A Hacker Can Hold Your Patient Records Hostage—And Your Florida Practice May Not Be Fully Covered
It is 7:42 on a Monday morning. The front-desk team at a Florida medical practice is preparing for the first appointments of the day when every workstation displays the same message:
Your files have been encrypted. Follow the instructions below to restore access.
The electronic health record will not open. The scheduling system is unavailable. Staff cannot verify medications, review patient histories, retrieve lab results, or determine who is supposed to be seen next.
Patients are already arriving. Phones are ringing. The practice manager calls the software vendor, who explains that the problem is not simply an application outage. Someone has gained access to the practice’s network and encrypted its files.
Then a second problem emerges: data may have been stolen before the systems were locked.
The physician-owner calls the insurance agent expecting immediate help. The general liability policy does not appear to provide the required cyber response. The malpractice policy may contain limited privacy coverage, but not the full combination of digital forensics, data restoration, breach counsel, notification expenses, extortion response, and business interruption the practice now needs.
The owner believed the practice was covered. It had insurance, an outside IT provider, and a cloud-based EHR. But none of those facts, by themselves, guaranteed protection against this event.
Why Medical Practices Are Attractive Ransomware Targets
Healthcare organizations hold exactly the kind of information cybercriminals value: names, dates of birth, Social Security numbers, insurance information, billing records, diagnoses, prescriptions, lab results, and detailed treatment histories.
Medical practices also have limited tolerance for downtime. A retail business might temporarily process transactions manually. A healthcare provider may be unable to deliver safe patient care without access to medical histories, medication lists, imaging, laboratory results, and scheduling information.
That pressure gives an attacker leverage.
Healthcare systems can also involve numerous points of entry:
- Electronic health record platforms
- Billing and payment systems
- Remote-access tools
- Email accounts
- Connected medical devices
- Cloud storage
- Third-party vendors
- Employee laptops and mobile devices
The threat is not limited to hospitals. Verizon’s 2025 healthcare breach analysis found that ransomware appeared disproportionately in breaches involving small and midsize organizations. Its healthcare snapshot reported ransomware involvement in 88% of the SMB breaches examined, compared with 39% for larger organizations. The percentage is specific to Verizon’s analyzed dataset—not every medical practice—but it destroys the comforting assumption that attackers only pursue large health systems.
Healthcare breaches are also unusually expensive. IBM’s 2026 research placed the average healthcare breach cost at approximately $6.64 million, the highest industry average for the fifteenth consecutive year. That figure includes large organizations and should not be treated as the expected cost for a small practice. The lesson is that healthcare incidents create multiple categories of expense at the same time.
Sources: Verizon 2025 Healthcare DBIR Snapshot and IBM Cost of a Data Breach Report.
The Dangerous Coverage Assumption
The critical question is not whether your practice has insurance. It is whether the policies you purchased are designed to respond to a ransomware attack.
Practice owners commonly assume protection will come from one of three places. Each assumption needs to be tested against the actual policy or contract.
“Our General Liability Policy Will Cover It”
Commercial general liability insurance is primarily designed for claims involving bodily injury, property damage, and certain personal or advertising injuries. It is not automatically a comprehensive cyber policy.
Some business policies may offer limited cyber endorsements, but the scope and limits can be narrow. A small endorsement should not be confused with dedicated coverage for ransomware response, forensic investigation, notification, data restoration, extortion, and lost income.
“Our Malpractice Policy Will Cover It”
Medical malpractice insurance is principally designed to address allegations that professional services caused patient injury. A ransomware attack is a different category of event.
Some malpractice policies include limited privacy, regulatory, or breach-response benefits. Others exclude significant cyber exposures or provide limits that may be inadequate for a serious incident.
The presence of any cyber-related wording does not answer the question. The practice must determine exactly what is covered, what is excluded, what limit applies, and whether defense or response expenses reduce that limit.
“Our EHR or IT Vendor Is Responsible”
A cloud-based EHR and outside IT support can improve security, but they do not automatically transfer all financial responsibility away from the practice.
A vendor agreement may limit the vendor’s liability, exclude consequential damages, cap recovery at the fees paid under the contract, or divide security obligations between the vendor and the medical practice.
A breach can also begin outside the EHR platform through compromised email, stolen credentials, remote desktop access, a staff laptop, or another connected vendor.
The correct question is not, “Do we use a reputable vendor?” It is, “If an incident happens tonight, who pays for every part of the response?”
What a Ransomware Attack Can Actually Cost
The ransom demand is only one component of the loss—and sometimes it is not the largest one.
Sophos reported that among healthcare organizations affected by ransomware in its 2025 study, the median ransom demand was approximately $343,000 and the median payment was about $150,000. Those figures came from surveyed organizations and should not be treated as a guaranteed outcome for any particular practice.
The total financial impact can include:
- Digital forensics: Specialists may need to determine how the attacker entered, what systems were affected, and whether information was removed.
- System restoration: Servers, workstations, applications, and backups may need to be cleaned, rebuilt, or replaced.
- Lost revenue: The practice may lose days or weeks of appointments, procedures, billing, and collections.
- Emergency IT services: Incident-response work is specialized and can cost substantially more than ordinary IT support.
- Legal and regulatory guidance: Privacy counsel may be needed to determine notification and reporting responsibilities.
