← All case studies

The Doctor Will See You Now

Fictional company: Millbrook Medical Group

A mid-size medical practice lost more than $700,000 and exposed 12,000 patients' protected health information because their IT company built an environment that worked but was never secured. Open RDP. A departed employee's active account. No MFA. No monitoring. No cyber insurance. The attacker didn't need to be good. The door was open.

Lisa unlocked the front office at 7:15 on a Monday morning and found that nothing worked. No charts. No schedule. No way to verify a single insurance card. The phones rang anyway. The first patients were in the waiting room by 8:00, and there was nothing to tell them.

The attacker had been inside Millbrook's network for six days by then. To understand how, you have to go back to what Millbrook was, and to what the company it trusted had built.

Millbrook Medical Group runs family medicine and internal medicine across three locations in a mid-size metro area. Eight physicians. Roughly forty staff between front desk, billing, medical assistants, and nurses. Mix of Medicare, Medicaid, and commercial insurance. The practice has been operating for over twenty years.

Lisa is the office manager. She handles HR, vendor relationships, billing oversight, and whatever else doesn't fall neatly under clinical care. There is no IT staff. Everything technology-related is outsourced to Keystone Technical Solutions, a regional IT company that bills Millbrook about $4,500 a month.

Keystone started as a break-fix shop and grew into managed services. They set up networks, configure workstations, deploy printers, and keep email running. They are good at making things work. They handle Millbrook's electronic health record (EHR) hosting, server management, workstation support, and backups.

Keystone is not a security company. They don't position themselves as one. But when Dr. Patel, the senior partner, asked "are we secure?" Keystone said yes. The servers were running. Antivirus was installed. Nobody had complained. That answer satisfied the doctors. Nobody asked what "secure" actually means.

What Keystone built

The EHR runs on a Windows Server at the main office. Patient records, scheduling, billing, prescriptions, lab results. Self-hosted, not a cloud service. Keystone installed it, maintains it, and runs the backups. The server sits on the same network as everything else.

Three office locations connect back to the main office through a site-to-site VPN. The VPN works. Traffic between offices moves through encrypted tunnels. But once inside the tunnel, there's nothing separating one location's workstations from another's, or any workstation from the server. The VPN connects the offices. It doesn't protect what's inside them. A flat network across all three sites means a compromised machine at the satellite clinic has the same access to the patient database as a workstation sitting ten feet from the server.

Dr. Patel wanted to chart from home. Keystone opened Remote Desktop Protocol (RDP) directly to the internet so he could reach the server. No VPN for his home connection. No Remote Desktop Gateway. No multi-factor authentication. Just the server's remote access exposed on the public IP with local Windows credentials. It worked. Dr. Patel could log in from his home office and see his patients' charts. That was the requirement, and Keystone met it.

Basic antivirus ran on the workstations. Nothing on the server. No endpoint detection and response (EDR). No managed detection and response (MDR). No monitoring of any kind.

Nightly backups ran to a NAS, a network-attached storage box, sitting on the same flat network. It was a consumer model, the kind built for a household media library, not the kind that offers immutable, tamper-proof retention. No offsite copy either. Keystone never tested whether the backups could actually restore a working system.

Passwords were simple. No complexity requirements. No expiration. No lockout after failed attempts. No MFA on anything. Not RDP. Not email. Not the EHR.

Data everywhere

Nobody at Millbrook had ever written a policy about where patient information should live. The EHR held the official records, but copies of sensitive data had spread across every surface.

Front desk staff scanned insurance cards and driver's licenses and saved them to their local desktops. Billing staff kept spreadsheets of outstanding balances with patient names, dates of birth, and insurance IDs on their workstations and on a shared drive. Physicians dictated notes into Word documents saved locally before transcribing them into the system. Scanned intake forms with Social Security numbers sat in folders on the file server going back years. Employee records, including payroll data, W-2s, and direct deposit information, lived on the same file share as patient data. The practice's financial records, profit and loss statements, accounts receivable, vendor contracts, sat alongside everything else.

There was no data classification. No policy restricting where protected health information (PHI) could be stored. No encryption on the local drives. No data loss prevention (DLP) tooling to catch sensitive files piling up on workstations. Twenty years of patient records and business data, scattered across every machine in the practice, all on the same flat network.

The door

Rachel was a medical billing specialist. She left Millbrook six months ago. Voluntary departure, no issues. Lisa processed the HR paperwork. Nobody submitted a ticket to Keystone to disable the account. There was no offboarding checklist connecting HR departures to IT actions. Rachel's Windows account was still active on the domain. Still had RDP access to the server.

