August 21, 2026 Your Cyber Insurance Might Not Pay: The Security Controls Dental Practices Now Have to Prove
Most dental practices treat cyber insurance the way they treat fire insurance: pay the premium, file the certificate, and assume that if the worst happens, the policy will respond. That assumption is now the most dangerous one in the building. Insurers have quietly rewritten how these policies work, and the practices most exposed today are not the uninsured ones — they are the ones holding a policy they believe will pay, that will not.
The reason is simple economics. Insurers spent several years paying out enormous ransomware and business-email-compromise claims, decided they could no longer price that risk blindly, and responded by underwriting hard. A cyber policy in 2026 is no longer something you merely buy. It is something you have to qualify for, on a detailed application, by attesting that specific security controls were already in place — and those attestations are legally binding.

Why the market changed under your feet
When an insurer loses money on a class of claims, it has two levers: raise prices or reduce the risk it accepts. The cyber market pulled both, but the second one is what catches practices off guard. Carriers now insist that the businesses they cover run a baseline of defenses before a policy is issued, because a well-defended organization is far less likely to suffer a catastrophic loss in the first place. The underwriting questionnaire became the gatekeeper, and the questions on it are pointed, technical, and specific.
For a dental practice, this is a quiet trap. The person filling out the renewal application is often the office manager or the practice owner, working from memory or optimism, ticking boxes that sound reasonable. “Do you require multi-factor authentication for remote access?” Yes, probably. “Are your backups kept offline and tested?” We have backups, so—yes? Each of those checkmarks is a formal statement the insurer will rely on, and, if a claim is ever filed, scrutinize.

The controls insurers now demand
The good news is that the required controls are not exotic. The bad news is that many practices only partially meet them. Across today’s cyber applications, the same short list appears again and again:
Multi-factor authentication, everywhere it matters. Not just on email, but on remote access, VPNs, administrative accounts, and practice-management logins. Missing MFA on remote access is one of the single fastest ways to have an application declined or a claim disputed. And it has to be real MFA — as we explained when stolen session cookies let attackers walk past MFA entirely, how it is implemented matters as much as whether the box is checked.
Endpoint detection and response (EDR), not legacy antivirus. Traditional signature-based antivirus no longer satisfies most carriers. They want EDR — ideally managed (MDR), so a human is watching alerts and can act on a threat in progress, not just a program quietly quarantining files after the fact.
Backups that are immutable, offline, and actually tested. This is where the most claims quietly die. It is not enough to say you have backups. Insurers ask whether they are encrypted, kept offline or immutable so ransomware cannot reach them, and — critically — whether you have verified a restore. As we keep telling practices, your backups are only as good as your last test restore. An untested backup is an assumption, and insurers no longer accept assumptions.
Disciplined patching and network segmentation. Carriers want to see that critical updates are applied promptly and that a single compromised machine cannot reach everything. Sensible network segmentation is both a security control and, increasingly, an underwriting question.
A written incident-response plan, staff training, and least-privilege access. Insurers reward organizations that can prove their security posture and quietly penalize those that only claim it. A documented plan, phishing-aware staff, and accounts that carry only the access they need round out the list.

How a paid-up policy becomes a denied claim
Here is the scenario that should keep a practice owner up at night, and it plays out regularly. A clinic suffers a ransomware attack. It files a claim, confident because it pays its premium every year. The insurer investigates — and cyber claims are investigated thoroughly. It emerges that the “offline backups” attested to on the application were in fact a synced folder the attacker had already reached and encrypted, and that the “endpoint protection” was a consumer antivirus product that had not updated in months. The claim is denied on the grounds of material misrepresentation of security controls.
Nothing about that denial is a technicality. The insurer priced and issued the policy based on the risk profile the practice described. When the reality does not match the attestation, the contract that reality was built on can be voided — leaving the practice to absorb the full cost of the incident itself. And that cost is not abstract. As we have covered, ransomware in healthcare is now a patient-safety and business-continuity crisis, not merely an IT expense, with downtime, breach-notification obligations, and reputational damage stacking on top of any ransom.

Why this hits dental practices specifically
A dental office sits in an awkward spot. It holds exactly the kind of data attackers and regulators care about — protected health information, payment details, and identity records — but it rarely has an in-house IT department to answer an underwriter’s questions accurately. The application lands on the desk of someone whose expertise is running a practice, not enumerating endpoint-detection coverage or verifying backup immutability. The result is a gap between what gets attested and what is actually running, and that gap is precisely what a denied claim is made of.
There is also a compliance dimension. Under both HIPAA and Ontario’s PHIPA, a practice is expected to safeguard patient information with reasonable, current measures. The very controls insurers now demand — MFA, tested backups, patching, access control — are the same ones a regulator would expect to see. Getting them right is not two separate projects; it is one, serving both your coverage and your duty of care.
What to do before your next renewal
The work belongs before renewal, not after an incident. Treat the insurance questionnaire as a security to-do list rather than a form to survive. First, get an honest, independent assessment of what your practice actually runs: is MFA enforced on every remote and administrative login, is real EDR deployed on every machine, are your backups genuinely immutable and restore-tested, are your systems patched on a disciplined schedule? Second, close the gaps before you sign anything — so that every attestation you make is simply true. Third, keep evidence: the configuration screenshots, the restore-test logs, the patch reports that demonstrate the controls were in place. If a claim is ever filed, that documentation is what turns a contested payout into a paid one.

The bottom line for your practice
Cyber insurance is still worth having — but only if it would actually respond when you need it. In 2026 that is no longer a function of paying the premium; it is a function of provably running the controls you attest to. The practices at greatest risk are the ones that assume a policy in the drawer equals protection, right up to the moment a denied claim reveals otherwise. Read your application as what it is: a binding description of your security, which had better match reality.
If you would like an independent review of whether your practice actually meets the controls your cyber insurer requires — MFA everywhere, managed endpoint detection, immutable and tested backups, disciplined patching, and a real response plan — contact Compudent Systems. We help dental practices across Ontario close the gap between what an insurance application asks and what is genuinely running, so the coverage you pay for would hold up when it counts.
Sources & further reading:
- Cyber Insurance Requirements in 2026: What Your Business Needs
- Cyber Insurance Requirements 2026: What Insurers Now Demand