Case Study · Healthcare & Dental
Ransomware at 1 a.m. Open on Time at 8
An after-hours intrusion tried to encrypt a dental practice’s servers. A 24/7 SOC contained it while the office slept, and immutable backups restored clean systems before the first patient was seated.
This is an account of a real engagement CRC Cloud delivered. Identifying details are generalized and the client is not named — a public client list would tell attackers exactly who is protected and by whom. Named references are available privately during a serious evaluation.
The attack came when no one was watching — except the SOC
Just after 1 a.m., an endpoint began behaving abnormally: rapid file access, a suspicious process spawning encryption activity, and an attempt to reach the practice-management server. Ransomware crews deliberately strike overnight and on weekends, betting that no one will notice until the damage is done. In a practice, “until morning” means a waiting room full of patients and a system that won’t open a single chart.
Detection, containment, recovery — in that order
| Step | What the response did |
|---|---|
| Detect | Endpoint detection and response flagged the anomalous encryption behavior in real time; the SOC was alerted within minutes |
| Contain | The affected endpoint was isolated from the network automatically, cutting the attack off from the servers before it could spread |
| Assess | SOC analysts confirmed the blast radius, verified the servers were untouched, and identified a clean restore point |
| Recover | Immutable, encrypted backups restored the single affected system to a clean state hours before opening |
Because the backups were immutable, the attacker couldn’t encrypt or delete them — the recovery copy was never in play. See how backup & DR works →
The controls that turned a disaster into an incident
24/7 Security Operations
A monitored environment means 1 a.m. is watched. The threat was contained while the practice slept, not discovered when the doors opened.
Immutable backups
Recovery copies an attacker can’t alter or delete. That is the difference between a clean restore and paying a ransom.
Audit-ready evidence
Centralized logging captured the full timeline — what happened, when it was contained, what was and wasn’t touched — the record HIPAA expects after an event.
The schedule ran as if nothing had happened
One endpoint was rebuilt from a clean image. The servers and the patient records were never encrypted. The practice opened on time, and the incident became a documented, contained event rather than a closure and a breach headline.
Hours
to a clean restore — not days
No PHI
patient data never encrypted or exfiltrated
$0
ransom paid
See how we serve healthcare & dental practices, our HIPAA approach, or the other case studies.