Call Book the Fire Drill
For dental & medical clinics · Toronto & GTA

It’s Monday. The schedule won’t load - and neither will a single patient file.

Your clinic rehearses that Monday morning - safely - so the team stops the click that causes it and knows exactly what to do if it ever lands. Because one wrong click on Friday can lock your practice-management system and every patient file by Monday, and PHIPA makes it your problem the moment it does.

  • Walk through a safe ransomware “lockout” tabletop with your whole clinic
  • Your front desk learns the phishing click that starts it - and how to stop it
  • Leave with a PHIPA-aware incident plan and a scored 30-day action plan

A 20-minute scoping call, then one flat quote. No jargon, no pressure.

A medical-clinic professional
Built for the clinics we train
What your clinic walks away with

Live and on-site for your whole team - then a plan you can act on the next morning.

  • A one-page “locked out” response plan, by the phone
  • A front-desk routine for spotting malicious attachments
  • A PHIPA-aware breach-notification checklist
  • A scored 30-day plan, prioritized by real risk
Book the Fire Drill

20-minute call · no obligation · flat quote after.

The Cyber Fire Drill
live · on-site · GTA
Insured & authorized in writing - certified senior partners for deep technical work Safe & authorized - no malware, no shaming Built around ransomware and PHIPA - the exact morning every clinic fears Toronto & the GTA
The attack that targets you

The Monday-morning lockout

Clinics are a favourite target: patient data is sensitive, downtime is unbearable, and a busy front desk opens a lot of attachments. Here is the path attackers take.

  1. 1
    The click

    A front-desk inbox gets a believable attachment - an “insurance form,” a “new patient intake,” a “lab result.” One click runs the attacker’s code.

  2. 2
    The spread

    Quietly, over hours or days, it moves from that one computer to the server that runs your scheduling, charting and imaging.

  3. 3
    The lock

    You arrive to a ransom note. The schedule, the charts, the X-rays - all encrypted. The day’s patients are in the waiting room and nothing works.

  4. 4
    The aftermath

    Beyond the ransom, PHIPA may require you to notify affected patients and the Information and Privacy Commissioner of Ontario. The clinical disruption is only half the cost.

Most clinic ransomware starts with a single email and a single click - not a master hacker. That means the strongest, cheapest defence is a trained front desk and a plan everyone has practised.

Rehearse it before it’s real
In the room

What your team will face in the room

We run the attacks that actually hit clinics - authorized, safe, and tuned to your front-desk reality. No real patient data is ever touched, no malware, no shaming anyone.

Ransomware lockout (the tabletop)

A guided “what do we do right now” walkthrough of a locked-out Monday - who calls whom, what stays off, how you see patients while you recover.

The malicious attachment

The fake intake form, lab result or insurance PDF aimed at your front desk. Your team learns the tells before they click - The Phishing Gauntlet, clinic edition.

PHIPA & the breach clock

What counts as a privacy breach, what PHIPA expects of you, and the simple notification checklist that keeps a bad day from becoming a regulatory one.

The “IT support” call

A caller claiming to be your IT company, walking a staff member into handing over access - and the MFA-fatigue prompts that come with it. One rule shuts it down.

What you walk away with

Not a slide deck. A plan, and new habits.

Every Fire Drill ends with something you can use the next morning - written down, scored, and built for how your team actually works.

A one-page ransomware response plan your clinic can post by the front desk
A PHIPA-aware breach-notification checklist (who to tell, and when)
A plain-English leadership readout: where you stand and what to fix first
A scored 30-day action plan, and a follow-up office hour to keep it moving
Simple pricing
Fire Drill 90 (live team training) from $1,800 +HST

The Cyber Fire Drill, tailored to dental and medical clinics. One flat fee, on-site, scheduled around your patient hours. See the full offer ladder - from the $750 baseline checkup to the Cyber Readiness Day - on the pricing page.

Book the Fire Drill See all pricing
Questions

The things teams in your sector ask first.

Is the simulation safe around our patient data?

Completely. We never touch real patient records, we run no malware, and we don’t harvest credentials. Everything is a controlled, authorized exercise. Your PHI stays exactly where it is.

We already have an IT company - why do we need this?

Your IT provider keeps the systems running; we train the people. Most clinic breaches start with a human click, not a server flaw. The two work together - in fact your IT company is welcome in the room.

Does this actually help with PHIPA?

Yes. You leave with a PHIPA-aware incident and breach-notification checklist, and a clearer picture of your obligations. It’s practical readiness - not legal advice - and pairs with our insurance-readiness service if you need formal policies.

How disruptive is it to clinic hours?

Minimal. We design the session around your schedule - a lunch-and-learn block, an admin morning, or after close. The core drill runs about three hours for your whole team.

When you need proof on paper
Clinics that need the paperwork done properly

We build the practical policy pack and the cyber-insurance questionnaire evidence PHIPA-minded clinics get asked for - plain-English readiness, not legal advice - and refer formal privacy advisory to vetted specialist partners when you need it.

See insurance readiness

Rehearse the attack before it’s real.

Book a 20-minute scoping call. We’ll tailor the drill to your dental & medical clinics, send one flat quote, and get a date on the calendar.

Book the Fire Drill (647) 835-6368

Not ready to book? Grab the free Clinic ransomware & PHIPA plan

contact@bastani.org · WhatsApp