This is a dental ransomware recovery playbook for the hours and weeks after an attack has already happened. It covers containment, keeping the practice running clinically, preserving evidence, coordinating with your insurer and counsel, restoring cleanly from validated backups, testing before you reconnect, and the after-action review.

It is deliberately not a general security guide. For prevention, controls, and threat background, read the complete guide to dental practice cybersecurity.

Nothing here is legal advice. Notification obligations, ransom decisions, and law-enforcement engagement should be handled with qualified counsel, your cyber insurance carrier, and, where appropriate, the FBI or CISA.

Quick Answer

If ransomware is running in your practice right now: disconnect affected machines from the network but do not power them off, stop using the environment, call your IT provider and your cyber insurance carrier before touching anything else, switch to paper downtime procedures so patient care continues, and preserve systems and logs for forensic review. Do not restore from backup until someone has confirmed how the attacker got in and that the backup copy is clean. Recovery order should follow clinical priority: scheduling and patient records first, then imaging, then billing. Coordinate any notification decision with counsel and your insurer rather than announcing anything on your own timeline.

Hour Zero: Contain Without Destroying Evidence

The first decisions matter more than the fast ones.

Disconnect, do not wipe. Pull network cables and disable Wi-Fi on affected machines, or isolate the network segment at the firewall. Leave the machines powered on where you can — memory contents and running processes can help investigators determine scope, and a hard shutdown can also corrupt partially encrypted files.

Assume spread until proven otherwise. The initial intrusion may predate visible encryption. Treat the whole environment as suspect, including the server, imaging workstations, and any machine that mounted a shared drive.

Protect the backups first. If backup systems are still reachable from the compromised network, isolate them immediately. Backups are a common target before production systems are encrypted. If you have an offline or immutable copy, confirm it is intact and leave it untouched until you have a clean place to restore into.

Cut credentials. Disable remote access, revoke VPN sessions, and force password resets on administrative accounts from a known-clean device. Do not reset everything from an infected workstation.

Start a written timeline. One person, one document, timestamps in order: when it was noticed, who was told, what was disconnected, what was observed on screen. This record becomes essential later for the insurer, for counsel, and for the after-action review.

Do not communicate with the attacker on your own. Ransom negotiation, if it happens at all, belongs with your insurer's appointed specialists.

Who to Call, in What Order

  1. Your IT provider or internal IT lead — to contain and assess.
  2. Your cyber insurance carrier — contact the carrier promptly and confirm any consent or panel-vendor requirements before retaining outside firms, because terms vary by policy. Carriers often supply or approve the forensic firm and breach counsel.
  3. Breach counsel — to direct the investigation and advise on notification obligations.
  4. The forensic team — engaged through the carrier or counsel wherever possible.
  5. Law enforcement — the FBI's IC3 and CISA accept reports and can provide guidance. CISA and the FBI advise against paying ransoms, though the decision remains yours in consultation with counsel and your carrier.
  6. Practice leadership — a small, named group makes decisions; everyone else follows the plan.

Keep these numbers on paper. During an incident, the contact list stored on the encrypted server is not available.

Keeping the Practice Running: Clinical Downtime Procedures

Recovery duration varies with the scope of the incident, evidence collection, backup integrity, and restoration testing, so plan for care to continue without systems.

Scheduling. Use the last printed or exported schedule. Assign one person to phone confirmations and rescheduling, working from a paper list. Decide early which appointment types can proceed safely without access to records and imaging, and which must be moved.

Clinical documentation. Record notes on paper forms with patient identifier, date, provider, and procedure. Number the forms sequentially so nothing is lost during later data entry, and store them securely — paper records containing patient information carry the same confidentiality obligations as electronic ones.

Imaging. If imaging systems are offline, document what was taken and when so studies can be reconciled after restoration. Avoid moving images onto personal devices or consumer cloud accounts.

Payments and billing. Expect a backlog. Note charges on paper and hold claim submission until the practice management system is verified rather than re-entering into an unverified environment.

Patient-facing communication. Say plainly that a technical issue is affecting systems, what it means for their appointment, and when you will update them. Do not speculate about causes or data exposure in public statements — coordinate any statement referencing patient data with counsel.

Internal communication. Use an out-of-band channel: personal phones, a text group, or a whiteboard. Assume practice email may be compromised or unavailable until confirmed otherwise.

Evidence Preservation

Forensic answers determine both remediation and notification, and both depend on evidence surviving the first day.

  • Preserve firewall, VPN, endpoint, and cloud sign-in logs promptly, because retention varies by system and older records may roll off.
  • Keep at least one encrypted machine untouched as a sample. Forensics may need it to identify the variant and entry point.
  • Photograph ransom notes and on-screen messages, including file extensions and any contact identifiers.
  • Do not rebuild, reimage, or "clean up" a machine before it has been examined, and do not run new tools across the environment without the forensic team's direction.
  • Record every action taken during containment in the timeline document.

