Book a call
Signal Edition 2026

Canadian Dental Cybersecurity & Resilience Assessment Findings

Findings from 453 Canadian dental practices assessed between 2014 and 2025. A preliminary signal intended to support the development of a shared benchmark for dental cyber resilience in Canada.

Prepared by
Anne Genge, BA, CIPP/C
Practices assessed
453
Assessment period
2014โ€“2025
Version
1.0 ยท 2026

Where capability was absent, undocumented or not demonstrated

100%a governance documentation gap
453 of 453
95.6%no formal training reported
433 of 453
92.6%no documented AI governance policy
163 of 176
91.5%recovery issues identified
161 of 176
90.1%no evidence of proactive detection
408 of 453
74.6%assessment threshold not met
338 of 453

Important information

How to read this report

  • This report is general educational and informational material. It is not legal advice and is not a compliance assessment of any individual practice.
  • The 453 assessed practices are not a representative sample of Canadian dentistry. Findings describe the practices assessed, not the profession as a whole.
  • Findings reflect conditions observed at the time each assessment was conducted between 2014 and 2025. They do not establish current prevalence in 2026.
  • Findings do not, by themselves, establish negligence, legal compliance, or non-compliance on the part of any practice.
  • Recommendations are general. They require adaptation to the requirements and circumstances that apply to a given practice.
  • The six-domain framework described here is preliminary. It is not a certification, a regulatory approval, or a guarantee against incidents or recovery failure.

What the findings describe

Throughout this report, a finding means that a control or practice was absent, not documented, or not demonstrated during assessment. This edition does not classify each finding by verification method, and a finding should not be read as confirmation that a control was entirely absent in operation. Where a figure rests on information provided by the practice, that is stated alongside it.

Findings at a glance

What the assessments found

Denominators differ between findings and are shown with every figure. The recovery and AI findings draw on subsets of the dataset and should not be read as covering all 453 practices.

Governance & leadership

Zero

practices had complete governance documentation at assessment

Every assessed practice had at least one significant gap in documented policy, training, accountability, or awareness. In many cases the documentation was absent rather than incomplete.

453 of 453 practices ยท n = 453 ยท documentation review

Human readiness

95.6%

did not report a formal cybersecurity awareness training program

4.4% reported a formal training program. The absence of a reported program does not by itself establish the level of staff knowledge or capability.

433 of 453 practices ยท n = 453 ยท reported by practice

AI readiness & governance

92.6%

had no documented AI governance policy

13 of 176 practices had a policy in place. The absence of a policy does not establish whether or how AI tools were being used.

163 of 176 practices assessed after AI measures were introduced

Recovery & continuity

91.5%

had issues identified that could materially affect recovery

Backup and recovery assessment identified issues affecting recovery expectations in 161 of 176 practices reviewed.

161 of 176 practices assessed for backup and recovery

Detection & response

90.1%

had no evidence of proactive detection and response capability

Evidence of a proactive capability to detect or respond to a cyber threat was not found in 408 of 453 practices.

408 of 453 practices ยท n = 453

Technical safeguards

74.6%

did not meet this report's assessment threshold for technical controls

25.4% met the threshold applied in these assessments. The threshold is internal to this report and does not represent a legal or regulatory standard.

338 of 453 practices ยท n = 453

On denominators

Four findings are based on all 453 assessed practices. The recovery finding is based on 176 practices that underwent backup and recovery assessment. The AI finding is based on 176 practices assessed after AI governance measures were introduced. These two groups of 176 are not assumed to be the same practices.

Executive summary

What these assessments observed

Canadian dentistry has adopted digital technology broadly over the past decade. Electronic records, digital imaging, cloud services, remote access, online communications, and more recently artificial intelligence tools are common across the practices assessed for this report.

Across 453 assessments conducted between 2014 and 2025, gaps in documented governance, recovery readiness, detection capability, and staff training were found consistently. Every assessed practice had at least one significant governance documentation gap, and the majority had no documented or demonstrated capability in each of the other areas measured.