On a Monday evening, an automated scanner found Millbrook's public IP with remote desktop exposed. These scanners run continuously. Search engines like Shodan catalog every IP address with remote access services visible to the internet. Credential stuffing against the endpoint. Rachel's account, with a predictable password, worked. The attacker was inside the network. No alert fired. No second factor was required. No failed-login lockout engaged. Nobody was watching.

Six days

The attacker mapped the network from Rachel's old session. Flat network across all three locations. Everything reachable. The server running the EHR. The file shares holding scanned insurance cards, intake forms, billing spreadsheets, employee payroll records, and financial statements. The NAS with the backups.

Over the next five days, the attacker staged and exfiltrated data. Not just patient records. Everything. Protected health information on roughly 12,000 patients accumulated across more than twenty years of practice: names, dates of birth, Social Security numbers, insurance IDs, diagnosis codes, medication lists. Employee records with Social Security numbers and direct deposit details. The practice's profit and loss statements, accounts receivable, and vendor contracts. Because sensitive data lived on every workstation and file share with no restrictions, the attacker didn't have to crack the EHR database to get what they wanted. It was already scattered across the network in spreadsheets, scanned documents, and local folders.

The EHR database itself may well have been encrypted at rest. It didn't matter. Encryption at rest protects a stolen hard drive. It does nothing for an attacker who is already inside the network on a valid account, reading the data the same way any authorized user would. The attacker wasn't stealing a disk. They were logged in.

On Day 6, ransomware deployed. The EHR database encrypted. File shares encrypted. The NAS backup, sitting on the same flat network with no protection of its own, encrypted. Every server, every share, every backup. Locked.

The response

Lisa called Keystone. They confirmed what she already suspected by the time they arrived: everything was encrypted, and so was the NAS. There was no other copy anywhere, on-site or off. Keystone had never set one up, and had never tested whether the one backup that existed would have restored anything even if it had survived.

Dr. Patel's first instinct was to treat it as a server problem. He told the partners it was an IT issue and told Lisa to handle it. He didn't want lawyers involved. "We don't know anything was actually taken." Two weeks later, the forensics firm hired by the practice's general counsel found Millbrook's records on a dark web marketplace. Names, dates of birth, Social Security numbers, diagnosis codes, medication lists. His patients. His practice. For sale. The encrypted servers hadn't made it real. The listing did.

What Millbrook lost

The practice operated on paper for four weeks. Appointments were rescheduled or cancelled. Revenue dropped to nearly zero for billable services that require EHR documentation. Eight physicians averaging roughly $2,000 per day in collections, offline for twenty working days, cost the practice an estimated $320,000 in revenue, and some of those claims will never be recovered because insurers deny late submissions.

There was no backup to rebuild from. Staff spent weeks reconstructing patient data from paper records, pharmacy call-backs, and faxed lab results. Some data was permanently lost. Two experienced staff members quit during the recovery.

Some patients left, picked up within weeks by a regional health system with same-day scheduling and a patient portal, the ones who could switch without disrupting an ongoing course of care. Others stayed, but staying wasn't confidence. It was friction working in Millbrook's favor for once: a chronic condition tracked for a decade, an insurance network with no other nearby option, a relationship with a physician they trust more than they currently trust the practice.

The staff felt this differently than the patients did. Payroll records, Social Security numbers, direct deposit details, W-2s, all of it sat on the same file share and went out the same door. The people who had spent years defending Millbrook to worried patients were now worried about their own identities, and some of them noticed that the practice that couldn't protect their information also hadn't told them anything until the notification letters arrived. That's part of why two of them quit.

Millbrook had no cyber insurance. The practice carries malpractice, general liability, and property insurance. Cyber never came up. Keystone never recommended it. The doctors never asked. Every dollar of the incident response came out of the practice's operating budget: roughly $50,000 in forensics to find the dark web listing, $55,000 to notify 12,000 patients, $65,000 for a year of credit monitoring at bulk rates, more than $150,000 in legal counsel and still growing, and $75,000 to rebuild the IT environment with a new MSP.

Total exposure: more than $700,000 and still climbing.

