An 11-location dental group, encrypted on a Thursday night.
Practice management server, imaging server, and the backup share, all encrypted. Chairs were seeing patients again in 31 hours.
- 31 hrs
- To first chair back in service
- 0
- Ransom paid
- 4 days
- To full operation across all 11 sites
What happened
A front-desk workstation at the group’s third-largest site executed a loader delivered through a fake browser update. The operator moved laterally within the hour, reached the practice management server, and began encrypting at 11:42pm on a Thursday.
Managed detection flagged the process behaviour on the workstation at 11:38pm, four minutes before encryption began on the server. The analyst isolated the workstation, then the server, then disabled the compromised account. Total elapsed time from confirmed detection to containment was nine minutes. Two of the eleven sites were never touched.
Why it did not get worse
Three controls decided the outcome, and all three had been put in place during onboarding rather than during the incident. Backups were immutable, so the operator could not delete or encrypt them — the attempt is in the logs. Network segmentation kept the imaging servers on a separate segment with deny-by-default egress, which is why two sites were unaffected. And the response authority in the contract meant the analyst isolated hosts at 11:47pm without needing to reach an owner who was asleep.
The last restore test before the event was 34 days old and had been timed. That timing is why we could tell the managing partner, at 1am, how long the recovery would take rather than guessing.
The recovery
Practice management database restored from the immutable copy and validated against the previous day’s production log. First chair back in service at 6:40am Saturday, 31 hours after encryption started. All eleven sites fully operational by the following Monday afternoon.
No ransom was paid and no negotiation was opened.
The part most write-ups leave out
We ran the breach risk assessment under §164.402 with the group’s counsel and completed it on day three. The forensic finding was that the operator was interrupted before staging or exfiltrating data, and the assessment concluded a low probability of compromise, documented against all four required factors.
That conclusion is only defensible because the logging existed beforehand. Twelve-month log retention is not an expense until the week you need to prove a negative, at which point it is the whole case.
What changed afterward
The group moved from Secure to Compliant at the next renewal. The tabletop that had been scheduled for the following quarter was held six weeks early, with the actual event as the scenario. Local administrator rights were removed from all clinical workstations, which had been on the risk management plan as a medium-priority item and was reprioritized on day five.
The whole result, in one table.
Including the figures that are less flattering than the headline. A case study that only contains good numbers is an advertisement.
Two more, also with numbers.
Twelve acquired practices, three PM systems, one standard.
A dental support organization had grown by acquisition for four years and inherited twelve environments nobody had ever standardized.
Read it OCR data requestAn OCR data request answered in nine business days.
A specialty physician group received a data request following a business associate’s breach. The request had a thirty-day clock on it.
Read it