An interpretation, not a measured trend

The observation that resilience has not advanced at the same pace as technology adoption is the author's interpretation of patterns seen across these assessments. It is not a longitudinal finding. Assessment methods and evaluation criteria changed over the observation period, and results from different years were not standardised for comparison. This report does not measure change over time.

The goal is not perfection. The goal is progress.

Develop a shared benchmark

A dental-specific measurement framework would allow resilience to be assessed consistently and tracked over time, alongside the legal and professional obligations that already apply.

Conduct a broad measurement initiative

Wider participation would give a more complete picture of resilience across the profession than assessment data alone can provide.

Look beyond technology management

Governance, accountability, recovery readiness, detection, and human preparedness each shape resilience alongside technical controls.

About this report

Why this report exists

Canadian dental practices depend on digital technology for patient care, practice operations, communication, imaging, records management, and increasingly for artificial intelligence applications. As that dependence has grown, cybersecurity, privacy, and operational resilience have become more significant components of practice management.

This report draws on assessment data from 453 Canadian dental practices assessed between 2014 and 2025 to describe patterns observed across those assessments. Its purpose is not to evaluate compliance, rank practices, or estimate how common these conditions are across Canadian dentistry. It is to describe what was found, identify areas where support may be useful, and contribute to discussion about how resilience might be measured more consistently.

Cyber resilience is not solely a technology issue.

It touches leadership, governance, privacy, business continuity, and patient trust. Addressing it involves decisions that sit with practice owners as well as with the technical providers who support them.

Anne Genge

About the author

Anne Genge

BA, CIPP/C

Anne Genge began working in dentistry in 1994 and has more than 30 years of experience with dental professionals and practices. She is a speaker and educator on privacy, cybersecurity, and AI governance in dental and healthcare settings, and a contributor to Oral Health Journal and Dental Tribune International.

This report was authored by Anne Genge, drawing on assessment data collected across two Canadian dental cybersecurity organizations between 2014 and 2025. See the disclosure section for the author's commercial relationships with those organizations.

Dataset & methodology

What was measured, and how

The report is based on assessment data from 453 unique Canadian dental practices assessed between 2014 and 2025, drawn from the assessment records of two organizations.

453Unique practices assessed
2014โ€“2025Assessment period
360Alexio Corporation assessments (79.5%)
93Myla Training Corp assessments (20.5%)

The dataset includes practices from multiple provinces reflecting a range of practice sizes, operational models, and technology environments. To protect confidentiality, provincial-level findings are not reported and no practice is identifiable in this report. Assessment methods included consultant assessments, full cybersecurity assessments, and client-generated assessments.

Limitations

  • The dataset is not a statistically representative sample of Canadian dental practices, and findings should not be read as national prevalence estimates.
  • Practices were not randomly selected. They entered the dataset through assessment activity, which may bias the sample toward practices already seeking help or already engaged with a provider.
  • Assessment methods and evaluation criteria changed across the observation period. Results were not standardised to make different years comparable.
  • Findings are pooled across 2014 to 2025. They describe the period as a whole and do not establish conditions in any single year, including 2026.
  • Not all measures were available across all assessment types. Denominators are reported with each figure.
  • AI governance measures were introduced in later assessment periods and apply to a subset of the dataset only.

Interpretation of findings

Findings reflect conditions observed at the time each assessment was conducted. The presence of a finding should not be interpreted as evidence of negligence, non-compliance, or inadequate professional practice. Resilience exists on a continuum, and practices continue to change their capabilities over time.

A signal, not a census

The value of this report lies in the patterns it describes and the discussion it may support, not in the precision of any single figure.

Definitions & evidence basis

What each finding means

The terms below carry specific meanings in this report. Where a definition rests on a threshold or criterion internal to these assessments, that is stated.

