Applied Cybersecurity for Dental Practices

Applied Cybersecurity for Dental Practices

Challenges, regulatory framework and protection strategies

1 Introduction

Digital transformation has profoundly reshaped the practice of dentistry. Dental clinics, like the broader healthcare sector, rely increasingly on digital technologies for patient record management, medical imaging, appointment scheduling, billing and communication. While this digitaliization enhances efficiency and the quality of care, it simultaneously exposes these organizations to significant cybersecurity vulnerabilities. The growing adoption of digital tools, which optimizes day-to-day operations, also expands the potential attack surface. Every new interconnected system and every new database becomes a potential entry point for malicious actors and a valuable target. There is therefore an inherent tension between the operational benefits of digitaliization and the imperative of security.

The protection of health data, which is extremely sensitive by nature, is a critical concern. Dental records contain confidential personal and medical information whose compromise can have devastating consequences: unauthoriized access, data theft or alteration, disruption of care, substantial financial losses, reputational damage and legal liability for practitioners.

The value of these data extends far beyond their financial worth on illicit markets; it encompasses the fundamental trust between patient and practitioner, the integrity of individual medical histories, and the risk of misuse for identity theft or targeted manipulation campaigns. Securing this information therefore goes beyond a mere technical or legal obligation and becomes a matter of public trust and professional ethics at the very heart of the healthcare system.

This article provides an in-depth analysis of the specific cybersecurity challenges and solutions faced by dental practices. It examines the threat landscape, the applicable regulatory framework, prevention and protection strategies, incident management, and the resources and support available.

2 The cyber-threat landscape and specific vulnerabilities in dental practices

Dental practices, despite their often modest size, represent prime targets for cybercriminals because of the nature of the data they handle and certain structural vulnerabilities.

Why are dental practices attractive targets?

Several factors explain why dental practices appeal to cyberattackers.

  • The value of health data: Medical records consolidate permanent and extremely sensitive personal information, such as medical histories, identification numbers, prescriptions and diagnostic results. These data can be resold on the dark web at a price significantly higher than financial information, sometimes up to 50 times more, due to their permanence and their potential use for complex fraud schemes or identity theft. This high commercial value provides a direct incentive for cybercriminals.
  • Risk factors inherent to small organizations: Dental practices, operating mainly as very small enterprises or small and medium-sized enterprises (SMEs), present specific vulnerabilities. They rarely have dedicated IT or cybersecurity staff, and their security budgets are often limited compared with large institutions. As an indication, while 40% of French hospitals did not have a dedicated cybersecurity officer in 2023, the situation is likely to be even more critical within independent practices. The obsolescence of IT systems is another aggravating factor. The use of outdated hardware or software, or even operating systems whose technical support has ended (such as Windows 7, still used in some hospitals in 2022 and potentially in older practices), generates known, unpatched security flaws. The criticality of operations also makes practices vulnerable. A cyberattack, especially ransomware, can paralyse the activity of the practice, leading to appointment cancellations and disruption in the continuity of care. Yet many practices are not adequately prepared to face such incidents, lacking a formaliized emergency plan and robust, regularly tested backup strategies.

The absence of backups is explicitly identified as a major issue. Consult our complete guide on data backup in medical and dental practices.

This combination of high-value data, often limited security resources and strong dependence on information systems for daily operations creates what experts call a "triangle of vulnerability". Cybercriminals therefore perceive dental practices as potentially lucrative targets, offering a rapid return on investment and significant impact, especially through ransomware that exploits the immense pressure to recover data and resume activity.

• The human factor as the weakest link: A significant proportion of successful cyberattacks, estimated at 70% in the hospital sector and extrapolable to dental practices, is attributable to human error. The lack of training and staff awareness of cyber risks is striking. Practices such as the use of weak or reused passwords, poor management of access rights, or lack of awareness of phishing techniques open breaches that attackers can exploit.

Overview of common cyberattacks

Dental practices are exposed to a variety of cyberattacks, some of which are particularly frequent and damaging.

  • Ransomware: Ransomware attacks represent the most feared threat. These malicious programs encrypt the practice's data, rendering it inaccessible, then demand the payment of a ransom, often in cryptocurrency, in exchange for a decryption key. The consequences are often severe: paralysis of the information system, forced return to paper records, massive appointment cancellations, and sometimes the threat of public disclosure of the stolen data if the ransom is not paid.

In France, the Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI) reported that around 11% of IT incidents reported in 2023 concerned the healthcare sector, which includes several hundred dental and orthodontic practices.

A concrete example illustrates the impact: in November 2021, ten dental practices were simultaneously affected, resulting in the encryption of appointment data, payments, patient histories and X-rays, a ten-day lockout and a ransom demand of 15,000 euros. Faced with such attacks, the official recommendation from ANSSI is never to pay the ransom.

