AI usage policy for law firms and dental offices
A copyable staff AI policy, plus browser and device controls to manage client data, approved tools and incident reporting.
Read articleCompliance
Nine checks for a dental security provider: devices, accounts, HIPAA responsibilities, response, evidence, backups and the full price.
Choose a dental security provider by asking it to prove the scope behind your insurance answers. A renewal is a useful deadline for checking what is deployed, who acts and which records the practice can produce. It is not a reason to buy an undefined bundle.
Obsidian Ridge's Ridge Core includes endpoint MDR and Microsoft 365 or Google Workspace ITDR at $25 per person per month, month-to-month with no minimum and business onboarding separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Ridge Plus costs $50 per person per month on an annual term, billed monthly, with no minimum. It adds staff training, email-security configuration and a secure browser to Ridge Core; business onboarding is separate. The checks below apply to our proposal too. Compare the dental programme, MDR provider comparison and practice cost guide against the same inventory.
Ask which control each question refers to and what evidence supports the answer. Keep a dated copy. Record exceptions and partial coverage. A future deployment date is different from a control already operating. Use free application help when the wording is unclear.
Include front-desk computers, clinical workstations, laptops and servers. Identify devices the provider cannot support and the person responsible for them. A staff-based rate does not replace a machine inventory. Ask how changes to the inventory will be recorded during the policy period.
Identify the Microsoft 365 or Google Workspace tenant, administrator accounts and MFA coverage. Managed ITDR and endpoint MDR cover different activity. Require the provider to state supported Google or Microsoft actions rather than relying on a generic identity-security label.
Who watches at night? Who may isolate a workstation? Who contacts the practice and who restores its applications? Our SOC and follow-through responsibilities are stated above. Your IT provider and clinical software vendor still need named roles for their systems.
The ADA's HIPAA resources help dental practices navigate their obligations; they do not certify a security vendor. Determine whether a provider is a business associate for the engagement and address the required agreement. Ask which safeguards it operates and which remain with the practice. ADA HIPAA resources; HHS business-associate guidance.
Ask for a redacted device-coverage record, incident report and training-completion export. Check whether each identifies the relevant period and systems. Do not treat a purchased licence as proof of completed training or uninterrupted monitoring. The training comparison separates delivery from reporting.
Get the backup scope and a dated restore-test result from the responsible provider. Ask how restoration of the practice-management system is coordinated. Obsidian Ridge does not include managed backup in the monthly tiers; the Sprint can check the evidence without becoming the backup operator.
Identify the billed unit, contract, onboarding, log add-ons and separately billed response work. Business setup here is $500 for up to 25 machines, or $1,000 for 26 to 100. Core is month-to-month; Plus is annual, billed monthly. The pricing page and cost guide identify those boundaries. Do not compare a device rate with a person bundle as though they include the same services.
The practice must approve truthful answers and understand the exceptions. The security provider explains its controls; the broker and carrier handle the insurance decision. Assign each remaining gap to a person and a date instead of letting it disappear into a proposal.
HHS describes risk analysis, access safeguards, training, activity review and contingency planning as parts of the Security Rule programme. Insurance evidence can overlap with that work, but the application does not replace the practice's full programme. HHS Security Rule summary.
Keep the responsibilities with the people who can perform them. A monitoring provider, IT firm, practice manager and adviser may each hold different records. The useful outcome is an answer the practice understands and can support.
Obsidian Ridge offers a free, one-off cyber-insurance questionnaire review for small businesses. Email your carrier's questionnaire to security@obsidianridge.io; our CISSP-led practice replies within one business day, serving the Research Triangle and businesses across the United States. We are not an insurance agent or broker. Use the application-help page and questionnaire worksheet. The Readiness Sprint costs $1,500 to $3,500 once for a 7-business-day engagement. The deliverable is the same at each scope: a signed evidence pack and a record of controls and gaps. The Sprint is the paid evidence engagement if that additional work is needed. It does not guarantee insurance approval or a particular premium.
Fetched October 2, 2026.
Last updated
October 2, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Use the actual application, then verify covered devices, identity controls, response ownership, backup tests, training records and the evidence supporting each answer. Record partial deployment and gaps instead of assuming the provider covers everything.
Determine whether the provider is a business associate for the engagement and obtain an appropriate business associate agreement where required. HIPAA responsibilities depend on the services and information involved, not a vendor logo.
No. The carrier decides what it accepts and what coverage it offers. A provider can explain controls and organize evidence, but should not guarantee approval or a premium outcome.
Obsidian Ridge offers a free, one-off cyber-insurance questionnaire review for small businesses.
Email your carrier's questionnaire to security@obsidianridge.io; our CISSP-led practice replies within one business day, serving the Research Triangle and businesses across the United States. We are not an insurance agent or broker.
Related reading
A copyable staff AI policy, plus browser and device controls to manage client data, approved tools and incident reporting.
Read articleCompare five SIEM options on evidence, retention, response, pricing, contract terms and minimums for a small practice.
Read articleMonthly costs for 5, 10 and 20 people, with onboarding, contract terms and the work a medical or dental practice still needs.
Read article