Cyber Insurance Renewal: A Checklist for Dental and Medical Practices

MFA, immutable backups, EDR, patching and an incident plan: what insurers ask dental and medical practices at renewal, and how to answer with evidence.

2 min readVault Data Servers

Cyber insurance renewals used to be a one-page form. Now the questionnaire runs to several pages, the answers are tied to whether a claim gets paid, and "we think so" is not a safe answer to any of them. Here is what insurers ask dental and medical practices about, in roughly the order they care.

1. Multi-factor authentication

Expect questions about MFA on email, on remote access (VPN or remote desktop), and on administrator accounts. Insurers treat missing MFA on email and remote access as the single biggest predictor of a claim, because stolen passwords are how most incidents start. "MFA for most people" is not the same as "MFA for everyone" — the doctor who was exempted because it was inconvenient is the gap that matters.

2. Backups you can restore

The questions have moved past "do you back up?" to:

  • Are backups kept offline or immutable, so ransomware that reaches your network can't encrypt them too?
  • Are they encrypted?
  • When did you last test a restore, and how long did it take?

An untested backup is a hope. If you can't name the date of your last successful restore test, schedule one before you sign the form.

3. Endpoint protection

Insurers increasingly ask specifically about endpoint detection and response (EDR) — security software that watches behaviour and can isolate a machine — rather than traditional antivirus alone. Know which you have and whether it is on every workstation and server, including the imaging PC and the computer in the back that nobody thinks about.

4. Patching

How quickly are critical security updates applied to operating systems and key applications? Is anything running an operating system that no longer receives updates? Imaging and lab equipment often runs older software for vendor reasons; insurers want to know it exists and that it is separated from the rest of the network.

5. Email security and training

Expect questions about email filtering, whether staff receive security awareness training, and whether you run phishing simulations. Practices are attractive targets for invoice and payroll fraud, and the front desk opens more email attachments than anyone.

6. Privileged access

Who has administrator rights? Do staff browse the web and read email while logged in as administrators? Are vendor remote-access tools controlled and logged, or left installed and always on?

7. A plan for when it happens

Do you have an incident response plan — who to call, in what order, and what not to touch? Do you know your HIPAA breach notification obligations? Insurers want to see that a practice won't spend the first day of an incident working out who is in charge.

Answer accurately, and keep the evidence

The questionnaire becomes part of the policy. If an answer turns out to be wrong after an incident, the insurer may dispute or reduce the claim. Before you sign:

  • Verify each answer rather than going from memory.
  • Keep evidence: MFA enrolment reports, backup and restore-test logs, training records, patch reports.
  • Where the true answer is "not yet," say so and attach the date it will be done. A credible plan reads better than an answer you can't support.

Much of this overlaps with your HIPAA risk analysis. Keeping both current means renewal becomes an afternoon of collecting documents rather than a week of guessing.

How we handle this

Cybersecurity at Vault Data Servers

See the service
All articles

Talk to us

Want a second opinion on your setup?

Call us directly. You'll get someone who can answer the technical question, not read it off a script.

1.480.907.0700