  • Phishing and social engineering: Phishing is a social engineering technique that aims to trick users into revealing confidential information (credentials, passwords) or into running malicious software. Attackers impersonate legitimate entities (administrations, suppliers, colleagues) through fraudulent emails, text messages or phone calls. More than half of healthcare professionals are unable to identify a fraudulent email. These attacks can lead to the theft of patient records and the paralysis of information systems.
  • Other relevant threats: In addition to ransomware and phishing, dental practices can fall victim to data theft (intrusions into databases to exfiltrate sensitive information) or, more rarely for small organizations, denial-of-service (DDoS) attacks aimed at making their online services (website, appointment booking) unavailable.

The following table summariizes the main cyber threats facing dental practices.

ThreatDescriptionMain impactFrequency
RansomwareData encryption, ransom demandTotal paralysis of the practiceHigh
PhishingFraudulent emails/SMS to steal credentialsData theft, unauthoriized accessVery high
Data theftIntrusion and exfiltration of sensitive informationLeak of patient recordsMedium
IoT attackCompromise of connected objects (imaging, sensors)Gateway into the networkRising
Human errorPoor handling, weak password70% of incidents in healthcareVery high

Emerging threats and future trends

The cyber-threat landscape is constantly evolving, with new attack vectors appearing and existing techniques becoming more sophisticated.

  • The Internet of Things (IoT) in the dental practice: The proliferation of connected objects (IoT) in the environment of dental practices — smart chairs, digital X-ray systems, monitoring sensors, surveillance cameras, connected televisions in waiting rooms — introduces new attack surfaces. These devices, often less secure than traditional computers and equipped with weak default passwords, can be easy entry points for cybercriminals. Once compromised, an IoT device can be used as a pivot to infiltrate the main network of the practice, exfiltrate data or disrupt the operation of other equipment. Securing these devices requires basic measures such as isolation on a separate network segment, changing default credentials, rigorous application of updates and disabling non-essential features. The obsolescence of IT systems, already a problem for workstations, is not only a technical weakness but also the symptom of a gap between the pace of technological change and the capacity of small healthcare structures to adapt. This highlights the need for more structural, financial and training support mechanisms to maintain an adequate level of security on a national scale, in line with initiatives such as France's Ségur de la santé for hospitals, which could inspire targeted actions for self-employed professionals.
  • Artificial Intelligence (AI): a tool for both attack and defense: Artificial intelligence (AI) represents a double-edged sword in cybersecurity. On one hand, it is used by attackers to increase the sophistication and personaliization of their actions: generation of ultra-realistic phishing emails, creation of deepfakes for identity impersonation, automation of password cracking, and coordination of attacks against connected objects. In France, 82% of companies are reported to have already faced "AI-augmented" cyberattacks. On the other hand, AI offers promising perspectives for strengthening defenses: faster and more accurate threat detection through behavioral analytics, automation of incident response, and decision support for security teams. AI is therefore both a threat vector and a potential attack surface if AI systems themselves are compromised. The introduction of IoT and AI into dental practices, while driving innovation in care, will exponentially increase the complexity of cybersecurity management. Practitioners will have to secure not only their traditional IT systems but also a myriad of interconnected and intelligent devices, which will require increased expertise and vigilance — a notable challenge for small organizations.

3 Regulatory and normative framework: obligations and recommendations

Cybersecurity management in dental practices is governed by a complex but coherent set of laws, regulations and recommendations issued by national and European authorities. The complexity of this framework can be a challenge for small organizations, but understanding it is essential to ensure data protection and compliance.

The General Data Protection Regulation (GDPR)

Enforced since 25 May 2018, the GDPR (Regulation (EU) 2016/679) is the cornerstone of personal data protection in Europe and applies directly to dental practices.

  • Applicability and fundamental principles for health data: The GDPR governs all processing of personal data, whether digital (management software, electronic patient records) or on paper. Health data, because of their intimate nature, are classified as "special categories of data" (formerly "sensitive data") and benefit from reinforced protection. Their processing is in principle prohibited, except in specific cases listed in Article 9 of the GDPR, particularly when necessary for preventive medicine, medical diagnosis, the provision of care or treatment, or the management of healthcare systems and services. Dental practices must respect the fundamental principles of the GDPR: lawfulness, fairness and transparency of processing; purpose limitation (data must only be collected for specified, explicit and legitimate purposes); data minimiization (only strictly necessary data must be processed); accuracy; storage limitation; integrity and confidentiality (security obligation); and accountability (the practice must be able to demonstrate its compliance).
  • Specific obligations for dental practices: Several concrete obligations derive from the GDPR for dentists:
  • Maintain a record of processing activities: This internal document must list all personal data processing carried out by the practice (e.g. patient file management, billing, appointment booking). The CNIL offers templates to facilitate this task.
  • Inform patients: Patients must be informed clearly and accessibly about the collection and use of their data, as well as their rights (access, rectification, erasure, restriction, portability). This information can take the form of a poster in the waiting room or a notice included in documents given to patients.
  • Carry out a Data Protection Impact Assessment (DPIA):

A DPIA is required when the processing of data is likely to result in a high risk to the rights and freedoms of individuals. Large-scale handling of health data may fall within this scope.

