CyberSecurity Treatment Plan

Dr. Lavine and Alex Nottingham JD MBA discuss how to treat cybersecurity like a dental treatment plan: diagnose first, then act. A proper risk assessment is required by HIPAA and protects your practice from data loss, fines, and shutdowns.

Resources:

About Dr. Lorne Lavine

Dr. Lavine is the Digital Dentist. A former periodontist turned cybersecurity, IT, and HIPPA expert for dental offices, Dr. Lavine lectures and educates globally to keep dentistry safe from all the various cyber threats.

About Alex Nottingham, JD, MBA

Alex is the CEO and Founder of All-Star Dental Academy®. He is a former Tony Robbins top coach and consultant, having worked with companies upwards of $100 million. His passion is to help others create personal wealth and make a positive impact on the people around them. Alex received his Juris Doctor (JD) and Master of Business Administration (MBA) from Florida International University.

Episode Transcript

Transcript performed by A.I. Please excuse the typos.

00:00
not unusual for a practice to lose at least 15 to 20 percent of their patient population almost immediately when that letter goes out. That they lost through a flood and they weren’t able to recover their data and they’re no longer in business because of that. The gist of the whole thing is that that practice was fined $350,000 simply from the fact that they failed to report. I think most practices would agree that that would be pretty devastating. Wow, that uh…

00:29
has gotten my attention.

00:33
This is Dental All-Stars, where we bring you the best in dentistry on marketing, management and training.

00:42
Welcome to Dental All-Stars. I’m Alex Nottingham, founder and CEO of All-Stars Dental Academy. And with me is Dr. Lorne Levine, the digital dentist. And our topic today is cybersecurity treatment plan. Please welcome Lorne. Thanks, Alex. Pleasure to be here. Yes. So for those who do not know who you are, you are the digital dentist. You’re a former periodontist. Just give us a little quick background about who you are and then we’re gonna get right into the…

01:11
cybersecurity treatment stuff. Yeah. So I was a full-time practicing periodontist. I did that for 10 years, which was honestly about nine and a half years too long. I did not love it. Perio is tough as anyone that does Perio is well aware. Growing up, my family owned a large electronics business. So I was always into tech and I basically kind of converted my life from full-time practice. had done my own IT for my own practice and

01:41
started helping other officers of this and turned it into a full-time career and decided, know what, I don’t love Perio and moved out to LA and I’ve been here for close to 25 years. And we work with dental practices all over North America to help them with IT, cybersecurity, HIPAA compliance, anything tech related, that’s what we do. Yes, and we’ve been working with you since the beginnings of All-Star well over 10 years ago.

02:10
I’m almost 15. So I was going, I’ll keep it 10. So I stay. Yeah. I want to age yourself. No, no, but yeah, you’re the best in the business when it comes to cybersecurity. So, and I think, cause we’ve done so many webinars in the past and I liked the idea we talked about in the green room about a treatment plan. And, and so we’re going to get to that, what that looks like, how that comes about. But tell me first, uh,

02:40
How does, this is assuming, the issue we’re exploring in the podcast is once you know your problem, how do you create a cybersecurity treatment plan versus just throwing technology at it and just hoping it works, which a lot of people do. So walk me through first, how does one identify they have a problem in this space? What are they looking for? And then,

03:04
What do we do about it? And what are some of the mistakes where people just throw things at it and how are we gonna do it where it’s an actual treatment plan, which dentists know what that’s all about? Well, I think dentists will also understand the whole concept that it’s hard to develop that treatment plan unless you’ve diagnosed first. Most dentists, when a new patient shows up, they don’t just start treating them. I I hope not. mean, usually it’s an emergency, but normally you’re gonna do your…

03:30
intra-oral and extra-oral exams and restorative charting and imperial probing, x-rays, and based on all of that, you’re gonna put together a treatment plan and start the treatment. And in dentistry, I think we tend to do it the right way in that that treatment plan is normally sequenced, is gonna look at the things that are most pressing, that’s gonna be at the top of the treatment plan and work your way down. A lot of times in IT, least the…

03:56
plans that I’ve seen and we’re just as guilty of this as other IT companies, oftentimes we don’t do that. We throw just a list of things, say here’s all the things and this is how you should address it. So you have to diagnose first. And there are a number of ways of doing it. Whenever we’re talking with an office about working with them, what we always do, we call it a security audit or a technical audit. And it’s that diagnostic, it’s not meant to be a deep dive.

