Bastani Security
Book the Fire Drill
Free resource · For dental & medical clinics · Toronto & GTA

The ransom note loads before the schedule does. Here's exactly what to do in the first hour.

Most clinic ransomware starts with one click at the front desk and ends with a PHIPA decision nobody rehearsed. This free kit gives you three things you can use today: a red-flags checklist for the attachments your front desk actually opens, a one-page "we're locked out" plan to tape by the phone, and a plain-English PHIPA breach-decision and IPC-notification checklist. Print it, post it, and your team is readier than most clinics on the street.

  • A front-desk red-flags checklist tuned to real intake, lab-result and insurance lures - not generic spam advice
  • A one-page "we're locked out" response plan you can tape beside the front-desk phone
  • A PHIPA breach-decision and IPC Ontario notification checklist in plain English
  • Built around Dexis, Tracker and AbelDent - and we never use real patient information
Email me the editable pack

Yours free - no signup wall. Want the editable templates or a hand rolling it out? Just ask.

01

Front-desk red flags: the attachment and link checklist

Your front desk opens dozens of attachments a day - intake forms, lab results, insurance PDFs and claim responses. That's the door attackers knock on. This is the 30-second check to run before clicking, written for the messages a clinic actually receives. If two or more of these are true, stop and verify by phone before you open anything.

The sender's display name is a known lab, insurer or patient, but the actual email address (hover over it) is a gibberish or near-miss domain - "intake@dental-records-secure.com" instead of the practice or insurer you know.
It's an "insurance form," "new patient intake," "lab result," or an "insurance claim response" you weren't expecting, for a patient you don't recognize, or it arrived outside the sender's normal hours.
The attachment is a .zip, .html, .htm, .iso, or a file that asks you to "enable content," "enable macros," or "enable editing" to view it - real intake and lab files never need that.
A link wants you to log in to view a document - and the page looks like your email, your PMS, or a portal but the web address isn't the one you normally use. Go to the site you know, don't click through.
The message creates urgency or fear: "account will be suspended," "unpaid claim," "respond within 24 hours," "patient complaint attached." Pressure is the tell.
A caller or email claims to be "your IT company" or software support and asks someone to install remote-access software, read out a code, or approve a login prompt they didn't start.
A QR code arrives by email or on a flyer asking staff to scan it to "verify" a login, claim or payment - treat a QR code like a link you can't read.
When in doubt, the rule is one line: don't open it, don't click it, don't approve it - verify with the sender on a number you already have, then decide.
02

The one-page "we're locked out" plan - tape this by the phone

If a screen shows a ransom note, or the schedule, charts or imaging won't load across more than one computer, treat it as a possible attack - not an IT glitch. The first hour decides how bad the day gets. Assign these roles before anything happens; in the moment, just follow the list in order.

Stay calm and stop using the affected computers. Don't pay anything, don't reply to the note, don't reboot or run "fixes" - that can destroy the evidence you'll need later.
Disconnect, don't power off: unplug the network cable and turn off Wi-Fi on affected machines to stop the spread, but leave them ON so logs and forensic evidence survive (the Cyber Centre's guidance - don't wipe what you'll need).
Pull the rest of the clinic offline: disconnect the server and any other workstations from the network and the internet so it can't jump from Dexis, Tracker or AbelDent to the next machine.
Call your IT provider or MSP now - this is the number that should already be written on this page - and tell them you suspect ransomware, not a slow computer.
Start a written timeline on paper: the time you noticed it, which screens showed what, who clicked what and when. Photograph the ransom note with a phone. This log is gold for IT, your insurer and any PHIPA decision.
Call your cyber-insurance broker / breach hotline before you take big steps - many policies require it, and they bring in incident-response help. The number goes on this page too.
Decide who talks to patients in the waiting room and what they say - a calm "our systems are down, we're rebooking you" - and assign one person so the message stays consistent.
Do not pay the ransom or negotiate on your own. The Canadian Centre for Cyber Security advises against paying, and your insurer and IR team handle that call. Report it to the Canadian Anti-Fraud Centre (1-888-495-8501) and consider local police.
Once contained, switch to the PHIPA decision below - because a lockout that exposed or could have exposed patient records is a privacy matter, not just a technical one.
03

The PHIPA breach-decision checklist (Ontario)

Under Ontario's Personal Health Information Protection Act (PHIPA), a clinic is a health-information custodian, and ransomware that touches patient records can be a privacy breach even if no data was obviously stolen - "unauthorized use or disclosure" includes records being encrypted, accessed, or copied by an attacker. Work through these questions with your privacy contact (and, for anything legal, your lawyer). This is practical readiness, not legal advice.

