Oct 11, 2026

News

Securing the Next 250: What This Year's Cybersecurity Theme Means for Your Practice

Every October, cybersecurity people put on their favorite "there are two types of people" meme and remind everyone that passwords shouldn't be your pet's name. This year's official theme from CISA and the National Cybersecurity Alliance is "Securing the Next 250," tied to America's 250th anniversary, and underneath the branding is a genuinely useful point: the basics that protected the last 250 years don't automatically protect the next 250 days of your practice's patient data.

We're not here to pile onto the "cybersecurity is scary" stack this month. You've heard that part already. What's actually useful is what the data says is still going wrong at practices just like yours, and the short list of things that fix most of it.

What Actually Changed (Or Didn't)

A recent Software Advice survey of healthcare providers found that 22% of small medical practices have experienced a ransomware attack, and that number has climbed over the past three years. Large hospital systems get hit more often in raw terms (45%), but they also have IT departments, dedicated budgets, and an incident response plan sitting in a drawer somewhere. Small practices mostly don't: the same survey found close to half of small medical practices have no formal cyberattack response plan at all. Not a bad plan. No plan.

That gap is exactly why small practices get targeted, not despite being small, but because of it. Attackers aren't picking hospitals because they're prestigious targets. They're picking whoever is easiest to get into, and a five-person practice running on whatever software was installed five years ago is usually the easier door, the IT equivalent of a locked front gate with the side door propped open.

Why This Actually Matters

None of this is about scaring you into buying something. It's about one uncomfortable but fixable truth: most practices that get hit weren't unlucky, they were unprepared in a specific, nameable way. Reused passwords. No MFA on email. A staff member who clicked a link because it looked exactly like a real vendor invoice, because it was designed to.

That last one is getting harder to catch, not easier. Phishing emails used to give themselves away with bad grammar and a sender address that was obviously wrong. The newer ones are written cleanly, timed around real billing cycles, and sometimes reference details scraped from a practice's own public website. "Just look for typos" stopped being reliable advice a while ago, which is exactly why the fix isn't "try harder to spot it." The fix is MFA, so a clicked link doesn't automatically become a compromised account.

What This Means If You're a South Florida Practice

If you're running a small medical office in Palm Beach, Broward, or Miami-Dade, you're sitting in the exact profile attackers like: real patient data worth something on the black market, HIPAA obligations that make a breach expensive before the ransom demand even shows up, and historically thinner IT budgets than the hospital system down the road. None of that is a reason to panic. It's a reason to spend twenty minutes this month actually checking the basics instead of assuming someone already did.

Cybersecurity Awareness Month is a decent forcing function for that, even if the branding is a little much. Use the nudge. Skip the lecture.

Practical Takeaways

A few things worth doing before October runs out, none of which require a committee meeting:

  • Turn on MFA everywhere it's available, especially email and your EHR. This one change blocks the overwhelming majority of account-takeover attempts, and takes less time than reading this sentence did.

  • Write down, or have us write down, an actual response plan: who gets called first, what gets shut off, who notifies patients. Having this before an incident is the difference between a bad day and a bad year.

  • Run a real phishing test on your staff, not a lecture, an actual simulated email. You'll learn more from one test than from a year of reminders.

  • Check when your software was last updated. If the honest answer is "I don't know," that's the answer that matters most this month.

  • If you don't have a written HIPAA risk assessment on file, that's the single highest-leverage thing to fix before the month ends.

None of this requires a 250-year plan. It requires about an hour, and knowing which hour matters. If you want help finding that hour, that's what we're here for.

Get expert clarity

Frequently asked questions

Can my staff use the free version of ChatGPT or Claude at work?

Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.

What is a BAA and why does it matter for AI tools?

A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.

Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?

No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.

What should our practice do before letting staff use AI with patient information?

Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.

How does UpsiteGroup help with this?

We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence