A dental cybersecurity risk assessment is a structured review of how well your practice protects patient data, clinical systems, and daily operations. It is not a product demo and not a general threat lecture. It is a repeatable exercise that produces a score, a list of gaps, and a plan.

This page is a working dental cybersecurity checklist you can run yourself. It gives you a scoring method, 25 concrete checks grouped by control area, score bands to interpret the result, and a prioritized 30-day plan. If you want the wider background on threats, controls, and terminology first, read the complete guide to dental practice cybersecurity and come back here to score your environment.

Quick Answer

A dental cybersecurity risk assessment scores your practice against a fixed set of security controls across identity and access, email, endpoints, network and Wi-Fi, backups and recovery, monitoring, vendors, staff, and incident response. Score each of the 25 checks below as 2 (fully in place and verified), 1 (partly in place or unverified), or 0 (not in place). Total the result out of 50, compare it to the score bands, and work the 30-day plan starting with the lowest-scoring items in identity, backups, and email. Set aside uninterrupted time for a first pass and include the practice owner or manager along with whoever manages your IT. The HIPAA Security Rule expects a risk analysis of this kind to be performed and revisited, not done once and filed away.

How to Score This Assessment

Use the same three-point scale on every check so results are comparable over time.

ScoreMeaning
2The control is in place for all users, systems, or locations, and someone has verified it recently.
1The control exists partially, applies to some users or devices only, or nobody has verified it.
0The control is not in place, or you cannot answer the question.

Two rules keep the score honest. First, "we think so" is a 1, not a 2 — verification means someone looked at the setting, the log, or the restored file. Second, record who answered and the date, so the next assessment measures change rather than memory.

Maximum score is 50. Write your total at the end and keep the sheet; the value of a dental security assessment comes from repeating it.

The 25-Point Dental Cybersecurity Checklist

Identity and Access (Checks 1-4)

1. Multi-factor authentication on email and remote access. Every account that can read email or reach the practice network from outside requires a second factor. Partial coverage is a 1. CISA treats MFA as one of the highest-value controls available to small organizations.

2. Unique named accounts. No shared logins for front desk, operatories, or imaging workstations. Shared accounts make audit logs meaningless and complicate offboarding.

3. Least-privilege and admin separation. Day-to-day accounts are not local administrators, and administrative work happens under a separate credential.

4. Offboarding within one business day. Departing staff, temps, and former contractors lose access to practice management software, email, VPN, and any cloud portal on the same or next business day. A written offboarding list is what turns this from a 1 into a 2.

Password hygiene sits underneath all four checks; if yours is inconsistent, see password management for dental offices.

Email Security (Checks 5-7)

5. Advanced email filtering. Inbound mail is scanned for malware, malicious links, and impersonation attempts beyond basic spam filtering.

6. SPF, DKIM, and DMARC published. All three records exist for your sending domain, and DMARC is at least at a monitoring policy with reports going somewhere a human reads.

7. External-sender warning and payment-change procedure. External email is visually flagged, and any request to change bank details or send patient data is verified by phone using a number you already have on file.

Endpoints (Checks 8-11)

8. Managed endpoint protection on every device. Endpoint detection and response, or at minimum centrally managed antivirus, is installed on every workstation, laptop, and server — including imaging and scanner PCs.

9. Supported operating systems and software. No production system runs an operating system or practice management version past its vendor end-of-support date.

10. Patching on a defined cycle. Operating system and application updates are applied on a schedule, and someone can show which machines are behind.

11. Disk encryption on portable devices. Laptops and any tablet holding patient information use full-disk encryption, and screens lock automatically.

Network and Wi-Fi (Checks 12-14)

12. Business-grade firewall with current firmware and no default credentials. Remote management from the public internet is disabled unless deliberately configured and protected.

13. Guest Wi-Fi separated from clinical systems. Patient and personal devices sit on an isolated network with no route to practice management, imaging, or backup systems.

14. Controlled remote access. Remote support and after-hours access run through a VPN or a managed remote-access tool with MFA. Open remote desktop exposed to the internet scores 0.

Backups and Recovery (Checks 15-17)

15. Backups cover everything that matters. Practice management databases, imaging archives, document stores, and cloud email are all included — not just the file server.

16. One copy is offline or immutable. At least one backup copy cannot be deleted or encrypted by an account compromised on your network.

17. Restores are tested, not assumed. A real file or database restore has been performed recently and the result was checked. If nobody has restored anything in the last year, this is a 0.

Backup design details, including the 3-2-1 approach and retention choices, are covered in dental backup solutions.

Monitoring and Logging (Checks 18-19)

18. Alerts reach a person. Security alerts from endpoint protection, firewall, and cloud email go to a monitored inbox or service desk, not to an unread mailbox.

19. Logs are retained and reviewable. Sign-in logs for email and practice management, plus firewall logs, are retained long enough to reconstruct events after an incident.

