Back to resources

Ransomware gets a lot of coverage when it hits a hospital system or a major corporation. Those stories create the impression that small practices aren't targets. They're too small to bother with. Attackers want big payouts from big organizations.

That impression is wrong, and it's getting more wrong every year.

The economics of targeting small practices

Large organizations have security teams, incident response retainers, and layers of technical controls. Breaching them takes real effort and carries real risk of detection. Small practices typically have one IT person (or none), no dedicated security tools, and no plan for what to do when something goes wrong.

From an attacker's perspective, a solo therapy practice or a three-person law firm is not a smaller version of a hospital. It's an easier version of a hospital, with data that's just as valuable and defenses that are dramatically weaker.

Healthcare data sells for more than credit cards. A stolen credit card number is worth a few dollars on criminal markets. A complete patient record, including name, date of birth, insurance information, and health history, sells for $250 to $1,000. Healthcare data is among the most valuable categories of stolen information.

How ransomware attacks on small practices actually happen

The majority of successful ransomware attacks on small practices follow one of three paths:

Phishing emails

A staff member receives an email that looks legitimate. An insurance form. A patient inquiry. A notification from a software vendor. The email contains a link or attachment. When it's opened, malware installs silently on the device. The attacker now has access to the network and can move toward the data they want before triggering the ransomware payload.

Compromised credentials

A staff member's email password is guessed, purchased from a prior breach, or captured through phishing. The attacker logs in, establishes persistence, and eventually either deploys ransomware or exfiltrates data quietly. Practices without multi-factor authentication (MFA) are particularly vulnerable to this pathway.

Unpatched software

Older software versions often contain known vulnerabilities. Attackers scan for systems running unpatched versions and exploit them automatically, without any interaction from staff. Practice management software, remote desktop tools, and networking equipment that isn't regularly updated are common entry points.

What happens after an attack

In a ransomware attack, your files are encrypted and you lose access to them. The attacker demands payment (typically in cryptocurrency) in exchange for the decryption key. Payment does not guarantee recovery. Many practices that pay receive a partial key, a non-functional key, or no key at all.

Beyond the ransom itself, the real costs include:

Double extortion is now common: Many ransomware groups don't just encrypt your data. They exfiltrate it first, then threaten to publish it publicly if you don't pay. Paying the ransom doesn't prevent the data from being leaked. It just removes the immediate leverage.

The controls that make you a harder target

You don't need to be impenetrable. You need to be harder to breach than the next practice on the attacker's list. Most ransomware operations are volume businesses. They run campaigns against hundreds of targets and take the ones that don't push back.


None of these controls require a large budget or a full-time IT team. All of them move you meaningfully further from the at-risk end of the target spectrum. The goal isn't to be invulnerable. The goal is to be the practice an attacker skips.

Want to see how your practice stacks up against the most common attack vectors?

The free Cyber Health Score takes 5 minutes and flags the gaps ransomware groups exploit most often.

Get your free Cyber Health Score