An Indiana dental practice finds ransomware on its records server

An Indiana dental practice says ransomware touched its records, imaging, and management systems, but left the files encrypted.

MedRisk Staff
By
2 Min Read

Bright Smile Dental Care, a practice in Fishers, Indiana, is notifying patients after ransomware turned up on a server that ran its records and imaging software.

The practice discovered the intrusion on August 3. The compromised machine held patient records, the software that runs the practice’s operations and its dental imaging system. Consultants came in right away to work out how far the intruders got and to shut the incident down.

The categories the notice names could all be in play: patients’ names, dates of birth, addresses, email addresses and phone numbers. Also named were insurance details, information about dependents, health records and, in a few cases, Social Security numbers.

Bank and payment account details were untouched, the practice said.

Bright Smile told patients it judges the danger to them to be minimal. The files on the server were encrypted, and the notice reports no sign the intruder had “the encryption keys necessary to view the underlying data.” Investigators also found nothing to suggest records were copied before they were locked, the move extortion crews usually make first.

Written notices are going to every patient the practice can reach. The national consumer reporting agencies are being told as well, and the practice says it has begun a fresh review of its own security policies.

For anyone whose Social Security number was involved, Bright Smile is arranging free credit monitoring from TransUnion, with sign-up details in the letter.

For a small practice, the episode is a reminder that imaging and management servers are a single point of failure for both care and compliance.

Share This Article