  • Manage data breaches: In the event of a security incident resulting, for example, in the leak or loss of patient data, the practice must notify the incident to the CNIL within 72 hours if the breach poses a risk to the rights and freedoms of individuals. If the risk is high, the patients concerned must also be informed.
  • Frame relationships with processors: Practices must ensure that their service providers (software publishers, data hosts, online appointment services) offer sufficient guarantees regarding data protection. Written contracts, compliant with Article 28 of the GDPR, must formaliize these relationships.
  • Appoint a Data Protection Officer (DPO): The appointment of a DPO is mandatory in certain cases, especially for organizations whose core activities lead them to process sensitive data on a large scale. A large group practice (more than 10,000 patient records, according to one interpretation) could be affected. The DPO can be internal, external or shared.

Penalties for non-compliance: Failure to comply with the GDPR exposes dental practices to severe sanctions. These can be administrative, with fines of up to 20 million euros or 4% of global annual turnover. Criminal sanctions are also provided, for example for misuse of data for other purposes (up to 300,000 euros in fines and 5 years of imprisonment). The CNIL has already sanctioned actors in the healthcare sector for security breaches that led to medical data leaks, such as the 1.5 million euro fine imposed on Dedalus Biologie.

Health Data Hosting (HDS)

The question of the hosting of health data is crucial and specifically regulated in France.

  • Certification requirements for hosts: The "Health Data Hosting" (HDS) certification is a legal obligation in France for any entity that hosts personal health data on behalf of a third party. This concerns providers of physical or virtual infrastructure, managed service operators, software publishers in SaaS (Software as a Service) or cloud mode, and providers of outsourced backup services. This certification, issued by accredited bodies after a rigorous audit, aims to guarantee a high level of security, confidentiality, availability and traceability of hosted health data. It covers aspects such as physical security of data centers, logical security of systems, access management, backups, business continuity and data reversibility.
  • Implications for dental practices: When a dental practice chooses to outsource the storage or processing of its patients' health data — for example, by using a cloud-based practice management software, an online backup solution or a medical document-sharing platform — it has the obligation to use a provider with HDS certification for the activities concerned. It is the responsibility of the practice to verify the validity and scope of its provider's HDS certificate. The obligation to use HDS-certified hosts is a strong security measure. However, while it shifts part of the security responsibility to the provider, it does not relieve the practice of its own due diligence and responsibility as data controller.

A poor understanding of this shared responsibility can create a false sense of security, whereas the practice must ensure contractually (via GDPR clauses) and through ongoing vigilance that its processor respects its commitments.

  • Choice of compliant software and backup solutions: Practice management software must mandatorily comply with the GDPR. If the software is offered in cloud mode and hosts health data, the publisher or its hosting provider must be HDS-certified. Several criteria must be considered when choosing software, including its features, ergonomics, but also and above all its security and compliance guarantees. It is strongly recommended to host health data in France or, failing that, within the European Economic Area, to ensure the application of the GDPR and for issues of data sovereignty.

National directives and reference frameworks

In addition to the GDPR and HDS certification, several national bodies issue rules and recommendations to guide healthcare professionals in securing their information systems.

  • The General Security Policy for Health Information Systems (PGSSI-S): Developed by the Agence du Numérique en Santé (ANS), the PGSSI-S is the reference documentary corpus for the security of health information systems in France.

It applies whenever personal health data are processed digitally. The PGSSI-S includes enforceable reference frameworks (i.e. mandatory application in certain contexts) and practical guides aimed at helping healthcare actors define and achieve the appropriate levels of security.

  • Recommendations from the Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI): ANSSI is the national authority for the security of information systems. It publishes many guides and best practices, many of which are relevant to dental practices, even though they are not always specifically targeted.

Among the most important are the "IT Hygiene Guide" (which presents 42 essential measures), guides on managing ransomware attacks, preparation and management of cyber crises, and the EBIOS Risk Manager risk analysis method. ANSSI also offers support to healthcare establishments, and its recommendations, such as the "Zero Trust" security model, can inspire the approaches of practices.

  • Role and recommendations of the Agence du Numérique en Santé (ANS) and CERT Santé: The ANS plays a driving role in the digital transformation of the healthcare system and the promotion of secure e-health. It provides guides, funds security audits for establishments, and issues technical reference frameworks (for example, on electronic identification of healthcare professionals). The CERT Santé (Computer Emergency Response Team), a service of the ANS, is the alert and incident response center for cybersecurity in the healthcare sector. It operates 24/7 in the event of a major attack and regularly publishes threat overviews.
  • Directives of the Ordre National des Chirurgiens-Dentistes (ONCD): As the professional body, the ONCD also has a role to play in raising awareness and supporting practitioners on cybersecurity issues. It distributes specific recommendations such as "Good cybersecurity practices for dentists" or the "IT Security Handbook for self-employed healthcare professionals".

