Local teams serve Vancouver, Edmonton and Calgary. Our regular hours are Monday to Friday, 7am to 5pm MT, and our emergency line is always answered by a person. Call (604) 813-7881 for a free consult with Tony. No pressure, no jargon.
Dental Cybersecurity: ransomware protection for the day someone clicks
One click on a fake invoice and the clinic is locked
Patient records, images and payments sit on a handful of computers. We protect them in layers, watch every day, and know what to do if something slips through. Our stack checks over 40 million security events per month. Book a free IT review.
What does a dental clinic need to stay safe from ransomware and phishing?
No single tool does it. A clinic needs a managed network and firewall, filtering that blocks bad sites, software that spots threats on every computer and server, multi-factor sign in, regular updates, staff who know a suspicious email when they see one, and tested backups. Canadian Dental Association (CDA) cybersecurity guidance and your cyber insurance policy are good checklists to measure yourself against.
- 40M+security events analyzed per month
- 24/7emergency line (604) 813-7881, answered by a person
- 30 daysbackup copies stay locked
- Monthlysecurity report card for your team
Dentist or office manager? Start here.
If you own the clinic
- Will one click close us? Layers mean one mistake shouldn’t. And if something slips through, locked backups give you a way back.
- What will insurance ask? Multi-factor sign in, tested backups and training. We help you answer honestly.
- What’s it cost? Security is part of the managed plan, from $55 to $125 per PC per month.
If you run the office
- Something looks off? Call (604) 813-7881 or message us. A person answers.
- How’s the team doing? A monthly report card shows who’s spotting the fakes.
- Patient Wi-Fi? Kept on its own network, away from charts and imaging.
Why it matters, in plain words
The tech names sound dull. The reasons behind them aren’t.
Business firewall
Why the box from your internet company isn’t protecting you
An ISP router connects you to the internet. A business firewall inspects what comes in and stops known attacks before they reach a computer.
Read more: Why the box from your internet company isn’t protecting you
DNS filtering
Why a bad link can fail before the page even loads
Every website visit starts with a lookup. DNS filtering checks it against known bad sites and blocks the match before anything downloads.
Read more: Why a bad link can fail before the page even loads
Multi-factor sign in
Why a stolen password shouldn’t open your email
Fake sign in pages steal passwords every day. A second check on a phone or security key stops most of those logins cold.
If something slips through, immutable backups are the way back. See all the plain guides.
The layers we put in place
If one layer misses something, the next can catch it.
Network and firewall
Cisco Meraki manages your network, Wi-Fi and firewall (the lock on your internet front door). Guest and patient Wi-Fi is kept on its own separate network, called a VLAN. The firewall is a Cisco Meraki MX with Advanced Security, sized to handle full 1 Gbps speeds with its protection switched on, so security doesn’t slow your clinic down. That protection has two parts: IDS spots suspicious traffic and IPS stops it.
Web and DNS filtering
DNS security from Cisco (or an equivalent service if price is a concern, since we’re technology agnostic) stops your computers from reaching known bad websites, like a locked gate on the road to the internet.
Threat detection
We provide 24/7 monitoring with email and SMS alerts to our team. Huntress, a separate security team, watches computers and servers and reviews what the software finds.
Multi-factor sign in
Email, remote access and practice systems ask for more than a password, such as a code sent to your phone. Remote desktop is never exposed to the internet.
Updates and patching
Weekly patching. Windows, practice software and imaging updates are applied every week, planned around your clinic hours. Full-disk encryption is on by default, unless a software vendor requires otherwise. In that case we follow the vendor and make sure you know it’s a software restriction.
Staff awareness
Most attacks start with an email, so we offer security awareness training to our clients.
Security awareness training for your team
A team that can spot a fake email is one of the best protections a clinic has. Here’s how our training works.
- Your staff take quizzes that test whether they can spot the tricks attackers use.
- Each month, the clinic gets a report card showing how the team is doing.
- If someone fails a quiz, management is told instantly, so on-the-spot training can happen right away.
Ask us how it fits your clinic. There is no pressure.
A separate Wi-Fi name isn’t a separate network
Many clinics give guests their own Wi-Fi name and password and assume patients can’t reach anything important. Often that isn’t true. A Wi-Fi name only changes what shows on a phone’s screen. If guests and clinic computers still share one network, a guest’s phone sits right next to your imaging computers, charts and server.
What really separates them is a VLAN. A VLAN is a virtual wall inside your network. Devices on one side can’t reach devices on the other unless we allow it. DHCP is the service that hands each device its address when it connects, a bit like a front desk handing out room numbers. We give guest and patient Wi-Fi its own VLAN and its own DHCP, so guests get their addresses from a different pool and are kept away from clinic computers, imaging and the server. They get the internet and nothing else. If you aren’t sure how your Wi-Fi is set up, ask your provider to show you.
A new Wi-Fi name, same network
Guests can still sit next to your computers, imaging and server.
A real wall, with its own address book
Guests get the internet and nothing else, under firewall rules.
What to do if ransomware hits your clinic
- Disconnect the affected computers from the network.
- Call us right away at (604) 813-7881. A person answers 24/7.
- We help contain it, check your backups and restore clean systems.
- We work out what was touched, so you can answer your lawyer and the privacy commissioner.
See what happens when something fails. Reporting duties depend on the province. Ask your lawyer, and see OIPC Alberta or OIPC BC. This isn’t legal advice.
Security support in your city
Vancouver clinics will usually look at BC PIPA and OIPC BC first. Edmonton and Calgary clinics will look at the Alberta HIA, Alberta PIPA and the OIPC of Alberta. Our Vancouver team works from an office on Seymour St. Our Edmonton team comes to your clinic, and the Edmonton address we list is for mail only. Our Calgary IT specialists are local, with no walk-in office, so we come to you. Read the privacy rules guide for the legal sources. We also serve clinics in Burnaby, Richmond, Surrey, Delta and Langley, in St. Albert, Sherwood Park, Morinville and Whitecourt near Edmonton, and in Airdrie and Cochrane near Calgary.
Cyber insurance
Insurers commonly ask whether a clinic uses multi-factor sign in, tested backups and monitoring. Read your policy, answer honestly, and ask us if you want a plain list of what is in place at your clinic.
What security can’t do
No provider can promise that an attack will never happen. Layers lower the chance and the damage, and tested backups are what get you running again. See how our backups work.
Dental cybersecurity questions
Why are dental clinics targeted by ransomware?
Clinics hold sensitive records and can’t work without their systems. Small teams have little time for security, so layers and monitoring matter.
Is antivirus enough?
Not on its own. Filtering, detection, updates, sign in protection and tested backups work together.
