
Cyber insurance used to be easy to buy. A few pages of questions, a premium, a policy in the drawer. That era is over. Insurers paid out so much on ransomware and business email compromise that they rewrote the playbook: applications now ask technical questions in technical language, renewal questionnaires arrive weeks before the deadline, and the answers are checked against reality if you ever file a claim.
For a dental practice, this changes the relationship between IT and insurance. The policy is no longer a purchase, it is a technical contract with requirements your systems have to actually meet. Here is what underwriters now expect, why, and what to do about it before your next renewal.
Key takeaways
- Applications now ask about MFA, backups, endpoint protection, and patching; answering "yes" without the systems in place puts the payout at risk, not just the premium.
- Backup requirements increasingly specify isolation or immutability, meaning the backup cannot be reached from the production network an attacker controls.
- Cyber insurance is now effectively an IT audit that happens annually; practices with a managed IT provider have the answers documented already.
The four questions every application now asks
1. Is multi-factor authentication enabled?
MFA on email, remote access, and administrative accounts has become the single most-weighted control on cyber applications. The reason is a string of statistics the industry has internalized: stolen or abused credentials are the leading way attackers get in, and MFA breaks that path. An application with "no" next to MFA is either declined or priced as if a breach is expected.
What underwriters want to see:
- MFA on every email account
- MFA on anything that provides remote access to your systems
- MFA for anyone with administrator rights
2. Are backups isolated and tested?
"Where is your backup?" used to be the whole question. Now it continues: "Can ransomware reach it?" If your backup server sits on the same network with the same credentials as everything else, the honest answer is yes, and that answer now costs you. Modern ransomware crews find and encrypt backups first, on purpose, to remove your alternative to paying.
What underwriters want to see:
- At least one backup copy isolated from the production network (off-site or offline) or stored immutably so it cannot be altered
- Regular restore testing, not just backup success notifications
A backup that has never been restored is a claim waiting to be denied. Test it and write down the result.
3. What endpoint protection and patching do you have?
Applications ask whether devices run supported operating systems with current patches and managed endpoint protection (EDR where required). The supporting logic is simple: most incidents exploit known vulnerabilities that already had fixes available. Practices running unsupported versions of Windows on imaging or front-desk workstations should know that this exact fact now appears on applications.
4. Who has administrative access, and how is it controlled?
Underwriters want to know that admin rights are limited, monitored, and not used for daily work, and that access is removed promptly when staff leave. Shared logins at the front desk, an IT vendor with permanent full access, and former employees whose accounts still work are all findings now, not just bad habits.
What the policy requires after you sign
The application is the entry fee; the policy's conditions are the contract. Three matter most for dental practices:
- Prompt notification: Policies require reporting a suspected incident within a short window, often 48 to 72 hours. Late reporting is a classic basis for reducing or denying a claim. This means your staff's reflex when something looks wrong is to call, not to investigate quietly for a week.
- Preferred providers: Policies name their own response firms, legal counsel, and forensics. Going outside the panel without approval can mean paying for it yourself. The response plan in your drawer should list the insurer's numbers, not just your IT provider's.
- Continuous representation: Renewal applications ask whether anything has changed since last year. A security incident you handled quietly and did not report at renewal can void the next policy. Honesty is not just the best policy; it is the only valid application.
How a dental practice gets ready for renewal
Six to eight weeks before renewal, run this sequence:
- Pull last year's application and answer this year's honestly. Flag every "no."
- Fix the cheap and fast gaps first: enable MFA everywhere it is missing, remove old accounts, get patching current on anything that touches patient data.
- Fix the structural gaps next: isolate or immutablize one backup copy, and run a documented restore test.
- Collect the evidence: screenshots of MFA enforcement, the backup test record, the endpoint-protection dashboard, the account list. Underwriters increasingly ask for proof, not promises.
- If the questionnaire is beyond what the practice can answer internally, involve your IT provider before the deadline, not after a denial.
The practices that sail through renewals are the ones whose IT was already doing these things, because their provider documents them as a matter of course. The practices that get declined or re-priced are usually discovering the requirements for the first time in the application itself.
Frequently Asked Questions
Does cyber insurance cover ransomware in a dental practice?
Generally yes, ransomware is a core covered peril, subject to the policy's conditions: prompt reporting, using the insurer's response providers, and the controls you represented in the application being actually in place. Coverage typically extends to recovery costs, business interruption, notification obligations, and sometimes the ransom itself. What voids coverage is misrepresentation: claiming MFA and backups that did not exist when the incident happened.
How much does dental cyber insurance cost?
Premiums vary by practice size, data volume, revenue, and, above all, the controls questionnaire. A practice with MFA everywhere, isolated tested backups, and a managed IT provider presents a different risk than one answering "no" to four core questions, and pricing reflects the difference more each year. Treating the questionnaire as an IT roadmap rather than a form usually pays for itself at renewal.
What happens if you claim MFA on the application but it was not actually enabled?
If a claim is filed and the insurer's forensics find the control missing or disabled, the payout can be reduced or denied for misrepresentation, and the application answers may have contractual force. The only safe approach is to treat every "yes" as a statement of verified fact, with evidence filed alongside the application.
Do we need cyber insurance if we have strong IT controls?
Controls reduce the likelihood and the premium; they do not eliminate the tail risk of a major event with notification costs, legal fees, business interruption, and patient communication at scale. Strong controls plus insurance is the pairing underwriters reward: the application gets easier and cheaper precisely because you need it less.
Conclusion
Cyber insurance has quietly become an annual IT audit with money on the line. The questionnaire is a checklist of the things a security-minded practice should have anyway: MFA, isolated and tested backups, managed patching, controlled access, and honest answers kept honest by evidence. Practices that treat the application as a to-do list get cheaper policies and better protection; practices that treat it as paperwork get the lesson during a claim, which is the expensive time to learn it.
Our managed IT services keep the controls in this article implemented and documented, our ransomware incident-response article covers the day the policy is for, and the FAQ page collects the rest of the questions practice owners ask us about security and compliance.
Sources/References
- Cybersecurity and Infrastructure Security Agency (CISA), #StopRansomware: https://www.cisa.gov/stopransomware
- HHS, HIPAA Breach Notification Rule: https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
- NIST, Contingency Planning Guide for Information Technology Systems (SP 800-34): https://csrc.nist.gov/pubs/sp/800/34/r1/final
- FBI Internet Crime Complaint Center (IC3), annual reports: https://www.ic3.gov/