Then there is the fraud. Medical records reportedly sell for anywhere from tens of dollars to four figures on dark web markets, many multiples of a stolen credit card number, because they enable several fraud types at once: tax fraud with stolen Social Security numbers, insurance claims for procedures that never happened, medical identity fraud where a thief's diagnoses get written into the victim's actual chart so the wrong blood type shows up in an emergency years later. Victims tend to find out long after the fact, when their benefits are exhausted or a collections agency calls about a bill they never incurred. The same fraud economy applies to the employee data: stolen W-2s and routing numbers enable tax refund fraud and direct-deposit redirection, no medical angle required.

OCR, the Office for Civil Rights at HHS, reviews every reported breach affecting 500 or more individuals; a 12,000-record breach appears on the public breach portal and triggers a compliance review automatically. Millbrook had no prior risk assessment on file, though the HIPAA Security Rule requires covered entities to conduct one. No security policies were documented, no training records existed, no access controls were documented. The practice had assumed it was compliant because Keystone handled IT and nobody said otherwise, checking boxes on forms nobody fully understood and trusting an IT company to interpret compliance requirements it wasn't qualified to assess. The penalty schedule runs from roughly $145 per violation up to more than $2 million per violation for willful neglect that goes uncorrected, adjusted for inflation every year. The absence of any compliance documentation removes the strongest mitigating argument the practice could make.

Litigation is running in both directions. Patients filed a class action alleging negligence, mapping each absent control (open remote access, a departed employee's active account, no MFA, no monitoring) to a standard that existed, was freely available, and was ignored. Millbrook sued Keystone, arguing Keystone held itself out as the technology expert and built an environment that was anything but. Keystone's defense: the statement of work says IT management and support, not cybersecurity. They did what they were contracted to do and nothing they weren't paid to do. Both sides will spend years in discovery. The patients are the ones whose data is for sale.

People

Nobody at Millbrook owned security as a responsibility. Dr. Patel assumed Keystone handled it. Keystone assumed they were only hired for IT. Lisa tried once to bring in an outside vendor for a security assessment. Dr. Patel declined. "We pay Keystone for that." They didn't. But Dr. Patel had never read the contract. Neither had Lisa.

The doctors treated their IT the way an absent landlord treats a rental property. They hired someone, they stopped looking, and they assumed the building was maintained because nobody called with a complaint. The building was theirs the whole time. So was the liability.

This is where the "it doesn't take a CISO" advice breaks down. It's true that a practice this size doesn't need a full-time Chief Information Security Officer. But when nobody in the organization understands what security looks like, designating an internal owner just moves the problem. You can't assign someone to verify controls they don't know exist. What Millbrook needed was advisory: a security consultant, a virtual CISO (vCISO) engagement, or a qualified MSP with actual cybersecurity credentials who could walk in, assess the environment, and say "here are the ten things that will get you sued." That runs $1,000 to $3,000 a month for an ongoing vCISO relationship, or $3,000 to $8,000 for a one-time assessment, which is where most small organizations should start. It costs money because it requires expertise the practice doesn't have.

When Rachel left, Lisa processed HR paperwork. Nobody told the MSP. There was no checklist connecting HR departure to IT account disable. The account stayed active because the process to remove it didn't exist. This is a people problem before it is a technology problem.

The physicians had no awareness of what their IT environment looked like. Dr. Patel didn't know RDP was exposed to the internet. He didn't know what RDP was. He knew he could chart from home. Staff had no security awareness training, no phishing exercises, no guidance on where sensitive data should and shouldn't be stored. HIPAA-specific awareness training for a practice this size runs $1,200 to $2,500 a year, cheap against everything that followed.

Process

Millbrook's partners assumed compliance because nobody told them they weren't compliant. They filled out forms, checked boxes, and trusted that Keystone's presence meant the regulatory requirements were met. That gap between assumption and reality is where HIPAA enforcement finds its footing and where litigation gets expensive.

A risk assessment, $3,000 to $8,000 from a qualified assessor, would have forced someone to actually look at the environment. Walk through the office. Ask what's on the server. Ask what's exposed to the internet. Ask who has access and whether they still work here. The assessment produces the list of things that need to change, not a document for a filing cabinet. Millbrook never had that list because they never looked.

Nobody periodically compared active user accounts to current employees. Nobody reviewed who had RDP access, admin privileges, or access to protected health information. A quarterly review, free, just a spreadsheet and a calendar reminder, would have caught Rachel's account months before the attacker found it.

When the attack happened, nobody knew what to do. Lisa called Keystone. Nobody called a lawyer. Nobody preserved forensic evidence. Nobody knew the HIPAA breach notification clock starts at discovery and runs for 60 days. Millbrook assembled its response team from scratch in the worst week of the practice's existence. An incident response plan, free using HHS's published resources or $2,000 to $5,000 for a consultant to tailor one, prevents the chaos that turns a bad week into a financial catastrophe.

