We recently helped a dental practice add a standalone Cyber Liability policy. They weren’t completely uninsured before. Their Business Owners Policy actually included some cyber coverage, but it was only around $25,000 of coverage and relatively limited compared with what a broader standalone cyber policy could provide.
The process of moving to a dedicated cyber policy was also more involved than simply adding another checkbox to the BOP. The practice had to work with its IT company to answer questions about its security controls, systems and procedures. That experience highlighted something I think many small medical and dental practices can miss:
Cyber risk isn’t just an IT problem.
It’s a patient-data problem. It’s a financial problem. It’s potentially a regulatory problem. It’s an operational problem. And ultimately, it’s a business risk that the practice owner needs to understand, even if someone else manages the computers.
Your Data Has Value
A small dental office may look at a national hospital system or major corporation and think: “Why would a cybercriminal bother with us?” But size isn’t the only thing that makes an organization attractive. Think about the information a medical or dental practice may store:
- Patient names
- Addresses
- Dates of birth
- Insurance information
- Medical histories
- Treatment information
- Billing information
- Employee information
- Payment information
- Login credentials
That information has value. It can potentially be used for identity theft, fraud, social engineering and other malicious activity. Travelers notes that small businesses can be attractive targets because they often possess valuable customer and payment information while having fewer security resources than larger organizations. Common threats include phishing, ransomware, business email compromise and data breaches.
For healthcare businesses, there is another layer. HIPAA’s Security Rule requires covered entities and business associates to use administrative, physical and technical safeguards to protect electronic protected health information, or ePHI. HHS.gov
That means protecting patient information isn’t simply good customer service. For practices subject to HIPAA, it is also part of their regulatory responsibility.
A Data Breach Can Create Responsibilities Beyond Fixing the Computer
Suppose someone gains unauthorized access to patient information. Calling the IT company and removing the attacker may only be the beginning. Depending on what happened, the practice may need assistance with:
- Determining what information was accessed
- Digital forensic investigation
- Legal guidance
- Patient notification
- Credit monitoring
- Regulatory response
- Public relations
- Restoring data and systems
HHS’s Breach Notification Rule requires covered entities to provide notifications following certain breaches of unsecured protected health information, including notice to affected individuals and HHS, with additional requirements in some circumstances.
A broader cyber policy can potentially provide access to resources and coverage for several parts of that response. For example, Travelers describes cyber coverage options that can include forensic investigations, notification expenses, regulatory defense, litigation expenses, crisis management, data restoration and cyber extortion, depending on the policy selected.
That’s very different from simply paying somebody to repair a computer.
Having “Cyber Coverage” Doesn’t Tell the Whole Story
This is something our dental client demonstrated well. They technically had cyber coverage. But there is a big difference between:
“My policy includes something called Cyber.” and: “My business has a cyber insurance program designed around the exposures we actually have.”
Some Business Owners Policies may include a small amount of cyber coverage automatically or make limited coverage available by endorsement. That can certainly be better than having nothing. But a practice storing substantial amounts of patient information should understand:
- What the limit actually is
- Which cyber events are covered
- Whether breach-response expenses are included
- Whether regulatory defense is included
- Whether ransomware or cyber extortion is addressed
- Whether social engineering or fraudulent fund transfers are addressed
- Whether data restoration is covered
- What incident-response resources are available
Cyber policies can contain several different insuring agreements, limits and sublimits, so simply seeing “Cyber” on a declarations page doesn’t tell you very much by itself.
Your Network Doesn’t Always Have to Be the One Compromised
Another misconception is that a cyber loss only happens when someone hacks directly into your system. I’ve seen a real-world example of why that’s not always true. A business owner in my family received a large invoice from a company he regularly did business with. That other company’s network had been compromised.
The legitimate invoice communication was intercepted, and the attacker sent what looked like essentially the same email, with a nearly identical email address, the same subject matter and the correct amount, but fraudulent payment instructions.
The payment was made. The loss was in the hundreds of thousands of dollars. The business making the payment wasn’t the organization whose system had originally been compromised. It still suffered the financial consequences.
This type of event is generally referred to as business email compromise or social engineering fraud, and it illustrates why cyber risk extends beyond simply keeping hackers out of your own network.
For a medical or dental practice, think about how many outside organizations you communicate with: Billing companies, IT vendors, Labs, Suppliers, Insurance companies, Practice-management software vendors, Banks, or other healthcare providers.
