Response Plan · 7 pages
Ransomware & Downtime Response Plan for Dental Practices
What to do in the first hour of a ransomware event or major outage, written for a practice owner or office manager, not an IT department.
Dental practices are a soft, high-value target. A single-location office sits on years of protected health information, runs insurance payment flows an attacker can disrupt to force a fast payout, and almost never has a dedicated IT security team watching the network at 6:00am on a Saturday. That combination, valuable data and thin defenses, is exactly what ransomware operators screen for. It is not a matter of being a big enough or interesting enough target. Automated scanning finds the gap; the practice's size never enters into it.
Nothing here replaces a formal, practice-specific incident response plan built with your IT provider, your insurance broker, and where appropriate an attorney. Think of this as the version that works when nobody has time to think: a short, ordered list of what to do first, what to check next, how to keep the practice open This document on paper, provides generaland what incident compliance response clock guidance starts for dental ticking practices. It isthe not moment you legal advice, notdiscover complianceaadvice, problem. not insurance advice, and not a substitute for a formal, practice-specific incident response plan built with your IT provider, your insurance broker, and legal counsel. Deadlines, notification requirements, and coverage terms vary by policy, state, and circumstance; confirm every one of them with the appropriate professional before acting on them. © NexGen IT Solutions. You may print and share this document freely within your organization.
The first 15 minutes
What you do in the first quarter hour determines how much of your data survives, how much the investigation costs, and whether your insurance claim gets paid. Move fast, but do not improvise past this list.
The single most important rule Do not pay or negotiate with the attacker, and do not decide on your own to refuse to pay either, without guidance from your cyber insurance carrier and legal counsel first. Paying does not guarantee your data comes back, may be illegal depending on who the attacker turns out to be, and can void the exact insurance coverage you are relying on if it happens before your carrier is involved. Your insurer likely has a negotiator on retainer for this. Let them run it.
- Isolate affected devices from the network immediately. Unplug the network cable or disable Wi-Fi on any machine showing ransom notes, unusual behavior, or files you cannot open. This stops the encryption from spreading to machines that are still clean. Speed matters more than technique here; pulling a cable is faster than finding a network switch.
- Do not power off or restart the affected machines. It is tempting to shut a screaming computer off. Don't. Powered-off machines lose evidence in memory that investigators and your insurer's forensics team need to determine what happened and how far it spread. Isolate from the network, but leave the machine running.
- Do not wipe, reimage, or reinstall anything yet. The instinct to "just start clean" destroys the forensic trail before anyone has looked at it, and can complicate or void an insurance claim. Wiping is a recovery step, not a first step.
- Call your IT provider immediately. Before you troubleshoot anything yourself. Every extra minute a live incident runs unmanaged is more machines encrypted and more decisions made without someone who has done this before.
- Call your cyber insurance carrier's claims line immediately. Most policies require notification within a specific window, sometimes as short as 24 to 72 hours, and many require you to use their approved incident response vendors to stay covered. Find this number now, not during the incident, and write it on this page.
- Notify the office manager and the doctor or practice owner right away. Decisions about paying a ransom, closing the schedule, and talking to patients belong to practice leadership, not to whoever happened to notice the ransom note first.
- Do not use potentially compromised email or messaging to discuss the incident. If email is on the same network or the same account that was breached, the attacker may be reading it. Coordinate by phone or text on personal devices until your IT provider confirms which systems are clean.
- Photograph the ransom note and any error screens before doing anything else. A phone photo of the ransom note, the group name, the contact instructions, and any deadline shown on screen is evidence your insurer, your IT provider, and possibly law enforcement will all ask for.
Assessing the damage
With affected devices isolated, the next job is figuring out exactly what happened and how bad it is. This is usually done together with your IT provider, but staff can gather most of this before they even arrive.
- Identify which systems are affected: practice management software, imaging server, email, and phones. Check Dentrix, Eaglesoft, Open Dental, or whichever PMS you run, separately from your imaging server, your email platform, and your phone system. They may not all be down, and knowing which ones still work shapes everything in Section 3.
- Check backup integrity and how recent the last successful backup actually was. Not whether backups exist, whether the most recent one completed successfully and is untouched by the attack. A backup drive that stays connected to the network can be encrypted right along with everything else.
- Determine whether patient data appears to have been copied out, not just encrypted. Modern ransomware groups frequently steal data before encrypting it, then threaten to publish it as separate leverage. This distinction changes your HIPAA breach analysis in Section 4, so ask your IT provider to look for signs of data exfiltration specifically, not just encryption.
- Document a timeline of what happened, in writing, starting now. When the first symptom appeared, who noticed it, what they clicked or opened beforehand if known, and every step taken since. Your insurer, any forensics vendor, and potentially your attorney will all ask for this, and memory fades fast under stress.
- Record exactly what the ransom note says. The group name, the ransom amount if stated, the contact method, and any deadline. Your IT provider and insurer may recognize the group and know what to expect from them.
- Check whether the server, individual workstations, or both were encrypted. A single infected workstation is a very different recovery than an encrypted server holding your patient database. This determines how fast you can be back up.
- Check whether any cloud-based systems were affected. Cloud X-ray storage, a patient portal, online scheduling, or a cloud-hosted PMS can be compromised through stolen credentials even if nothing in the building was touched directly. Confirm these separately.
- Preserve logs, screenshots, and affected files before any restoration begins. Once you restore from backup, evidence of exactly what the attacker touched becomes much harder to reconstruct. Let your IT provider or forensics team capture what they need first.
Keeping the practice open on paper
Patients are still arriving whether your systems are up or not. A short, rehearsed paper fallback keeps the day running and keeps patient trust intact while recovery happens in the background.
