems or specialized drivers. If an upgrade could interrupt image capture or invalidate support, document the exception, isolate the device from general office traffic where feasible, restrict internet access, and establish a replacement plan. Leaving it unmanaged is not a risk treatment.
Email, encryption, monitoring, and training
Assess the controls most likely to prevent or reveal phishing, ransomware, misdirected email, and unauthorized data access.
| Control | What to test | Minimum evidence |
|---|---|---|
| Email protection | Phishing filtering, suspicious-link handling, impersonation controls | Email security configuration or service report |
| Encryption | Secure remote access, approved patient communications, encrypted devices and backups | Encryption settings and policy documentation |
| Endpoint protection | Active protection, centralized alerts, current status | Endpoint console report |
| Patch management | Operating systems, browsers, security tools, network equipment | Patch report and exception log |
| Audit logging | Log collection and meaningful review of security events | Sample review record and retention setting |
| Training | HIPAA and phishing training for workforce members | Attendance record and training material |
Staff training should cover more than generic password reminders. Include realistic actions: reporting a suspicious invoice, checking an unexpected password-reset notice, handling a patient request sent to the wrong email address, and escalating a lost mobile device.
3. Score Risks and Build a Funded Remediation Plan
Use likelihood and impact to avoid reactive spending
A risk register helps distinguish a minor inconvenience from a problem that could stop operations or expose patient data. NIST’s guide for conducting risk assessments supports evaluating threats, vulnerabilities, likelihood, and impact to prioritize risk treatment.
Use a simple scale consistently. The exact numbers matter less than the discipline of documenting why a risk is ranked where it is.
| Score element | Low | Medium | High |
|---|---|---|---|
| Likelihood | Uncommon and difficult to exploit | Plausible with ordinary conditions | Likely due to active exposure or known weakness |
| Impact | Limited disruption with little ePHI exposure | Meaningful workflow disruption or contained exposure | Major downtime, broad ePHI exposure, or inability to provide care |
| Suggested response | Track and review | Set a scheduled remediation date | Act promptly, assign an owner, and verify completion |
A workstation missing a noncritical update may be medium risk. An unprotected administrator account used for remote access is commonly a high-priority issue because one compromised credential could affect multiple systems.
Assign an owner, budget, and completion test
Every remediation item should include a decision, not just a recommendation.
| Remediation field | What good documentation looks like |
|---|---|
| Finding | “Cloud backup exists, but no full restoration test has been completed.” |
| Risk rating | High, because recovery capability is unverified |
| Accountable owner | Practice owner, office manager, or named vendor contact |
| Budget decision | Approved, deferred with reason, or rejected with alternate safeguard |
| Due date | Specific calendar date |
| Completion evidence | Restore-test report showing what was restored and how long it took |
| Residual risk | Remaining risk after the action is complete |
Owner sign-off matters because remediation often requires spending decisions, workflow changes, or vendor coordination. If a risk is intentionally deferred, document why, who accepted it, and when it will be reconsidered.
Choose managed support with clear accountability
A managed provider can reduce the operational burden, but outsourcing work does not outsource the practice’s responsibility to oversee ePHI safeguards. When reviewing dental managed IT services, ask for a clear description of monitoring, patching, access management, incident escalation, backup restoration support, documentation, and reporting responsibilities.
Use these questions with managed IT, cloud backup, imaging, billing, and hosted software vendors:
- Do you create, receive, maintain, or transmit ePHI for our practice?
- Is a BAA required, and who provides it?
- Which security controls do you operate, and which ones must the practice operate?
- How are privileged vendor accounts approved, protected, logged, and removed?
- How quickly will you notify us of a suspected security incident affecting our systems or ePHI?
- What backup, restoration, and retention responsibilities are included?
- Can you provide evidence of patching, monitoring, access reviews, or recovery testing relevant to our environment?
4. Test Ransomware Recovery and Incident Response
Test restoration, not only backup completion
Backups are useful only if the practice can restore the required systems and data within an acceptable timeframe. A backup dashboard showing “successful” does not prove that practice management records, images, configuration files, and user access can be recovered.
| Recovery test | What to validate | Decision criterion |
|---|---|---|
| File restore | A representative patient-related file can be recovered without corruption | Verify file completeness and access permissions |
| Practice-management restore | Core database or supported recovery process works | Confirm appointments, charts, billing, and access are usable |
| Imaging restore | Images and image-indexing functions are available | Confirm clinical users can retrieve records |
| Full outage drill | Staff can operate through the documented downtime process | Measure recovery time and identify missing dependencies |
| Backup security check | Backup deletion or encryption is restricted | Confirm separate credentials and protected backup storage |
Set two practical targets:
• Recovery time objective: How long the practice can operate without a system before patient care, scheduling, or billing becomes unacceptable.
• Recovery point objective: How much recent data the practice can afford to lose if a restore is required.
For instance, a practice may decide it can tolerate four hours without online scheduling but cannot accept losing a full day of clinical records. Those choices should drive backup frequency, replication, and restoration priorities.
Keep an incident response playbook that staff can use
An incident plan should be concise enough to use under pressure. Include named decision-makers and alternatives if the primary person is unavailable.
