Small Medical Practices Are Now the Biggest Target for Healthcare Ransomware

The numbers flipped in 2025. For years, healthcare data breaches were a hospital story. Health systems with tens of thousands of employees, sprawling EHR deployments, and attack surfaces measured in hundreds of facilities made the headlines. Then something changed. The hospitals got better at security. The attackers shifted downmarket. And small medical practices, the independent clinics with six providers and no IT staff, became the path of least resistance.
HHS breach data from 2025 shows small and mid-sized practices now account for over 60 percent of reported healthcare data breaches. The average practice has no dedicated security person. The EHR gets patched when someone remembers, or when the vendor forces an update. Passwords are shared because the front-desk person covers for the medical assistant who covers for billing, and nobody has time to create individual accounts. And the HIPAA Security Rule, which for two decades let small practices document their way out of security controls they couldn’t afford, just took that option off the table.
The HIPAA Security Rule overhaul that finalized across 2025 and into 2026 did one thing that changes the calculus for every small practice in the country. It deleted the word “addressable.”
For twenty years, the Security Rule categorized certain controls as addressable. Multi-factor authentication was addressable. Encryption of ePHI at rest and in transit was addressable. Penetration testing was addressable. A practice could evaluate an addressable control, determine that implementing it was not reasonable given the practice’s size and budget, document that decision in a risk assessment, and remain compliant. That framework acknowledged a reality: a three-doctor family practice in Spokane Valley does not have the same resources as a hospital system. The rule gave small practices flexibility.
That flexibility is gone. Under the amended rule, multi-factor authentication is mandatory on every system that touches electronic protected health information. Encryption of ePHI at rest and in transit is mandatory, period. Vulnerability scanning is required every six months. Penetration testing is required annually. HHS explicitly rejected a request from industry groups to exempt small and rural providers from the penetration testing requirement. The agency’s response, published in the final rule commentary, stated that small providers are “at the greatest risk of a breach” and that exempting them would “undermine the purpose of the rule.”
The deadlines are rolling through 2026. Most small practices don’t know the rule changed. Many of the ones that do know haven’t started. And the enforcement posture is no longer advisory. OCR resolution agreements from 2024 and 2025 show small covered entities receiving civil monetary penalties and multi-year corrective action plans for failing to conduct risk assessments, failing to encrypt patient data, and failing to implement access controls. The cost of coming into compliance after OCR opens an investigation is, in every publicly documented case, higher than the cost of coming into compliance before one.
What a ransomware attack actually does to a medical practice
The clinical damage comes first. When the EHR locks, medication lists become inaccessible. Allergy records become inaccessible. Lab results, imaging reports, specialist consultation notes, all of it goes dark. The provider seeing a patient with chest pain can’t pull the last EKG. The provider refilling blood pressure medication can’t check the current dose. The provider evaluating a sick child can’t see whether there’s a history of allergic reactions. These are not hypotheticals. They are the clinical reality of every minute the EHR is down.
Then the operational collapse begins. Referrals can’t be processed because the clinical summary is locked. Prior authorizations sit because the insurance portal credentials were stored in the encrypted system. Prescriptions can’t go electronically to the pharmacy. Lab orders can’t be generated. Lab results that arrive during the outage can’t be filed. Every patient encounter generates a paper chart that has to be manually re-entered once systems come back, a process that takes weeks and introduces errors at every step.
Billing stops. The practice can’t submit claims. Revenue drops to zero while rent, payroll, and vendor contracts continue to run. Appointments get cancelled. Patients who can’t wait transfer their records elsewhere. Some of them don’t come back. Staff who have only ever worked in an EHR environment are suddenly running a paper-based practice they were never trained for. The average EHR downtime after a ransomware attack on a small practice is fifteen to twenty-one days. For a practice operating on standard primary care margins, three weeks without revenue is existential.
The financial cost breaks into layers. The ransom demand comes first. Many small practices pay it, not because they want to fund criminal operations but because paying looks like the fastest way to get patient care back online. The FBI says don’t pay. The practice, looking at a locked EHR on Monday morning with forty patients scheduled, makes a different calculation. The ransom ranges from $25,000 to over $100,000 depending on the attacker and the practice’s perceived ability to pay.
Then the forensic investigation starts. The practice has to determine what was accessed, whether patient data was exfiltrated, and which patients need to be notified. That investigation typically costs between $20,000 and $50,000 for a small practice. The breach notification process follows: identify every affected patient, prepare HIPAA-compliant notification letters, mail them within sixty days, and offer credit monitoring. Each step costs money the practice wasn’t planning to spend.
The OCR investigation opens next. The practice must produce its most recent security risk assessment, policies and procedures, business associate agreements, training records, and incident response documentation. If any of these are missing, incomplete, or out of date, the investigation expands from the breach itself to the practice’s overall compliance posture. Civil monetary penalties for HIPAA violations are tiered by culpability. Even a penalty at the low end, combined with the direct breach response costs, pushes the total well past $300,000. The Ponemon Institute’s annual healthcare breach study confirms this figure consistently across years of data. Most independent practices don’t survive it. They close, or they get acquired by a larger group.
The controls that prevent this cost a fraction of that number. MFA on every account that touches patient data. Encrypted devices and encrypted email. Automated backups, stored offsite, tested every quarter. Endpoint protection on every workstation. A documented risk assessment updated every year. Security awareness training that staff actually remember. A written incident response plan that tells people what to do when the EHR locks, because the moment of crisis is the wrong time to figure it out.
These are not enterprise controls. They are available to every practice, at a cost measured in hundreds of dollars per month, not thousands. The question is whether the practice puts them in place before the phishing email arrives. Because the data from 2025 makes one thing clear. It will arrive. Small practices are the target now. The only variable is whether the practice is ready when the email lands
Need help getting your Spokane practice ready for the HIPAA Security Rule changes?
Entre provides IT services for medical practices across Spokane and the Inland Northwest. HIPAA compliance, EHR security, encrypted backup, MFA deployment, and 24/7 monitoring built for the regulatory reality medical practices face in 2026.
Schedule a security assessment

















