Ransomware in a Regulated Practice: Downtime Is the Cheapest Part
A plumbing contractor in Santa Clarita and a 4-provider medical practice a few miles away can run the same number of computers, the same server, the same internet connection. Ransomware lands on both on the same Tuesday morning. The plumber loses a few days of scheduling and dispatch, pays or restores, and is back. It is expensive, it is miserable, and then it is over.
The practice has the same bad Tuesday, and that is the opening move. The outage is the part that ends soonest. What follows it are several separate processes, running at the same time, on deadlines the Santa Clarita practice does not set, and none of them are stopped by paying anybody. Here is the chain, and the parts of it that were decided months earlier.
Overview
There is a comfortable story that a small practice is too small to be worth attacking, and a second comfortable story that attacks are random weather. Neither survives contact with the data.
Cisco Talos, reporting on its own incident response engagements for Q1 2026, found healthcare and public administration tied as the most targeted verticals at 24% each. That is not randomness. The methods involved were ordinary and unglamorous, which is the part worth holding onto: phishing in more than 1 in 3 engagements, valid stolen credentials in 24%, and exploitation of an internet-facing application in 18%. Nobody needed a novel technique to get in. The reason Talos gives for the sector concentration is the same reason a practice manager would give if asked. These are organizations with constrained budgets, aging equipment, and almost no tolerance for being down.
Low tolerance for downtime is the whole business case. An attacker is not pricing your data. An attacker is pricing your urgency, and in a regulated practice the urgency is manufactured by the regulation itself.
That is a different claim from the usual line about medical data being valuable, and it is the one that actually holds. A Santa Clarita medical or dental practice, or an accounting firm under the FTC Safeguards Rule, cannot treat a security incident as a private operational problem the way a contractor can. The moment protected information is involved, the incident stops being yours to manage quietly and becomes a set of obligations owed to other people, on clocks that started without your permission.
The Challenge
The notification clock starts at discovery, not at resolution. Under the HIPAA Breach Notification Rule, a covered entity must notify each affected individual without unreasonable delay and in no case later than 60 days after discovering the breach. Where a breach affects 500 or more individuals, the Secretary of Health and Human Services is notified on that same 60-day schedule rather than in the annual batch that smaller breaches go into. And where it affects more than 500 residents of a single state or jurisdiction, prominent media outlets serving that area must be notified as well.
Read that again with an office manager's eyes. The clock does not wait for you to understand what happened. It does not pause while a forensics firm works through disk images. 60 days from discovery, whether or not the investigation has produced a clear answer, letters go out.
The record is permanent and public. HHS maintains a public list of breaches affecting 500 or more individuals. It is searchable, and it does not expire. A contractor who quietly restores from backup has a bad quarter nobody outside the company ever learns about. A practice that crosses the threshold has a line on a federal website with its name on it, and that line will still be there when a prospective patient searches the practice name 4 years from now. In a market the size of the Santa Clarita Valley, where a medical or dental practice lives on referrals from a professional community of a few hundred people who all know each other, that is not an abstract reputational cost. Valencia, Saugus, Newhall, Canyon Country and Stevenson Ranch are one referral network wearing 5 names.
The regulator arrives second, and the investigation is about you. This is the part practices are least prepared for. After a reported breach the Office for Civil Rights does not investigate the attacker. It investigates whether the entity was doing what the Security Rule already required before the attack happened. OCR's Risk Analysis Initiative has now produced more than 12 enforcement actions, and the finding is the same one every time. In the agency's own framing, an entity cannot protect electronic protected health information if it has not identified the risks and vulnerabilities to that information in the first place.
So the sequence is this. You are the victim of a crime. You report the crime, because the law requires you to. The report opens an inquiry into your own conduct. Both things are true at once, and neither one cancels the other.
The outage is clinical, not commercial. When a contractor's systems go down, work is delayed. When a practice's systems go down, the schedule is gone and the charts are unreachable while people are sitting in rooms. Care either stops or continues on paper without the history that makes it safe. That converts an IT decision into a patient safety decision and collapses the window in which anyone can think clearly, which is the same dynamic our piece on downtime and operational resilience describes in the general case, sharpened by the fact that the people waiting are patients.
