A Houston story
The Tuesday a Katy dental practice got its nineteen years back by lunch
the owner-dentist of a two-chair practice on Mason Road in Katy
It is 7:05 on a Tuesday in August, already 84 degrees, and the first patient is a crown prep at 7:30. The owner-dentist opened on Mason Road nineteen years ago with one chair and a loan. Nineteen years of charts, X-rays and ledgers live on the server in the closet behind the sterilization room.
The remote-access tool on that server had a flaw the vendor fixed in June. Nobody installed the fix, because nobody knew there was one. At 3:40 that morning someone in another time zone found the open door, walked in, and started encrypting.
The hygienist logs in at 7:12 and the schedule will not load.
The agent on the server had already cut the encryption off at 3:41 and woken an engineer, not the dentist. By 7:20 the engineer is on the phone. The offline backup from midnight restores the database by 11:15. The crown prep runs late. The 1:00 patient never knows. The breach analysis shows the copying was stopped before a single record left the building.
The screen shows a note instead of the day's schedule, and nineteen years of patient records are on the other side of it.
What changes the ending
- An offline, tested backup of the practice-management database that restores in hours, not the weeks a rebuild takes (CIS 11 Data Recovery).
- Patching the remote-access tool and the server the week the fix ships, because unpatched flaws are now the number one way in (CIS 7 Continuous Vulnerability Management).
- A protection agent on the server that stops encryption at 3:41 a.m. and wakes an engineer, not the dentist (CIS 10 Malware Defenses).