Significant governance gap

One or more absent or incomplete items in the written cybersecurity and privacy documentation reviewed at assessment. Based on document review.

Formal training program

A structured cybersecurity awareness training program reported by the practice at assessment. Based on information provided by the practice, not on testing of staff knowledge.

Proactive detection and response

Evidence at assessment of a capability to detect and respond to cyber threats. Recorded as absent where no such evidence was identified.

Recovery issue identified

An issue found during backup and recovery assessment that could materially affect recovery. This report does not present these findings as the results of full restoration testing.

Assessment threshold, technical controls

A threshold applied within these assessments, met when a practice had six or more of thirteen core technical controls in place. The threshold is internal to this report.

Documented AI governance policy

A written policy governing the evaluation, approval, or use of AI-enabled tools, identified at assessment in practices assessed after AI measures were introduced.

On the technical assessment threshold

The six-of-thirteen threshold is an internal assessment measure developed for these reviews. It is not drawn from, and should not be read as equivalent to, any external standard or regulatory requirement. Meeting the threshold does not establish legal compliance, adequate overall security, or that a practice would withstand or recover from an incident.

Readers looking for an externally established baseline for small and medium organizations may wish to consult the Canadian Centre for Cyber Security's baseline controls, referenced at the end of this report. That guidance is provided as context and was not used to produce the figures in this report.

On verification

This edition does not separately classify each finding as confirmed absence, undocumented, self-reported, or technically tested. Findings should be read as the absence of documented or demonstrated capability at the time of assessment. Where a figure rests on information provided by the practice rather than on review or observation, it is labelled as reported.

Domain one of six

Recovery & continuity

91.5% of practices assessed for backup and recovery had issues identified that could materially affect their ability to recover.

161 of 176 practices assessed for backup and recovery ยท 8.5% had no such issues identified

No issues identified โ€” 8.5% (15 of 176) Issues identified โ€” 91.5% (161 of 176)

Expectations and assessment findings diverged

Many practices assessed for backup and recovery expected that they could recover from a cyber incident or technology failure. Assessment frequently identified gaps between those expectations and what the backup arrangements in place appeared able to support.

While many practices had invested in backup technology, recovery capability was often assumed rather than verified. Issues identified included untested backups, recovery timelines that had not been established, and differences between what practices believed their backup solution covered and what it appeared to cover.

Having backups and being able to recover are not the same thing.

The testing gap

Among the most common findings was the absence of backup testing. Practices often reported confidence that backups were working because backup jobs appeared to complete successfully, without formal recovery testing to confirm that data could be restored completely, accurately, and within an acceptable timeframe.

Recovery is a continuity issue

Extended downtime can affect patient scheduling, clinical operations, treatment planning, financial operations, communications, and patient trust. Recovery capability is a component of organizational resilience rather than a purely technical concern.

Recommended action

Test your backups and verify your ability to recover. Recovery plans, restoration procedures, and recovery timelines are worth reviewing and validating regularly so that recovery capability matches practice needs and patient care requirements.

Key takeaway

Recovery confidence is worth basing on testing rather than assumption.

Scope note

This finding covers the 176 practices that underwent backup and recovery assessment, not all 453 practices in the dataset. It reflects issues identified during assessment and is not the result of full restoration testing.

Domain two of six

Governance & leadership

Not one of 453 assessed practices had complete governance documentation in place at assessment.

453 of 453 practices had at least one significant documentation gap ยท n = 453

At least one significant governance documentation gap โ€” 100% (453 of 453)

Cyber resilience is often approached as a technology issue. These assessments suggest governance deserves equal attention. Across all 453 practices, at least one governance-related gap was identified. In some cases fundamental documentation was absent, and in some the practice was unaware such documentation was expected.

Many practices had implemented individual security measures or operational controls. Comprehensive governance documentation was less common. Cybersecurity activity was frequently managed as a set of separate tasks rather than as a program supported by accountability, policy, and review.