Did the incident involve personal health information at all? In a clinic, ransomware on the system that runs Dexis, Tracker or AbelDent almost always does - names, charts, imaging, billing, health-card numbers.
Was PHI used, disclosed, or accessed without authority, or stolen, lost, or made unavailable? Encryption by an attacker, or data they could have copied before locking you out, counts - "we can't prove they took it" is not the same as "it wasn't a breach."
Identify whose information is affected and roughly how many patients - even a rough scope shapes your notification duties.
Determine your duty to notify affected patients: PHIPA requires notifying individuals at the first reasonable opportunity when their PHI is stolen, lost, or used/disclosed without authority. Plan who calls or writes, and what you say.
Determine your duty to notify the Information and Privacy Commissioner of Ontario (the IPC): PHIPA and its regulation require notifying the IPC in defined circumstances (for example, breaches involving theft, a pattern of similar breaches, or where reporting to a regulatory College is required). Check the current IPC guidance and your situation with counsel.
Consider your duty to notify the relevant regulatory College (for example, the RCDSO for dentists or the CPSO for physicians) where PHIPA's reporting rules apply.
Document everything: what happened, what PHI was involved, what you decided about notification and why, and the dates. PHIPA expects custodians to track privacy breaches and report breach statistics to the IPC annually.
Review afterward: what control would have stopped this - MFA on email, tested backups, front-desk training - and write it into your plan so the next answer is faster. (See the Cyber Centre and IPC Ontario for current guidance; confirm specifics with your lawyer.)
04

Before the bad day: five things worth doing this week

This kit is for the emergency. These five are the quiet, boring controls that mean the emergency either never happens or barely lands - the ones that show up on every clinic's cyber-insurance application and PHIPA risk review. None of them require a big project.

Turn on multi-factor authentication (MFA) for email and your practice-management logins - most clinic break-ins start with one stolen password, and MFA blocks the majority of them.
Make sure your backups are real and tested: that they cover Dexis / Tracker / AbelDent and the imaging server, that at least one copy is offline or immutable so ransomware can't encrypt it too, and that someone has actually restored a file to prove it works.
Write the three phone numbers on the one-page plan now - your IT provider/MSP, your cyber-insurance broker or breach hotline, and your privacy/PHIPA contact - so nobody is searching for them mid-crisis.
Give the front desk five minutes on the red-flags checklist at a team huddle, and agree the clinic rule out loud: when an attachment or login looks off, we verify first, and nobody gets in trouble for slowing down.
Decide today who makes the PHIPA call and who speaks to patients, so those aren't questions you're answering for the first time while the waiting room fills up.
How to use this

Print all three pages, tape the "we're locked out" plan beside the front-desk phone, and fill in your IT, insurance and privacy phone numbers before you need them. This is practical readiness, not legal advice - confirm your PHIPA obligations with your own lawyer and the current IPC Ontario guidance.

A checklist is a start. A drill makes it stick.

The Cyber Fire Drill runs these exact attacks against your team - safely - so the habits in this toolkit become muscle memory. Three hours, on-site, with a scored 30-day plan.

Book the Fire Drill See the dental & medical clinics page →
Is this really free, and do you ever touch our patient data?

It's free, and no - we never use real patient information for anything. This kit is built from public PHIPA, IPC Ontario and Canadian Centre for Cyber Security guidance and our own clinic experience. The same rule holds in our live training: no real patient data, no malware, no harvesting passwords, and nobody gets named or shamed.

We already have an IT company. Doesn't this cover us?

Your IT provider keeps the systems running and is exactly who you call in the first hour - they're on the plan for a reason. But most clinic ransomware starts with a human click at the front desk, and the PHIPA decision afterward is yours, not theirs. This kit covers the people-and-decisions side IT can't do for you. Your IT company is welcome in the room when we train your team.

How is this different from your Cyber Fire Drill?

This kit is the printed version of a few things we cover. The Cyber Fire Drill is the live, roughly three-hour, on-site version for your whole clinic - your front desk rehearses the malicious-attachment moment, your team walks the locked-out tabletop together, and leadership leaves with a PHIPA-aware plan scored to where you actually stand. Reading the plan is good; living through it once is what your team remembers. Book a Cyber Fire Drill, or a 20-minute call, when you're ready.

More resources in the resource library · questions? contact@bastani.org