The ransom note loads before the schedule does. Here's exactly what to do in the first hour.
Most clinic ransomware starts with one click at the front desk and ends with a PHIPA decision nobody rehearsed. This free kit gives you three things you can use today: a red-flags checklist for the attachments your front desk actually opens, a one-page "we're locked out" plan to tape by the phone, and a plain-English PHIPA breach-decision and IPC-notification checklist. Print it, post it, and your team is readier than most clinics on the street.
- A front-desk red-flags checklist tuned to real intake, lab-result and insurance lures - not generic spam advice
- A one-page "we're locked out" response plan you can tape beside the front-desk phone
- A PHIPA breach-decision and IPC Ontario notification checklist in plain English
- Built around Dexis, Tracker and AbelDent - and we never use real patient information
Yours free - no signup wall. Want the editable templates or a hand rolling it out? Just ask.
Front-desk red flags: the attachment and link checklist
Your front desk opens dozens of attachments a day - intake forms, lab results, insurance PDFs and claim responses. That's the door attackers knock on. This is the 30-second check to run before clicking, written for the messages a clinic actually receives. If two or more of these are true, stop and verify by phone before you open anything.
The one-page "we're locked out" plan - tape this by the phone
If a screen shows a ransom note, or the schedule, charts or imaging won't load across more than one computer, treat it as a possible attack - not an IT glitch. The first hour decides how bad the day gets. Assign these roles before anything happens; in the moment, just follow the list in order.
The PHIPA breach-decision checklist (Ontario)
Under Ontario's Personal Health Information Protection Act (PHIPA), a clinic is a health-information custodian, and ransomware that touches patient records can be a privacy breach even if no data was obviously stolen - "unauthorized use or disclosure" includes records being encrypted, accessed, or copied by an attacker. Work through these questions with your privacy contact (and, for anything legal, your lawyer). This is practical readiness, not legal advice.
Before the bad day: five things worth doing this week
This kit is for the emergency. These five are the quiet, boring controls that mean the emergency either never happens or barely lands - the ones that show up on every clinic's cyber-insurance application and PHIPA risk review. None of them require a big project.
Print all three pages, tape the "we're locked out" plan beside the front-desk phone, and fill in your IT, insurance and privacy phone numbers before you need them. This is practical readiness, not legal advice - confirm your PHIPA obligations with your own lawyer and the current IPC Ontario guidance.
A checklist is a start. A drill makes it stick.
The Cyber Fire Drill runs these exact attacks against your team - safely - so the habits in this toolkit become muscle memory. Three hours, on-site, with a scored 30-day plan.
Is this really free, and do you ever touch our patient data?
It's free, and no - we never use real patient information for anything. This kit is built from public PHIPA, IPC Ontario and Canadian Centre for Cyber Security guidance and our own clinic experience. The same rule holds in our live training: no real patient data, no malware, no harvesting passwords, and nobody gets named or shamed.
We already have an IT company. Doesn't this cover us?
Your IT provider keeps the systems running and is exactly who you call in the first hour - they're on the plan for a reason. But most clinic ransomware starts with a human click at the front desk, and the PHIPA decision afterward is yours, not theirs. This kit covers the people-and-decisions side IT can't do for you. Your IT company is welcome in the room when we train your team.
How is this different from your Cyber Fire Drill?
This kit is the printed version of a few things we cover. The Cyber Fire Drill is the live, roughly three-hour, on-site version for your whole clinic - your front desk rehearses the malicious-attachment moment, your team walks the locked-out tabletop together, and leadership leaves with a PHIPA-aware plan scored to where you actually stand. Reading the plan is good; living through it once is what your team remembers. Book a Cyber Fire Drill, or a 20-minute call, when you're ready.
More resources in the resource library · questions? contact@bastani.org