Cyber Insurance for Dental and Medical Practices in Washington

Dental and medical practices hold the data that is most expensive to lose: health information, insurance IDs, birth dates, and often Social Security numbers. A practice needs cyber coverage that pays for HIPAA and Washington breach response, regulatory defense, ransomware, and lost income, including outages at practice management and claims vendors. Health care filed 332 Washington breach notices on record.

By Trella Commercial · Updated October 4, 2026

The short version

  • Health care is a top target in Washington. It filed 332 of the 1,675 breach notices in Attorney General records, 24% of recent notices, and 114 ransomware notices.
  • Two sets of rules apply to a breach. HIPAA's Breach Notification Rule for protected health information, and Washington's breach law, which requires Attorney General notice even when HIPAA governs.
  • Not all your data is HIPAA data. Website tracking, marketing lists, and wellness services may fall under Washington's My Health My Data Act instead.
  • Your vendors are your risk. The 2024 Change Healthcare ransomware attack showed a claims vendor's outage can stop a practice's revenue.
  • Coverage features to insist on: regulatory defense and penalties, dependent business interruption, ransomware without a low sublimit, and privacy liability that covers wrongful collection.

What Washington's breach data shows for health care

From Trella Commercial's analysis of Washington Attorney General breach notices:

MeasureHealth care
Breach notices filed, 2015 to 2026332
Share of recent notices (July 2023 to July 2026)24%
Share of health care breaches caused by cyberattacks72%
Ransomware notices114
Notices reaching the Attorney General more than 30 days after discovery (since March 2020)89%

Across all sectors, 37% of notices involved medical information and 28% involved health insurance ID numbers. The late-filing share for health care partly reflects HIPAA's longer timeline, explained below.

HIPAA and Washington law: which rules apply

RequirementHIPAA Breach Notification RuleWashington (RCW 19.255)
What it coversUnsecured protected health information held by covered entities and business associatesPersonal information of Washington residents, including medical information and health insurance IDs
When it is a breachPresumed a breach unless a risk assessment shows a low probability the information was compromisedUnauthorized acquisition that compromises personal information, unless not reasonably likely to cause harm
Notice to individualsWithout unreasonable delay, no later than 60 calendar days after discoveryNo more than 30 calendar days after discovery
Notice to the governmentHHS: at the same time as individual notice for 500 or more people; annually, within 60 days after year end, for fewer than 500Attorney General when more than 500 Washington residents are notified
Media noticeProminent media outlets when more than 500 residents of a state are affectedOnly as part of substitute notice
Business associates and vendorsMust notify the covered entity without unreasonable delay, no later than 60 daysMust notify the data owner immediately

How they fit together: under RCW 19.255.030, a HIPAA covered entity that complies with the federal rules is deemed compliant with Washington's law for protected health information, but must still notify the Washington Attorney General, on HIPAA's timeline.

Data that is not protected health information, such as employee records or a separate retail or wellness line, follows Washington's 30-day rule. See Washington data breach notification law.

The My Health My Data Act gap

Washington's My Health My Data Act exempts protected health information governed by HIPAA, but a practice often collects health-related data outside HIPAA:

  • Website tracking pixels and analytics on appointment and service pages
  • Marketing lists and email campaigns about treatments
  • Wellness, cosmetic, or retail services offered outside the covered practice
  • Apps or patient portals run by vendors with their own data practices

For one practice's experience, see the dental practice story.

That data can bring consent and privacy claims under the Act. Check that your cyber policy's privacy liability covers wrongful collection claims and does not exclude tracking technologies. See Washington's My Health My Data Act.

Vendor outages: the Change Healthcare lesson

In February 2024, a ransomware attack on Change Healthcare, a major medical claims and payment processor, disrupted claims processing and payments for providers nationwide. Many practices had no breach of their own but lost cash flow for weeks.

The coverage that addresses that is dependent business interruption: lost income when a vendor you rely on goes down. For a practice, list the vendors you cannot operate without:

  • Practice management and electronic health records
  • Claims clearinghouse and payment processing
  • Imaging and lab systems
  • Scheduling, reminders, and patient communications
  • Phone and internet

Ask whether your policy covers each type, whether it covers vendor accidents as well as attacks, and what the sublimit is. More in cyber business interruption.

Coverage features that matter most for practices

FeatureWhy it matters for health careWhat to check
Breach responseHealth breaches mean HIPAA and state notices, call centers, and monitoringWhether costs erode the main limit
Regulatory defense and penaltiesHHS Office for Civil Rights and state Attorney General investigations follow health breachesWhether "privacy regulations" include HIPAA and state law, and insurability of fines
Ransomware and extortionHealth care is a frequent ransomware targetSublimits and coinsurance on extortion
Business interruptionA down schedule or billing system stops revenueWaiting period and period of restoration
Dependent business interruptionClearinghouse and practice software outagesVendor types covered and sublimit
Privacy liabilityPatients sue after exposureCoverage for wrongful collection and tracking claims
Social engineeringFake vendor invoices and payroll changesSublimit vs your largest payments
PCIPatient card paymentsOnly if you store or process card data directly

What insurers ask health practices

Beyond the standard controls (see what a cyber insurance application asks), expect questions about:

  • Number of patient records, current and former
  • Whether patient data is encrypted, including on laptops and imaging devices
  • HIPAA risk assessments and policies
  • Business associate agreements with vendors
  • Medical devices or imaging systems on your network running old software
  • Who has remote access, including vendors that support your systems

Common questions

Does my malpractice insurance cover a data breach?

Usually not. Medical and dental professional liability covers claims about patient care. Some malpractice policies include a small cyber or data breach endorsement, but its limits and coverage are typically narrow. A standalone cyber policy is designed for breach response, ransomware, and privacy claims.

How long does a medical practice have to report a breach?

Under HIPAA, affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. A HIPAA covered entity that follows the federal rules is deemed compliant with Washington's breach law for protected health information, but must still notify the Washington Attorney General when more than 500 Washington residents are affected.

Does the My Health My Data Act apply to dental offices?

Protected health information governed by HIPAA is exempt. But data a practice collects outside HIPAA, such as through website tracking, marketing, or separate wellness or cosmetic services, may be covered. Review where your practice collects health-related information.

What happens if our practice management vendor is hacked?

You may lose access to schedules and billing, and patient data you are responsible for may be exposed. Dependent business interruption covers the lost income if your policy includes it; breach response and privacy liability address the exposed data, since the notice duty usually stays with you.

How much cyber insurance does a dental or medical practice need?

It depends on the number of patient records, how long you could operate without your systems, your largest payments, and any contract or hospital requirements. See how much cyber insurance a small business needs for a worked example of a physical therapy clinic.

Sources

This page is general information, not legal advice. HIPAA and state law obligations should be confirmed with a health care privacy attorney. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.