Ransomware and Your Practice: Why a Tested Restore Matters More Than a Backup

Most practices have backups; few have restored from one lately. How ransomware reaches backups, what survives it, and why restore drills decide downtime.

2 min readVault Data Servers

Ask a practice whether it has backups and almost every one says yes. Ask when it last restored from one — actually brought the practice system back from a backup and checked it worked — and the room goes quiet. That gap is where ransomware does its damage.

How ransomware actually hits a practice

It rarely arrives as a dramatic break-in. More often a password is phished or reused, someone logs in remotely, and over days or weeks the attacker looks around, disables what they can, and finds the backups. Only then do they encrypt everything at once — the practice management system, imaging, shared files, and any backup they can reach.

That last part is the point. A backup that sits on the same network, with the same credentials, is just one more thing to encrypt.

Backups that survive the attack

  • Immutable or offline copies. At least one copy should be impossible to change or delete for a set period, even by an administrator account. If the attacker steals the keys to the building, this copy still can't be touched.
  • Off-site replication. A second location protects against more than ransomware: fire, flood, theft, or a failed server room.
  • Separate credentials. The account that manages backups should not be the same one people use every day, and should require multi-factor authentication.
  • Coverage of everything that matters. Not just the patient database, but imaging, documents, and the configuration needed to rebuild servers. Restoring data onto a machine you then have to rebuild by hand from memory can take days.

Why the restore test is the part that matters

Backups fail quietly. A job that stopped running after a software update, a database that was backed up while it was locked and is unreadable, an imaging folder that was never included because it lived on a different drive. None of it shows up until the day you need it.

A restore drill answers the questions that actually decide how long your practice is closed:

  • Does the backup open, and is the data complete?
  • How long does a full restore take? (This is your real recovery time, whatever the plan says.)
  • How much recent work would be lost? (Your real recovery point.)
  • Who knows how to do it, and is it written down?

Run one on a schedule — monthly for the systems the practice can't function without — and keep a record each time. It is also exactly the evidence cyber insurers and HIPAA reviewers ask for.

The day it happens

If you see ransom notes or files that won't open: disconnect affected machines from the network without powering them off, call your IT provider and your cyber insurer before doing anything else, and don't pay or contact the attacker on your own. Your insurer may require specific responders, and acting first can complicate a claim. Then follow your breach-assessment process — a ransomware incident involving patient data is presumed to be a reportable HIPAA breach unless a risk assessment shows a low probability that the data was compromised.

The practices that come through these incidents in a day or two are not the ones with the most expensive software. They're the ones that had already proven, on an ordinary Tuesday, that their restore works.

How we handle this

Backup & Recovery at Vault Data Servers

See the service
All articles

Talk to us

Want a second opinion on your setup?

Call us directly. You'll get someone who can answer the technical question, not read it off a script.

1.480.907.0700