Policies are one part of governance

None of the 453 practices had a complete set of written cybersecurity and privacy policies meeting the criteria applied in these assessments. This does not mean no policies existed. Many practices had individual policies, privacy documents, or operational procedures. What was not observed was complete documentation against the criteria used.

Cybersecurity involves leadership

Technology alone does not establish accountability, set priorities, allocate resources, or maintain oversight. Those are leadership functions. Recovery readiness, detection, human readiness, and technology management are each shaped by governance decisions.

Cyber resilience involves leadership, not only technology.

What we observed

  • Incomplete or outdated cybersecurity and privacy documentation
  • Unclear ownership of cybersecurity responsibilities
  • Limited oversight and review processes
  • Inconsistent training and awareness activities
  • Limited validation of recovery and response capabilities

Recommended action

Assign clear accountability for cybersecurity and privacy oversight, and establish a regular process for reviewing policies, training, recovery readiness, and cyber risk management activities against the requirements that apply to your practice.

Key takeaway

Governance gaps were identified at every assessed practice. Many can be addressed without significant technology investment.

Domain three of six

Privacy & information protection

Privacy and information protection gaps were identified across the assessed practices, most often in documentation, accountability, and breach response planning.

Qualitative finding ยท not separately quantified in this edition

Why this domain has no figure

Privacy observations were recorded during assessment but are not reported here as a separate quantified finding, because a defined privacy criterion and its own denominator are not established in the source data for this edition. The governance figure should not be read as a measure of privacy practices. A future edition may report this domain quantitatively.

Dental practices hold sensitive personal health information. Privacy law places obligations on practices to safeguard that information and to respond appropriately when it is compromised. Across these assessments, formal programs operationalizing those obligations were frequently absent, including in practices that described themselves as aware of their responsibilities.

Privacy and cybersecurity are connected

Privacy breaches in dental practices frequently follow cybersecurity incidents. Ransomware, unauthorized access, and data exfiltration each threaten the confidentiality and integrity of patient information. Privacy governance and cybersecurity governance reinforce one another. Absent privacy policies, unclear data handling practices, and limited breach response planning each increase the potential impact of a security event.

Canadian regulatory context

Which privacy requirements apply to a given dental practice depends on the jurisdiction in which it operates, the activities it carries out, and how patient information moves. Provincial health privacy statutes such as Ontario's PHIPA, Alberta's HIA, and British Columbia's PIPA are examples rather than an exhaustive list, and several other provinces have their own health information legislation.

The federal Personal Information Protection and Electronic Documents Act may also apply. Organizations subject to a provincial private-sector law deemed substantially similar to PIPEDA are generally exempt from it for personal information handled within that province, but organizations handling personal information that crosses provincial or national borders in the course of commercial activity are subject to PIPEDA regardless of where they are based. That is relevant to practices using cloud services, hosted imaging, or communications platforms operated outside their province.

Professional regulatory colleges also set expectations for records and patient information that operate alongside privacy legislation. Requirements have changed over the 2014 to 2025 period, and what applies today did not apply unchanged throughout.

This report focuses on Canadian requirements and does not assess the applicability of foreign laws or contractual obligations.

What we observed

  • Absent privacy documentation, or documentation not reflecting current operations
  • Inconsistent approaches to patient consent and notification
  • Limited documentation of data handling, retention, or disposal practices
  • Unclear accountability for privacy oversight within practices
  • Limited processes for identifying and responding to privacy breaches
  • Limited staff awareness of privacy obligations and reporting responsibilities

Recommended action

Establish documented privacy policies, assign clear accountability for privacy oversight, and implement a process for identifying and responding to privacy incidents, in alignment with the federal, provincial, and professional requirements that apply to your practice.

Key takeaway

Privacy governance and cybersecurity governance reinforce each other. Gaps in one increase exposure in the other.

