Ransomware gets a lot of coverage when it hits a hospital system or a major corporation. Those stories create the impression that small practices aren't targets. They're too small to bother with. Attackers want big payouts from big organizations.
That impression is wrong, and it's getting more wrong every year.
The economics of targeting small practices
Large organizations have security teams, incident response retainers, and layers of technical controls. Breaching them takes real effort and carries real risk of detection. Small practices typically have one IT person (or none), no dedicated security tools, and no plan for what to do when something goes wrong.
From an attacker's perspective, a solo therapy practice or a three-person law firm is not a smaller version of a hospital. It's an easier version of a hospital, with data that's just as valuable and defenses that are dramatically weaker.
Healthcare data sells for more than credit cards. A stolen credit card number is worth a few dollars on criminal markets. A complete patient record, including name, date of birth, insurance information, and health history, sells for $250 to $1,000. Healthcare data is among the most valuable categories of stolen information.
How ransomware attacks on small practices actually happen
The majority of successful ransomware attacks on small practices follow one of three paths:
Phishing emails
A staff member receives an email that looks legitimate. An insurance form. A patient inquiry. A notification from a software vendor. The email contains a link or attachment. When it's opened, malware installs silently on the device. The attacker now has access to the network and can move toward the data they want before triggering the ransomware payload.
Compromised credentials
A staff member's email password is guessed, purchased from a prior breach, or captured through phishing. The attacker logs in, establishes persistence, and eventually either deploys ransomware or exfiltrates data quietly. Practices without multi-factor authentication (MFA) are particularly vulnerable to this pathway.
Unpatched software
Older software versions often contain known vulnerabilities. Attackers scan for systems running unpatched versions and exploit them automatically, without any interaction from staff. Practice management software, remote desktop tools, and networking equipment that isn't regularly updated are common entry points.
What happens after an attack
In a ransomware attack, your files are encrypted and you lose access to them. The attacker demands payment (typically in cryptocurrency) in exchange for the decryption key. Payment does not guarantee recovery. Many practices that pay receive a partial key, a non-functional key, or no key at all.
Beyond the ransom itself, the real costs include:
- Downtime (the average recovery time for small businesses is 3 to 4 weeks)
- Forensic investigation to understand how the breach occurred
- Regulatory notification requirements if patient data was exposed
- HIPAA enforcement investigation if the breach meets reporting thresholds
- Potential civil liability if clients or patients sue
- Cyber insurance claims that may be partially or fully denied
Double extortion is now common: Many ransomware groups don't just encrypt your data. They exfiltrate it first, then threaten to publish it publicly if you don't pay. Paying the ransom doesn't prevent the data from being leaked. It just removes the immediate leverage.
The controls that make you a harder target
You don't need to be impenetrable. You need to be harder to breach than the next practice on the attacker's list. Most ransomware operations are volume businesses. They run campaigns against hundreds of targets and take the ones that don't push back.
- Multi-factor authentication on all accounts: Eliminates the credential compromise pathway for most attackers.
- Staff phishing awareness: Even a one-hour annual training reduces click rates significantly.
- Tested, offsite backups: If you have clean backups, you can recover without paying. Test restoration quarterly so you know the backups work before you need them.
- Endpoint protection software: Modern endpoint tools can detect and block ransomware before it fully executes.
- Software update policy: Patch operating systems and key applications within two weeks of security updates being released.
None of these controls require a large budget or a full-time IT team. All of them move you meaningfully further from the at-risk end of the target spectrum. The goal isn't to be invulnerable. The goal is to be the practice an attacker skips.
Want to see how your practice stacks up against the most common attack vectors?
The free Cyber Health Score takes 5 minutes and flags the gaps ransomware groups exploit most often.
Get your free Cyber Health Score