Your IT Guy Is Not Your Cybersecurity: The Dental HIPAA Wake-Up Call

Here is the uncomfortable truth most consultants won’t say out loud: your IT guy is not your cybersecurity. He hooks up your printers, keeps EagleSoft running, and swaps a hard drive when one dies. That is a completely different skill set from defending a database full of Social Security numbers, insurance IDs, and clinical histories that criminals will pay real money for. And in 2023, when a chain with more than 1,000 locations got its scheduling systems, phones, and business applications shut down by a cyberattack, the excuse “my IT has it handled” officially stopped being a strategy.

On the Bulletproof Dental Practice podcast, Pete Boulden sat down with a former Secret Service officer — a man who was personally caught in a government breach that exposed 22.1 million records — to break down exactly how practices get hit and what actually protects them. This article is built on that conversation. No fear-selling, no product to push. Just the playbook.

Why would a hacker target a dental practice instead of a bank?

Because you are softer, and your data is worth more than you think. A dental record is a stacked hand: name, date of birth, address, Social Security number, insurance credentials, sometimes payment cards — all in one file. A stolen credit card gets cancelled in an hour. A medical identity does not. That is why healthcare climbed onto the list of the most-targeted small-business sectors, landing at roughly number four.

Pete has said it plainly on the show: a dental office is a far richer target than a hair salon or a car dealership. You hold more valuable information, and your business is built on protecting it — which means a criminal knows you will pay to get it back. That combination is catnip for ransomware crews. The industry runs about five years behind mainstream small business on security, and the attackers know that too.

What is “human hacking” and why is it the real threat?

Everyone pictures a hacker as a hoodie behind a keyboard in another country, hammering your firewall for months with no guarantee of getting in. That is the expensive, hard way. The cheap, reliable way is human hacking — social engineering — and estimates in the episode put it on track to represent the overwhelming majority of business breaches.

Here is how the guest described the attack, step by step, and it should chill every owner:

  • The attacker books an appointment as a new patient and quietly scouts your front office.
  • They identify the one team member — call her Mary — who has the system access they need.
  • They mine her public social media. Not for blackmail — for connection. They notice she volunteers at an animal shelter.
  • They engineer a warm, friendly interaction around that shared “passion,” then hand her a USB drive.
  • Mary plugs it in. Nothing crashes. Nothing sparks. It looks broken, so she pops it out and moves on.

That is it. No firewall was breached because no firewall was involved. Every antivirus subscription and every Norton license in the building is now irrelevant, because the attacker walked straight past the technology and manipulated a human being. And there is no smoking gun — no alert, no crashed computer. The pipeline is open and silently feeding data out, and you may never know it happened.

Isn’t my antivirus and firewall enough?

No — and this is the mental shift that matters. Firewalls leave breadcrumbs: if someone attacks your perimeter and you have real cybersecurity monitoring running alongside IT, you get notified — what country, what actor, what attempt. The human route leaves no breadcrumbs at all. That is precisely why sophisticated actors are moving to it. Software got better at the perimeter, so the attackers stopped attacking the perimeter and started attacking your people.

As Pete admits on the episode, even he — an owner who scrutinizes every “who is this from” field — nearly fell for a near-perfect Google impersonation email where the address and branding were flawless. If it can almost get the tech-forward host of a dental podcast, it will get your busy front desk on a Tuesday morning.

What should a dental owner actually do this week?

Pete pushed the guest hard for practical, non-paranoid steps. Here is the tactical stack that came out of it — none of it requires a five-figure contract:

  • Run a dark-web check today. A free monitoring tool (the guest keeps one.google.com open as a permanent browser tab) will show you which of your credentials are already exposed. Live on the episode, Pete ran it and surfaced 61 data breaches tied to his own imported information in seconds. Assume you are already compromised, because the odds say you are.
  • Buy a baseline audit — not a contract. A one-time cybersecurity audit runs around $1,500 and tells you whether you are under attack right now. Do not sign a year-long deal out of fear. Get the baseline, then decide.
  • Separate cybersecurity from IT — on paper. Write an actual protocol. Do not delegate this to the same vendor who manages your servers and holds your GoDaddy and Google Business logins. Knowing IT and knowing cybersecurity is like speaking Spanish and speaking Mandarin — related, not the same.
  • Train the humans, bluntly. One rule, said out loud in a team meeting: if a “rando” hands you a USB drive, it does not go in a company computer. If you are not 1,000% sure of a sender, the attachment does not get clicked. Obvious? Yes. Skipped constantly? Also yes.
  • Freeze your personal credit. All three bureaus let you freeze for free. Do it for yourself, your spouse, and your kids. It costs nothing and it is the single best defense against the identity theft that follows a breach.
  • Consider the cloud. Moving your practice-management software off local servers shifts a large chunk of the infrastructure-security burden onto a vendor whose entire business is protecting it. It does nothing against human hacking — but it shrinks your technical attack surface.

