Call Book the Fire Drill
For dental clinics · Toronto & GTA

It’s Monday, 8 a.m. The schedule won’t load - and neither will a single X-ray.

Your front desk rehearses that exact morning - safely - so they stop the click that causes it and know the first hour cold. Because one fake supplier invoice on Friday can encrypt your schedule and imaging by Monday, and with charts involved, PHIPA becomes part of your morning too.

  • Your front desk drills the real scams: fake supply invoices, patient-record phishing, the “IT support” call
  • A safe ransomware tabletop - who calls whom, what stays off, how you see patients while you recover
  • Certificates and the dated completion record your insurance renewal asks about

A 20-minute scoping call, then one flat quote. No jargon, no pressure.

A dental-clinic professional
Built for dental clinics like yours
What your clinic walks away with

Live and on-site for your whole team - then a plan you can act on the next morning.

  • A one-page “locked out” response plan, laminated, by the phone
  • A front-desk routine for spotting the attachment that starts it all
  • A PHIPA-aware breach checklist - who to tell, in what order
  • A scored 30-day plan, prioritized by real risk
Book the Fire Drill

20-minute call · no obligation · flat quote after.

The Cyber Fire Drill
live · on-site · GTA
Insured & authorized in writing - certified senior partners for deep technical work Safe & authorized - no malware, no shaming Built around the Monday-morning lockout - the exact morning every clinic fears Toronto & the GTA
The attack that targets you

The Monday-morning lockout

Dental clinics are a favourite target: patient data is sensitive, a booked-solid schedule makes downtime unbearable, and a busy front desk opens a lot of attachments. Here is the path it actually takes.

  1. 1
    The click

    A believable email lands at the front desk - a supplier “statement,” a lab “report,” an insurance “form.” One click on a Friday afternoon runs the attacker’s code.

  2. 2
    The spread

    Quietly, over the weekend, it moves from that one computer to the machine that runs scheduling, charting and imaging.

  3. 3
    The lock

    Monday, 8 a.m.: a note on every screen. The schedule, the charts, the X-rays - encrypted. The waiting room is full and nothing works.

  4. 4
    The aftermath

    Beyond the downtime - often a week or more - patient records mean PHIPA duties: assessing the breach, notifying affected patients and the privacy commissioner where required. The clinical disruption is only half the cost.

Almost every clinic ransomware case starts with one email and one click - not a master hacker. Which means the strongest, cheapest defence is a trained front desk, separated Wi-Fi, tested backups, and a first hour everyone has rehearsed. That’s exactly what we build.

Rehearse it before it’s real
In the room

What your team will face in the room

We run the scams that actually hit GTA dental offices - authorized, safe, and tuned to your front-desk reality. No real patient data is ever touched, no malware, no shaming anyone.

The fake supplier invoice

A dental-supply “bank details have changed” email, timed like the real ones. The callback habit that stops it becomes muscle memory - for invoices, labs and e-transfers alike.

Ransomware lockout (the tabletop)

A guided walkthrough of the locked-out Monday: who calls whom (insurer first), what stays off, and how you keep seeing patients while you recover.

The patient-info phone call

A friendly caller who wants a chart, a code, or a password - and the polite, airtight front-desk script that ends the call without ending the relationship.

PHIPA & the breach clock

What counts as a privacy breach, what Ontario expects of a clinic, and the plain-English checklist that keeps a bad day from becoming a regulatory one.

What you walk away with

Not a slide deck. A plan, and new habits.

Every Fire Drill ends with something you can use the next morning - written down, scored, and built for how your team actually works.

A one-page ransomware response plan posted by the front desk
A PHIPA-aware breach-notification checklist (who to tell, and when)
Per-person certificates plus the dated completion record for your insurer
A scored 30-day action plan, and a follow-up office hour to keep it moving
Simple pricing
Fire Drill 90 (live team training) from $1,800 +HST

The Cyber Fire Drill: Dental Edition - from $1,800 for the 90-minute drill to $3,900 for the full three hours, fixed, scheduled around patient hours. Founding rates while our first-ten-client program lasts. See the full offer ladder - from the $750 baseline checkup to the Cyber Readiness Day - on the pricing page.

Book the Fire Drill See all pricing
Questions

The things teams in your sector ask first.

Is the training safe around our patient data?

Completely. We never touch real patient records, run no malware, and harvest no credentials. Demo data is synthetic, simulations are authorized in writing, and if a screen with patient information ever needs looking at, your person drives. Your PHI stays exactly where it is.

We already have a dental IT company - why do we need this?

Keep them - we don’t touch their lane. They keep the systems running; we train your people and check what falls between the cracks: staff habits, guest Wi-Fi separation, backups actually restoring, insurance answers. Your IT provider gets a copy of everything we find, and most thank us.

How disruptive is it to clinic hours?

One room, one block of time, nothing installed. Most clinics run the 90-minute drill over an admin morning or lunch block; the full three-hour edition fits an admin afternoon. We schedule around your patient hours, evenings included.

What does it cost, and what about the checkup first?

The 90-minute drill is $1,800; the full Fire Drill is $3,900, plus HST - fixed, published, whole team. Many clinics start with the $750 Baseline Security Checkup: 20 controls scored in 90 minutes, and the fee credits toward the drill or the fixes.

After the drill
Clinics that want the basics actually done

The Security Tune-Up closes what the checkup and drill find: MFA enforced, email security configured, guest Wi-Fi separated from the machines that run the clinic, backups restore-tested. Fixed price, after-hours changes, your IT company copied on everything.

See the Security Tune-Up

Rehearse the attack before it’s real.

Book a 20-minute scoping call. We’ll tailor the drill to your dental clinics, send one flat quote, and get a date on the calendar.

Book the Fire Drill (647) 835-6368

Not ready to book? Grab the free cyber-readiness checklist

contact@bastani.org · WhatsApp