Articles

Is Your Practice Actually Protected From Ransomware? A Dental IT Specialist’s Checklist

The Dentalligentsia Postcast Recap - With Shawn Lamb
“Don’t be afraid to fail. Fall flat on your face, get up, and learn from it. And do something you’re scared of — a lot.” — Shawn Lamb, Advantage Technologies

The sentence Shawn Lamb hears most often from dentists is the one that keeps her up at night: “We’re just a small office. They’re not going to come for us.”

Her answer, from twenty years inside dentistry: “Really, you’re who they’re coming for — because that’s what you think, and they know the way that you think.”

Lamb is a Technology Consultant at Advantage Technologies, a managed IT provider that has specialized exclusively in dental for 25 years — roughly 800 client practices from Michigan down I-75 to Florida, and, in a claim almost nobody in her industry can make, not one breach in those 25 years. Before IT she spent about 15 years running dental practices — office manager at 19, boots on the ground — which is why she speaks fluent dental and why her warnings land. We had her on the Dentelligentsia podcast for a conversation every practice owner should hear before, not after, the bad email arrives.

How the attack actually works

Nobody clicks a link labeled “ransomware.” The way in is a convincing email — an Amazon tracking link, a banking confirmation — landing in front of a front-desk team member sorting twenty of them a day while trying to be helpful. One click. “I don’t think anybody is out there blatantly putting their office at risk,” Lamb said. “It’s that simple, and if you don’t have everything in place to prevent those emails from coming in, it’s a very easy thing to happen.”

What follows is patient. The intruders sit quietly in the system — indefinitely, if unprotected — waiting for the data files to get, in Lamb’s word, juicy. Then the alert arrives: we have your patient files. Pay, or they go to the dark web. And a dental practice’s files are worth paying for: insurance details, Social Security numbers, and — despite compliance rules — credit card numbers stored in patient files for convenient monthly payments.

Now the arithmetic of refusing. The average practice hit by ransomware is down 17 business days — no schedule, no imaging, no billing. HIPAA requires notifying every patient the practice has ever seen that their information was breached, which is marketing material no one recovers from easily. Practices that pay — sometimes hundreds of thousands — usually don’t get their data back anyway, the files often hit the dark web regardless, and the ones that pay get hit again, because they’ve identified themselves as players of the game. Lamb has watched practices close their doors over it.

Her firm’s countermeasure gives a flavor of what proactive actually means: fake, deliberately tempting data files planted in the system. The moment an intruder touches one, the alarm goes off. A trap, set years before it’s needed.

The basics half of offices are missing

Forget the exotic stuff — Lamb’s audits find the fundamentals absent. A physical firewall — an actual piece of hardware standing between your network and the world (“I always picture Mr. Clean,” she said, and now so do we) — is expected under HIPAA. Half the offices she assesses don’t have one and don’t know they’re supposed to. The office HIPAA compliance officer is usually a dental assistant doing five other jobs.

And a firewall you have but nobody updates is theater. Who’s checking the patches? Who’s verifying the backup — not assuming it, verifying it, daily? Who knows that running outdated versions of your practice management and imaging software is itself a compliance problem? In Lamb’s onboarding audits, three-quarters of offices aren’t on current versions and don’t know it.

Then there’s the calendar nobody tracks: operating systems reach end-of-life roughly every five years, at which point the maker stops issuing security patches and every machine running it becomes non-compliant overnight. Those upgrade years ripple through everything — server, workstations, the computers driving your pan and CBCT — which is convenient in exactly one way: five years is also the natural life cycle of a healthcare computer. If your IT provider isn’t talking to you a year ahead of the next end-of-life date, in Lamb’s words, fire them immediately.

Managed IT versus the neighbor kid

The industry term is MSP — managed service provider — versus break-fix. Lamb’s translation: when she asks a new office who handles their computers, the answer is often “the hygienist’s husband” or “the neighbor kid who set up his home computer,” on speed dial for when something breaks.

The break-fix model means every problem is discovered by your team, during patient hours, at hourly rates, by someone learning dentistry on your clock. The managed model means someone who has already fixed your exact problem — probably that same day, across 800 similar offices — is preventing it before it surfaces. Advantage’s version is deliberately not à la carte: enterprise-grade firewall, switch, and wireless access points included and replaced at no charge beyond installation, warrantied and updated, because in Lamb’s view that’s simply what a dental office needs, not an upsell menu.

Her favorite ritual answers the question every good IT provider eventually gets: “Things have been smooth — do I still need you?” She pulls up the monthly threat report showing everything quietly blocked and prevented, and asks the doctor: are you ready to maintain this yourself? “The answer I normally get is heck-to-the-nah.”

The everyday stakes are productivity, not just catastrophe

The security case gets the headlines; the daily case pays the bills. Lamb’s favorite turnaround: an office whose Wi-Fi couldn’t hold a connection operatory to operatory, so hygienists’ sensors dropped mid-appointment, every appointment — a 45-minute slot with a technology tax on it. A properly designed network ended it, and that office manager still calls Lamb with family news two years later.

Her diagnostic question for any office is simply “walk me through your morning.” One hygienist described powering on her computer, hanging schedules in every operatory, making coffee, changing into scrubs, pouring a second cup — and returning to a machine still booting. Twelve minutes. “To them, they don’t know that’s not normal.” It’s not normal. Neither is a pan or CBCT producing slow, muddy images because the computer driving it was never specced for the job — a fix that, more than almost anything else in IT, doctors actually celebrate.

Two more cheap wins. Staff training runs about $5 a team member — pick the modules you want, phishing-test emails included, run as education rather than gotcha, because “just don’t click things” works about as well as it does with her three boys. And if you want Facebook and Instagram blocked on office machines — both a temptation and an attack surface — that’s a checkbox.

Buying a practice? Audit the IT before you sign

The advice we underlined for our own clients: Lamb does complimentary IT assessments — address, no obligation — and in four and a half years has never done one that came back clean. For a buyer, that audit is negotiating power: if the practice you’re acquiring runs on aging machines and unsupported software, that can be $40,000 of equipment you’re inheriting, and you want that number in the deal conversation, not discovered after closing, when — as she put it — “now you have what you have.”

The mirror image applies to sellers: the practice still dipping film has a buyer problem coming, because new graduates have never touched it and won’t start. Modernizing five years before the sale — a theme our transitions guests keep landing on from every direction — keeps the practice desirable and the process unhurried.

One boundary worth knowing: cyber threats are external. The internal kind — embezzlement, fraud — is a different discipline entirely, handled by dental-specific CPAs, attorneys, and standard operating procedures. Lamb tells a story about being handed the owner’s entire checkbook and every credit card in week two of her first office management job at nineteen. Different Mr. Clean required.

Her life advice matched her security advice, which is probably not a coincidence: don’t be afraid to fail, own your mistakes in front of your kids and your clients, and treat people the way you want to be treated — then follow through. That last one, she says, is the whole business plan.

The full conversation with Shawn Lamb, “Dental Cybersecurity & IT Mistakes That Could Cost You Everything,” is on the Dentelligentsia podcast. And since the network gets designed when the walls are open — cabling, access points, server room and all — the time to think about IT is during the buildout, not after move-in. When you’re there, talk to us.

And follow Shawn Lamb on Linked In or check out the Advantage Technologies website.

Recent:

No results found.

What Our Clients Are Saying