Article Read Time

A small health care practice in a Kentucky county seat lost access to its patient records on a Monday morning last winter. The front desk could not pull up a single chart. Appointments backed up into the parking lot. The office manager told me later that she had always assumed criminals went after the big hospital systems, not a clinic with two doctors and six staff. She was wrong, and she is not alone in that assumption.
The small health care practice has become a favorite target, and the reason is plain. You hold the same valuable records a large hospital holds: names, birth dates, Social Security numbers, insurance details, and medical histories. A stolen medical record sells for far more on criminal markets than a stolen credit card number, because a card can be canceled in an afternoon and a medical history cannot. Yet a small practice rarely has the staff, the budget, or the full-time security help that a hospital keeps on hand. To an attacker, that is a locked door with the key left under the mat.
When a small health care practice gets hit, what actually goes wrong?
Most breaches at small practices start in an ordinary way. Someone clicks a link in an email that looks like it came from a lab, a billing service, or the practice’s own software vendor. That is phishing, which means a fake message built to trick you into giving up a password or opening a bad file. From there, two things tend to happen.
The first is ransomware. That is a program that locks up your files and demands payment to unlock them. When it hits a clinic, the schedule, the billing system, and the patient charts can all go dark at once. Some small health care practice may pay. Many that pay never get everything back.
The second is a quiet theft of records. The attacker copies patient files and sells them, and the practice may not notice for weeks. By then the damage to patients is already done, and the practice still carries the legal weight of the loss.
That legal weight is real. Under the federal health privacy law known as HIPAA, a practice that loses patient records must notify affected patients, and often the government and the media as well. Fines can climb into six figures for a small office, and that figure does not count the cost of lost time, lost trust, and patients who quietly move their families to another doctor. A breach is not one bill. It is a line item that keeps reappearing for years.
The fundamentals that actually hold
Here is the good news, and I mean it plainly. The measures that stop most attacks are not exotic, and they do not require a large budget. They require attention and consistency.
Start with a second login step, sometimes called multifactor authentication, which means a code or a prompt on your phone in addition to your password. If a criminal steals a staff password, that second step still keeps them out. Turn it on for email, for your records system, and for anything that touches patient data.
Keep good backups, and keep one of them offline. Think of a backup as a spare set of keys stored at your sister’s house, not on the same ring as the originals. If ransomware locks your files and you have a clean, separate copy, you can rebuild instead of paying a stranger.
Update your software when the updates arrive. Those updates often close the exact doors attackers walk through. A device running old software is an unlocked window.
Train your people, because your staff is your front line, not your weak spot. Show them what a fake email looks like. Make it normal to pause and ask before clicking. A clerk who feels free to say “this looks off” is worth more than most software you can buy.
Write down a simple plan for a bad day. Who do you call first? How do you reach patients if the system is down? Where is the backup, and who knows how to restore it? A plan written before an emergency beats a scramble during one.
A Small Health Care Practice doesn’t have to do this alone
Some of the best help is free. The federal Cybersecurity and Infrastructure Security Agency, known as CISA, publishes plain guidance made for small organizations like the small health care practice. If records are stolen, the FBI takes reports through its Internet Crime Complaint Center, called IC3. Your state offers resources too, and a local InfraGard chapter can connect you with people who do this work every day.
When you do want a partner to sit down and walk the practice through its risks, that is a conversation Commonwealth Sentinel is glad to have. Not a sales pitch, a conversation. You can reach us at 502-234-5554.
The office manager I mentioned rebuilt her practice from a backup she almost did not keep. She keeps two now, and she checks them. That is the whole lesson. The clinic that plans on a calm day is the one still seeing patients on the hard one.