What was taken cannot be reissued. A stolen payment card is cancelled by lunchtime and the fraud liability sits with the bank. A record holding a name, a date of birth, a Social Security number, an insurance identifier and a clinical history cannot be cancelled, reissued, or made stale. The patient carries it for the rest of their life. That is why the exposure keeps generating obligations long after the systems come back: notification costs, credit monitoring, state attorney general interest layered on top of the federal process, and the civil claims that tend to follow a public listing.
Why It Matters
5 reasons this is worth an afternoon:
Paying stops 1 clock out of 4. A ransom payment may return your data. It does not stop the notification deadline, it does not close the OCR inquiry, and it does not remove the entry from the public list. Practices that assume payment ends the incident have budgeted for the outage and not for the chain, and that is how a survivable week becomes an unsurvivable year. It is also the moment the cyber insurance application you signed becomes the most consequential document in the building.
There is a statistic you will see everywhere, and we are not going to use it. Search for why practices get attacked and you will be told, repeatedly, that a medical record sells for 10 times a credit card number on criminal markets. Or 50 times. Or that it is simply the hottest item there is. We went looking for where that figure comes from. Every source we found is a vendor blog citing another vendor blog, the multipliers contradict one another, and none of them resolve to a primary market observation. It may well be directionally true. It is not checkable, so it does not belong in a piece that asks you to check things. The durable version needs no number at all: the record cannot be cancelled, so its usefulness to a criminal does not expire.
Small is the shape of the target, not an exemption from it. A 12-person practice holds the same category of information as a regional hospital, under the same rule, with a fraction of the defense and none of the security staff. An attacker working for a living optimizes return against effort rather than against absolute size. The hospital has a security operations centre. The practice has whoever also handles the printer. That gap, rather than the size of the prize, is what makes the small practice the efficient target.
Almost everything about the aftermath is decided before it happens. The severity of the chain above is not determined on the day of the attack. It is determined by whether the backups were offsite and immutable, whether a restore had ever actually been tested, whether the data was encrypted at rest, whether there is a current risk analysis to hand to OCR, and whether anyone can say who had access to what. Every one of those is a decision made on an ordinary quiet week, months earlier, by somebody who had no particular reason to think that week mattered.
Encryption changes the arithmetic more than anything else on the list. Where protected information is encrypted to the standard the government recognises and the keys were not taken, the information is not treated as unsecured, and the notification obligations do not attach in the same way. That is the single largest lever a small practice has over the size of its own chain, and it is a configuration setting rather than a project. It is also one of the safeguards the proposed Security Rule update would move from addressable to required, which is a reasonable argument for doing it now rather than waiting to be told.
What Organizations Should Watch For
- A backup that has never been restored from. A copy nobody has tested is a plan nobody has tested. The date of the last successful restore is a fact, and if nobody can produce it, the honest answer is that you do not have one. Our piece on backup versus recovery covers the distance between a copy existing and a copy working.
- Backups reachable from the network they are backing up. The nightmare version of every ransomware story is the one where the backup was encrypted along with everything else, because it sat on the same network, reachable with the same credentials. Offsite and immutable are two separate properties and you want both.
- A risk analysis that is old, thin, or nonexistent. This is the first document OCR asks for and the most common deficiency it finds. One produced after an incident is not evidence of anything.
- Unencrypted laptops, phones and tablets. Especially personal devices that reach patient or client email. A lost encrypted device is a hardware replacement. A lost unencrypted one is a notification event.
- Nobody who can say who has access to what. Departed staff, vendor logins, a shared front desk account, the login created for a temp two summers ago. The access list is the first thing an investigator reconstructs and usually the first thing a practice discovers it does not have, for the reasons our piece on offboarding as a security event sets out.
- The route in that nobody is watching. Phishing remains the leading way attackers arrive, and the tells everyone was trained to look for have largely stopped being reliable, which our pieces on the inbox as attack surface and what AI did to the phishing tells both cover.
- A contract with no breach notification clock in it. If your IT provider is not obligated in writing to tell you within a stated number of hours, your 60-day deadline is running while you are waiting for somebody to call you back.
- The assumption that the EHR vendor covers it. Their obligations run to their platform. The workstations, the server, the imaging, the local file share and the email are yours. Who backs up what should be answered system by system in writing, which is the same discipline our piece on third-party vendor risk applies to the rest of the relationships in the building.
Recommended Actions
- Find out when your last successful restore test was, and get the date in writing. If the answer comes back as an assurance that backups are running fine, that is not an answer to the question asked.