- Identify and report the suspected event immediately.
- Isolate affected devices or accounts without destroying potential evidence.
- Contact the designated IT, security, legal, insurance, and leadership contacts.
- Preserve relevant logs, messages, screenshots, and timing details.
- Determine whether ePHI may be affected and follow the applicable breach-assessment and notification process.
- Restore systems only after containment and recovery steps are approved.
- Document what happened, what was decided, and what controls will change afterward.
Review the plan after changes, not just annually
A recurring review is essential, but it should not be the only trigger. NIST’s introductory HIPAA Security Rule implementation guide supports treating risk analysis as an ongoing process and mapping safeguards to assessment items.
Reassess when the practice opens a location, acquires another office, changes practice management software, adds cloud imaging, enables remote access, changes a billing vendor, experiences a security event, or installs new connected clinical equipment.
5. Maintain Evidence and Improve the Program
Keep a minimum evidence file for each control
A defensible assessment includes proof. Store evidence in a restricted location that is available to the people responsible for compliance and incident response.
| Assessment area | Useful evidence examples |
|---|---|
| Asset inventory | Dated device list, serial numbers, system owner, support status |
| Access management | User access report, termination checklist, privilege-review record |
| Security configuration | MFA settings, firewall report, endpoint protection report |
| Training | Training roster, completion dates, phishing-reporting instructions |
| Vendor oversight | BAA, contract scope, security contact list, service reports |
| Backup recovery | Restore-test records, recovery times, exception documentation |
| Risk management | Risk register, budget approval, remediation status, owner sign-off |
| Incident readiness | Incident plan, contact tree, tabletop exercise notes |
Use the checklist as a monthly management tool
The full risk analysis may be scheduled periodically, but smaller reviews should happen more often. I recommend a short monthly review of unresolved high-risk findings, terminated accounts, endpoint alerts, backup status, phishing reports, and vendor changes.
Quarterly, review access permissions and test at least one recovery procedure. Annually, refresh the complete assessment, workforce training, policy set, and incident-response exercise. This cadence should be adjusted when the practice experiences major technology or workflow changes.
Connect security improvements to the practice’s technology plan
Security controls work best when they are built into procurement and workflow decisions. Before purchasing new imaging equipment, a patient communication platform, or cloud software, ask how it handles ePHI, who administers access, whether it integrates with backup and logging processes, and whether vendor support creates an unmanaged remote-access path.
For a broader view of integrated safeguards and operations, review the best HIPAA compliant IT solutions for dental practices. The goal is not to buy every available security product. It is to build controls that fit the practice’s actual systems, risks, staffing, and recovery requirements.
FAQ
How often should a dental practice complete a cybersecurity risk assessment?
Complete a thorough risk analysis on a recurring basis and revisit it after significant changes to systems, vendors, locations, workflows, remote access, or a security incident. A practical approach is an annual comprehensive review supported by monthly and quarterly control checks. If the practice implements a new cloud imaging platform in the middle of the year, waiting for the next annual review may leave a meaningful gap.
What systems count as ePHI in a dental office?
Any electronic system that creates, receives, maintains, or transmits identifiable patient health information can be in scope. This commonly includes practice management software, imaging systems, email, patient portals, claims platforms, scanned records, cloud storage, backups, remote-access tools, laptops, tablets, and mobile devices used for practice work.
What should a dental office ask vendors during a security assessment?
Ask whether the vendor handles ePHI, whether a BAA is required, what safeguards the vendor operates, what the practice must operate, how vendor access is protected, how incidents are reported, and how data is backed up or returned at contract end. Request evidence where appropriate instead of relying only on verbal assurances.
How should a dental office test backups and ransomware recovery?
Test actual restoration. Recover representative files, validate practice-management data, confirm imaging availability, and measure the time required to return essential workflows to service. Also verify that backup administration uses separate protected credentials so an attacker who compromises an office account cannot easily delete or encrypt recovery copies.
Conclusion
Turn the checklist into an accountable plan
A dental office cybersecurity assessment checklist for practice owners is most effective when it identifies real systems, assigns clear responsibilities, requires evidence, and tracks remediation through completion. The checklist should make uncertainty visible early, before a phishing email, failed restore, or vendor issue turns into a patient-data and downtime crisis.
Start with the highest-impact gaps
Begin with the systems that hold the most ePHI and the controls that could stop a major incident: unique accounts, MFA, protected backups, tested restores, vendor oversight, endpoint protection, and incident response. Then use the risk register to make informed budget and timing decisions.
A completed checklist is not the finish line. It is the record that shows what the practice protects, who is responsible, and what still needs to be improved.
Sources/References
Verified guidance
- U.S. HHS OCR — Summary of the HIPAA Security Rule: https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
- NIST — Guide for Conducting Risk Assessments: https://csrc.nist.gov/pubs/sp/800/30/r1/final
- NIST — An Introductory Resource Guide for Implementing the HIPAA Security Rule: https://csrc.nist.gov/pubs/sp/800/66/r2/final
- U.S. HHS OCR — Security Rule Guidance Material: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html