Guide
How dental offices can prevent ransomware
Ransomware can lock the computers your practice runs on and stop the schedule cold. These are the habits and safeguards that make an attack less likely, and recovery faster if one gets through.
What ransomware is and why dental offices are targets
Ransomware is malicious software that locks up your files, usually by encrypting them, and then demands payment for the key to unlock them. In a dental office, that can mean the schedule, patient charts and billing records all become unreadable at once, on every computer the ransomware can reach.
Many ransomware groups also copy data before they encrypt it, then threaten to publish it if you don’t pay. So even a practice with good backups can face a privacy problem, not only a downtime problem.
Healthcare offices are attractive targets for a simple reason: they depend on their data to see patients. A practice that cannot open its schedule or charts is under heavy pressure to get running again quickly, and attackers count on that pressure. Patient records are also valuable to criminals in their own right.
Being a small office is no protection. Many attacks are automated and simply look for any system with a weakness, whatever the size of the business behind it.
How ransomware gets into a dental office
Ransomware rarely arrives through anything exotic. It usually comes in through one of a handful of everyday openings, which is good news: you can shrink the risk from each one.
Phishing email
An email that seems to come from an insurance company, a supplier, a patient or even a colleague asks someone to open an attachment, click a link or enter a password. One click at the front desk can be enough to start an infection.
Exposed remote access
Remote access lets staff, doctors or vendors reach office computers from somewhere else. When it is left open to the internet without strong protection, attackers can find it with automated scans and keep trying passwords until one works.
Unpatched software
Software makers regularly release updates that fix security holes. Computers, servers and network equipment that miss those updates keep the holes open, and attackers actively look for systems that are known to be behind.
Stolen or weak passwords
Passwords that are reused from other sites, shared between staff or easy to guess give attackers a way in that looks like a normal login. Once inside, they hunt for accounts with more access so they can reach the server and the backups.
A ransomware prevention checklist for your practice
No single tool stops ransomware. Protection comes from layers, so that if one safeguard fails, the next one catches the problem. Use this list to check where your office stands.
- Keep everything updated, including operating systems, practice and billing software, web browsers, the server and network equipment such as routers. Plan updates so they happen regularly, not only when someone remembers.
- Run malware protection on every computer and server, keep it current and make sure someone notices when it raises an alert. Read about malware and virus protection for dental offices for more on this layer.
- Turn on multi-factor authentication, which asks for a second proof such as a code from a phone, for email, remote access and any online account that holds practice or patient data.
- Give each person only the access their job needs. Everyone has their own login, and day-to-day work happens in a standard account, not an administrator account. This principle of least privilege limits how far ransomware can spread from one account.
- Keep guest Wi-Fi separate from staff Wi-Fi, so patients’ phones and visitors’ laptops never share a network with your server and workstations.
- Set up remote access carefully. Only the people who need it should have it, it should require multi-factor authentication, and it should never be a remote desktop connection left open to the internet.
- Train your team to spot phishing, and make it easy and blame-free to report a suspicious email or an accidental click right away.
- Keep backups that ransomware cannot reach, and test them. This is the safeguard that decides how quickly you recover.
Layers of ransomware protectionIn short
- UpdatesClose the security holes attackers look for
- Malware protectionOn every computer and server, kept current
- LoginsOwn login, least access, second sign-in step
- NetworkGuest Wi-Fi apart, remote access locked down
- A trained teamPhishing spotted and reported right away
- BackupsOut of ransomware’s reach, and tested
If one layer fails, the next one catches it
If your network was set up years ago and nobody has looked at it since, it is worth checking it against this list. Our dental office network security page explains how a network can be secure without slowing your team down.
Backups that ransomware cannot reach
Good backups are your way out of a ransomware attack. If you can wipe the affected computers and restore clean copies of your data, you do not need the attacker’s key to get back to work.
Many ransomware attacks go after backups too. A backup drive that is always plugged into the server, or a backup folder that any staff login can open, can be encrypted along with everything else. A backup plan that holds up against ransomware has a few features in common:
- It follows the 3-2-1 rule: at least three copies of your data, on two different types of storage, with one copy kept away from the office.
- At least one copy is offline or unchangeable, either disconnected from the network or stored so that it cannot be altered or deleted, even by someone with a valid login.
- Backup access is protected separately, with its own credentials that are never used for everyday work, so a stolen staff password does not unlock the backups.
- Restores are tested regularly. A backup only counts once you have restored from it and confirmed the data opens in your practice software.
- You know how long a full recovery takes, so you can plan how the office keeps running while systems come back.