04:23
We’re not spending hours and hours going through every system. We’re doing that 30,000 foot view from above where we want to see what’s going on here. Do they have systems in place? What’s the hardware look like? What’s the software look like? Are they doing the basics? If we’re talking about an office that we’re already working with, we absolutely highly recommend that you do a formal risk assessor.

04:50
If it’s done, and the problem with a risk assessment, with knowing exactly how to do it, is that if you look online, if you look at the actual HIPAA law about, do I, do I need to do a risk assessment? How do I do it? There’s literally one sentence that says you have to do it, and they don’t give you any guidance. There’s a document out there by the National Institute of Standards and Technology, NIS. It’s document 800-30, and it,

05:19
goes through the steps of how to create a risk assessment. It’s unbelievably dry. And if you suffer from insomnia, it’s a great cure for that because it’s 95 pages of just droning on. But any dentist will understand the concept that all that it says is that you need to be comprehensive. And one of my pet peeves is that there are companies out there that’ll say, hey,

05:46
go on to our website or go to this website and take this 10, 15 minute quiz and boom, you’ve done your risk assessment. And having had clients of ours that have gone through HIPAA audits, I’m quite confident that the auditor, if they’re in a good mood, they’ll say, you know, they’ll laugh and say, no, seriously, where’s your real risk assessment? Cause that’s not a risk assessment. When we do it for a client, it takes about seven to eight hours.

06:16
Most of that is done behind the scenes. We have a questionnaire that we’ll go over with the dancers or the office manager, things about the physical layout of the office. Most times we’re not actually going to the office. So we need to know about alarm systems and locks on the door and video surveillance, things like that. But software does most of the work behind the scenes. But when it’s done properly, where we go through that whole process of developing that, doing that risk assessment,

06:46
it will generate their version of a treatment plan called a HIPAA management plan. And it’s, we’re talking about cybersecurity and HIPAA interchangeably. And I think that’s actually a good thing, Alex, because in most cases, you are killing two birds with one stone. The things that you do to get yourself more cyber secure are also going to get you more HIPAA compliant.

07:13
So a lot of times you don’t have to worry about each one individually. Now there’s obviously a number of HIPAA rules that aren’t necessarily related to IT, but one of the things that we always try to tell people is that, listen, we’re gonna be able to knock out a lot of these things and get you as HIPAA compliant as we ideally can. We’ve never and hopefully never will promise an office that we can get you 100 % compliant, because it’s just impossible.

07:40
like seven, 800 pages of rules and regulations. But the whole purpose of that risk assessment is to identify where do you have vulnerabilities in the IT portion of things, on your policies and procedures, on just your behavior. And it’s pretty comprehensive. As I said, we do a network scan. We do what’s called pen testing, penetration testing, to see if we can get through the firewall.

08:10
We inventory the software. You know, we look at things for the HIPAA standpoint. There’s typically three areas of HIPAA. There’s administrative, there’s technical and physical safeguards. We look at all that as well. And, and then we look at the, the roadmap of how we’re going to resolve those. And I had always warned people that just as with patients, it’s not enough to just do a treatment plan. have to actually do the treatment. Same thing here.

08:40
And we’ll talk about the different systems that you probably need to think about incorporating. But just from a labor standpoint, when we do these risk assessments and we have a management plan, it takes at least five to 10 hours of labor to start resolving some of these issues. And they run the gamut from password policies to user accounts of people that are no longer in the practice or encryption or, you know.

