Stay Vigilant: The American Dental Association Received a Warning from the FBI Regarding Cyber Threat Targeting Dental Practices
As a Managed Service Provider (MSP) specializing in serving medical and dental offices, we actively work with our clients to stay ahead of cybersecurity threats. The American Dental Association (ADA) and the American Association of Oral and Maxillofacial Surgeons (AAOMS) recently received a warning from the Federal Bureau of Investigation (FBI) about a credible cybersecurity threat targeting oral and maxillofacial surgery practices. While there are no known victims as of now, the proactive measures are crucial to prevent potential attacks.
The Evolving Threat to Dental Practices
According to the FBI, the group behind these attacks has previously and successfully targeted plastic surgeons and cosmetic surgery practices and is now believed to be shifting its focus to oral and maxillofacial surgeons. However, it is essential for all dental practices, including those of general dentists and other specialists, to remain vigilant as they might also become targets.
Cybercriminals often employ sophisticated social engineering tactics such as:
Phishing and Spear Phishing
Deceptive emails designed to trick recipients into revealing sensitive information or downloading malware. Spear phishing is spoofing addresses of authority figures in your organization and making plausible-sounding requests, typically for gift cards or something similar.
SMSishing
Similar tactics executed through text messages or instant messaging apps. These especially target corporate phones with messages similar to spear phishing in email.
Vishing
Voice-based phishing attacks conducted via phone calls or voicemail. These will typically include yes or no questions, which are then used to authorize charges, ie, can you hear me? Yes. In these situations, if you’re not sure what’s happening, never answer yes. Instead, answer I can hear you.
Real-World Example of a Cyber Threat
In one notable scenario, a cybercriminal posed as a prospective patient, requesting assistance with online new patient forms. When the forms were emailed back, they contained malicious attachments that deployed malware when the attachments were opened by the unsuspecting staff. Such tactics highlight the importance of vigilance and skepticism towards unsolicited communications.
Key Precautions for Dental Practices
To safeguard your practice against these threats, the Cybersecurity & Infrastructure Security Agency (CISA) recommends the following precautions:
- Educate Your Team: Regularly train staff to recognize and avoid phishing attempts.
- Enforce Strong Passwords: Implement policies requiring robust, unique passwords. Hint: Password123 is NOT a password, it’s an invitation.
- Implement Multifactor Authentication: Add an extra layer of security by requiring multiple forms of verification, like a code that is sent to a cell phone or authenticator.
- Keep Software Updated: Ensure all business software is up-to-date to protect against vulnerabilities. Do not disable auto updates unless specifically instructed to do so.
- Backups: As always, ensure you have appropriate data backups for all of your operational and patient records.
Reporting and Advocacy
The ADA urges any dental practice experiencing fraudulent or suspicious activities to report incidents to the FBI Internet Crime Complaint Center at ic3.gov. If you are one of our active clients, we also encourage you to use our ticketing system. The ADA continues to advocate at the federal level for measures to protect the healthcare infrastructure from cyber threats. For the latest updates and advocacy efforts, visit ADA.org.
Conclusion
Staying informed and proactive about cybersecurity is paramount for dental and medical practices. As your MSP, we are committed to providing the support and expertise necessary to secure your practice.
For personalized assistance and more information on how we can help protect your dental practice, contact us today. Your security is our priority.