The short answer: a dental backup passes when there are at least three copies in three places, one copy is immutable (ransomware-proof), verification happens daily, a restore has been tested in the last quarter, and someone can state your recovery time in hours. Score anything less and the gap is worth closing this month, not this year.

The checklist

  1. Three copies exist — production data, a local backup, and an off-site copy. A single external drive is one dead drive away from zero.
  2. One copy is off-site — automatically, nightly. A drive that goes home in a staff member’s bag is a breach risk wearing a backup costume.
  3. One copy is immutable — locked so nothing, including ransomware with admin credentials, can alter or delete it. Modern ransomware hunts backups before revealing itself; immutability is the counter.
  4. Backups run automatically — no human ritual. Anything requiring someone to remember will eventually meet a vacation.
  5. Verification is daily and reported — a system confirms each backup completed and is readable, and a human sees that report. Silent failure is the default failure mode of backups.
  6. A restore was tested this quarter — actually performed, timed, and documented. This is the question that eliminates most “yes we have backups” answers.
  7. Imaging is included — X-rays, pans, and CBCT volumes, not just the practice management database. Practices routinely discover their images were never in the backup set.
  8. Recovery time is a number — “How long until we see patients?” should have an answer in hours, agreed in writing. If it’s a shrug, it’s days.
  9. Recovery point is a number — how much recent work you’d lose. Multiple recovery points per day is the dental standard; “last night, hopefully” is not.
  10. Someone is accountable — one named party owns backup success, failure, and testing. “The software handles it” means nobody does.
Scoring: 10/10 — sleep well. 7–9 — good bones, close the gaps. Under 7 — your practice’s continuity currently depends on luck, and the downside is expensive. Under 4 — please call someone this week, even if it isn’t us.

Why immutability became non-negotiable

Ransomware operators learned years ago that victims with working backups don’t pay. Current attacks locate and encrypt or delete backups first — using the same admin credentials that run your network. An immutable copy breaks that plan: it cannot be altered even by an administrator, so there is always a clean point to restore from. It’s the difference between our clients’ zero ransom payments and the practices you read about.

For how backup fits the bigger picture — recovery objectives, continuity planning, and ransomware response — see our backup and disaster recovery service, or the first-hour ransomware guide for the day you hope never comes.