09:09
unencrypted thumb drives. mean, the list goes on and on. So it’s really critical that an office understands that this is a HIPAA law. You have to do a risk assessment and have a management plan. It has to be done on a regular basis. We certainly recommend no less than once a year. And, but you also really need to make sure that you follow up because the flip side to that is if, Guy forbid, you’re ever audited.

09:39
And they see that you’ve done this risk assessment, but don’t have anything to show for it. You’ve done it. You’ve got the plan, but you never lifted a finger to actually resolve the issues. Uh, they call that willful neglect. And that’s when you start to see some of these multi hundred thousand million dollar plus fines and settlements, uh, because of the fact that people never did anything about it. So just to clarify, you are required.

10:08
to do risk assessment as a dental office. It is a HIPAA Okay, it’s a HIPAA law. It’s important to understand, because people get a lot of confusion about HIPAA. There are two types of HIPAA rules and regulations. There are required, which is pretty self-explanatory, you gotta do it, and there’s addressable. And there’s some confusion out there about what addressable means. The actual definition of addressable is that you must do it if it’s reasonable and appropriate.

10:37
If it is not reasonable and appropriate, come up with an alternative or document that there is no alternative. And unfortunately, there are some speakers out there that have basically said, is kind of your get out of jail free card. As long as you document that you don’t think it’s reasonable and appropriate, you’re off the hook. The problem with that thought process is that whole concept of reasonable and appropriate.

11:06
Who gets to decide that? Well, initially you do. It’s your practice, you get to decide. The problem is that if you’re ever audited, it’s up to them. And I’ll give you a perfect example. Encryption is a addressable HIPAA concern. It is not required, unlike the risk assessment, which to get to your point that yes, a risk assessment is absolutely required. But encryption, which we’ll talk about in a few minutes, that is addressable.

11:34
The problem is, let’s say that you get audited and you’re trying to explain, well, why you think it is unreasonable and inappropriate to encrypt your data. All versions of Windows Server from 2012 onwards, Windows 10, Windows 11, all of them have a free built-in encryption software called BitLocker. It’s part of the operating system.

12:01
Now, if you don’t know what you’re doing, you should probably hire an IT company to help you actually set it up and configure it. But it’s really hard to make the argument, gee, we don’t think this was really reasonable and appropriate, even though there’s a free program that’s built into our software that all we have to do is flip the switch and it’s in place. So I would be very cautious to offices about not doing the things that are addressable, because it really says you must do it.

12:28
unless it is not reasonable and it’s a hard argument to me. But it’s assessment. Well, I see like two issues here, right? So you have the legislative requirements and whether there’s a workaround or not. And I think dentists tend to be more safe in general, accountants and lawyers too. And then there’s also, happens, forget even just being fined if…

12:57
you get hacked. If you lose your data, what’s going to happen? I had a practice that we talked about before that, um, that they lost through a flood and they weren’t able to recover their data and they’re no longer in business because of that. And so these are like, like silly things, uh, to happen. So, and then I would also suspect that if there is a breach that requires a HIPAA notice or whatever, that that may get to the

13:27
to the regulatory bodies, that what did you do, that you had to do that, did you do the risk assessment, did you have proper stuff? So now it just kind of compounds. So I think, like you said, you could address two birds at the same time. Like, let’s make sure we check off the legal requirements at the same time of protecting. I think…

13:55
for those that are listening and maybe just kind of quickly and then I want to get kind of into what are the different modalities and how to build treatment plan. like what so okay, we got the legislature fine. I got to do it. I don’t to be fine. Okay. But really what can go wrong? It does. Can you give me an overview of the modalities? So you know, you have encryption, you have malware. What are the modalities?

14:22
And what are they protecting you from? And what have you seen happen when it wasn’t installed properly? Um, we’ve seen basically destruction of practices. We have seen, um, people that did not have a proper backup, which will probably be the first thing that we talk about when we go into the individual steps. Cause I think that is unbelievably critical. Uh, we have seen practices lose all their patient information. We have seen practices hit with ransomware.

