How a cyberattack actually reaches patient records.
Most security advice for medical practices is a list of rules with no explanation of why they exist. This page is the explanation. Everything below is something your practice already has — and every arrow between them is a path an attacker can travel.
Highest
breach cost of any industry
Healthcare has held that position for over a decade running, driven by regulatory penalties and the sheer sensitivity of the data.
Permanent
consequences for patients
A stolen card is reissued in days. A Social Security number, birth date, and diagnosis cannot be reissued at all.
HIPAA
reportable in 60 days
A breach affecting 500 or more people must be reported to HHS, the affected patients, and in many cases the media.
How an attack reaches patient records
Every box is something your practice already has. Every arrow is a path an attacker can travel. Click any box or any arrow label to see real examples.
Click any box — or the label on any arrow — to see what it is, with real examples.
Every path on that map has one thing in common.
None of them can be closed by a rule written in advance. The device cannot be patched, the email cannot be blocked without blocking patients, and the staff cannot be expected to spot an attack written by AI while treating someone.
What works instead is watching behavior — noticing when something on that map starts acting unlike itself, and containing it automatically, before it reaches records.