- Confirm at least one backup copy is offsite and cannot be altered or deleted from inside your network, including by your IT provider. Immutability is a property of the storage rather than a promise from a person, and it is the difference between the two versions of the bad Tuesday.
- Get the list of every device holding protected information, and confirm each one is encrypted. Include phones and tablets, including personally owned ones that reach practice email. Any device touching patient data is in scope regardless of whose name is on the bill.
- Read your current risk analysis. If you cannot find it, that is the finding. Then ask what a proper one costs and whether it sits inside your managed service or arrives later as a separate project, because the answer to that question tells you something about the provider as well as about the assessment. The assessment covers most of the same ground if you would rather start from a structured picture.
- Put a breach notification deadline into your provider agreement, stated in hours. The law gives you 60 days from discovery, and discovery depends entirely on somebody telling you. Ours is written at 72 hours and it is published, so you can read the clause before you ever call.
- Write down the sequence for the first day, before there is a first day. Who is called, who talks to patients, who decides about paying, and which counsel you have already spoken to. The decisions made in the first 6 hours shape the next 12 months, and those are the worst possible hours in which to be making them for the first time. That plan is what disaster recovery should mean in practice, and it belongs on paper long before it is needed.
The SecureLynx Perspective
Observe:
Every SecureLynx client gets the same foundation, and the reason is this chain rather than a marketing preference. Managed detection and response on every endpoint, automated patching, disk encryption, and immutable offsite backups held under object lock so they cannot be altered or deleted by anyone, including us. Being in the Santa Clarita Valley matters here in a way it does not for most services: when a server is down and patients are in rooms, somebody has to physically be there, and our on-site commitment for the valley is written into the service level agreement rather than described as a priority.
Adapt:
The first restore test is run during onboarding and the date goes on your record, because a backup nobody has restored from is not yet a backup. That record lives in the client portal alongside the dated training, the phishing test results and the timestamped offboarding entries, which is the same evidence OCR asks for after an incident and the same evidence a cyber carrier asks for before one. It is exportable, and you hold the primary copy. The Security Risk Assessment is inside onboarding rather than billed afterward, and it is kept current as the practice changes, because charging a practice to document the work you are already doing for them is a strange way to run a security business.
Protect:
Then the honest limits. We cannot promise nothing will go wrong, and anyone who does is selling you a dream. We are not your lawyer and nothing here is legal advice about your notification obligations, which belong with counsel the moment an incident is real. We cannot certify you compliant, because no MSP can and no such certification exists. What we will tell you is exactly what is in place before it happens and exactly what happens after, both in writing, both published before you call. Our breach notification commitment is 72 hours from discovery, written into the agreement rather than promised on a page, and the whole of it is on the legal page for you to read first. Point every question on this page at us before you point it at anyone else.
Common questions
We are a small Santa Clarita practice. Are we really a target, or is that a sales line?
You are targeted by sector rather than by name, and the distinction matters. Cisco Talos, reporting on its own incident response engagements for Q1 2026, found healthcare and public administration tied as the most targeted verticals at 24% each. The methods were ordinary: phishing in more than 1 in 3 engagements, stolen but valid credentials in 24%, and exploitation of an internet-facing application in 18%. Nobody researched your practice specifically. The sector is known to have constrained budgets, aging equipment and almost no tolerance for being down, so an attacker with a working technique aims it where it pays. Being small protects you less than most owners expect, because the effort required to hit a small practice is also small.
If we pay the ransom and get our data back, is the incident over?
No, and this is the most expensive misunderstanding in the subject. Payment addresses the encryption and nothing else. It does not affect the notification deadline, which runs 60 days from discovery regardless of who has been paid. It does not prevent an Office for Civil Rights inquiry, which examines your safeguards rather than the attacker conduct. It does not remove a qualifying breach from the public list HHS maintains. And where information was copied out as well as encrypted, payment buys a promise from a criminal that the copy was deleted, which is not something you can verify. Budget for the chain, not for the outage.
What is the single most useful thing we could do this month?
Establish the date of your last successful restore test, and if there is not one, arrange one. Everything else in a ransomware scenario is downstream of whether the recovery actually works, and it is the item most often assumed rather than checked. A close second is confirming that protected information is encrypted at rest on every device, including phones and tablets that reach patient or client email, because encryption to the standard the government recognises changes whether an exposure is a notification event at all. Both are questions your IT provider should answer with a date and a list rather than with a reassurance.