Industry Insight
The Health Information Privacy Code (HIPC) applies additional obligations to dental practices beyond the standard Privacy Act โ breaches of patient health information face stricter regulatory scrutiny.
Why Dental Businesses Need Cyber Insurance
Dental practices hold some of the most sensitive data in the health sector: complete dental health histories, radiographs, treatment records, prescription information, patient photos, and detailed personal and financial information including payment card and health insurance details. This data is protected under both the Privacy Act 2020 and the Health Information Privacy Code (HIPC) โ which imposes additional obligations for health information specifically. A breach of patient health records triggers significant regulatory obligations and reputational risk in a sector where patient trust is fundamental.
Top Cyber Risks for Dental Businesses
- !Patient health record breach (dental history, radiographs, treatment records)
- !Practice management software ransomware
- !Payment card data theft
- !Health insurance fraud via compromised accounts
- !Phishing targeting reception and practice managers
Recommended Coverage for Dental Businesses
Typical Premium Range
Premiums vary based on revenue, data held, security controls in place, and coverage limits selected. Our brokers will find the best rate for your specific profile from multiple insurers.
Why Dental Practices Need Cyber Insurance
Dental practices may be smaller businesses, but they hold data that is extremely sensitive under New Zealand law. Patient dental records โ including health histories, radiographs, treatment records, prescription documentation, and patient photos โ are classified as health information and subject to both the Privacy Act 2020 and the Health Information Privacy Code (HIPC). The Health Information Privacy Code imposes obligations that go beyond the standard Privacy Act framework, including specific rules about who can access patient information and how it must be protected.
Health Information: A High-Risk Data Category
Under the Privacy Act 2020, health information is explicitly recognised as a sensitive data category. A breach of patient dental records is far more likely to meet the serious harm threshold for mandatory notification than a breach of general business contact information. This means dental practices โ unlike many small businesses โ face a high practical probability of mandatory notification obligations if patient records are compromised. The costs of notification, OPC investigation response, and patient communication can be significant for a practice without dedicated compliance resources.
Practice Management Software: The Critical Vulnerability
Most NZ dental practices rely on a small number of specialised practice management software platforms for patient records, appointment booking, treatment charting, and billing. These platforms hold comprehensive patient data and are connected to both clinical records and payment systems. Ransomware that targets dental practice management systems can simultaneously lock patient records (preventing treatment) and billing systems (preventing revenue collection). Recovery from such an attack typically takes one to two weeks โ during which appointments may need to be cancelled and manual backup records used.
Payment Card Data and Health Insurance
Dental practices process significant payment card transactions and interact with Southern Cross and other health insurance funds for claims processing. Compromise of payment terminals or practice management system billing modules can expose patient payment card data. Health insurance credential theft โ where criminals use compromised patient information to make fraudulent health insurance claims โ is also a growing concern in the health sector.
Ransomware and Patient Care Impact
When ransomware encrypts a dental practice's systems, the impact extends beyond data and financial loss to direct patient care impact. Without access to patient health records, treating dentists cannot safely proceed with complex treatments where knowledge of allergies, medications, and prior treatment history is essential. This creates both clinical risk management obligations and potential professional liability exposure if treatment complications arise in the absence of available records.
Building Patient Trust After a Breach
Patient trust is the foundation of any healthcare practice. A cyber incident that exposes patient health information โ or forces a practice to contact patients to notify them of a breach โ can cause lasting reputational damage. Cyber insurance includes crisis communications support to help manage patient communication professionally and minimise the reputational impact of an incident.
Written by the CyberCover Advisory Team
Licensed NZ insurance advisors specialising in cyber risk for New Zealand businesses. All content reviewed for accuracy and NZ regulatory compliance.
Last updated: May 2026 ยท Get personalised advice โ
Frequently Asked Questions
Does the Health Information Privacy Code impose additional obligations on dental practices after a breach?
Yes โ the Health Information Privacy Code applies specific rules about health information handling and protection. A breach of patient dental records is subject to both the standard Privacy Act 2020 breach notification framework and HIPC-specific obligations. In practice, dental practices are likely to face mandatory notification obligations to the Privacy Commissioner for significant patient record breaches.
What if ransomware locks our patient records during a busy appointment day?
Cyber insurance responds immediately โ your insurer provides 24/7 access to a cyber incident response team who assess the attack, work to restore systems, and advise on patient communication. Business interruption coverage compensates for appointment cancellations and lost revenue during the recovery period.
Are we covered if a member of staff accidentally emails patient records to the wrong person?
Many cyber policies include coverage for accidental disclosure as well as deliberate attacks. An email sent to the wrong recipient containing patient health records is a privacy breach that may trigger notification obligations โ cyber insurance covers the legal advice, notification costs, and OPC response.
Does cyber insurance cover the cost of patient notification letters and communications?
Yes โ breach notification costs including postage, printing, patient communication materials, and credit monitoring services where offered are covered under standard cyber insurance policies. For dental practices with hundreds or thousands of patient records, these costs can be substantial.