14:50
where they’re unable to retrieve their patient information, which is basically the same as losing it, and they didn’t have a backup in place. We’ve seen practices who you mentioned a breach. One of the requirements of brief notification is that you have to notify all of your patients in writing of the breach and what data may have been compromised. And usually we’re talking about social security numbers, credit card information, things like that. Not unusual.

15:20
for a practice to lose at least 15 to 20 % of their patient population almost immediately when that letter goes out. it’s, of course there’s the fines and penalties, which can be way up there. There was a recent case in Indiana and I can’t remember the name of it. I think it might’ve been a group practice or a DSO. They were hit with ransomware in 2020, I believe, and lost a lot of data.

15:49
on the patient information when patients were calling, they didn’t report it. And when patients were calling up, just, you know, wanting to get their records transferred for whatever reason, they told them, oh, we’re really sorry. We had a hard drive crash and we can’t recover that information. Well, someone slipped up about two years later in 2022 and someone had called for their information and were told, no, we were hit with ransomware and we lost that information.

16:19
They ended up reporting that to Health and Human Services, Office of Civil Rights. Meanwhile, the gist of the whole thing is that that practice was fined $350,000 simply from the fact that they failed to report. Because if there is a breach, you have a set period of time in order to notify your patients. I think it’s 90 days. It could be 60, but it’s relatively quickly. Two years, it was way beyond.

16:46
So they eventually did send out the notices to patients, but at that point it was too late. So, and I think that was a relatively small fine considering the severity of the problems. whether it’s financial ruin, whether it is patients leaving the practice or literally having no clue who’s coming in the next day, who has outstanding balances because you’ve lost all the data. I think most practices would agree that that would be pretty devastating.

17:16
That has gotten my attention. So, okay. So we see that the, uh, and that’s in anything that we do, what’s the risk in, in, doing it versus not doing it and how likely is it happened? like, unfortunately, this is a dental practice for most dentists is everything. It is their income. is their retirement, uh, or it’s a large portion of it and losing it entirely.

17:44
or having it be damaged so it would take years to recover is not an acceptable risk to take. okay, so now let’s kind of explore, I guess, I don’t know if we’re going to treatment plan or what are the modalities and then maybe even after you go over the modalities, what do people typically, when they’re getting into this IT stuff, what mistake are they making implementing, hence the digital dentist’s cybersecurity treatment plan, essentially.

18:15
Well, I can answer the last question first, which is that, you know, most dentists, most highly trained professionals out there have a fairly high IQ. And there is this belief, I think, among a lot of my peers that they can handle a lot of this on their own. That, listen, this doesn’t seem so hard. I mean, I can find backup software, I can encrypt it, I can get antivirus software. You know, I don’t need someone to hold my hand through this.

18:44
and wear a good IT and a lot of IT companies are what’s called managed service providers or MSPs, which is what we are where the whole approach to IT is to be proactive. We don’t want to be on the receiving end of a call. Hey, I just got hit with a ransomware virus. What do I do? We want to be there at the beginning to say, hey, I never want to go through a ransomware event. What can I do to make sure that that happens?

19:13
So I do think most dentists could probably handle a lot of the things from the setup standpoint that I’m talking about. Some of them are fairly complex and they probably wouldn’t have the skill set. But when the you know what hits the fan, the question is, are you gonna know what to do? And that’s where I think that you’re better off. And I realize that it may sound a little self-serving and I apologize about that. But I think most offices would benefit at least if they’re not gonna.

19:42
have services from an IT provider, at least to consult with someone that can help guide them on the plan. So, usually a treatment plan that we put together for an office might have eight to 10 things on it. And sometimes I’ll modify based on what the client has said to me, just like with patients. A patient comes in, even though you might see something that there’s a bombed out tooth with a

20:11
know, endo involvement and you know it needs to be treated. If that’s not the patient’s chief complaint, if they’re having pain somewhere else, you’re probably going to deal with the chief complaint first. You know, you’ll get to the other one pretty quickly, but you want to at least get them out of pain, get them a place where they’re comfortable so that you can then proceed with the other treatment. If you don’t get that done first, a lot of times they’re just not going to come back and you’ve lost them and they’ve lost the ability to get the treatment that they need. a lot of times I’ll mix this up.