Vendors and Third Parties (Checks 20-21)

20. Vendor inventory with access notes. You can list every vendor that touches patient data or connects to your network — IT provider, practice management vendor, imaging support, billing, transcription — and what access each holds.

21. Business associate agreements in place. Signed agreements exist for vendors handling protected health information, per HHS guidance on business associates.

Staff Awareness (Checks 22-23)

22. Security awareness training at least annually, plus at hire. Training is recorded, including who attended and when.

23. A known way to report something suspicious. Every team member knows exactly who to tell within minutes if they clicked a link or noticed odd behavior, and reporting is treated as helpful rather than blameworthy.

Incident Response (Checks 24-25)

24. A written incident response plan with current contacts. One page is enough to start: who to call, in what order, and who can authorize taking systems offline. Include your IT provider, cyber insurer, and legal counsel with after-hours numbers. NIST SP 800-61 is a useful reference structure.

25. Clinical downtime procedures. Staff can check in patients, record clinical notes, and communicate without computers for at least a day, using printed schedules and paper forms stored where they can be reached when systems are down.

Score Bands

Add your 25 scores for a total out of 50.

TotalBandWhat it means
40-50MatureControls are broadly in place and verified. Focus on testing, tabletop exercises, and closing the remaining 1s.
28-39DevelopingThe basics exist but coverage or verification is inconsistent. Prioritize inconsistent coverage and verification.
15-27At riskSeveral foundational controls are missing. Treat identity, backups, and email as urgent.
0-14CriticalFoundational gaps can leave the practice exposed to major disruption. Get help scoping remediation immediately.

Bands are a planning aid, not a compliance verdict. A practice scoring 44 with an untested backup still carries serious risk, which is why check 17 deserves attention regardless of the total.

Prioritized 30-Day Action Plan

Use this as a recommended framework rather than a guarantee of completion; the time windows are a suggested order of work, and the pace will depend on your systems, staffing, and vendor availability. Work the plan in order, starting with the items that reduce the most risk for the least effort.

Days 1-7 — stop the common entry paths. Enable MFA on email and every remote-access path. Remove shared logins and any account belonging to someone who has left. Turn on external-sender warnings and confirm SPF, DKIM, and DMARC exist. Confirm no remote desktop port is exposed to the internet.

Days 8-14 — make recovery real. Confirm what the backup actually covers, including cloud email and imaging. Add or verify an offline or immutable copy. Perform a test restore of one database and one folder, and write down how long it took. If the restore fails, that becomes the top priority for the rest of the month. Practices without capacity to do this internally often bring in a partner for backup and disaster recovery.

Days 15-21 — harden endpoints and the network. Get managed endpoint protection onto every device, including imaging workstations. List anything running unsupported software and set replacement or upgrade dates. Separate guest Wi-Fi from clinical systems. Change any default device credentials and update firewall firmware.

Days 22-30 — write down the human parts. Draft the one-page incident response plan with after-hours contacts. Print downtime forms and store them somewhere reachable without a computer. Schedule staff training and tell the team how to report a suspected click. Build the vendor list and confirm business associate agreements.

Then set a date to run this dental office cybersecurity audit again. Quarterly works well for practices in the developing or at-risk bands; annually is a reasonable floor once you are consistently in the mature band.

What to Do With the Results

Keep the completed sheet, the date, and the names of the people who answered. Share the total and the three lowest-scoring checks with whoever owns your IT — internal staff or an external provider — and ask for a written plan with owners and dates for each gap.

If a gap needs outside help to close, our dental cybersecurity services cover the technical safeguards described above. If your assessment surfaced an incident already in progress, or you are recovering from one, follow the dental ransomware recovery playbook instead of continuing this checklist.

Frequently Asked Questions

How often should a dental practice run a cybersecurity risk assessment?

At least annually, and again after any material change such as a new location, a practice management migration, a server replacement, or a security incident. HHS guidance treats risk analysis as an ongoing process rather than a one-time task.

Is this checklist the same as a HIPAA risk analysis?

No. It covers many of the same technical safeguards, but a formal HIPAA risk analysis includes documented scope, asset inventory, threat and vulnerability identification, likelihood and impact ratings, and retained documentation. Use this checklist to find gaps quickly; use it as an input to the formal analysis, not a replacement.

Who should complete the assessment?

Someone who knows how the practice actually works, paired with someone who can check settings. In most offices that is the office manager plus the IT provider. Answers based on assumption should be scored 1.

What if we score poorly?

A low score is useful information, not a verdict. Work the 30-day plan in order — identity, backups, email — because this checklist treats those three areas as the recommended first priorities for a dental practice. That ordering is a recommendation, not a measurement of your specific environment.

Do small practices really need all 25 controls?

Most apply regardless of size, because attacks are frequently opportunistic rather than chosen by headcount. Scale the implementation, not the coverage: a two-operatory practice still needs MFA, tested backups, and a downtime plan.