Nobody read Keystone's statement of work closely enough to understand the boundary between what Keystone was responsible for and what fell to the practice. Nobody asked for documentation of what was exposed to the internet, how backups were configured, or when the last access review happened. Outsourced IT is outsourced labor, nothing more. The accountability stays with the practice: HIPAA holds the covered entity responsible regardless of who manages the infrastructure.

Millbrook had no cyber insurance, roughly $5,000 to $12,000 a year for a practice this size. The application would have required answering questions about MFA, monitoring, backups, access controls, and risk assessments. Answering honestly would have meant writing "no" on nearly every line. That's uncomfortable, but it's also the point: the application surfaces the gaps whether or not the practice ends up covered.

Technology

Remote access with nothing standing between it and the internet. Millbrook had RDP exposed directly on the public IP. Keystone solved Dr. Patel's access problem the fastest way they knew how: no VPN, no Remote Desktop Gateway, nothing between a login prompt and anyone on the internet who found it. A VPN with MFA, $0 to $50 a month, or a Remote Desktop Gateway, built into Windows Server at no extra cost, would have put a layer in front of that server that a stolen password alone couldn't get through. The wrong answer is a direct line from the internet to the server with nothing in between, which is what Millbrook had.

No multi-factor authentication. Not on remote access. Not on email. Not on the EHR. Nowhere. MFA on the remote connection would have made the stolen credentials insufficient on their own. The attacker had a valid username and password. A second factor, whether a push notification, a hardware token, or a one-time code, changes that from an open door to a locked one. Microsoft Entra MFA is included in most Microsoft 365 business plans that practices this size typically already pay for. Duo, a standalone MFA product, starts at $3 per user per month. For 48 people, that's roughly $150 per month. Determined attackers do find ways around MFA, so this is not a guarantee. But it closes the simplest and most common path. The practice spent more than $700,000 because nobody spent $150 a month.

Weak passwords with no policy. No complexity requirements. No expiration. No lockout after failed attempts. A predictable password on a departed employee's account. A password policy enforced at the domain level is a Group Policy setting. It is free. It takes ten minutes to configure. Account lockout after repeated failed attempts would have slowed or stopped the credential stuffing that got the attacker in.

No EDR, no MDR, no monitoring. Basic antivirus on workstations. Nothing on the server. No behavioral detection. No 24/7 monitoring. Nobody watching for lateral movement, unusual logins, or data staging. The attacker operated for six days inside the network without detection. EDR with MDR monitoring for a practice with roughly 50 endpoints, including workstations, the server, and tablets, runs $8 to $15 per endpoint per month, or roughly $400 to $750 per month. A monitored alert on "RDP login from an unfamiliar IP at 9 PM on a Monday to an account that hasn't been used in six months" would have flagged this on Day 0. Detection without response is just a log. The monitoring has to reach a person who acts on it.

Flat network across three locations. No VLANs separating clinical systems from administrative workstations from the server. No firewall rules between segments. Once the attacker was inside, everything was reachable. Segmentation using VLANs, which most business-grade firewalls already support, would have contained the lateral movement and limited what a single compromised account could reach. The hardware to do this was likely already in place. Nobody configured it.

Backups on the same network, on hardware that was never going to protect them. Nightly backups ran to a consumer-grade NAS on the same flat network. When the ransomware deployed, it encrypted the NAS right along with the servers. Immutable backups, files that once written can't be modified or deleted for a set retention period by anyone, including ransomware that gains access to the network, would have stopped that. Most business-grade NAS devices and cloud backup services offer it. The box Keystone installed wasn't one of them, and moving to one that was would have cost real money, not a settings change. Offsite or cloud backup with immutability built in runs $100 to $300 a month for this data volume. That would have been the only surviving, current copy when the NAS went down with everything else.

What the full technology stack costs. VPN or gateway: $0 to $50 per month. MFA: $150 per month. EDR with MDR: $400 to $750 per month. Offsite backup: $100 to $300 per month. Total: roughly $650 to $1,250 per month. The practice was already paying Keystone $4,500 per month for IT that included none of it.

