Aggregate dataset — Batch 1
96 Dental Practices, Scanned From Outside. Here's What Your Insurer Would Find.
We ran a passive, external scan against 96 of 100 U.S. dental practice domains (4 failed to scan after repeated retries) in July 2026. 50% had at least one critical-severity finding. The single most common significant gap was email authentication — 96% of practices had no DMARC record configured.
Grade Distribution
Scored 100 → 0, deducting per unique finding by severity. No domain in this batch scored an A.
Average Score by Category
Higher is healthier. These are the six categories this scan actually measures.
Email authentication is the clear weak point across the dataset — consistent with the DMARC/SPF/CAA gaps below. Everything else is fairly healthy on average, which tracks with most of these being near-default hosting setups rather than actively misconfigured systems.
Most Common Findings
| Finding | Severity | % of domains |
|---|---|---|
| DMARC not configured | HIGH | 96% |
| SPF not configured | HIGH | 58% |
| Exposed service (non-cleartext port) | MED/HIGH* | 99% |
| Certificate invalid | CRITICAL | 39% |
| Cleartext credentials exposed (FTP) | CRITICAL | 26% |
| Self-signed certificate | HIGH | 21% |
| CAA record missing | LOW | 98% |
| DNSSEC not enabled | LOW | 100% |
*Inherited directly from the scan API's own per-port risk label, not assigned by our severity taxonomy.
These require internal access or documentation — a passive external scan structurally can't see them, no matter how the tooling improves:
- MFA enforcement (vs. just "available")
- EDR/MDR monitoring status
- Backup immutability and restore testing
- Patch SLA / time-to-remediate history
- Incident response plan and tabletop exercises
- Security awareness training completion
- Vendor/third-party risk assessments
Methodology
All checks are passive and external: DNS records, TLS configuration, HTTP response headers, exposed ports, and public breach-exposure data. No authentication was attempted against any system, and no practice's internal network was accessed.
Every discovered subdomain (cPanel, webmail, webdisk, mail, etc.) is scanned, but findings are deduplicated by issue type per practice — the same problem across five subdomains counts once, not five times, so practices on shared hosting with many auto-generated subdomains aren't penalized just for having more surface area.
Scoring starts at 100 and deducts per unique finding: CRITICAL −25, HIGH −15, MEDIUM −8, LOW −3, INFO 0, floored at 0. Taxonomy v1.0 — severity weights are a first pass and may be recalibrated in a future batch.
Refresh Cadence
This dataset is re-run against a larger or updated domain list every 4–6 weeks, with the published numbers updated in place and prior figures kept for longitudinal comparison.
Last updated: July 22, 2026 · Sample size: 96 of 100 domains attempted · Method: passive external scan, see methodology.