Domain four of six

Detection & response

90.1% of assessed practices had no evidence of a proactive capability to detect or respond to a cyber threat.

408 of 453 practices ยท 9.9% had such capability identified

Capability identified โ€” 9.9% (45 of 453) No evidence identified โ€” 90.1% (408 of 453)

The ability to detect and respond to cyber threats is a component of resilience. Identifying suspicious activity early can reduce operational disruption, limit the impact of an incident, and improve recovery outcomes.

Detection is a time advantage

Where an incident develops over a period before its effects become visible, earlier detection creates more opportunity to contain it. Detection gaps extend the window in which activity can continue unnoticed.

Governance connection

Many detection and response gaps identified during assessment were linked to governance. Where ownership, accountability, and oversight were unclear, monitoring, vulnerability management, and incident response processes tended to receive less consistent attention.

Effective detection involves both technology and defined response processes.

Technology gaps observed

  • Absence of endpoint detection and response capabilities
  • Inadequate endpoint protection
  • Outdated or poorly maintained security tools
  • Limited security monitoring capability
  • Limited visibility into threats and vulnerabilities

Process gaps observed

  • Unclear responsibility for reviewing alerts
  • Undefined escalation procedures
  • Informal or undocumented incident response processes
  • Inconsistent follow-up on identified vulnerabilities

Recommended action

Establish a documented process for monitoring, reviewing, escalating, and responding to security events, supported by appropriate detection technology and clearly assigned accountability.

Domain five of six

Human readiness

95.6% of assessed practices did not report a formal cybersecurity awareness training program for their team.

433 of 453 practices ยท 4.4% reported a formal program ยท based on information provided by the practice

Reported a formal program โ€” 4.4% (20 of 453) Did not report one โ€” 95.6% (433 of 453)

People are part of resilience

Technology plays a critical role in resilience, and so do the people using it. Across the practices assessed, the large majority did not report a formal cybersecurity awareness training program.

Phishing, social engineering, credential theft, impersonation, and fraudulent payment requests are among the threats commonly directed at dental practices. These target people rather than systems, and technology alone does not fully prevent them. Recognition and response capability are generally developed through education.

Leadership shapes culture

Human readiness is not solely a staff matter. Practice leadership sets expectations, accountability, reporting culture, and reinforcement. Where leaders prioritize awareness, it tends to be sustained.

Commonly reported threat types

  • Phishing emails targeting staff and practice owners
  • Fraudulent payment and vendor impersonation requests
  • Credential theft through deceptive communications
  • Social engineering attacks exploiting trust
  • Impersonation of IT providers, insurers, or regulators

Recommended action

Establish a regular cybersecurity awareness training program for the whole team, covering phishing, social engineering, and payment fraud recognition, with clear expectations for reporting suspected incidents.

What this figure does and does not show

This finding records whether a practice reported a formal training program. It does not measure staff knowledge, and the absence of a formal program should not be read as an absence of capability.

Domain six of six

Technical safeguards

74.6% of assessed practices did not meet this report's assessment threshold for core technical controls.

338 of 453 practices ยท 25.4% met the threshold of six or more of thirteen core controls

Threshold met โ€” 25.4% (115 of 453) Threshold not met โ€” 74.6% (338 of 453)

Technical controls are an essential component of resilience. Across the assessment period, foundational controls including password management, endpoint protection, and multi-factor authentication were observed more frequently in later assessments than in earlier ones.

That observation is qualitative. Assessment criteria changed over the period and results were not standardised across years, so this report does not measure the rate or significance of any change. Some of what was observed may reflect growing awareness within the profession, and some may reflect platform and vendor requirements that made certain controls standard.

Controls and resilience are not the same

Practices frequently had individual security tools in place while also showing gaps in governance, recovery planning, monitoring, training, and accountability. Technical controls contribute to resilience without establishing it on their own.

Tools alone do not create resilience.

