Ransomware in a dental office: what Tuesday morning looks like, and what decides how it ends
Here is what a ransomware attack looks like from the front desk. It is Tuesday, 7:50 a.m. The receptionist opens the practice management software and instead of the schedule there is a text file explaining that every file on the server has been encrypted and how to pay to get them back. The imaging software will not open either. The first patient is in the parking lot. Nobody knows who is booked today, what they are booked for, or whether their insurance was verified.
That is the whole attack, from the practice’s side. Everything after that is recovery, and how long recovery takes depends almost entirely on decisions made months earlier. This post is about those decisions.
What ransomware is, and why dental offices
Ransomware is software that encrypts your files and demands payment for the key. It gets in through an email attachment someone opens, a password that was guessed or reused, or a piece of software that was never patched. Once it is on one machine it spreads to everything it can reach, including the backup drive plugged into the server.
Dental practices are a good target for three reasons. The records are valuable: names, addresses, dates of birth, insurance details, health information. The office cannot function without the system, so there is pressure to pay. And a small practice rarely has anyone whose job is security, so the basics are often missing. Attackers know all three.
What it costs
Ignore the headline ransom figures; they vary and they are the smaller part. The cost is downtime measured in days, recovery measured in weeks, and the breach obligations that follow. Take the formula from The Hidden Cost of Downtime and put five days of closed operatories into it with your own production number. Then add the IT hours to rebuild, the patient calls to reschedule, and the notification work below.
On the obligations: if patient information was accessed or taken, your privacy law requires you to notify the affected patients, and in some circumstances the regulator. In Ontario that is PHIPA and the Information and Privacy Commissioner; in the United States it is HIPAA’s breach notification rule. I am not a lawyer, and the details of when and how depend on your jurisdiction, so have someone qualified check them before you need them. The point for this post is that “we paid and got our files back” does not end a breach.
The controls that actually matter
In rough order of how much they change the outcome.
1. A backup that is offline and has been restored. This is the difference between a bad week and a bad quarter. The backup must be somewhere the ransomware cannot reach (not a drive permanently plugged into the server), and it must have been restored at least once so you know it works and how long it takes. Almost every practice has backups. Far fewer have ever tested a restore. A cloud PMS moves this to the vendor, which is one of its strongest arguments; ask them how they do it.
2. Own logins, strong passwords, two-factor. Most attacks start with a credential. One shared password on a sticky note is the front door left open. Every team member on their own login through a password manager, with two-factor authentication on email and remote access, closes most of the easy routes in. See One login for everyone.
3. Patching, with a name on it. Windows, the PMS, the imaging software, the browser. Someone has to own the job of keeping them current, and the owner has to be able to ask “when were we last patched” and get an answer. If your IT company does it, ask them for the report.
4. A team that pauses before clicking. Ten minutes at a huddle, twice a year, on what a phishing email looks like and what to do with one (forward it, do not open it) does more than any poster. Make it safe to report a mistake; the attack you hear about at 9 a.m. is recoverable, the one reported at 5 p.m. is not.
5. Antivirus and a locked-down network. Endpoint protection on every workstation and the server, and no reason for the patient wifi to touch the clinical network.
6. A one-page plan for the morning it happens. Who unplugs the server. Who calls the IT company. Where the paper schedule is (see the “PMS is down” procedure in The process lives in the system). Who calls the patients. Who calls the insurer and, if needed, the lawyer. Written down and kept somewhere that is not on the server.
On cyber insurance
Worth having, with two cautions. Policies increasingly require the controls above (two-factor, tested backups, patching) as a condition of paying out, so the insurance is not a substitute for doing them. And read what it covers: some policies cover the ransom and the recovery, some cover the notification costs, some cover both. Ask your broker to be specific.
Where to start
If you do one thing after reading this, restore your backup to a spare machine and time it. If it works, you have bought yourself a bad week instead of a bad quarter. If it does not, you have found out on a Tuesday when nothing was wrong, which is the cheapest possible time to find out.
Question ten of the twelve-question assessment is about exactly this. Most practices answer it “no” the first time.