- Patient notification: The practice may have to identify affected individuals, prepare notices, and manage mailing or call-center expenses.
- Credit or identity monitoring: Affected patients may be offered monitoring services depending on the information exposed and the response strategy.
- Public relations: The practice may need professional help communicating with patients, employees, referral partners, and the public.
- Extortion response: Specialists may be needed to communicate with the attacker, evaluate the demand, and coordinate a lawful response.
- Reputational harm: Patients may postpone care or transfer records after learning their information was compromised.
Paying a ransom does not guarantee that every file will be restored, that stolen data will be deleted, or that the attacker will not return.
Source: Sophos State of Ransomware 2025.
A Ransomware Attack May Also Become a HIPAA Event
A ransomware incident is not merely an IT emergency. When electronic protected health information is involved, it may trigger obligations under the HIPAA Privacy, Security, and Breach Notification Rules.
HHS guidance explains that when ransomware encrypts electronic protected health information, a breach is presumed unless the covered entity or business associate can demonstrate a low probability that the information was compromised through the required risk assessment.
Depending on the facts, response obligations may include notification to affected individuals, notification to the HHS Secretary, and—in certain larger incidents—notification to the media.
The regulatory clock matters. The organization cannot simply wait until every technical detail is known before beginning its legal analysis and response.
Sources: HHS Ransomware and HIPAA Fact Sheet and HHS Breach Notification Rule.
What Cyber Liability Insurance Is Designed to Cover
Cyber liability insurance is designed specifically for many of the financial and operational consequences created by a cyberattack.
Depending on the carrier, policy, limits, endorsements, and exclusions, coverage may include:
- Digital forensic investigation
- Privacy and breach-response counsel
- Data restoration
- Ransomware and cyber-extortion response
- Notification and call-center expenses
- Credit or identity monitoring
- Cyber business interruption
- Public relations and crisis management
- Regulatory defense and certain penalties where insurable
- Claims brought by patients or other affected parties
- Cybercrime or social-engineering coverage when specifically included
Cyber policies are not identical. Some contain waiting periods before business-interruption coverage begins. Some restrict ransomware payments, social engineering, unencrypted devices, or losses involving unsupported software. Coverage can also depend on the security controls represented in the application.
A policy should therefore be evaluated alongside the practice’s actual technology, vendors, backups, remote-access procedures, employee training, and incident-response plan.
Why This Matters for Florida Medical Practices
Florida has a large concentration of independent physician offices, specialty groups, dental practices, behavioral-health providers, medical spas, outpatient facilities, and other healthcare organizations.
Practices throughout Miami-Dade, Broward, Palm Beach, Orlando, Tampa, Jacksonville, Naples, Sarasota, and surrounding communities may hold thousands of sensitive patient records without employing a full-time cybersecurity team.
That does not make a practice irresponsible. It does mean the practice may depend heavily on outside vendors while still retaining legal, operational, and financial obligations of its own.
Cyber insurance cannot replace secure backups, multifactor authentication, staff training, software updates, access controls, or an incident-response plan. Likewise, technical security alone cannot reimburse the practice for lost revenue, forensic expenses, notification costs, or covered claims after an attack.
The stronger strategy combines prevention, response planning, vendor oversight, and appropriate insurance.
Questions to Ask Before the Next Attack
- Does our current insurance specifically cover ransomware?
- What cyber limit applies?
- Are forensic and legal expenses inside or outside that limit?
- Does the policy cover business interruption?
- How long is the waiting period?
- Does coverage include data restoration?
- Are ransomware payments covered when legally permissible?
- Does the policy provide access to an incident-response team?
- Are dependent business interruption and vendor outages addressed?
- Have our application answers remained accurate as our systems changed?
Frequently Asked Questions
Does medical malpractice insurance cover a cyberattack?
Not necessarily. Medical malpractice policies primarily address claims arising from professional healthcare services. Some policies contain limited privacy or cyber benefits, but those provisions may not provide the breadth or limits of a dedicated cyber policy.
How much can a data breach cost a medical practice?
The amount varies based on the number and type of records, length of downtime, restoration requirements, notification obligations, legal expenses, and whether data was stolen. IBM’s industry averages include major healthcare organizations and should not be used as a quote for a small practice.
Does cyber insurance cover ransomware?
Many cyber policies can cover specified ransomware-related expenses, such as incident response, forensics, restoration, extortion negotiation, and business interruption. Coverage depends on the policy and compliance with its conditions.
Do cybercriminals really target small medical practices?
Yes. Small organizations can be attractive because they possess valuable information, often have fewer internal security resources, and cannot tolerate prolonged downtime. Verizon’s research shows ransomware has a disproportionate impact on smaller organizations within its analyzed breach data.
Will an EHR vendor’s insurance protect the medical practice?
Not automatically. Vendor contracts frequently divide responsibilities and limit liability. Each practice should review its agreements and maintain protection for obligations and losses that remain with the practice.
Would Your Practice Be Covered Tomorrow Morning?
Do not wait for a locked screen to discover the limitations of your existing insurance. Review how cyber coverage could respond to ransomware, data restoration, HIPAA notification expenses, forensic investigation, and lost income.
Explore Medical Practice Cyber Insurance
Coverage availability, terms, conditions, exclusions, limits, and pricing vary by insurer and applicant. This article provides general educational information and is not legal, cybersecurity, or insurance advice.