Technology areas reviewed

  • Password management
  • Endpoint protection
  • Multi-factor authentication
  • Encryption
  • Secure remote access

Recommended action

Implement and regularly review foundational cybersecurity controls, including multi-factor authentication, endpoint protection, patch management, secure remote access, and access controls, as part of a broader approach to resilience.

About the threshold

The six-of-thirteen threshold is internal to this report. It is not an external standard, and meeting it does not establish legal compliance, adequate overall security, or resilience to an incident.

Special focus

AI readiness & governance

92.6% of practices assessed after AI governance measures were introduced had no documented AI governance policy.

163 of 176 practices ยท 13 of 176 had a documented policy

Documented policy โ€” 7.4% (13 of 176) No documented policy โ€” 92.6% (163 of 176)

Policy has not kept pace with availability

Artificial intelligence tools are increasingly present in dental practice operations, including administration, communications, marketing, documentation, and clinical workflows. Among practices assessed after AI governance measures were added to the assessment, 13 of 176 had a documented policy governing their evaluation, approval, or use.

This finding records the presence or absence of a documented policy. It does not measure whether or how AI tools were being used in those practices, and the absence of a policy should not be read as evidence of either adoption or misuse.

Looking ahead

These figures are an early indicator rather than a measure of AI maturity. Future work may offer more insight into AI governance, risk management, literacy, policy development, and responsible adoption in dental settings.

AI governance areas assessed

  • Acceptable use policies
  • Privacy considerations for AI tools
  • Data handling and retention
  • Vendor oversight and due diligence
  • Staff guidance and training
  • Risk management processes

Recommended action

Establish basic governance expectations for the evaluation, approval, and use of AI-enabled tools, including privacy, security, accountability, and staff guidance.

Scope note

AI measures were introduced in later assessment periods and cover 176 practices, not the full dataset. This group is not assumed to be the same 176 practices assessed for backup and recovery.

Framework

The six-domain assessment framework

Cyber resilience is treated here as the ability of a dental practice to prevent, detect, respond to, and recover from cybersecurity incidents while continuing to protect patient information and maintain patient care.

Governance & leadership

Accountability structures, policy frameworks, oversight processes, and leadership engagement.

Privacy & information protection

Data handling, patient information safeguards, breach response, and regulatory alignment.

Recovery & continuity

Backup integrity, tested recovery procedures, and continuity planning.

Detection & response

Monitoring capabilities, endpoint detection, and incident response processes.

Human readiness

Staff awareness, training, phishing preparedness, and reporting culture.

Technical safeguards

Authentication, encryption, endpoint protection, and access management controls.

Indicators reported in this edition

These are six separately measured indicators, not six comparable domain scores. Denominators differ, as shown. Privacy is part of the framework but is not quantified in this edition, and AI governance is reported as an additional indicator rather than as one of the six framework domains.

Governance documentation gap
453 of 453
100%
No formal training reported
433 of 453
95.6%
No documented AI policy
163 of 176
92.6%
Recovery issues identified
161 of 176
91.5%
No detection evidence
408 of 453
90.1%
Assessment threshold not met
338 of 453
74.6%

Framework note

This framework is a preliminary structure intended to support measurement and discussion. It is not a validated scoring model, a certification, or a regulatory instrument, and it is not used to rank practices.

It is offered as a starting point that could be refined through collaboration with professional associations, educators, insurers, and cybersecurity practitioners.

Looking ahead

The case for a shared benchmark

What a benchmark would add

These findings describe cybersecurity and resilience conditions observed across 453 assessed practices. Their most useful contribution may be to support a more consistent approach to measuring resilience across the profession.

A dental-specific benchmark would not create obligations. Legal duties under federal and provincial privacy law, professional expectations set by regulatory colleges, and established cybersecurity guidance such as the Canadian Centre for Cyber Security's baseline controls already apply and continue to apply. What a shared benchmark could add is consistent measurement, comparability between practices and over time, and a common reference point for the profession, its educators, its insurers, and its technology providers.