20:41
Um, lot of times someone will say to me, you know, lot of the clients that we get will come to me and say, Hey, I’m reaching out to you because I had a recent incident where we lost data, where we didn’t have a proper backup. And that’s almost always going to be one the first things is that we look at is okay, what are you doing from a, from a backup standpoint? Um, because it’s critical from a, for a dental office is usually too overriding concepts for their backup. Number one.

21:12
how quickly can I get up and running if my server goes down? And number two, how well prepared am I if there’s a real disaster, if the fire or flood or theft or something like that, and I lose everything within my physical office. So, and listen, if you talk to 10 different managed service providers, you’re gonna get 10 different ideas about how to do a backup. What I’ve been advocating for decades now is a two-pronged approach.

21:41
a local backup, which is 99.9 % of the time, that’s what we’re going to restore from because it’s right in the office. This is much faster. The ideal way to set up a backup is to do what’s called an image. It’s basically a snapshot of the entire server, not just the data, but the program files, the network settings, everything. Because what you want to be able to do is to be able to boot up a

22:08
another copy of the server, which is what that image is. And within minutes, as far as the rest of the computers in the office are concerned, the server’s back up and running. It really should be something that you measure in minutes. And we’re going through a process now where we do backup and we’ve been doing it. We’ve got well over 150 clients that we just handle backup for them. And we found that the restore process that should be relatively quickly isn’t as fast as we want it to be.

22:37
that in some cases people that have lots of cone beam images and multiple terabytes, it was taking hours and hours to get that restore done. So we’re going through a process now of evaluating different systems as well. Just like with dentists, you’re constantly evaluating new materials, new techniques, whatever. We do that as well. So you have to have that local backup and it should be something that can be restored quickly, but you have to have something that’s offsite.

23:04
And a lot of offices in the past have used external hard drives. we still, we were not talking out of an office out of doing it. External hard drives work perfectly fine, but most practices just don’t want to have to deal with that. You know, they forget it or it takes a while to run the backup in the evening. And they just, it’s just a pain in the rear to be honest with you. So what we advocate for most offices is a cloud backup on top of the local backup.

23:34
that it’s done automatically, it’s offsite. The critical thing, and again, I apologize if this sounds self-serving, it’s not enough for the software telling you, the backup was successful. That doesn’t necessarily mean it was successful. There’s really only one way to know for sure that your backup has worked, and that is to turn off your server and…

23:59
try to fire up that copy in the office. Can you get that thing up and running within a few minutes? And if that fails, what about the data that’s in the cloud? Can you get that downloaded in a reasonable timeframe? mean, normally you’re not gonna download all those cone beam images, which could be terabytes of data. You just wanna get the practice management software, which is usually three, four, five gigabytes of data, so that you can at least get up and running.

24:24
be able to call patients, tell them there’s a problem at the office, be able to reschedule it as needed. But we highly recommend that you have that two-pronged approach because you want to be able to recover from anything. And normally if ransomware wipes out your local data, I haven’t yet and doesn’t mean it won’t ever happen. We have yet to see a situation where a backup that got hit locally with ransomware

24:54
also then hit the cloud backup. Cause normally what’ll happen is that once the local backup is corrupted, the cloud backup will say, these aren’t the same files. And it’ll stop. It won’t actually, if it’s, if it’s a properly designed backup system, shouldn’t allow you to take corrupted with ransomware type files and back that up to the cloud as well. it seems like you have multiple layers and the backup is the heart of it, I guess. And then you have.

