Your IT Guy Is Not Your Cybersecurity: The Dental HIPAA Wake-Up Call
Here is the uncomfortable truth most consultants won’t say out loud: your IT guy is not your cybersecurity. He hooks up your printers, keeps EagleSoft running, and swaps a hard drive when one dies. That is a completely different skill set from defending a database full of Social Security numbers, insurance IDs, and clinical histories that criminals will pay real money for. And in 2023, when a chain with more than 1,000 locations got its scheduling systems, phones, and business applications shut down by a cyberattack, the excuse “my IT has it handled” officially stopped being a strategy.
On the Bulletproof Dental Practice podcast, Pete Boulden sat down with a former Secret Service officer — a man who was personally caught in a government breach that exposed 22.1 million records — to break down exactly how practices get hit and what actually protects them. This article is built on that conversation. No fear-selling, no product to push. Just the playbook.
Why would a hacker target a dental practice instead of a bank?
Because you are softer, and your data is worth more than you think. A dental record is a stacked hand: name, date of birth, address, Social Security number, insurance credentials, sometimes payment cards — all in one file. A stolen credit card gets cancelled in an hour. A medical identity does not. That is why healthcare climbed onto the list of the most-targeted small-business sectors, landing at roughly number four.
Pete has said it plainly on the show: a dental office is a far richer target than a hair salon or a car dealership. You hold more valuable information, and your business is built on protecting it — which means a criminal knows you will pay to get it back. That combination is catnip for ransomware crews. The industry runs about five years behind mainstream small business on security, and the attackers know that too.
What is “human hacking” and why is it the real threat?
Everyone pictures a hacker as a hoodie behind a keyboard in another country, hammering your firewall for months with no guarantee of getting in. That is the expensive, hard way. The cheap, reliable way is human hacking — social engineering — and estimates in the episode put it on track to represent the overwhelming majority of business breaches.
Here is how the guest described the attack, step by step, and it should chill every owner:
- The attacker books an appointment as a new patient and quietly scouts your front office.
- They identify the one team member — call her Mary — who has the system access they need.
- They mine her public social media. Not for blackmail — for connection. They notice she volunteers at an animal shelter.
- They engineer a warm, friendly interaction around that shared “passion,” then hand her a USB drive.
- Mary plugs it in. Nothing crashes. Nothing sparks. It looks broken, so she pops it out and moves on.
That is it. No firewall was breached because no firewall was involved. Every antivirus subscription and every Norton license in the building is now irrelevant, because the attacker walked straight past the technology and manipulated a human being. And there is no smoking gun — no alert, no crashed computer. The pipeline is open and silently feeding data out, and you may never know it happened.
Isn’t my antivirus and firewall enough?
No — and this is the mental shift that matters. Firewalls leave breadcrumbs: if someone attacks your perimeter and you have real cybersecurity monitoring running alongside IT, you get notified — what country, what actor, what attempt. The human route leaves no breadcrumbs at all. That is precisely why sophisticated actors are moving to it. Software got better at the perimeter, so the attackers stopped attacking the perimeter and started attacking your people.
As Pete admits on the episode, even he — an owner who scrutinizes every “who is this from” field — nearly fell for a near-perfect Google impersonation email where the address and branding were flawless. If it can almost get the tech-forward host of a dental podcast, it will get your busy front desk on a Tuesday morning.
What should a dental owner actually do this week?
Pete pushed the guest hard for practical, non-paranoid steps. Here is the tactical stack that came out of it — none of it requires a five-figure contract:
- Run a dark-web check today. A free monitoring tool (the guest keeps one.google.com open as a permanent browser tab) will show you which of your credentials are already exposed. Live on the episode, Pete ran it and surfaced 61 data breaches tied to his own imported information in seconds. Assume you are already compromised, because the odds say you are.
- Buy a baseline audit — not a contract. A one-time cybersecurity audit runs around $1,500 and tells you whether you are under attack right now. Do not sign a year-long deal out of fear. Get the baseline, then decide.
- Separate cybersecurity from IT — on paper. Write an actual protocol. Do not delegate this to the same vendor who manages your servers and holds your GoDaddy and Google Business logins. Knowing IT and knowing cybersecurity is like speaking Spanish and speaking Mandarin — related, not the same.
- Train the humans, bluntly. One rule, said out loud in a team meeting: if a “rando” hands you a USB drive, it does not go in a company computer. If you are not 1,000% sure of a sender, the attachment does not get clicked. Obvious? Yes. Skipped constantly? Also yes.
- Freeze your personal credit. All three bureaus let you freeze for free. Do it for yourself, your spouse, and your kids. It costs nothing and it is the single best defense against the identity theft that follows a breach.
- Consider the cloud. Moving your practice-management software off local servers shifts a large chunk of the infrastructure-security burden onto a vendor whose entire business is protecting it. It does nothing against human hacking — but it shrinks your technical attack surface.
Where does HIPAA fit into all of this?
HIPAA is the floor, not the ceiling. Remember when HIPAA landed and practices realized a violation could cost six figures? That is the compliance frame most owners still live in — spend the minimum, check the box, move on. Cybersecurity is a different animal because the threat is active and adaptive. There is real movement at the federal level toward a dedicated annual cybersecurity certification for healthcare, distinct from IT and distinct from your current HIPAA training. Owners who treat security as a living protocol instead of a once-a-year checkbox will be the ones still standing when the certification lands.
The Bulletproof read: this is a leadership problem, not an IT ticket
Here is where Craig Spodak’s side of the house matters. Bulletproof is built on transparency and trust with your team — sharing numbers, building people up, refusing to run a practice on suspicion. Cybersecurity can pull you the other way, into paranoia, into locking everyone out, into treating your own team as the threat. The answer is not fewer trusted people. It is better-trained, better-led people who understand why a USB drive from a stranger is a loaded weapon. You protect the practice by building a culture sharp enough to spot the con — not by turning the office into a bunker.
Dentistry is hard enough. You already carry the clinical load, the team, the equipment, the risk of the building. Now cybersecurity gets bolted on too. You should not carry that alone — and the whole reason Bulletproof exists is that you don’t have to. This is exactly the kind of blindside the best owners in the country war-game together before it ever hits their office.
That is what happens inside our world. At Bulletproof Summit, owners trade the real playbooks — the systems, the vendors, the mistakes — so you learn from someone else’s breach instead of your own. Inside the Bulletproof Mastermind, you get a room full of growth-minded owners who pressure-test your defenses and your decisions, month after month. Dentistry does not have to be a lonely profession, and you do not have to face the next threat by yourself.
The best is yet to come — but only for the owners who lock the doors before someone else finds them open.
The 1% of dentists, who want 100% from life.
Blog
1+1=3 The Power Of Alignment and Delegation For You and Your OM with Erika Pusillo
, October 31, 2024
Look at These 3 Stats if You’re Thinking of Going Out of Network with Teresa Duncan
, January 11, 2023
Knowing What You Don’t Want with Judy Kay Mausolf of Culture Camp and Erika Pusillo
, November 30, 2022
Cabo This Week, Immersion Learning, Biggest Breakthroughs, Your Personal KPI is Net Worth
, November 2, 2022
Business is not Productivity, Productivity is not Profitability with Chris Salierno
, September 22, 2021
3 Biggest Bottlenecks of an Entrepreneurial Dentist: PART 2 with Perrin DesPortes of TUSK Partners


















































































































































































