A cyber incident somewhere else in that chain can still create problems for your organization.
Employees Are Part of Your Cybersecurity System
Technology matters. Multifactor authentication matters. Backups matter. Updates, security software and access controls matter. The Federal Trade Commission recommends measures including MFA, regular backups, security updates and employee training as part of small-business cybersecurity. But one of the controls I think small businesses should pay particular attention to is employee training.
Cybercriminals don’t always need to defeat sophisticated security technology.
Sometimes they just need one employee to:
- Click the wrong link.
- Open the wrong attachment.
- Enter credentials into a fake login page.
- Approve a fraudulent payment request.
- Ignore something on the computer that doesn’t look quite right.
Travelers identifies employee training, MFA, software updates and backups among practical protections small businesses can use against phishing and other cyber threats. A strong cybersecurity partner can help put technical protections in place. But employees also need to know what suspicious activity looks like and what to do when they see it.
Your IT Company and Your Cyber Insurance Should Complement Each Other
When our dental client applied for broader cyber insurance, some of the questions required them to work directly with their IT provider. That’s actually a useful exercise. Cyber underwriters may want to understand things such as:
- Multifactor authentication
- Data backups
- Security and software updates
- Access controls
- Employee training
- Incident-response procedures
- Vendor relationships
- Protection of sensitive data
The application isn’t just bureaucracy. Those questions can expose areas where the business itself may need stronger controls. And a good IT or cybersecurity partner can be valuable both before and after something goes wrong.
If you don’t already have somebody you trust in that space, your insurance agent may also know cybersecurity firms they have worked with or recommended to other clients. Independent insurance agencies have substantial amounts of sensitive customer information themselves, so we’re dealing with many of the same cybersecurity concerns our clients face.
Small Doesn’t Mean Uninteresting to Cybercriminals
A dental office with eight employees may assume that criminals are focused on national hospital systems. But cybercrime doesn’t have to produce a national-news-level breach to be profitable.
Attackers can use automated tools, phishing campaigns and commonly exploited weaknesses to target smaller organizations at scale. Travelers specifically notes that limited IT resources, outdated software and weak credentials can make small businesses attractive targets.
The question shouldn’t be: “Are we big enough for someone to target us?”
A better question is: “What information or access do we have that would be valuable to someone else?”
For a healthcare practice, the answer can be substantial.
Cyber Insurance Isn’t a Replacement for Cybersecurity
This distinction matters. Buying insurance doesn’t mean you can ignore security controls. The two should work together. Good cybersecurity can help reduce the chance of an incident. Cyber insurance can help the organization respond financially and operationally when an incident still gets through. And even sophisticated organizations with strong defenses can experience cyber events. The goal is to make your business harder to compromise and better prepared to respond if something happens.
What Should a Medical or Dental Practice Ask?
You don’t need to become a cybersecurity engineer. But as a practice owner, I would want answers to a few basic questions:
- What patient and employee information do we store?
- Who has access to it?
- Do we use multifactor authentication?
- Are our backups reliable and protected?
- Are employees trained to recognize phishing and social engineering?
- Who do we call immediately if something looks wrong?
And from the insurance side:
- Do we actually have Cyber Liability coverage?
- Is it simply a small BOP endorsement, or a broader standalone policy?
- What are the limits?
- What types of events does it respond to?
- What incident-response resources come with it?
Those are questions worth answering before somebody needs them.
The Bottom Line
Medical and dental practices hold something cybercriminals want: valuable information and access.
Patients trust practices with information that is deeply personal and, in many cases, legally protected. Protecting that information requires good technology, good employees, good procedures and a good response plan. Insurance is one piece of that system.
So instead of asking: “Do I have some cyber coverage?”
I would ask: “Do I understand what our data is worth, how exposed we are, and what would happen if that information were compromised?”
If you’re not sure how your current insurance program would respond to a cyber event, or whether the small cyber limit included on your BOP is actually enough, we can help review what you currently have and determine whether a broader cyber policy is worth considering.
Cyber insurance varies significantly by carrier and policy. Coverage depends on the applicable insuring agreements, terms, limits, sublimits, conditions and exclusions. Cybersecurity and regulatory obligations should also be discussed with qualified IT, cybersecurity and legal professionals where appropriate.