25:23
Um, you have the, you know, antivirus and malware and all that to protect it on one level. You have a local, if that gets corrupted, there’s additional scanning and protection on the, the, the, um, uh, offsite, but as well, even if the local gets corrupted, you have multiple instances before that, before it was corrupted and the same, uh, same thing on the back. So it’s like, there’s so many levels of, of, uh, and in terms of it can’t happen.

25:52
to you, I remember maybe seven, eight years ago, I got a malware or ransomware on mine. And I don’t know if I had a really good backup. So, uh, maybe I had some drop box, but it was over any of that stuff. You couldn’t get back. Uh, and, uh, fortunately I’m not running a dental practice. So that wasn’t devastating, but it, it like, and everything’s getting more and more sophisticated and we have to stick up, stay up with it, uh, with respect to it.

26:19
So, okay, so backup is like the core of the treatment plan. Yeah, backups are kind of like your last line of defense. You had mentioned the things that we think are critical, which is preventing ransomware. We talked about encryption. That’s typically the second thing that we’re going to recommend to an op-ed because it’s so easy for us to implement it. It takes a few hours of labor. We talk about encrypting the server. Any computer that has patient information on it should be encrypted. So encrypted means it’s hard to hack.

26:48
It’s almost, it’s, it’s almost impossible. It depends on the level, but 256 bit encryption SSL. mean, all that stuff. if it’s encrypted, like can a malware get to it or not really? It’s harder for malware to work on encrypted files. Um, but more importantly, it’s hard for anybody else to do anything with those files. If for example, there was a case here in California a number of years ago where somebody had a, um, a server that was stolen and they had to declare a breach.

27:18
because they couldn’t establish the fact that there was any encryption on the server. There wasn’t. If they had encrypted their server, they would be, they’d be out of the woods. That is literally, you do not have to declare a breach in that situation if you have evidence that you have encryption. even if the server failed, it was protected because of- Like let’s say somebody steals a server.

27:48
They go to plug it in. they, go so they want to extract data from it. There is, if it’s encrypted with BitLocker, there is a key. It’s a, I think it’s 40 digits, 48 digits, something like that, that they would have to manually enter in that key in order to be able to access the drives. Now the way that we do it, we make it a little easier for offices because that is a pain, but every time they reboot the server to have to reenter the key is you can also put that key on a thumb drive.

28:17
What you don’t want to do is leave that thumb drive in the server because it completely defeats the purpose. You want to hide it somewhere, take it home or whatever. But, um, if someone did not have that key, that 40 digit key, and then it’s letters and numbers, then they would not be able to access the hard drive. So that’s really what it’s doing is it’s getting you out of that requirement in the brush notification that you would have to actually declare that breach. it sounds like, again, as I’m listening to this, cause I’m a tech guy, I like tech, but

28:48
you have to do it in a sequence because there’s so many issues here, encryption, this, and they all have to work together, sequence properly. And like you said before, I like when you say treatment plan because you want to build a treatment plan that they’re going to actually do and like. If you make it so cumbersome, some people may like that, but some people may want to be more hands off with respect to that. And so that has to be

29:15
That’s the way you think of it. Just like when a practice is thinking about changing everything, they want to get new practice management software, they’re thinking about getting new digital x-ray system, maybe third party programs, we would never recommend that they do it all at once. Some offices are still putting progress notes in physical charts, so let’s start with that and then…

29:37
We’ll talk about maybe changing, adding this to the software, offices trying to get charters or paperless. You can’t do it all in one day. Oh, I see. So you recommend it, and I assume this is what you do at the digital dentist, is that you do it and you build the treatment plan. It doesn’t have to be done all at once. We take care of a cheap complaint and the major issues, and you can add these as you go along? We do both. So our recommendation, because everything that we do has an associated hip a lot.

30:06
They’re not really optional and they’re all addressing risk. So our ideal client is one that says, yes, I understand the need for this. I want to get a package of services from you. Go ahead and do what you need to do. Get it all settled. That’s what I would do. Which is what most people would do. We do have some other clients, whether there are some financial limitations, whether we haven’t earned their trust quite yet, whether there’s other issues.

