Ransomware Doesn’t Care How Long You’ve Been in Practice

Ransomware Dental IT Featured IMage

Westend Dental paid $350,000 for one ransomware attack. Not because the ransom itself was expensive. Because when the Medusa Locker group hit their systems, the practice told patients their hard drive got “accidentally formatted.” Federal investigators found out. The fine followed.

I run Willamette Valley IT, and dental offices make up our entire client base. I’ve had this exact conversation more times than I can count. A dentist who’s been in practice fifteen or twenty years, built a great reputation, runs a tight clinical operation, and still thinks ransomware is something that happens to hospitals or big corporations. It’s not. It’s happening to practices exactly like yours, and it’s happening more every year. This isn’t a scare tactic to sell you a service. It’s just what I’m watching happen to real offices, some of them a few miles from mine.

Why Dental Practices Became Ransomware’s Favorite Target

The Data You’re Sitting On

Think about everything sitting in your practice management system right now. Full names, birthdates, Social Security numbers, insurance details, medical histories, credit card numbers on file. That’s a complete identity theft kit sitting on a server in your back office. Criminals don’t need to break into a hospital to get that. Your office will do just fine.

Why “We’re Too Small” Doesn’t Hold Up

Here’s the part that surprises people. Ransomware attacks on healthcare jumped 58% in 2025, and dental and other secondary providers accounted for roughly a quarter of those incidents. You’re not too small to be worth the trouble. You’re actually a preferred target, because attackers assume, correctly a lot of the time, that a five-chair practice has weaker defenses than a hospital system with a full security team. Smaller isn’t safer. Smaller is easier.

What a Ransomware Attack Actually Costs a Practice

Beyond the Ransom Demand

The average dental ransomware incident in 2025 ran about $85,000 once you add up IT recovery, breach notification letters, legal fees, and the production you lose while your systems are down. Notice what’s missing from that number. It doesn’t include the ransom itself, which plenty of practices never pay anyway, since paying doesn’t guarantee you get your data back.

The HIPAA Bill Nobody Budgets For

This is the part that gets glossed over. A ransomware attack isn’t just an IT problem, it’s a compliance problem. Gums Dental Care in Philadelphia, PA paid $70,000 for failing to give a patient timely access to their own records after a breach. Westend Dental’s $350,000 penalty came down to something almost embarrassingly basic, the same login credentials across every server holding patient data, and no real password policy until 2024. So the fines often have less to do with the attack itself and more to do with what investigators find once they start looking at your setup. Shared passwords, no documented policy, no risk assessment on file. Those are the things that turn a bad week into a six-figure penalty.

Three Ransomware Myths Putting Your Practice at Risk

“My Backups Will Save Me”

Backups matter, a lot. But a backup that stays connected to your main network at all times is a backup that can get encrypted right alongside everything else. If you’ve never actually tested restoring from your backup, you don’t have a backup plan. You have a hope.

“Paying Fixes It”

Paying the ransom doesn’t erase the leak risk, doesn’t guarantee a working decryption key, and doesn’t undo the weeks of downtime that already happened. Plenty of practices pay and still end up rebuilding systems from scratch because the decryption tool the criminals hand over barely works.

“Our IT Guy Handles Security”

General IT support and dedicated security monitoring are not the same service. If your current setup is one person who fixes printers and resets passwords, that’s not a security program. That’s a help desk. Dental IT built for this specific threat looks different, and it should.

The Ransomware Trend Most Practices Haven’t Heard Of

Here’s something that caught my attention this year. Data-only extortion, where criminals steal your files and threaten to leak them without ever bothering to encrypt anything, jumped from 2% of cases to 22% in about twelve months. That’s an elevenfold increase, and it matters more than it sounds like it should. “We have good backups, we’re fine” is no longer a complete answer. If the attacker never locked your systems in the first place, your backups don’t help you at all. They just stole the data, and now they’re threatening to post it.

The second surprise is on the money side. Ransom demands actually dropped 91% industry-wide, from around $4 million in 2024 down to about $343,000 in 2025, even as the number of attacks went up. Attackers aren’t chasing fewer huge scores anymore. They’re running a volume business, hitting far more small targets for smaller, faster payouts. That volume model is exactly why a five-operatory practice in a mid-size town is just as much of a target as a large DSO.

Dental IT Basics That Actually Stop Ransomware

Multi-Factor Authentication Everywhere

This is the single highest-value thing you can do. MFA blocks over 99% of automated account takeover attempts, and yet the overwhelming majority of compromised business accounts never had it turned on. If your team logs into email, your practice management software, or remote access tools without a second verification step, fix that first. This week, not next quarter.

Password Managers

A password manager handles two problems at once. It generates a long, unique password for every login instead of the same one reused across your practice management software, email, and insurance portals. And it only autofills on the real website. If a phishing email sends your front desk to a lookalike login page, the password manager just won’t fill in the fields, because it knows that page isn’t the real one. That small refusal is often the only thing standing between a fake email and a stolen credential.

Backups You’ve Actually Tested

Keep at least one backup copy offline or disconnected from your live network, and actually run a test restore on a set schedule. Not annually. Quarterly, at minimum.

Patching and Staff Training

Unpatched software accounts for roughly a third of ransomware entry points, and phishing is behind the vast majority of successful attacks overall. Keep systems updated automatically where you can, and run short, regular phishing training with your front desk and clinical staff. Five minutes a month beats an $85,000 recovery bill every time.

Have an Actual Incident Response Plan

Most practices have never written down what happens in the first hour of an attack. Who do you call. Who talks to patients. Who decides whether to shut down the network. A one-page plan you’ve actually read beats a great plan that only exists in someone’s head. Write it down, print a copy, and keep it somewhere that isn’t only on the computer that might get locked.

What To Do This Week

Ransomware doesn’t care how long you’ve been practicing, how good your reviews are, or how many patients trust you. It cares whether your front door is locked. Most attacks succeed because of a handful of gaps that are genuinely fixable: unprotected logins, untested backups, and staff who’ve never been shown what a phishing email looks like.

Pick one thing from this list and fix it this week. Turn on MFA. Set your team up with a password manager. Test a backup restore. Write down your response plan. None of this is complicated, and none of it costs anywhere near what an $85,000 recovery bill does. If you want a second set of eyes on where your practice actually stands, that’s the conversation I have with dentists every week at Willamette Valley IT.