Where responsibility sits

The gaps described here do not reflect a failure of individual dentists. Dental professionals are trained to deliver patient care, not to design cybersecurity programs, draft privacy governance frameworks, or evaluate AI tools against regulatory requirements. Those are specialized disciplines requiring dedicated expertise.

At the same time, engaging a technical provider does not transfer a practice's privacy or professional responsibilities. Accountability for personal information generally remains with the organization that holds it, including where processing is outsourced. Practices retain responsibility for oversight of the providers they engage.

A shared benchmark could improve consistent measurement, coordination, and accountability, while existing obligations continue to apply.

A national body such as the Canadian Dental Association is well positioned to convene that work. Establishing a benchmark is an act of leadership on behalf of the profession and the patients it serves, not an assignment of blame.

A possible path

Now

Signal edition

Findings from 453 assessed practices. A preliminary six-domain framework is described. Discussion begins.

Next

Broader measurement

A more widely participatory measurement initiative across Canadian dental practices.

Annual

Repeat measurement

Consistent measures repeated over time, allowing change to be observed rather than inferred.

Ongoing

Continuous improvement

Findings inform education, policy, professional guidance, and technology practice.

Develop a dental cyber resilience benchmark

A shared benchmark would provide a consistent basis for measuring progress and identifying trends, complementing rather than replacing existing legal and professional obligations.

Conduct a broader measurement initiative

Wider participation would give a fuller picture of resilience across the profession, including recovery readiness, governance, human readiness, and AI governance.

Look beyond technology management

Resilience depends on governance, accountability, recovery readiness, detection and response, and human preparedness, alongside technical controls.

Resilience improves when it is measured, understood, and continuously strengthened.

Disclosure

Interests, funding and independence

The author's commercial interests

Anne Genge is Founder and Chief Executive Officer of Myla Training Corp and Co-Founder and President of Alexio Corporation. The assessment data underlying this report was collected by those two organizations, which contributed 93 and 360 assessments respectively.

Both organizations provide commercial services in areas this report discusses, including cybersecurity assessment, privacy and cybersecurity training, and related professional education. Readers should take that commercial interest into account when considering the findings and recommendations.

Funding and review

This report was prepared and funded by the author. No external sponsorship, grant, or commercial funding supported its preparation.

This edition has not undergone independent peer review or third-party validation. It is published as a preliminary signal, and feedback that would improve its accuracy is welcome.

Naming an association, regulator, publication, or other organization anywhere in this report does not imply that organization's endorsement, participation, or review.

Data handling

Findings are reported only in aggregate. No practice is named or identifiable in this report, and provincial-level and practice-type breakdowns are not published.

Appendix A

Statistics register

The approved wording and denominator for every figure reported. These are original findings from the assessment dataset described in this report.

Original assessment findings. Denominators differ between measures.
StatisticApproved wordingSample
453Findings are based on 453 unique Canadian dental practices assessed between 2014 and 2025.n = 453
100%Every assessed practice had at least one significant governance documentation gap. Not one of 453 practices had complete governance documentation in place at assessment.453 / 453
95.6%95.6% of assessed practices did not report a formal cybersecurity awareness training program. 4.4% reported one. Based on information provided by the practice.433 / 453
92.6%92.6% of practices assessed after AI governance measures were introduced had no documented AI governance policy. 13 of 176 had one.163 / 176
91.5%Among 176 practices that underwent backup and recovery assessment, 91.5% had issues identified that could materially affect recovery. Not the result of full restoration testing.161 / 176
90.1%90.1% of assessed practices had no evidence of proactive detection and response capability. 9.9% had such capability identified.408 / 453
74.6%74.6% of assessed practices did not meet this report's internal assessment threshold of six or more of thirteen core technical controls. 25.4% met it.338 / 453

Methodology notes

  • This is a signal edition describing assessment findings, not a nationally representative survey.
  • Findings should not be interpreted as national prevalence estimates or as current 2026 conditions.
  • Denominators are reported with every figure. The two subsets of 176 are not assumed to be the same practices.
  • The six-domain framework is preliminary and is not a validated scoring model.
  • The technical assessment threshold is internal to this report and is not an external standard.
  • Provincial-level counts and practice-type comparisons are not reported.
  • This edition does not report change over time. Assessment criteria changed across the period and results were not standardised for comparison.