The ONCD emphasiizes in particular the importance of staff training, the use of secure health messaging systems (such as MS Santé), and vigilance in the selection and contracting of digital service providers.

  • Advice from the Commission Nationale de l'Informatique et des Libertés (CNIL): The CNIL is the French supervisory authority for personal data protection.

It ensures the application of the GDPR and supports professionals in their compliance efforts. It publishes numerous resources: practical guides on the GDPR tailored to healthcare professionals, recommendations on technical aspects of security (password selection, backups, website security), information on data retention periods (for example, 20 years for medical records), and self-assessment checklists.

The multiplicity of regulations and recommendations from these various bodies (GDPR, HDS, PGSSI-S, ANSSI, ANS, CNIL, ONCD) may appear complex for a dental practice. This complexity, although aimed at a high level of protection, can paradoxically become an obstacle to compliance for small organizations with limited human and financial resources. There is a need for even more targeted and pragmatic vulgariization, simplification and support tools. Nevertheless, strong synergy and coherence emerge from the messages of these various authorities: the crucial importance of regular, tested backups, robust passwords, continuous staff training and preparation for incident management is a recurring theme. This convergence reinforces the scope of the recommendations, even though the dispersion of information sources can still create some confusion for the practitioner seeking a clear and centralized roadmap.

4 Cybersecurity prevention and protection strategies for dental practices

Faced with a complex threat landscape and a demanding regulatory framework, dental practices must adopt a proactive approach to cybersecurity, combining robust technical measures and rigorous organizational practices. The objective is to develop a true culture of security, shared by the entire team.

A. Fundamental technical measures

Implementing a secure IT infrastructure is the foundation of protection.

  • Securing the infrastructure: Each workstation and server must receive particular attention: operating systems (OS) and software kept up to date through the regular application of security patches, effective and up-to-date antivirus solutions, and hardened configurations. Automatic session locking after a period of inactivity is a simple but effective measure to prevent unauthoriized access in the event of a user's temporary absence. The Wi-Fi network of the practice, if any, must be secured by strong encryption (WPA2 or, ideally, WPA3), the default router password must be changed, and the broadcasting of the network name (SSID) can be hidden. Creating a separate "guest" Wi-Fi network, distinct from the practice's internal network, is strongly recommended for patients or visitors. A firewall, hardware or software, is essential to filter communications between the practice's network and the Internet, blocking intrusion attempts and controlling incoming and outgoing data flows. The firewall built into Windows (Microsoft Defender Firewall) must be enabled and correctly configured.
  • Rigorous access and identity management: Password strength is paramount. Passwords must be long (at least 12 characters), complex (combining uppercase, lowercase, numbers and special characters), and unique for each service or application. The use of a password manager is now a recommended practice to facilitate the creation and memoriization of strong passwords, without having to write them down or store them insecurely. Passwords must be renewed regularly and never saved directly in web browsers.

Multi-Factor Authentication (MFA or 2FA), which combines something the user knows (password) with something they have (a unique code generated by an application on their phone, a physical key) or something they are (fingerprint), must be implemented whenever possible, particularly for access to sensitive data, professional software and online services. MFA can reduce unauthoriized access attempts by up to 99%. The principle of least privilege must guide the management of access rights: each user (practitioner, assistant, receptionist) must have only the rights strictly necessary to perform their tasks.

  • Backup policy: Regular and reliable backups are the best protection against data loss, whether due to hardware failure, human error or a cyberattack such as ransomware. Backups must be frequent (daily for critical data) and automated as much as possible. It is advisable to use several backup media (external hard drives, NAS servers) and to diversify them (for example, a local copy and an outsourced copy in a secure and HDS-certified cloud if health data are stored there). The "3-2-1" rule (at least three copies of the data, on two different types of media, with one copy offsite) is good practice. Crucially, local backup media must be isolated from the main IT network after each backup operation to prevent them from being encrypted by ransomware. Finally, it is imperative to regularly test the restoration of data from backups to ensure their integrity and the functionality of the recovery process. Neglecting basic IT hygiene, such as updates or reliable backups, often due to lack of time or awareness, is like leaving the door wide open to cybercriminals and constitutes a direct link to vulnerability to common attacks.
  • Encryption of sensitive data: Encryption transforms data into a format that is unreadable without the appropriate decryption key. It must be applied to data in transit (when circulating on a network), for example through the use of the HTTPS protocol for all web communications and online applications, and by encrypting email attachments containing health data if an unsecured messaging system is exceptionally used. Data must also be encrypted at rest (when stored), including on laptop hard drives, USB drives and backup media.• Software updates and security patch management: Software publishers regularly release updates to fix security vulnerabilities that have been discovered. It is vital to systematically and quickly apply these patches to all components of the information system: operating systems, antivirus, web browsers, professional software, and any other application used. It is recommended to schedule dedicated time for these maintenance operations.
  • Secure selection and configuration of professional software and specific equipment: The choice of professional software is strategic. It must be GDPR-compliant and, if cloud-hosted, the host must be HDS-certified. Compatibility with national services such as Mon Espace Santé and MSSanté is also an important criterion. It is preferable to opt for software that has received certification or listing from recognized bodies such as the French National Authority for Health (LAP certification for prescribing software) or the ANS ("Ségur" listing). Digital imaging or radiology equipment, which is increasingly connected (falling under IoT), must be secured like any other connected object: changing default credentials, regular firmware updates, and, if possible, isolation on a dedicated network segment. Electronic payment terminals must also be configured and operated securely to protect transaction data.