What would have stopped it

Control Monthly cost Where it changes the outcome
VPN or RDS Gateway for remote access $0 to $50 Remote access is no longer directly reachable from the internet
MFA on remote access $150 (48 users) Stolen credentials alone are not sufficient
Account disable on employee departure Free (process) The stale account is not there to be compromised
Password policy with complexity and lockout Free (Group Policy) Credential stuffing is blocked or slowed
EDR with MDR monitoring $400 to $750 (~50 endpoints) Anomalous login flagged and investigated on Day 0
Network segmentation via VLANs Free (config on existing hardware) Lateral movement from the compromised session is contained
Immutable or offsite backups $100 to $300 Recovery uses a current, verified backup instead of starting over from paper
Data governance policy Free (document) Sensitive data is confined, reducing the blast radius of any breach

Two things belong ahead of everything on that table. A risk assessment, $3,000 to $8,000, or an ongoing security advisor or vCISO, $12,000 to $36,000 a year, is what tells a practice which of these gaps matters most and in what order to close them. Cyber insurance, $5,000 to $12,000 a year, doesn't prevent any of this. It funds the response when prevention fails anyway.

No single control is a guarantee. Any two of the technical controls together significantly changes the outcome. Any three, and the attacker is likely looking for an easier target. Millbrook had none.

Millbrook hired a cybersecurity-first MSP afterward and put in all of it: VPN with MFA, EDR with monitoring, offsite immutable backups, segmented networks, quarterly access reviews, a data governance policy, for roughly $900 a month on top of what the practice was already paying Keystone. Behind that number sits $715,000 the practice will not get back, litigation running in both directions for years, patients who moved to a competitor rather than wait and see, and 12,000 people whose records are still for sale to anyone who wants them. The attacker didn't need to be good. The door was open.

What to do tomorrow

Find out what's exposed to the internet, today. One question first: is anything listening on port 3389 on your public IP? If RDP is open to the internet, close it today. Then the broader version: ask your provider to document every way someone can reach your internal network from outside the building. VPN, RDP, remote desktop tools, cloud portals. For each one: is it protected by MFA? Is the firewall current? Are the credentials unique and strong? If your MSP can't answer these questions clearly, that is itself an answer.

Compare active accounts to your employee roster. Ask for a list of every active user account on your domain or in your systems. Compare it to the people who actually work for you today. If there's a name you don't recognize or someone who left months ago, disable the account now. Then build the offboarding checklist so it doesn't happen again.

Ask your MSP what their cybersecurity capability actually is. Then listen to the answer. If it sounds like "we keep things running," that's IT. It's not security. Ask whether they hold a SOC 2 report. Ask who on their staff holds security credentials, and in what discipline. If the answer is vague or defensive, you may need a separate security provider, and that is a common arrangement for organizations this size.

Check your insurance portfolio. If you hold sensitive data and you do not carry cyber insurance, you are self-funding every dollar of your breach response. Talk to your broker. Even if you can't qualify for a policy today, the application will show you exactly where your gaps are.

Discussion questions

  1. If an employee left your organization today, how long would their account stay active? Who is responsible for submitting the disable request? Is that process documented, or does it depend on someone remembering?

  2. How does remote access to your network work? Can you describe every method? Has anyone verified that each one is protected by multi-factor authentication and sits behind a current, properly configured firewall?

  3. Have you read your MSP or IT provider's contract? Does it mention cybersecurity, and if so, what specifically does it cover? If it doesn't, who is responsible for your security posture?

  4. Where does sensitive data live in your organization? Only in your primary system, or also on workstations, shared drives, personal folders, and email? Could you produce a map of where PHI, PII, and financial records are stored if a regulator asked for one?

  5. Do you carry cyber insurance? If yes, when did you last verify that your actual controls match what you attested on the application? If no, what is your plan to fund a breach response?

  6. If everything went down tomorrow morning, who would you call first? Do you have a lawyer who handles breach response? A forensics firm? A notification vendor? If you're assembling that team for the first time during the crisis, you're paying rush rates to people you've never vetted, during the worst week your organization has ever had.

Frequently asked

What is the The Doctor Will See You Now case study about?

A mid-size medical practice lost more than $700,000 and exposed 12,000 patients' protected health information because their IT company built an environment that worked but was never secured. Open RDP. A departed employee's active account. No MFA. No monitoring. No cyber insurance. The attacker didn't need to be good. The door was open.

Is Millbrook Medical Group a real company?

No. Millbrook Medical Group is a fictional company used to illustrate a real attack pattern. The tactics, techniques, and procedures are real and documented; the company, the people, and the specific details are invented.

What would have prevented this?

The case study breaks down what was missing — across people, process, and technology — and the specific compensating controls that would have stopped the attack, including one action to take this week.

Subscribe for new case studies