Ransomware Attack on Your Dental Practice: What to Do Right Now
DENTAL · Dec 24, 2025 · 6 min read
Step-by-step guide for dental practices hit by ransomware. What to do in the first hour, who to call, and how to recover.
Your Dental Practice Got Hit by Ransomware. Now What?
If you're reading this during an active attack, skip to "First 60 Minutes" below. If you're reading this to prepare, good - you're smarter than 90% of practices.
First 60 Minutes (Do This NOW)
1. STOP. Don't click anything else.
- Don't try to open files to "check"
- Don't restart computers
- Don't pay the ransom (yet)
2. Disconnect from the network
- Unplug ethernet cables from ALL computers
- Turn off WiFi on ALL devices
- This stops the spread
3. Take photos of the ransom screen
- Use your phone
- Get the bitcoin address, email, and any ID numbers
- This helps forensics later
4. Call your cyber insurance (if you have it)
- They have incident response teams on standby
- They'll guide next steps
- Don't wait - call immediately
5. Don't turn anything off
- Forensics needs the machines running
- Memory contains evidence that disappears on shutdown
First 24 Hours
Assess the damage:
- Which computers are encrypted?
- Are backups affected?
- Is patient data exposed?
Activate your incident response plan:
- If you don't have one, call an incident response firm
- Your cyber insurance can recommend one
- Don't try to handle this alone
Notify your IT provider:
- If you have managed IT, they should already know
- If you're using a "computer guy," this is beyond them
- You need incident response specialists
Consider HIPAA breach notification:
- Ransomware is presumed a breach unless proven otherwise
- You may need to notify HHS within 60 days
- You may need to notify patients
- Document everything for compliance
The "Should We Pay?" Question
Arguments for paying:
- Sometimes faster than recovery
- May be only option if backups are gone
- Insurance may cover it
Arguments against paying:
- No guarantee you get files back
- Funds criminal enterprises
- Makes you a target for repeat attacks
- May violate OFAC sanctions
Reality:
- About 50% of practices that pay get data back
- Average ransom: $50,000-150,000
- Average recovery cost (without paying): $150,000-300,000
- Your insurance company will have strong opinions
Recovery Process
If you have good backups:
- Wipe all affected machines
- Reinstall operating systems
- Restore from backup
- Verify no malware in backups
- Harden security before reconnecting
If backups are compromised:
- Negotiate with attackers (through professionals)
- Pay if advised and legal
- Decrypt and verify data
- Full security rebuild anyway
Timeline:
- Minimum 3-5 days to restore operations
- Often 2-4 weeks for full recovery
- 6+ months to verify no persistent threat
How This Happened
Most dental ransomware attacks come from:
Phishing emails (60%):
- "Your dental supply invoice is attached"
- Staff opens attachment, game over
Remote desktop exposure (25%):
- RDP open to internet
- Weak passwords
Unpatched software (10%):
- Old operating systems
- Outdated practice software
Infected websites (5%):
- Malicious ads on legitimate sites
- Drive-by downloads
Prevention (For Next Time)
- MFA everywhere - Stops 99% of account compromises
- Endpoint detection - Modern antivirus that catches ransomware
- Offline backups - Air-gapped, can't be encrypted
- Staff training - Phishing simulation, security awareness
- Email filtering - Block malicious attachments before arrival
- Network segmentation - X-ray systems separate from billing
The Real Cost
Beyond ransom and recovery:
- Lost production: $5,000-20,000/day
- Patient notification: $5-50/patient
- Legal/compliance: $20,000-100,000
- Reputation damage: Immeasurable
- Staff overtime/stress: Immeasurable
Prevention costs: $200-300/user/month
The math isn't hard.
Think your practice is protected? We find vulnerabilities before attackers do. Get Free Assessment
Need Help With Your Practice’s Security?
Free assessment, no obligation, real answers.
(469) 306-9520 • Serving Dallas-Fort Worth