- Switch to paper charting immediately for any patient seen while systems are down. Keep a supply of blank chart forms, treatment plan sheets, and consent forms printed and stored somewhere other than the network, such as a locked drawer at the front desk.
- Reach today's patients without relying on email or the practice management system. Keep a printed copy of tomorrow's schedule at close of business every day, specifically so you have names and phone numbers on paper if systems go down overnight. Call from a personal or backup phone line.
- Verify insurance eligibility manually by phone with each carrier. Keep a printed list of the major payers' verification phone numbers on hand. Online portals may be unreachable if the outage affects your internet-facing systems, not just internal ones.
- Hold a brief staff huddle at the start of the day to set expectations. Everyone should know the systems are down, what the paper workflow is for the day, and who is answering patient questions about the practice's status. Consistency matters more than polish.
- Work from the most recent printed schedule if the live system is unavailable. This is another reason to keep a daily printed backup of the schedule as a standing habit, not just an incident-response afterthought.
- Handle payment processing manually if the usual system is down. Confirm whether your card processor is independent of the affected network. If not, have a manual card imprint process or plan to invoice after systems are restored, and tell patients that up front.
- Keep a running log of everything charted on paper for later entry. Someone will need to transcribe every paper chart into the PMS once it is back online. Number the pages and keep them together so nothing gets lost or entered twice.
Notification & compliance steps
This is where a technical incident becomes a legal and compliance obligation. The clock on some of these deadlines starts the moment you discover the incident, not the moment you finish investigating it.
After the immediate crisis
- Work through the HIPAA breach risk assessment questions with your IT provider or counsel. Was PHI actually accessed or acquired, or only encrypted with no evidence of access? Who accessed it, if anyone? Was the data itself readable, or was it encrypted at rest? These answers determine whether this is a reportable breach at all.
- Know that the 60-day notification clock generally starts at discovery, not at resolution. Under the Breach Notification Rule, affected individuals generally must be notified within 60 days of when the breach was discovered, regardless of how long the investigation or recovery takes. Confirm your exact obligations with counsel; do not assume you have 60 days from today.
- Determine whether and when law enforcement should be involved. Ransomware is a federal crime. Reporting to the FBI's Internet Crime Complaint Center (IC3) at ic3.gov does not obligate you to anything and can provide information that helps your response, including whether the specific attacker group is known to leak data even after payment.
- Document every cost and every action for your cyber insurance claim. Forensics fees, IT provider time, overtime pay, lost production from canceled appointments, notification and credit-monitoring costs, and legal fees are all typically claimable. Keep receipts and a running log from day one; reconstructing it later is much harder.
- Confirm whether Michigan's state breach notification law applies on top of HIPAA. State law can impose its own timelines and requirements in addition to federal HIPAA rules. Your attorney or compliance consultant should confirm which apply to your specific facts.
- Identify whether any business associates need to be notified. If a vendor's system was the point of entry, or if their data was affected through your systems, your Business Associate Agreements likely define mutual notification obligations. Pull those agreements and check.
- Prepare a draft patient notification letter early, even before you know you need it. Having a template ready, reviewed in advance by counsel, saves critical time if notification turns out to be required. Waiting until day 55 of a 60-day clock to start drafting is a self- inflicted problem.
- Track HHS reporting requirements based on how many individuals were affected. Breaches affecting 500 or more individuals have different reporting timelines and media notification requirements than smaller breaches. Confirm the count and the applicable timeline with counsel as soon as it is known.
Recovery & lessons learned
Getting back online is not the finish line. A practice that restores its systems but skips this section is set up to relearn the same lesson the hard way.
Restoration has to happen carefully, not just quickly. Restoring from a backup that was connected to the network during the attack can reintroduce the same malware you just spent days getting rid of. Your IT provider should confirm the backup being restored predates the infection, and should rebuild affected machines from clean images rather than simply restoring files onto a potentially compromised operating system.
The recovery checklist, in order 1. Confirm the backup source is clean before restoring anything. Your IT provider should verify the restore point predates the intrusion, not just the encryption event, since attackers are frequently in a network for days or weeks before triggering ransomware. 2. Rebuild compromised machines from clean images rather than trusting a cleaned infected one. A full reimage is slower than a virus scan, and it is the only way to be confident the machine is actually clean. 3. Reset every password across every system, not just the ones that were obviously affected. Email, the practice management system, remote access, Wi-Fi, vendor portals, and any shared or service accounts. Assume the attacker saw more than you can prove they saw. 4. Re-enable multi-factor authentication everywhere and confirm there are no exceptions, including for the owner or doctor. Attackers who obtained one password will try it everywhere. 5. Bring paper charts into the practice management system, using the numbered log from Section 3 to make sure nothing from the downtime window is missed or entered twice. 6. Hold a post-incident review with the whole team while the details are still fresh: what worked, what took too long, what nobody knew who to call, and what would have helped in the first 15 minutes. 7. Update this plan with what you learned, including correct phone numbers, the name of your actual cyber insurance carrier and policy number, and any step that turned out to be missing. A plan that is never updated after a real incident is a plan that will fail the same way twice.
Turn this into a written plan you have actually tested This document gets your team through a bad morning. A complete incident response plan goes further: it names specific backup roles for every staff member, is rehearsed with a tabletop exercise at least once a year, and is kept current with your actual vendor contacts, insurance policy details, and system inventory. If your practice does not have one, or has not looked at it since it was written, that is worth fixing before an incident forces the issue.
Want the printable version?
Get the full response plan as a free PDF
Everything on this page, formatted to print or save, delivered straight to your inbox. No sales call required.
Download the free PDF