If it is ransomware
Contain, call, do not improvise.
Journal · Trust · H·03 | Last reviewed: October 1, 2026 | 4 min read | By CyberDental Group LLC, Hialeah, Florida
Short answer: If you suspect ransomware: disconnect affected machines from the network (do not power them off or wipe them), call your IT provider immediately, notify counsel and your cyber-insurance carrier, preserve evidence, switch to paper downtime procedures, and do not contact or pay the attackers without professional guidance. HHS treats ransomware that encrypts ePHI as a presumed breach unless a low probability of compromise is shown.
At a glance
| First action | Disconnect from network; do not wipe or power off |
| Second | Call IT provider: (954) 639-7049; call counsel and insurer |
| Do not | Pay, negotiate, delete files or reimage before guidance |
| HIPAA | Ransomware-encrypted ePHI is presumed a breach unless low probability of compromise is demonstrated |
| Florida | FIPA 30-day clock may apply; see notification article |
General information, not legal advice. Have an incident response plan before you need it, and call professionals immediately.
What are the signs of ransomware?
Files that will not open or have strange extensions, a ransom note on screen or in folders, systems suddenly slow or locked, several machines misbehaving at once, or a security alert that says files were encrypted. Treat any of these as an emergency. See When should a dentist call IT after hours?.
What should you do in the first 15 minutes?
- Disconnect. Unplug the network cable and turn off Wi-Fi on affected machines. If you cannot tell which are affected, disconnect the office from the internet at the router or firewall.
- Do not power off, wipe, reimage or delete anything. Evidence in memory and logs is valuable, and your IT provider may need the machine as it is.
- Call your IT provider immediately. CyberDental HelpDesk: (954) 639-7049. Say "possible ransomware," the time you noticed and what you saw.
- Use a different channel to communicate, such as phones, not the possibly compromised email or messaging.
- Write down the time and everything you observe.
What should happen in the first hour?
- Your IT provider contains the spread: isolating machines, disabling compromised accounts, blocking connections. See What EDR does in an operatory.
- Notify the decision-makers: owner, privacy officer and counsel.
- Call your cyber-insurance carrier, whose policy may require notice, specific vendors and approval before certain steps.
- Switch to downtime procedures: paper charts, manual schedule, phone tree. Decide how to treat patients safely.
- Preserve evidence: logs, ransom notes, screenshots, affected machine list.
What should happen in the first day?
- Scope the incident: which systems, what data, since when. Forensic help is often needed.
- Check backups are intact and uncontaminated before any restore. See Cloud backup that is actually HIPAA-shaped.
- Law enforcement: report to the FBI (IC3) and notify CISA; they can provide help and context.
- Begin the breach analysis with counsel for both HIPAA and Florida law.
- Plan recovery: restore from clean backups into a clean environment, reset credentials and verify before reconnecting.
What about paying the ransom?
This is a decision to make only with counsel, your insurer and incident-response professionals. Payment does not guarantee data recovery or that data was not copied, may carry legal risk, including sanctions issues, and can encourage further attacks. Do not negotiate or pay on your own.
What does HIPAA say?
HHS guidance states that when ePHI is encrypted as the result of ransomware, a breach has generally occurred, because the data was acquired by an unauthorized party, unless the entity can demonstrate a low probability that the PHI has been compromised, using a documented four-factor risk assessment. If it is a breach, notification duties follow. See HIPAA for dental offices, in plain English.
What does Florida law add?
Florida's FIPA has its own, shorter 30-day clock for notifying individuals and, at 500 or more Floridians, the Department of Legal Affairs. See Florida data-breach notification for dental practices.
What should never be done?
- Restart or wipe machines before guidance.
- Delete ransom notes or logs.
- Use the compromised email to discuss the incident.
- Contact the attackers or pay them alone.
- Delay calling because it might be nothing.
What prevents the worst outcomes?
MFA, patching, EDR with a SOC, segmented networks, immutable tested backups, and an incident plan everyone has read. See Why Florida dental practices get ransomed.
Frequently asked questions
What should a dental office do first if hit by ransomware?
Disconnect affected machines from the network without powering off or wiping them, call your IT provider immediately, notify counsel and your cyber-insurance carrier, and begin downtime procedures.
Should a dental practice pay a ransom?
Only after consulting counsel, the cyber-insurance carrier and incident-response professionals. Payment does not guarantee recovery and may carry legal risks.
Is ransomware a HIPAA breach?
HHS guidance says ransomware that encrypts ePHI is generally a breach unless the entity demonstrates a low probability that the data was compromised through a documented risk assessment.
Sources and further reading
Related in the Journal
- Florida data-breach notification for dental practices
- When should a dentist call IT after hours?
- What EDR does in an operatory
- Why Florida dental practices get ransomed
About CyberDental
CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.
- HelpDesk: (954) 639-7049
- Email: support@cyberdental.co
- Address: 480 W 84th Street, Suite B106, Hialeah, FL 33014
- Website: cyberdentalgroup.com