30:34
that they’ll say, Hey, you know, I know I need to do all these things. Um, I want to start with two or three. So what are the two or three that you think I should really focus on it first? And then as we get more comfortable, um, then we can add the other ones and that’s fine. We don’t want to turn a client away just because they rather do things in stages. So, um, so we talked about, you know, the need for the backup to, to that’s kind of like your last line of defense, but

31:03
A lot of what we would do if someone came to us and said, Hey, you know, I only can do one or two things right now. What should I do besides encryption, which is relatively easy. And all of that would be geared towards ransomware prevention. Um, there’s basically three or four parts to that puzzle. And it usually starts with a firewall. Most offices do not have a proper firewall in place.

31:33
A firewall is a device and it can be software and it can be built into a router, but we normally recommend a business class firewall. There’s companies like Sophos and Sonicwild and WatchGuard that are designed specifically for dental practices. That is your first line of defense. Most of the better firewalls out there will actually have anti-virus, anti-ransomware protection built into the firewalls. Like a subscription, pay a couple hundred bucks a year for that.

32:01
So we would always recommend that as the first line of defense. Nothing’s going to be a hundred percent, you know, effective that there’s new virus that come in all the time. So we would always recommend that you have some type of antivirus anti ransomware in place software. And there’s a lot of good companies out there. don’t have a strong preference. We usually use one from Sophos called Intercept X. There’s Hitman Pro there’s

32:31
Kaspersky, which I don’t think you can get anymore because it’s from Russia. Trend Micro. mean, there’s a lot of, the basic rule of thumb is that the free programs really aren’t as good as the ones that you end up paying 30, 40 bucks a computer a year. A third area of vulnerability is the operating system. Every version of Windows, they are finding security holes in them on an almost daily basis.

33:00
and they’re constantly releasing patches. And it’s critical that you keep up with those patches. We call patch method. It’s actually another hip a lot that people may not know about is that you have to keep everything current. That is why maybe a lot of you who may have been heard hearing from your IT company over the last few months, Microsoft is ending support and security patches for Windows 10 and for server 2016.

33:27
this October the 14th. So October 14th, 2025, there won’t be any further future security patches for those versions of Windows. By definition, you’re no longer going to be in compliance with HIPAA, not to mention the fact that you’re not going to be secure because you’re not patching it. know, those security holes are still going to be discovered and they’re going to be, they’re going to be, you know, hit by, by, by viruses. The problem with everything that I talked about,

33:56
firewalls, patching, antivirus software is that a lot of the new ransomware that we’ve seen out there are what’s called zero day. And there’s different definitions of zero day. The easiest way to understand zero day is that it’s so new that your antivirus, your software in the firewall doesn’t know that it’s a virus. doesn’t know what to do with it and it can get through. So

34:25
A number of years ago, there’s a special type of software that was developed called application whitelisting. And we started recommending this for our clients about four or five years ago. And this is like a real game changer. Now I would say if someone has an extremely limited budget, but they’re only going to do one thing, it would be to get this type of software, the application whitelisting. The way that that works is that we create a database on your network of all the good programs. And we compare that we have about 350 active clients. We had this.

34:54
Massive global database of all the good programs that are out there. And at a certain point we flip a switch. Only those programs are allowed to run. If a program tries to run and it’s not on that approved list, it gets stopped in its tracks. can’t do what it’s supposed to do. All viruses, all ransomware are just tiny little programs. Just a series of instructions that tells them what to do. In the

35:23
five years or so that we’ve been doing application whitelisting for our clients, we have yet to see a single office get hit with a virus, which is not something I could have said before then. And those were offices that have antivirus. So what I’m hearing is there, there’s, and this is the tip of the iceberg. There’s a lot of, well, it’s giving a broad brush, but there’s a lot of areas and ways you can go. And I think that that is why part of the purpose of talking about this is it’s best to get

35:52
an assessment or an evaluation. And I know you guys do it. And I think because if they’re maybe you give a code where you get a discount, I think you do for us at All Star or free assessment. It’s free for anyone that’s listening to this. We only charge for it, but we’ll do it free for any of your listeners. Just mention All Star. You go to the digitaldentist.com say, Hey, I listened to the podcast. I heard from All Star and I want to know like an evaluation. Where am I? What can we do?