Organizational and human measures

Technology alone is not enough; security also rests on clear processes and aware personnel.

  • Developing an Information Systems Security Policy (ISSP) adapted to the practice:

Even for a small organization such as a dental practice, formaliizing an ISSP, even a simplified one, is a structuring step. This strategic document, drafted by the responsible practitioner, possibly with the help of external advice, defines the security objectives, the rules to be followed, the responsibilities of each person and the procedures in the event of an incident. It must be based on an analysis of the practice's own risks and be regularly updated. An ISSP, even a concise one, constitutes a formal commitment to security, which can also reassure patients regarding the protection of their data.

  • Ongoing training and staff awareness on cyber risks and good practices: The practice staff (assistants, receptionists, other practitioners) are on the front line against cyber threats. Regular training and frequent reminders on good practices are therefore essential. Topics to be addressed include the recognition of phishing emails, the creation and management of passwords, the security of workstations, the proper use of secure messaging, and the procedure for reporting a suspicious incident. Educational resources exist, such as webinars (offered by the ANS or the regional health agencies), interactive tools such as cybersecurity awareness "escape games", fake phishing campaigns to test vigilance, and reminder posters.
  • Securing communications: The use of secure health messaging systems (MSSanté, operated by ASIP Santé, accessible via software such as Mailiz) is an obligation for the exchange of personal health data between healthcare professionals, as well as with patients via their "Mon Espace Santé" portal. These systems guarantee the encryption and authentication of correspondents. In addition, basic rules of confidentiality must be respected, such as never writing patient names on unsecured documents circulating with prostheses or plaster models, in order to preserve professional secrecy.
  • Management of service providers and subcontractors: Dental practices often use external service providers for their software, data hosting, IT maintenance, or online appointment booking services. It is crucial to ensure the GDPR compliance of these subcontractors and to formaliize the relationship by written contracts including the specific clauses of Article 28 of the GDPR, which define the obligations of each party regarding data protection.
  • General IT hygiene: Simple rules of digital hygiene must be adopted by all: do not use professional computers for personal purposes, be vigilant when browsing the Internet and systematically refuse non-essential cookies on non-professional websites. Physical security of premises and equipment (locking offices, access control) is also an aspect of data protection. Clear procedures must exist for the secure decommissioning of old IT equipment, including the irreversible erasure of the data they contain.
Download the condensed guide in PDF format 3 pages: threats, checklist, emergency contacts — to print and display at the practice.
Download the PDF

Checklist of essential cybersecurity measures

Infrastructure

  • Updates: OS, antivirus, professional software and browsers kept up to date
  • Firewall: enabled and configured on all workstations
  • Wi-Fi: WPA2/WPA3 encryption, changed password, separate guest network
  • Encryption: sensitive data encrypted at rest and in transit

Access and identities

  • Passwords: 12 characters minimum, unique, password manager
  • MFA: multi-factor authentication enabled wherever possible
  • Least privilege: each user has only the rights they need
  • Auto-lock: sessions locked after inactivity

Backups

  • 3-2-1 rule: 3 copies, 2 media types, 1 offsite
  • Automated: daily for critical data
  • Isolated: media disconnected from the network after backup
  • Tested: restoration verified regularly
  • HDS: certified host if cloud backup of health data

Organization

  • ISSP: formaliized security policy, even simplified
  • Training: staff regularly made aware (phishing, passwords)
  • Secure messaging: MSSanté / Mailiz for health data exchanges
  • Contracts: GDPR clauses with all subcontractors
  • Response plan: IRP documented and known to the team

In case of incident

  • Isolate: immediately disconnect affected machines from the network
  • Do not power off: unless advised otherwise by an expert
  • Contact: CERT Santé, IT provider, Cybermalveillance.gouv.fr
  • Notify: CNIL within 72h in case of personal data breach
  • Do not pay: the ransom — no guarantee of recovery

5 Cybersecurity incident management and business continuity

Despite all preventive measures, zero risk does not exist. It is therefore imperative for a dental practice to be prepared to react in the event of a cybersecurity incident and to ensure the continuity of its activity. The absence of a tested incident response plan (IRP) and a business continuity plan (BCP) can transform an already serious incident into a potentially devastating crisis for the organization.

