08/31/2026
BREACH OF THE WEEK
A dental practice in Connecticut went up on a ransomware leak site last weekend. The countdown on their page has run out.
I am not naming them. They are small, they are having the worst week of their career, and they do not need the traffic.
But here is what the criminals posted, because every owner should see it:
The whole patient database. Just over 8,000 files. Some records with Social Security numbers in them. Sample documents published publicly as proof. And a clock that has now expired, which means whatever that practice decided is decided.
The leak page lists their revenue at under $5 million a year.
Read that again. Eight thousand files. That is a one or two doctor office. Not a DSO.
Every time I say small practices get hit, someone tells me "we're too small to be a target." Small is not protection. Small is the reason.
No in-house IT, everybody sharing one login, a vendor who can dial into the server whenever he feels like it, and a backup nobody has ever tested. Two gigabytes walks out the door in minutes and nobody is watching.
The worst part is not the downtime. It is the Social Security numbers. That turns "we lost a day of production" into patient notification letters, state reporting, credit monitoring, and a permanent public listing your patients can look up.
Paying does not fix that. The data was copied before anything got locked. You cannot buy it back.
One thing from the comments on my last post, because it surprised a lot of people.
Two people who migrate practice management data for a living said the same thing independently: unencrypted databases sitting on practice servers are common. Not rare. Common. And the practice usually has no idea how easily that data can be pulled off their own machine.
Worth knowing the difference, though, because it is the part that trips owners up:
Full disk encryption protects a drive that leaves the building. Stolen laptop, old server going out the door. Once the server is on and running, it is doing nothing for you.
Database encryption is better. A copied file comes out unreadable.
Neither one does anything about someone already logged in with a valid password, pulling data the same way your software pulls it every day.
Encryption is the floor. Not the plan.
Five things you can do this week that cost nothing:
1. Multi-factor authentication on email, your PMS, and any remote access. Everyone, not just the doctor.
2. Get rid of shared logins. Every person gets their own.
3. Write down every vendor who can remote into your network, then find out which ones can get in without asking you first.
4. Actually restore a file from your backup and open it. A green checkmark is not a test.
5. Make sure your HIPAA Security Risk Analysis is current. OCR settled another ransomware case in June for $450,000 and the first thing they cited was not having one.
Last thing: please do not go hunting for the leaked files to see if anyone you know is in there. Leak sites can be dangerous. Don't.
Happy to answer questions in the comments. If anyone wants a second set of eyes on where their own practice stands, my inbox is open. 25 years in enterprise IT and Cybersecurity, CISSP, and I have helped walk more practices through this week than I would like to count