Acknowledgements

The author thanks the dental practices that participated in assessments and contributed to the observations reflected in this report, and acknowledges the contributions of team members at Myla Training Corp and Alexio Corporation involved in collecting and reviewing assessment data over the period.

Corrections

Corrections and questions about the findings or methodology can be directed to the author. Confirmed corrections will be reflected in the change log of a subsequent version.

Appendix B

External references

These sources provide regulatory and technical context. None of them verifies, validates, or was used to produce the original percentages reported above.

Office of the Privacy Commissioner of Canada

PIPEDA requirements in brief. Cited in support of the statements about federal applicability, substantially similar provincial laws, and information crossing provincial or national borders.
priv.gc.ca

Office of the Privacy Commissioner of Canada

Accountability, the first of the ten fair information principles under PIPEDA. Cited in support of the statement that accountability for personal information remains with the organization that holds it.
priv.gc.ca

Canadian Centre for Cyber Security

Baseline cyber security controls for small and medium organizations, version 1.2, February 2020. Cited as an example of externally established Canadian guidance. Not used to produce any figure in this report.
cyber.gc.ca

Note on legislation

Provincial health privacy statutes referred to in this report are Ontario's Personal Health Information Protection Act, Alberta's Health Information Act, and British Columbia's Personal Information Protection Act. These are given as examples. Other provinces have their own health information legislation, and which statute applies to a given practice depends on its jurisdiction, activities, and information flows. Requirements changed over the 2014 to 2025 period covered by this report.

Appendix C

Change log

Version 1.0, 2026. Changes from the earlier draft manuscript.
AreaChangeReason
TitleRenamed from Trend Report to Assessment Findings.The dataset is pooled across 2014โ€“2025 and does not support longitudinal trend claims.
FramingThe observation that adoption has outpaced resilience is now labelled as the author's interpretation rather than a finding.Not demonstrated by comparable measurement over time.
RecoveryWording changed from confident recovery to issues identified that could materially affect recovery.The figure does not rest on full restoration testing.
TrainingWording changed to did not report a formal program, and labelled as reported by the practice.Distinguishes self-reported information from observed evidence.
TechnicalThe six-of-thirteen measure is now described as this report's internal assessment threshold.Not an external standard; meeting it does not establish compliance.
PrivacyPresented as a qualitative finding with no percentage.No separate defined criterion and denominator established for this edition.
Legal scopeStatement that no American frameworks apply removed. PIPEDA, cross-border flows, and professional obligations added; provincial statutes presented as examples.Applicability depends on jurisdiction, activities, and information flows.
BenchmarkClaim that the absence of a national standard means nothing changes removed.Existing legal duties, professional expectations, and cybersecurity guidance already apply.
ClaimsRemoved: no national benchmark exists, first national initiative, one of the largest collections, the human layer is the most underprepared, incidents rarely begin with disruption.Not substantiated by the source data or a documented basis.
DenominatorsShown beside every figure, including the cover and the indicator chart.Recovery and AI findings cover subsets, not all 453 practices.
PeriodEleven years replaced with 2014โ€“2025 throughout.The stated range spans twelve calendar years inclusively.
New sectionsImportant information, definitions and evidence basis, disclosure, external references, change log.Transparency about scope, meaning, interests, and sources.
Author detailsCredential line reduced to BA, CIPP/C; academic affiliations removed pending confirmed wording.Avoids implying appointments or degrees beyond those confirmed.