A. Detection, analysis and first reflexes in case of attack

Rapidly identifying an attack is crucial to limiting its impact.

  • Warning signs: An unusual slowdown of systems, the appearance of suspicious error messages, the inaccessibility of files (sometimes renamed with strange extensions), a ransom demand displayed on the screen, or abnormal network activity can all indicate a compromise.

First reflexes

  • Isolate affected systems: The first and most urgent measure is to immediately disconnect suspicious or obviously infected machines from the practice's network (unplug the Ethernet cable, disable Wi-Fi). This aims to prevent the spread of the attack, especially in the case of ransomware, which can spread rapidly to other connected workstations and servers.
  • Do not immediately shut down the compromised machine (unless advised otherwise by an expert): Although the instinct may be to shut down the computer, this action could erase volatile information in memory (RAM) that would be valuable for subsequent forensic analysis aimed at understanding the attack.

Network isolation takes priority.

  • Contact experts and authorities: It is essential to quickly call on professionals. This may be a cybersecurity-specialized IT service provider, the CERT Santé if the incident is major, or the Cybermalveillance.gouv.fr platform, which can guide and put victims in touch with local experts.
  • Document the incident: From the very first moments, it is necessary to start documenting everything observed: the time of discovery, the precise symptoms, the messages displayed, the actions already taken, etc. This information will be useful for responders and for later notifications.

Emergency contacts in case of cyberattack

Reporting and assistance

Legal obligations

  • CNIL: data breach notification within 72h — cnil.fr/notifier-une-violation
  • Filing a complaint: police or gendarmerie (preserve evidence, do not shut down machines)

Professional resources

B. Developing and implementing an Incident Response Plan (IRP)

An Incident Response Plan (IRP) is a document that formaliizes how the practice will react to a cyberattack. Its existence and its knowledge by the team enable coordinated and effective action, thereby reducing damage and downtime. ANSSI offers guides for managing cyber crises that can inspire its drafting.

  • Key stages of an IRP:
  • Preparation: Identify the practice's critical information assets (patient records, professional software, backups), define a small response team (the practitioner, a lead assistant), clarify the roles and responsibilities of each, and list the key contacts (IT provider, cybersecurity expert, insurer, CNIL, ONCD).
  • Detection and analysis: Confirm that a security incident has indeed occurred, identify its nature (ransomware, successful phishing, etc.), assess its scope (which machines, which data are impacted) and its severity.
  • Containment: Take measures to prevent the attack from spreading further (for example, isolating other network segments if necessary, blocking compromised user accounts).
  • Eradication: Once the attack is contained, identify and eliminate its root cause (remove the malware, fix the exploited vulnerability, revoke fraudulent access).
  • Recovery: Restore the affected systems and data to a normal state of operation, generally from healthy and verified backups.
  • Lessons learned (post-incident): After the incident is resolved, conduct a "cold" analysis to understand what happened, assess the effectiveness of the response, and identify improvements to be made both to the IRP and to prevention measures.
  • Crisis communication: Communication management is an essential aspect of incident response.
  • Internal communication: Clearly inform the staff of the practice of the measures taken and the instructions to follow.
  • Communication with patients: If the data breach is likely to pose a high risk to the rights and freedoms of patients (for example, leak of medical records), the GDPR requires them to be informed. This communication must be transparent and indicate the measures taken.
  • Communication with authorities: Depending on the nature and severity of the incident, several notifications may be mandatory or recommended: notification to the CNIL within 72 hours in the event of a personal data breach presenting a risk; reporting to ANSSI via the CERT Santé for major incidents; filing a complaint with the police or gendarmerie. ANSSI offers a specific guide to anticipate and manage cyber crisis communication.
  • Decision whether or not to pay the ransom: In the case of a ransomware attack, the question of paying the ransom inevitably arises. The authorities, in particular ANSSI, strongly advise against paying. Payment offers no guarantee of recovering the data (cybercriminals may not provide the decryption key, or may provide a key that does not work or only partially), it encourages attackers to continue their criminal activities, and it does not protect against future attacks. This recommendation sometimes clashes with the reality of total paralysis of activity and the absence of functional backups, placing victims in a complex ethical, financial and operational dilemma. If payment is considered as a last resort (critical data otherwise irrecoverable), it should only be done after consultation with cybersecurity experts and the competent authorities.
  • Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP)

    Beyond the immediate response to the incident, it is crucial to have thought about how the practice can continue to operate, even in degraded mode, and how it can return to normal.

