Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Ransomware recovery

An 11-location dental group, encrypted on a Thursday night.

Practice management server, imaging server, and the backup share, all encrypted. Chairs were seeing patients again in 31 hours.

31 hrs
To first chair back in service
0
Ransom paid
4 days
To full operation across all 11 sites
The organization
Organization 11-location dental group
Market Middle Tennessee
Users 94
Systems Eaglesoft, on-premise SQL; two imaging servers
Engagement at time of event Chartline Secure, 7 months in

What happened

A front-desk workstation at the group’s third-largest site executed a loader delivered through a fake browser update. The operator moved laterally within the hour, reached the practice management server, and began encrypting at 11:42pm on a Thursday.

Managed detection flagged the process behaviour on the workstation at 11:38pm, four minutes before encryption began on the server. The analyst isolated the workstation, then the server, then disabled the compromised account. Total elapsed time from confirmed detection to containment was nine minutes. Two of the eleven sites were never touched.

Why it did not get worse

Three controls decided the outcome, and all three had been put in place during onboarding rather than during the incident. Backups were immutable, so the operator could not delete or encrypt them — the attempt is in the logs. Network segmentation kept the imaging servers on a separate segment with deny-by-default egress, which is why two sites were unaffected. And the response authority in the contract meant the analyst isolated hosts at 11:47pm without needing to reach an owner who was asleep.

The last restore test before the event was 34 days old and had been timed. That timing is why we could tell the managing partner, at 1am, how long the recovery would take rather than guessing.

The recovery

Practice management database restored from the immutable copy and validated against the previous day’s production log. First chair back in service at 6:40am Saturday, 31 hours after encryption started. All eleven sites fully operational by the following Monday afternoon.

No ransom was paid and no negotiation was opened.

The part most write-ups leave out

We ran the breach risk assessment under §164.402 with the group’s counsel and completed it on day three. The forensic finding was that the operator was interrupted before staging or exfiltrating data, and the assessment concluded a low probability of compromise, documented against all four required factors.

That conclusion is only defensible because the logging existed beforehand. Twelve-month log retention is not an expense until the week you need to prove a negative, at which point it is the whole case.

What changed afterward

The group moved from Secure to Compliant at the next renewal. The tabletop that had been scheduled for the following quarter was held six weeks early, with the actual event as the scenario. Local administrator rights were removed from all clinical workstations, which had been on the risk management plan as a medium-priority item and was reprioritized on day five.

Outcome

The whole result, in one table.

Including the figures that are less flattering than the headline. A case study that only contains good numbers is an advertisement.

Time to first chair in service 31 hours
Time to full operation, 11 sites 4 days
Ransom paid $0
Sites unaffected due to segmentation 2 of 11
Detection to containment 9 minutes
Reportable breach determination Low probability of compromise, documented
Collections lost, estimated by the group Under 2 days
Your turn

Where would you land on the same questions?

The readiness check runs the fifteen questions we open every assessment with. It takes about eight minutes and it names the §164 citation behind every gap.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.