Dental Records Are Medical Records
A point that gets missed in most dental practice cybersecurity conversations: the data your practice holds is clinical health data. X-rays, periodontal charts, treatment histories, medical history questionnaires asking about blood thinners, bisphosphonates, and cardiac conditions — this is special category personal data under UK GDPR Article 9, subject to the strictest processing obligations.
A breach of a dental practice's patient records is not equivalent to a breach of a retail customer database. It is a health data breach, and the ICO treats it accordingly. Dental practices have received ICO enforcement notices for inadequate security of patient records — both physical and digital.
Your website and patient-facing systems are the digital entry points to that data.
The NHS Contract Dimension
UK dental practices operating under NHS contracts are additionally subject to NHS data security requirements. The Data Security and Protection Toolkit (DSPT) — the NHS's annual self-assessment framework — applies to all organisations handling NHS patient data, including primary care dental practices.
The DSPT requires practices to demonstrate compliance across ten standards covering leadership, training, data handling, and technical security. Achieving "Standards Met" is required for maintaining NHS contracts; CQC inspections increasingly reference DSPT compliance as part of their assessments of well-led organisations.
Specific DSPT technical requirements relevant to your website and systems: HTTPS on all patient-facing digital services, MFA on systems that hold or process NHS patient data, a formal process for patching software vulnerabilities, and a documented incident reporting procedure.
Practices that handle NHS patient data and have not completed their annual DSPT submission, or whose submission is not at "Standards Met," risk NHS contract issues and are likely to have identifiable security gaps.
Your Practice Website: What It Probably Collects
Even a simple dental practice website typically processes personal data in several ways:
**Online appointment request forms** — name, date of birth, contact details, and sometimes an indication of the treatment type (which can imply health information). If you ask "Are you an existing patient?" with a patient number field, that is health data processing.
**New patient registration forms** — full medical history questionnaires submitted online are the most sensitive data your website handles. If these are sent by standard email, stored in unprotected form submissions, or accessible via a guessable URL, that is a significant data breach risk.
**Payment processing** — if you take deposits for private treatments online, payment card security applies. Using a payment platform (Stripe, Square, PayPal) correctly offloads card data handling to them; if you have built a custom payment flow, that is a different and more complex risk.
**Live chat** — practices using live chat widgets (Intercom, Drift, WhatsApp Business integration) may be capturing patient queries containing health information. Check where that chat data is stored and whether it is covered by your DPAs.
Specific Risks for Dental Practice Websites
**Practice management system integrations** — systems like Dentally, SFD, R4, Exact (Software of Excellence), and Carestream Dental increasingly offer patient-facing portals integrated with your website. The security posture of these integrations — specifically whether authentication is strong enough and whether patient data is siloed correctly between patients — deserves scrutiny. IDOR vulnerabilities (see our dedicated article) in patient portals have occurred in healthcare settings.
**Booking system widgets** — third-party booking widgets embedded in your site (Doctify, MyHealthcare, or the booking module of your PMS) are JavaScript that runs in your patients' browsers. If those third-party scripts are compromised (a supply chain attack on the widget provider), malicious code runs on your site. This is the same vector as Magecart attacks on e-commerce sites, applied to appointment booking.
**Google Reviews manipulation** — your Google Business Profile and NHS Choices listing are not website vulnerabilities, but they are the most visible part of your digital presence. GBP hijacking (where someone gains access to your listing) is rare but has occurred at dental practices. Secure the Google account associated with your GBP with MFA and a unique password.
**Ransomware via the website** — a compromised dental practice website can be used as an initial access point for a broader network compromise. If your website server is on the same network as your PMS server (common in smaller practices without network segmentation), a web server compromise can escalate to PMS access. This is the pathway by which ransomware attacks against NHS dental data have begun.
UK GDPR: What Dental Practices Must Have in Place
**Privacy notice** — your website must display a privacy notice explaining what patient data you collect, the lawful basis (for NHS patients this is the performance of a task in the public interest; for private patients it is typically contract), how long you retain it, and how patients can exercise their rights.
**Explicit consent for special category data** — processing health data requires explicit consent or another specific Article 9 condition. A tick box on a registration form that says "I consent to my data being used for treatment" is not adequate. Consult the ICO's guidance on special category data for the specific wording and process required.
**Data Processing Agreements** — every third-party system that processes patient data on your behalf (your PMS vendor, your booking platform, your live chat provider) needs a DPA. Most major vendors have these available; they need to be signed.
**Breach notification procedure** — if patient health data is compromised, you have 72 hours to notify the ICO. NHS practices also have obligations to notify NHS England and potentially patients directly. Having a written procedure in place before an incident means the 72-hour clock does not find you starting from scratch.
The Practical Starting Point
MFA on your PMS and on the email account associated with your NHS registration. If your PMS supports MFA (most modern cloud-based PMS platforms do), enable it today. If it does not, raise it with your vendor — it is a legitimate security requirement you can press them on.
Yrzo AI scans the public-facing elements of your practice website — authentication configuration, form security, HTTPS implementation, security headers, and exposed admin interfaces — in under 20 minutes. From £99 at yrzoai.dev.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →