Ransomware and the Clinic: What Actually Happens

A Coastal Bend dental practice was hit by ransomware recently. Here’s what an attack looks like day by day, what it costs a practice that can’t see patients, and the unglamorous defenses that stop it.

Doctor reviewing security information on a laptop in a medical office

Day by day: how an attack unfolds

It rarely starts with drama. Day one: someone on staff gets an email that looks like a patient intake form or an invoice from a supplier. They click. Nothing visibly happens — that is the point. The malicious software sits quietly, mapping your network: where the patient database lives, where the backups are, which computers belong to people with the most access.

Days two through five are silence. The attackers are patient. They disable or corrupt your backups first, because a practice with good backups doesn’t pay ransoms. Then, usually early in the morning before staff arrive, everything locks at once. Computers show the same message: your files are encrypted, here’s how to pay.

What follows isn’t a technical problem first — it’s a business problem. The schedule is gone. You can’t see who’s booked, can’t pull charts, can’t bill. The phones still ring. Patients still show up. And every hour the practice sits idle, payroll keeps running with nothing coming in.

What it costs a practice that can’t see patients

The ransom itself is the smallest question and usually the wrong one to focus on. Paying doesn’t guarantee your files come back, and it paints a target on your practice for the next crew. The real costs are the ones nobody puts in the ransom note.

First, downtime. A clinic that can’t access its schedule or records effectively can’t operate. Every day closed — or open but limping on paper — is a day of payroll with a fraction of the revenue. Second, recovery labor: every computer has to be wiped and rebuilt, the network has to be cleaned, and someone has to verify the attackers are actually gone before patient data goes back on those machines. Third, HIPAA’s Breach Notification Rule: if patient data was accessed, you may owe notifications to patients and, for larger breaches, to the media and the Department of Health and Human Services. Those letters are not cheap, and neither is the trust they cost.

A Coastal Bend dental practice went through this recently. The details are theirs to tell, but the shape of it is the same everywhere: days of disruption, a painful rebuild, and hard questions from patients about how their information was protected.

The recovery nobody plans for

Here is what recovery actually involves when backups don’t exist or don’t work. Every computer gets wiped and rebuilt from scratch — operating system, applications, EHR client, printers, the works. The network gets scrubbed to make sure the attackers are truly gone, because restoring patient data onto a still-compromised network just starts the clock over.

Then comes the data question. Without usable backups, you’re rebuilding patient records from whatever survived: paper charts, clearinghouse records, insurance portals, and staff memory. Schedules get reconstructed by calling patients. It is slow, error-prone work, and it happens while the practice is trying to function.

Meanwhile the clock is running on breach notification. HIPAA’s Breach Notification Rule generally requires notifying affected patients within 60 days of discovering a breach, and larger breaches get reported to the Department of Health and Human Services — and when enough people are affected, to the media. The notification letters, the questions, the patients who quietly move to the practice down the road: those costs keep arriving long after the computers are back on.

The unglamorous things that actually stop ransomware

There is no single product that stops ransomware. The practices that survive have boring habits, done consistently:

  • Backups that are tested and out of reach. A backup on the same network gets encrypted along with everything else. You need copies the attackers can’t touch — and proof, from an actual test restore, that they work.
  • Multi-factor authentication everywhere. Most ransomware starts with a stolen password. A second factor stops most of those attempts cold.
  • Updates installed promptly. Attackers exploit known flaws in software that already has a fix available. Patching is dull. So is brushing your teeth. Both prevent expensive problems.
  • Email filtering and staff training. The attack almost always arrives as an email. Filtering catches most; trained staff catch the rest.
  • Segmented networks. The billing computer should not be able to reach the imaging machine, and neither should be reachable from the waiting-room Wi-Fi. Limit what any one compromised device can touch.

What to do Monday morning

Ask three questions, and don’t accept vague answers:

  • “Are our backups isolated from our network, and when did we last prove a restore works?”
  • “Does every email account and remote access point require a second factor?”
  • “If ransomware hit us at 6 a.m. tomorrow, what is the first thing we would do — and who decides?”

If any answer is “I’m not sure,” you found this week’s project.

Not sure where your practice stands?

Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.

Call (361) 704-1373 or request yours online.

Request your assessment →

Not ready to book? Start with the checklist.

Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.

Your download link appears right after you submit. Prefer to talk? Call (361) 704-1373, Mon–Fri 8am–5pm CT.

Frequently asked questions

Should we ever pay the ransom?

Law enforcement advises against it: payment doesn’t guarantee your data comes back, and it marks you as a practice that pays. The better investment is backups you can actually restore from — then the ransom demand is irrelevant.

How long does recovery usually take?

It depends entirely on preparation. With tested, isolated backups, a practice can be rebuilding in hours. Without them, recovery stretches into days or weeks of manual rebuilds — and some practices never fully recover their data.

Does cyber insurance cover ransomware?

Often partially — but policies increasingly require you to have basics like multi-factor authentication and tested backups in place before they’ll pay. Read the requirements now, not after an incident.

Can ransomware spread to our patients’ devices?

Not typically. Ransomware targets your network and files. The risk to patients is their data being stolen or exposed, which is what triggers HIPAA breach notification — not their phones getting infected.

We have antivirus. Isn’t that enough?

Antivirus is one layer, and modern ransomware is built to slip past it. It can’t help if the attacker logs in with a stolen password, and it can’t restore encrypted files. You need the boring layers too: backups, updates, and multi-factor authentication.