36:20
and like customize it for you and build a cybersecurity treatment plan and then start to work towards it. Because I’m listening, again, I know technology and it’s overwhelming. Imagine a dentist hearing, well, what do I do? And on top of that, there’s a pressure that if I don’t do it right to the standard, not only am I in trouble with my practice, but on top of that, I could get violations that can be devastating. again, I…

36:51
I can’t recommend more. Free stuff is always good. I’m a frugal guy. I like free stuff. I just went shopping for the first time. Every five years I go shopping. My wife is better dressed so she’ll buy me things, but when I find one place, that’s it. Every five years. But again, the point with frugality is you don’t want to step over dollars to get pennies. You don’t want to have

37:18
When it comes to business and protection and things like this, I spare no expense and those that are listening should not. It’s good to be, be smart, but don’t be stupid. Don’t be stupid. Right. With that. Um, so forget frugality versus being cheap, uh, as a business person, uh, that’s very critical. All right. So the digital dentist.com.

37:41
Uh, for, and what do you call this? It’s called an invite. What do you call it? asked me for the website for, um, if you go to the website, there’ll be like a contact. Uh, so I want to, you know, I, you know, I want an evaluation. There’s different things on the website, but they all take you to the same place for us. get an email that’ll tell us that you reached out. We call it a security audit or a technical audit. All right. That’s cool. takes 20, 30 minutes. We hop onto your network with your permission. Obviously you can watch what we do. We run some tests. We ask you some questions.

38:11
And afterwards, so what usually is one of my technicians to do that, because I’ve got a trained technical team for that. Afterwards, we would set up a phone call with you and me personally. And I will go through, here’s what we found. Here is our treatment plan of recommendations. Here’s all the different options. Here’s what the different options would cost. As you know, Alex, and any clients that have worked with me know, this is not a hard sell. I’m here to educate. I’m here to let people know.

38:40
Yes, of course, we would love to work with you. We can help you with this process. But at the end of the day, it’s your practice, your money. All I can do is make the recommendations and help guide you. And of course, whatever you decide, you know, listen, we’re going to always recommend that full suite to cover all your bases. But we don’t look down on people to say, you know what, I just wanted you back up and ransomware protection now and I’ll deal with the other things afterwards. Fine. We’ll set that up. And when you’re ready to proceed, we’re ready to proceed. would say

39:09
The digital dentist, uh, because I worked with you so long is the standard in the industry. So if you’re shopping around or whatever, make sure you get the standard. You talk to the ones that are leading here in dentistry is Dr. Lauren Levine’s company, the digital dentist. Make sure you do that. It’s free. Can’t go wrong. So I recommend you do that. Um, and awesome. And, and it’s been a while and hopefully we’ll have you on our goals to have the good doctor, the good digital dentist on.

39:39
So if you have any questions or you have suggestions for topics, let me know because this gentleman is an endless source of knowledge on this area and we can talk about it and make sure we cover it. I think we’ve done stuff on AI and others, so please let us know allstartdentalacademy.com and then we have contact forms too. says, podcast. I want to hear for this. That’s all. Wonderful.

40:06
Again, thank you for joining us, Dr. Loren Levine. And please remember to follow us on Apple Podcasts, Spotify, YouTube, get the episodes as they are released, share with your friends. And until next time, go out there and be an All-Star.

40:24
We hope you enjoyed this episode of Dental All-Stars. Visit us online at AllStarDentalAcademy.com

Questions? We would love to connect with you!

Questions? We would love to connect with you!