Your Spokane Medical Practice Is One Stolen Password Away From an EHR Lockout

The front-desk coordinator opens an email that looks like it came from the EHR vendor. A system migration is scheduled. She needs to verify her login credentials. She clicks the link and enters her username and password. The email was not from the EHR vendor. The login page was not real. And the practice has just handed an attacker the keys to every patient record in its system.
That is the mechanism behind more than 60 percent of healthcare data breaches. Not a sophisticated exploit. Not a zero-day vulnerability. A phishing email that one person clicked, at a practice that had not yet turned on multi-factor authentication. The attacker now has a valid username and password for the practice’s electronic health record system. From a laptop in another country, they log in, escalate privileges, move laterally across the network, and deploy ransomware that encrypts every patient file, every billing record, every appointment schedule, and every backup that is connected to the network. The practice arrives Monday morning to a locked screen and a demand for payment in cryptocurrency.
That sequence is not hypothetical. The HHS Office for Civil Rights reported that healthcare data breaches affecting 500 or more individuals reached a record high in 2025. Small and mid-sized medical practices are the most frequently targeted segment, accounting for over 60 percent of reported incidents. The reasons are structural. Small practices typically lack dedicated IT staff. They run EHR systems that are patched inconsistently because taking the system offline for updates means losing appointment slots. They share passwords among clinical and administrative staff because the front-desk coordinator needs to cover for the medical assistant who needs to cover for the billing specialist, and creating individual accounts with appropriate permissions is work nobody has time for. They operate on the assumption that their size makes them an unlikely target, when in fact their size makes them an easier target than a hospital system with a security operations center and a full-time CISO.
For a Spokane medical practice, geography does not confer protection. A practice in Spokane Valley is reachable from anywhere on the planet the moment its network connects to the internet. The attacker does not know and does not care whether the practice is in Spokane, Seattle, or Singapore. What the attacker knows is that small medical practices handle the same categories of protected health information that hospital systems do , names, dates of birth, Social Security numbers, diagnoses, medications, insurance information, and payment card data , but with a fraction of the security infrastructure. The HIPAA Security Rule overhaul that finalized across 2025 and 2026 converted multi-factor authentication, encryption of ePHI at rest and in transit, vulnerability scanning every six months, and annual penetration testing from addressable to mandatory. The word “addressable” allowed a practice to evaluate a security control, determine that implementing it was not reasonable given the practice’s size and resources, and document that decision. That word is gone. The controls are now mandatory for every covered entity regardless of size. The compliance deadlines are rolling through mid-to-late 2026. Most small practices are not ready.
The enforcement posture has shifted from advisory to active. The HHS Office for Civil Rights has demonstrated through enforcement actions that small practices are not exempt from scrutiny. In multiple resolution agreements signed in 2024 and 2025, OCR imposed corrective action plans and civil monetary penalties on small covered entities that failed to conduct risk assessments, failed to implement MFA, and failed to encrypt patient data. The penalties were not theoretical. The corrective action plans required years of OCR oversight. The cost of coming into compliance after a breach is, in every documented case, higher than the cost of coming into compliance before one.
What Happens When an EHR Goes Dark
The clinical impact of an EHR outage is what distinguishes a healthcare ransomware attack from every other industry’s experience. When a manufacturing plant loses its systems, production stops and revenue is impacted. When a retail business loses its point-of-sale system, transactions move to cash and paper receipts. When a medical practice loses its EHR, patient safety is immediately in play. Medication lists, allergies, lab results, and imaging reports become inaccessible. The provider seeing a patient with chest pain cannot check the patient’s last EKG result. The provider refilling a blood pressure medication cannot verify the current dose. The provider evaluating a child with a rash cannot pull up the last well-child visit note to see if there is a history of allergic reactions.
Every clinical workflow that depends on the EHR , which in a modern practice is effectively every clinical workflow , stops. Referrals to specialists cannot be processed because the clinical summary cannot be transmitted. Prior authorizations sit unanswered because the insurance portal login credentials were stored in the system that is now encrypted. Prescriptions cannot be sent electronically to the pharmacy. Lab orders cannot be generated. Lab results that arrive during the outage cannot be reviewed or filed. The paper charts that most practices maintain as a backup are incomplete in the specific ways that matter most during an outage: the current medication list, the most recent lab results, and the last specialist’s consultation note are stored in the locked EHR, not in the paper chart.
The operational response to an EHR outage imposes its own costs. Every patient encounter during the outage period generates a paper chart that must later be manually entered into the EHR once systems are restored , a process that takes weeks and carries a high error rate. Appointments are cancelled or rescheduled, creating a backlog that takes months to clear. Patients who cannot wait transfer their records to another practice and do not return. Staff who spent years learning the EHR workflow must now function in a paper-based environment they have never trained for. Billing stops. Revenue stops. The practice continues to pay rent, salaries, and vendor contracts while generating no claims and receiving no reimbursements. The cash flow impact of a two-week EHR outage can be existential for a small independent practice operating on thin margins.
The financial impact unfolds in layers, each one arriving on a different timeline. The ransom demand, if the practice chooses to pay it , and many small practices do, despite the FBI’s recommendation not to, because paying the ransom appears to be the fastest path to restoring patient care , is only the first cost. The forensic investigation required to determine what was accessed and whether patient data was exfiltrated begins immediately and typically costs between $20,000 and $50,000 for a small practice. The breach notification process , identifying every patient whose protected health information may have been accessed, preparing notification letters that comply with HIPAA content requirements, and mailing them within the 60-day regulatory window , adds another significant cost in staff time, printing, postage, and legal review. The credit monitoring service offered to affected patients, which has become a standard expectation even for smaller breaches, adds a per-patient cost that scales with the number of individuals notified.
Then the regulatory response begins. The HHS Office for Civil Rights opens an investigation. The practice must produce its most recent security risk assessment, its policies and procedures, its business associate agreements, its training records, and its incident response documentation. If any of these documents are missing, incomplete, or out of date , and in most small practices, at least several of them are , the investigation shifts from the breach itself to the practice’s overall compliance posture. Civil monetary penalties for HIPAA violations are tiered based on the level of culpability, ranging from $100 to $50,000 per violation, with an annual maximum that can reach $1.5 million. Even a penalty at the lower end of that range, combined with the direct costs of the breach response, is enough to force a small practice to close or be acquired.
Industry data from the Ponemon Institute’s annual healthcare data breach study and HHS breach reporting confirms that the total cost of a healthcare data breach for a small practice routinely exceeds $300,000. That figure includes the direct costs , ransom, forensics, notification, credit monitoring, legal fees, and regulatory penalties , and the indirect costs: patient attrition, reputational damage, increased cybersecurity insurance premiums, and the operational disruption of functioning without an EHR for two to three weeks. Most small practices do not survive a breach of that magnitude as independent entities. The controls that prevent this outcome , MFA, encryption, tested backups, endpoint protection, a documented risk assessment, and annual security training , cost a fraction of that amount. The question is not whether the practice can afford to implement them. The question is whether the practice can afford not to.
Is your Spokane practice ready for the HIPAA Security Rule changes?
Entre provides healthcare IT services for medical practices across Spokane and the Inland Northwest. HIPAA compliance, EHR security, backup and disaster recovery, and 24/7 monitoring built for the regulatory reality of 2026.
Schedule a security assessment →

