- Office server
- Backup
- Offline copy
- Restore
A backup ransomware cannot reachIn short
- Three copiesTwo kinds of storage, one away from the office
- One copy offlineDisconnected or unchangeable, even with a valid login
- Separate loginNever used for everyday work
- Tested restoresConfirmed to open in your practice software
Clean copies get you back to work
Our practical guide to dental office data backup covers what to protect, the 3-2-1 rule and how to test a restore in more detail.
Ransomware risks to avoid in your office
Some everyday shortcuts make it much easier for ransomware to succeed. If any of these sound familiar, they are worth fixing first.
- Sharing one login between several people at the front desk or in the operatories.
- Using an administrator account for email and web browsing.
- Reusing passwords from personal accounts, or writing them on a note stuck to the monitor.
- Leaving remote desktop open to the internet because it is convenient for a vendor or a doctor working from home.
- Putting off updates indefinitely because a restart would interrupt the day.
- Keeping the only backup plugged into the server all the time.
- Letting patients and visitors use the staff Wi-Fi.
- Running old computers or software that no longer receive security updates.
- Opening attachments you were not expecting, even when the sender’s name looks familiar.
What to do if ransomware hits your office
Signs of ransomware include files that suddenly will not open or have strange new names, a ransom note on the screen or in your folders, and computers that slow to a crawl. If you see them, act quickly and calmly.
- Disconnect affected computers from the network. Unplug the network cable and turn off Wi-Fi on any computer that shows signs of ransomware. Leave it powered on if you can, because shutting down can erase evidence; shut a device down only if you cannot disconnect it. Do not wipe or reinstall anything yet.
- Call your IT provider right away. They can work out which systems are affected, keep the infection from spreading, preserve evidence and plan a clean recovery from backups. Avoid using a computer that might be infected to send email about the attack.
- Do not pay the ransom without expert advice. The FBI and CISA both discourage paying. Payment does not guarantee you will get your data back, and it encourages criminals to target more victims.
- Report the attack to law enforcement. The FBI asks victims to report ransomware to a local FBI field office or through its Internet Crime Complaint Center (IC3), and CISA also takes reports. Both publish ransomware guidance, collected on the federal StopRansomware.gov website.
- Check your other obligations. Contact your cyber insurance carrier if you have one, and get advice on whether HIPAA breach notification applies.
Write down what happened and when, and take a photo of any ransom note with a phone. Those details help your IT provider, your insurer and law enforcement.
Ransomware and HIPAA
For a dental practice, ransomware is a HIPAA question as well as an IT problem. The U.S. Department of Health and Human Services (HHS) addresses it directly in its Fact Sheet: Ransomware and HIPAA.
According to that fact sheet, when ransomware encrypts electronic protected health information (ePHI), HHS presumes a breach has occurred under the HIPAA Breach Notification Rule (45 CFR 164.400-414). That presumption stands unless the practice can demonstrate a low probability that the information has been compromised, based on the risk assessment factors set out in the rule. If it cannot, the breach notification requirements apply.
The fact sheet also points out that the HIPAA Security Rule (45 CFR Part 164, Subpart C) already calls for safeguards that help against ransomware, such as a risk analysis, protection from malicious software, security awareness training, security incident procedures and a data backup plan. Our HIPAA Security Rule IT checklist for dental offices walks through those safeguards in plain English.
This guide is general information, not legal advice. Talk to a qualified advisor about your practice’s obligations after an incident.
How My Dental IT helps
We configure dental office networks to be secure without slowing your team down, and protect practices against intruders, malware and unauthorized users. We install and maintain malware and virus protection that keeps digitally stored patient information safe, and set up backup systems and recovery software so vital data is not lost.
We also install server monitoring software so problems are caught in an emergency, keep you informed of every change and update to your systems, and sign a formal HIPAA business associate agreement with every customer. When a computer needs attention, you can start a remote support session with us.
Related reading
More ways to protect your practice’s data
Ransomware protection goes hand in hand with solid backups, the HIPAA basics and well-protected computers.
Guide
How to back up a dental office
What to protect, the 3-2-1 rule and why a backup only counts once you have tested the restore.
Guide
A HIPAA Security Rule IT checklist
The IT side of the Security Rule for a dental office, from risk analysis to business associates.
Service
Malware and virus protection
Installed and maintained to keep the patient information stored on your computers safe.
Make ransomware a bad day, not a disaster
Tell us about your office, and we’ll talk you through the network protection, malware protection and backups that fit your practice.