By Gary Salman, CEO, Black Talon Security
Cyberattacks against orthodontic practices do not always begin with a suspicious email or an employee clicking the wrong link. Sometimes the attack begins silently at the network’s edge, before anyone realizes something is wrong.
Threat actors continuously scan the internet for exposed devices, including firewalls and remote-access systems. They search for known vulnerabilities, outdated firmware, weak firewall configurations, and missing patches. In this scenario, an attacker identifies and exploits a vulnerability in an orthodontic practice’s firewall, turning its primary defense into an entry point.
Once inside your network, the attackers do not immediately deploy ransomware. Instead, they quietly map the environment, identify computers and servers, exploit additional weaknesses, and move around from system to system. Think of it like a burglar walking into your house, moving from room to room, opening doors, closets, safes and stealing your valuables (in this case your data).
As access expands, the attacker consolidates the practice’s most valuable information: patient records, email attachments, databases, financial records, HR files, billing documents, 2D and 3D diagnostic images, and intraoral and facial photographs. The data is copied and transferred outside the network back to the attacker’s network, creating a potential reportable breach of protected health information, and is used to extort you financially.
Next, the attacker opens a browser on a compromised computer and reviews your browsing history. A frequently visited link leads to the practice’s cloud-based practice management system. The attacker clicks on the link, and the login page appears to your practice management system. Because the browser saves the username and password, both are automatically entered. Without another authentication barrier, the attacker gains full access and downloads some or all of the practice’s patient data stored in the cloud.
The practice now faces a double compromise involving its local network and cloud environment. The attacker demands $2 million in the form of Bitcoin and threatens to publish or sell the stolen information on the dark web. The practice must address forensic, legal, regulatory, patient-notification, reputational, and financial consequences because of this relatively simple attack.
This scenario demonstrates why a firewall cannot be treated as a “set it and forget it” appliance. To address this ongoing and significant risk, practices must engage in daily vulnerability scanning of firewalls to identify weaknesses before criminals exploit them. It is like hiring a locksmith to try and pick your lock every day. Sometimes they may easily succeed. Daily vulnerability scanning should include firewalls, remote-access tools, servers, workstations, and other connected devices.
Practices should specifically identify Known Exploited Vulnerabilities, or KEVs—vulnerabilities confirmed to be actively exploited in real attacks. A KEV affecting an internet-facing firewall or critical internal system should be treated as urgent and patched daily rather than waiting for a routine maintenance cycle.
Attackers are creating AI-generated attacks, and scanning alone is not enough. Findings must drive remediation. Autonomous remediation can deploy eligible security patches quickly, correct common weaknesses, and shorten the interval between discovery and correction. After patching, another vulnerability scan should confirm that the patch was installed and the exposure was eliminated.
Internal scanning, network segmentation, and continuous monitoring can make internal movement more difficult. Practices should also use an enterprise password manager that requires a PIN, biometric check, or other verification before releasing credentials to sensitive systems. Multifactor authentication should be enforced on every cloud platform that supports it.
The lesson is simple: cloud systems cannot protect a practice when the device accessing them—such as a workstation on your network—has already been compromised. Effective cybersecurity requires multiple, independently verified safeguards capable of preventing, detecting, and containing an attack at every stage.
About Gary Salman and Black Talon Security
Gary Salman is CEO and co-founder of Black Talon Security. A leader in the cybersecurity field, Mr. Salman has a 25-plus-year background in law enforcement and healthcare technology. His firm monitors and secures over 2000 dental practices and 65K computers and networks worldwide and has trained tens of thousands of healthcare professionals.