    Objective: The BCP aims to maintain the critical activities of the practice during the crisis (for example, handling emergencies), while the DRP details the steps for restoring all systems and operations after the incident.

    Elements of a BCP/DRP for a dental practice:

    • Identification of the activities and data absolutely critical for operations.
    • Implementation of alternative manual procedures (for example, temporary use of paper patient records, manual agenda management, paper consent forms).Clear strategies for restoring data from backups (definition of priorities, estimation of restoration timescales).
    • Communication plan to inform patients of disruptions and temporary arrangements.
    • Plans must be documented, known to the team, and above all regularly tested (for example, through simulations) and updated according to changes in the practice and feedback. The lack of an emergency plan is a major vulnerability identified in many structures.

    The contribution of cyber insurance

    Taking out a cyber insurance policy can complement prevention and response measures.

    • Coverage offered: Cyber insurance contracts can cover various costs associated with a cyberattack: cybersecurity expert fees for investigation and remediation, data and systems restoration costs, business interruption losses due to activity disruption, patient and authority notification costs, and the civil liability of the practice if third parties suffer harm as a result of a data leak. In 2023, 69% of French companies (all sectors combined) had taken out cyber insurance.
    • Associated services: Some insurers also offer prevention services, such as vulnerability audits, cybersecurity training for staff, or access to an assistance hotline in the event of an incident.
    • Points of attention: It is crucial to carefully read the general and particular conditions of the insurance contract to fully understand the extent of coverage, exclusions, deductibles, compensation ceilings, and the obligations of the insured in terms of preventive security measures.

    The effective management of a major incident often exceeds the internal capabilities of a dental practice, highlighting its dependence on an external support ecosystem (specialized service providers, CERT Santé, Cybermalveillance.gouv.fr, insurers). Prior knowledge of these actors and how to engage them is therefore a key component of incident preparedness.

    6 Resources and support available

    Faced with the challenges of cybersecurity, dental practices are not alone. Many public bodies and professional institutions offer resources, guides and support to help them strengthen their digital security. The wealth of these resources is an asset, but their diversity can sometimes make information difficult to access for a practitioner seeking prioritized advice.

    A. Public bodies and support platforms

    • Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI): ANSSI is the national reference authority for cybersecurity and cyber defense. Its mission is to prevent and react to IT incidents. For professionals and businesses, including dental practices, ANSSI provides a wide range of resources:
    • Guides and best practices: The "IT Hygiene Guide", which compiles 42 essential measures, is a fundamental document. ANSSI also publishes thematic guides on the prevention of ransomware attacks, cyber crisis management, securing industrial information systems (some principles of which can apply to connected medical equipment), and the EBIOS Risk Manager risk analysis method.
    • Training and awareness: Although its training is often intended for specialized audiences, the principles and recommendations of ANSSI inform many awareness actions.
  • Agence du Numérique en Santé (ANS) and CERT Santé: The ANS has the mission of accompanying the digital transformation of the French healthcare system, ensuring in particular the security and interoperability of the systems.
  • CERT Santé: The government center for monitoring, alerting and responding to IT attacks in the healthcare sector (CERT Santé) is an operational service of the ANS. It provides 24/7 assistance to healthcare and medico-social establishments in the event of a major cybersecurity incident. It also issues alerts and information bulletins on threats.
  • Documentary resources: The ANS is responsible for the General Security Policy for Health Information Systems (PGSSI-S), which constitutes the reference framework for digital security in healthcare. It also publishes handbooks, technical reference frameworks (for example on electronic identification) and organizes awareness and training webinars. The CaRE program (Cybersecurity Acceleration and Resilience of Establishments) aims to raise the level of security of establishments; although mainly focused on larger structures, its lessons can be useful.
  • Commission Nationale de l'Informatique et des Libertés (CNIL): The CNIL is the French authority for the protection of personal data. It ensures the application of the GDPR and supports professionals in their compliance process.
  • GDPR guides and recommendations: The CNIL offers a wide range of content specifically intended for healthcare professionals to help them understand and apply the GDPR. This includes practical fact sheets on patient rights, maintenance of the processing register, carrying out DPIAs, management of data breaches, etc.
  • Security advice: The CNIL also publishes recommendations on technical aspects of security, such as the choice of strong passwords, good backup practices, website security, and protection against ransomware.
  • Cybermalveillance.gouv.fr: This government platform has the mission of assisting victims of cyber-malicious acts (individuals, businesses, local authorities), raising their awareness of digital risks and monitoring the threat landscape.
  • Victim assistance: The site offers an online diagnostic tool to identify the type of cyber-malicious activity encountered and provides tailored advice. It also allows victims to be put in touch with local listed service providers capable of intervening to resolve the incident.
  • Awareness: Cybermalveillance.gouv.fr publishes many practical sheets and quick-response guides on a variety of subjects (phishing, ransomware, security of connected objects, passwords, backups), as well as awareness kits. The platform had a strong audience in 2024, with more than 5.4 million unique visitors.
  • Professional bodies and associations

    Ordre National des Chirurgiens-Dentistes (ONCD): The ONCD plays an important role in informing and raising awareness among its members about ethical and regulatory obligations, including those relating to cybersecurity and data protection.