Rebuilding first and investigating later is a costly recovery mistake. Without knowing the entry point, you can restore straight back into the same compromise.

Clean Restoration From Validated Backups

Restoration begins only when you have a defensible answer to two questions: how did they get in, and is this backup copy clean?

Build a clean environment. Restore into rebuilt or newly imaged systems rather than machines that were encrypted. Reused systems can retain persistence mechanisms.

Select a restore point before compromise. The initial intrusion may predate encryption. Work with the forensic team to pick a point earlier than the first known attacker activity, then accept and plan for the data gap that creates.

Scan the backup before it touches production. Mount and scan the restore set in an isolated environment first.

Restore in clinical priority order. Practice management and patient records, then imaging, then billing and reporting, then non-essential systems. Publish the order so staff know what to expect.

Close the entry point before reconnecting. Reset all credentials, remove attacker accounts and scheduled tasks, patch the exploited path, and enforce multi-factor authentication on every remote-access route. Restoring without closing the door invites a second event.

If your backup coverage or retention turns out to be inadequate during this step, that finding belongs in the after-action plan. See dental backup solutions for design considerations, and our backup and disaster recovery services if you need help rebuilding the strategy.

Restoration Testing Before You Reopen Systems

Do not hand systems back to the team the moment data appears.

  • Data integrity: open recent charts, confirm imaging studies attach to the correct patients, and check that the schedule and ledger reconcile with paper records from downtime.
  • Application function: test check-in, charting, imaging acquisition, claim generation, and printing end to end.
  • Integrations: confirm imaging bridges, e-prescribing, payment terminals, and phone or messaging integrations work.
  • Security posture: verify endpoint protection is installed and reporting on every restored machine, that logging is flowing again, and that MFA is enforced.
  • Backups of the restored environment: run and verify a fresh backup before the environment carries live patient data again.

Have a clinical user, not only IT, sign off on each system. They will notice missing data that a technical test will not.

Phased Return to Service

Bring the practice back in stages so problems appear at small scale.

  1. Pilot: one operatory and one front-desk station on the restored system while everyone else stays on paper.
  2. Front office: scheduling and check-in for all users once the pilot is stable.
  3. Clinical: charting and imaging across operatories.
  4. Revenue cycle: billing, claims, and the downtime backlog, entered from the numbered paper forms.
  5. Everything else: reporting, marketing tools, and secondary integrations.

Keep heightened monitoring in place for several weeks. Reinfection and attacker return are real risks, and the period right after recovery is when unusual activity most needs a human watching it.

After-Action Review

Within a few weeks of stabilizing, hold a review while details are fresh. Cover:

  • Timeline: what happened, when it was detected, and how long each phase took.
  • Detection gap: how long the attacker was present before anyone noticed, and what would have shortened that.
  • Actual recovery time versus expectation: compare it to what leadership assumed beforehand.
  • Backup performance: what restored cleanly, what did not, and what the real data-loss window was.
  • Downtime procedures: what staff needed and did not have on paper.
  • Decision-making: whether the right people were reachable and authorized.
  • Remediation list: every gap with an owner and a date.

Retain the documentation. Your carrier, counsel, and any regulator involvement will benefit from a clear record, and the next assessment should start from this list.

Prevention Context: Closing the Loop

Prevention belongs in the recovery conversation only to the extent that it prevents the next incident. The controls that most consistently reduce ransomware impact for dental practices are multi-factor authentication on email and remote access, managed endpoint detection, patching supported software, network separation between guest and clinical systems, offline or immutable backups with tested restores, staff reporting culture, and a written incident response plan with downtime procedures.

Score your current position against each of those with the dental cybersecurity risk assessment checklist, and read the complete guide to dental practice cybersecurity for the underlying detail on each control.

Frequently Asked Questions

How long does dental ransomware recovery take?

It varies widely with the scope of encryption, backup quality, whether an offline copy survived, and forensic timelines. Practices with tested offline backups and a written plan generally recover faster than those discovering backup gaps mid-incident. Plan downtime procedures for longer than you expect to need them.

Should a dental practice pay the ransom?

CISA and the FBI advise against paying, noting that payment does not guarantee data recovery and may encourage further attacks. It is ultimately a business and legal decision that should be made with breach counsel and your cyber insurance carrier, never unilaterally or in direct contact with the attacker.

Do we have to notify patients?

Possibly, but the answer depends on the facts of the incident and the applicable federal and state requirements. HHS publishes breach notification rule guidance, and state laws may add obligations. Have breach counsel make that determination rather than deciding internally.

Can we just restore from backup and move on?

Restoring before the entry point is identified and closed risks immediate reinfection, and it can destroy evidence needed for the investigation and any notification analysis. Confirm the entry point, rebuild clean systems, scan the restore set, then restore.

What should we do first if we suspect an attack right now?

Isolate affected machines from the network without powering them off, stop using the environment, protect and isolate backups, and call your IT provider and cyber insurance carrier. Then switch to paper downtime procedures so patient care can continue while the response is organized.