Not All Defenses Are Worth the Same
Ransomware has become the defining threat to medical practices — it encrypts your records, halts patient care, and increasingly steals data before locking it, turning every incident into a reportable breach. But the advice practices get is a flat, endless list, as if every control mattered equally. It doesn't. Some defenses stop the most common attacks outright; others only help at the margins. This list is ranked by impact — how much real risk each one removes — so a practice with limited time and budget knows exactly where to start.
1. Multi-Factor Authentication on Everything Exposed
Highest impact. The majority of ransomware attacks begin with a stolen or guessed credential — on email, a VPN, a remote-access tool, or a cloud console. Multi-factor authentication defeats that stolen password before the attacker ever gets inside. If you do one thing on this list, do this. Start with the internet-facing accounts that attackers hit first, then extend inward. MFA is usually a settings change, not a purchase, and it removes more risk per hour of effort than anything else here. Phishing-resistant MFA raises the bar further.
2. Tested, Isolated, Offline Backups
Highest impact. MFA is your best chance to prevent ransomware; tested backups are what save the practice when prevention fails. The critical words are tested and isolated. A backup you have never restored is a hope, and a backup the ransomware can reach and encrypt is no backup at all. Modern attacks specifically hunt for and destroy connected backups first. You need at least one copy that is offline or otherwise immutable, and you need to actually restore from it periodically to prove it works. This is the difference between a bad week and a closed practice.
3. Fast Patching of Internet-Facing Systems
High impact. When attackers aren't using stolen credentials, they are exploiting known, unpatched vulnerabilities in the systems you expose to the internet — firewalls, VPNs, remote-access gateways, public servers. These are precisely the flaws that land on the CISA Known Exploited Vulnerabilities catalog, meaning they are being actively used right now. You cannot patch everything instantly, so prioritize by exposure: internet-facing first, always. Every day an exposed system stays unpatched is a day it is on the menu.
4. Endpoint Detection and Response (EDR)
High impact. Traditional antivirus recognizes known threats; ransomware crews use tools built to slip past it. EDR watches for the behavior of an attack — mass file encryption, credential dumping, lateral movement — and can isolate an infected machine before the damage spreads across the network. For a practice, the practical form is a managed EDR service, since the tool is only as good as the response behind it. This is where paid tooling starts genuinely earning its cost.
5. Network Segmentation
Moderate impact. When ransomware lands on one machine, a flat network lets it spread to all of them — including the servers running your EHR. Segmentation puts walls between zones so an infection in the front-office PC cannot immediately reach clinical systems and backups. It takes more effort to implement than the items above and won't stop the initial infection, but it can be the difference between one lost workstation and a practice-wide shutdown. It caps the blast radius rather than preventing the blast.
6. Security Awareness Training That Sticks
Moderate impact. Since credential theft and phishing kick off most attacks, staff who recognize a lure are a real line of defense. The caveat is that a once-a-year video changes almost nothing. Training earns its place on this list only when it is recurring, specific to the lures actually targeting healthcare, and reinforced by simulated phishing — the kind that changes behavior rather than checking a box. Done well it lowers your risk; done as an annual formality it mostly documents that you tried.
7. A Written, Practiced Incident Response Plan
Foundational. This ranks last not because it is optional but because it changes the outcome rather than the odds. When ransomware hits, the practices that recover fastest are the ones who already know who declares the incident, who to call, how to isolate systems, and how to evaluate whether PHI was exfiltrated. Building this after the attack starts wastes the hours that matter most. Write it down, keep it offline (a plan stored only on the encrypted network is useless), and rehearse the first 24 hours before you ever need them.
Start at the Top, Not the Bottom
The ranking is the point. A practice that nails the first three — MFA everywhere, tested and isolated backups, and fast patching of exposed systems — has already removed most of its ransomware risk at relatively low cost. The items further down add depth and shrink the damage when prevention fails, but they don't substitute for the top of the list. Don't let the length of a generic security checklist paralyze you. Work down from the highest-impact controls, finish each before moving on, and you will be measurably harder to ransom at every step.
Related Reading
- Infostealer malware and the credential threat
- The CISA KEV 14-day patching rule
- The first 24 hours after a suspected breach
- Phishing-resistant MFA for healthcare
Call to Action
Want to know which of these seven you are missing — before an attacker finds out for you? Schedule a walkthrough of HIPAA Security Suite, or take the 3-minute readiness quiz to see where your ransomware defenses stand today.