Where does HIPAA fit into all of this?

HIPAA is the floor, not the ceiling. Remember when HIPAA landed and practices realized a violation could cost six figures? That is the compliance frame most owners still live in — spend the minimum, check the box, move on. Cybersecurity is a different animal because the threat is active and adaptive. There is real movement at the federal level toward a dedicated annual cybersecurity certification for healthcare, distinct from IT and distinct from your current HIPAA training. Owners who treat security as a living protocol instead of a once-a-year checkbox will be the ones still standing when the certification lands.

The Bulletproof read: this is a leadership problem, not an IT ticket

Here is where Craig Spodak’s side of the house matters. Bulletproof is built on transparency and trust with your team — sharing numbers, building people up, refusing to run a practice on suspicion. Cybersecurity can pull you the other way, into paranoia, into locking everyone out, into treating your own team as the threat. The answer is not fewer trusted people. It is better-trained, better-led people who understand why a USB drive from a stranger is a loaded weapon. You protect the practice by building a culture sharp enough to spot the con — not by turning the office into a bunker.

Dentistry is hard enough. You already carry the clinical load, the team, the equipment, the risk of the building. Now cybersecurity gets bolted on too. You should not carry that alone — and the whole reason Bulletproof exists is that you don’t have to. This is exactly the kind of blindside the best owners in the country war-game together before it ever hits their office.

That is what happens inside our world. At Bulletproof Summit, owners trade the real playbooks — the systems, the vendors, the mistakes — so you learn from someone else’s breach instead of your own. Inside the Bulletproof Mastermind, you get a room full of growth-minded owners who pressure-test your defenses and your decisions, month after month. Dentistry does not have to be a lonely profession, and you do not have to face the next threat by yourself.

The best is yet to come — but only for the owners who lock the doors before someone else finds them open.

The 1% of dentists, who want 100% from life.

Blog

The Outsourced Team Member

, February 26, 2026

What if Elon ran your practice?

, February 5, 2026

New Year Reflections and Goals

, January 8, 2026

Getting Out of the Chair

, December 4, 2025

EOS + BULLETPROOF PATHWAY

, October 16, 2025

Revolutionizing Dental Care

, October 9, 2025

Packard’s Law

, September 26, 2025

BECOME UNF**KWITHABLE

, April 10, 2025

Invest Like the Rich

, March 27, 2025

HOW TO BOOST CASE ACCEPTANCE

, February 6, 2025

Do These Before End of Year

, December 17, 2024

State of Dentistry

, May 2, 2024

Who’s Got the Monkey

, April 17, 2024

Enrolling More Dentistry

, April 17, 2024

Freedom of Direction

, March 8, 2023

ALWAYS BE RECRUITING

, November 23, 2022

Bulletproof Storytime

, May 18, 2022

Mastermind Announcement

, May 14, 2022

Reduce the Friction

, March 30, 2022

Heroin and a Salary

, December 22, 2021

How it Started, How it’s Going

, December 10, 2021

All things Real Estate – Part 2

, November 24, 2021

All Things Real Estate – Part 1

, November 17, 2021

How To Talk To Your Team

, November 3, 2021

Your Revenue Doesn’t Matter

, October 21, 2021

Fortune Rewards the Bold

, September 15, 2021

Summit Wrap Up 2021

, July 28, 2021

Debt Repayment Methods

, June 16, 2021

Bottlenecks to Revenue

, June 9, 2021

The Bulletproof Pathway

, March 17, 2021

Comfort Zone & Lifestyle Creep

, February 17, 2021

1 VS. 5 Locations

, February 10, 2021

Team Alignment is EVERYTHING

, February 3, 2021

Work As Hard As You Can

, December 9, 2020

Becoming a Thoroughbred

, November 27, 2020

Dealing with Upset Patients

, October 22, 2020

Team Compensation Negotiations

, September 17, 2020

The Risk of Burnout

, September 9, 2020

When to Expand

, August 27, 2020

Don’t Blow Your Ask

, July 16, 2020

Your Last Dance

, June 2, 2020

Looking for Silver Linings

, April 7, 2020

HR Answers in a Corona World

, March 19, 2020

The Summit Recap

, March 3, 2020

Dr. Baird is BAAACK!

, February 20, 2020

The Insurance Conundrum

, January 9, 2020

2020: Your BEST Decade Yet

, January 2, 2020

Leadership with Dr. Jenny Perna

, December 19, 2019

Smartest in the Room

, September 19, 2019