    • Publications and guides: The Order regularly disseminates information via "La Lettre de l'Ordre des Chirurgiens-Dentistes", which addresses cybersecurity topics. It also provides practitioners with specific documents such as the "Practical Cybersecurity Sheet for Self-Employed Practitioners" or an "IT Security Handbook".
    • Support: The ONCD collaborates with bodies such as the ANS to develop the profession's digital tools, for example with regard to the integration of secure messaging into professional software.
    • Other professional associations or dental unions: Organizations such as the Union Française pour la Santé Bucco-Dentaire (UFSBD) or the Association Dentaire Française (ADF) also offer resources and information on cybersecurity and digital management of the dental practice. They can relay the recommendations of authorities or develop their own awareness tools.

    The effectiveness of this support ecosystem largely depends on a proactive approach by the dentists themselves. The mere existence of guides and platforms is not enough; individual and collective awareness of the issues, as well as active engagement in seeking information and implementing recommendations, are essential. Professional bodies and continuing education programs have a crucial role to play in encouraging this commitment. In addition, close collaboration between public entities and representatives of the profession is essential to ensure that prevention and assistance messages are adapted to the realities and specific constraints of dental practices. The following table summariizes the main actors and their contributions.

    OrganizationMain missionResources / supportWebsite
    ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information)Define cybersecurity standards and best practices, prevent threatsTechnical guides (IT hygiene, ransomware, crisis management), risk analysis methodsssi.gouv.fr
    ANS (Agence du Numérique en Santé) / CERT SantéSupport the secure digital transformation of the healthcare sector. Assistance in case of major incidentPGSSI-S, reference frameworks, webinars, handbooks. 24/7 assistance from CERT Santéesante.gouv.fr
    CNIL (Commission Nationale de l'Informatique et des Libertés)Ensure compliance with the GDPR and the protection of personal dataGDPR guides for healthcare professionals, security recommendations (passwords, backups), toolscnil.fr
    ONCD (Ordre National des Chirurgiens-Dentistes)Regulate the profession, disseminate good ethical and regulatory practicesCybersecurity practical sheets, information articles, recommendations specific to the professionordre-chirurgiens-dentistes.fr
    Cybermalveillance.gouv.frAssist victims of cyber-malicious acts, raise awareness of digital risksOnline diagnostic, quick-response sheets, connection with service providers, awareness campaignscybermalveillance.gouv.fr

    7 Conclusion

    Cybersecurity has become an unavoidable priority for dental practices. The growing digitaliization of the profession, while bringing undeniable benefits in terms of efficiency and quality of care, is accompanied by increased exposure to cyber threats. The criticality of the health data handled, the commercial value of this information, and the vulnerabilities inherent to small organizations make dental practices attractive targets for attacks with potentially severe consequences, ranging from the paralysis of activity to serious breaches of the confidentiality of patient data. Threats such as ransomware and phishing are particularly concerning, and the emergence of new attack vectors linked to the Internet of Things and artificial intelligence further complicates the landscape.

    Faced with these challenges, a strict regulatory framework, built around the GDPR and the specific requirements for health data hosting (HDS), imposes precise obligations on practitioners regarding data protection and information systems security. Complying with this is not only a legal necessity, but an ethical imperative and a guarantee of trust towards patients. Cybersecurity should no longer be seen as a technical constraint or a superfluous expense, but as a strategic investment essential to the long-term stability and reputation of the practice.

    To navigate this complex environment, dentists can rely on a range of preventive and protective measures, both technical (infrastructure security, access management, robust backups, encryption) and organizational (security policy, staff training, provider management). The development of incident response plans and business continuity plans is also crucial to minimize the impact of a successful attack. Many resources and support structures exist

    — ANSSI, ANS, CNIL, ONCD, Cybermalveillance.gouv.fr — to guide professionals on this path.

    Ultimately, cybersecurity in dental practices illustrates the broader challenges of the digital transformation of the healthcare sector. A constant balance must be sought between the adoption of technological innovations to improve care, the intangible protection of personal and medical data, the economic constraints of practitioners, and compliance with a dense regulatory framework. The future resilience of practices against constantly evolving threats will depend not only on the adoption of technological security solutions, but more fundamentally on their ability to anchor a genuine culture of cybersecurity within their daily practice. This implies vigilance at all times, continuous training of the entire team, agile adaptation to new threats, and active collaboration within the healthcare ecosystem to share knowledge and good practices. It is at this price that dental practices will be able to continue to practice their art with complete peace of mind, guaranteeing the security and trust of their patients in an increasingly connected world.