Duplin: 910-463-4299 / New Hanover: 910-815-0900

IT Blog

A hooded figure sits in front of a keyboard in a dark setting, with hands hovering over the keys, creating an abstract, glitch-like effect in vibrant blue and red tones.
Cyber Security Updates

Why Therapists Are Now a Top Target for Cybercriminals (And What To Do About It)

Meta: Therapy practices are now prime targets for cybercriminals, patient session notes, mental health diagnoses, and psychological histories are among the most valuable stolen records on the dark web. Learn why your practice is at risk and the concrete cybersecurity steps you must take to protect your patients, your reputation, and your business.

Why Therapists Are Now a Top Target for Cybercriminals (And What To Do About It)

Banks and big-box retailers dominate the breach headlines, but those organizations also have dedicated security teams, compliance budgets, and years of hardening behind them. Attackers noticed. Over the past several years, cybercriminals have been moving downmarket, toward smaller, less-defended targets that still hold data worth stealing.

The therapeutic relationship depends entirely on confidentiality, which is precisely what makes a breach so damaging, and so profitable for criminals. Hackers see the diagnoses, trauma histories, medication records, and session notes stored in a therapy practice as a digital goldmine, and for good reason: that data is permanent. Unlike a stolen credit card number that a bank can cancel in minutes, psychological records and therapy session notes can never be changed or reissued. The rise of telehealth and digital record-keeping has made the exposure worse. Every video platform, cloud-based EHR system, and digital intake form is another potential entry point, and the opportunity for data breaches, ransomware, and social engineering schemes has grown with each one added.

Knowing why your practice is a target is the first step toward securing it. What follows is a breakdown of the specific vulnerabilities that make therapy offices attractive to attackers, and the concrete steps that actually close those gaps.

Why Are Therapists Targeted?

Many therapists assume their practice is too small to interest serious hackers. It’s a logical assumption, but a dangerous one. Cybercriminals don’t pick targets based on size, they pick them based on the ratio of potential reward to effort required. A solo practice or small group office is frequently easier to compromise than an enterprise network with a security operations center, and the payoff is still real: patient records fetch premium prices, ransomware payments from a panicked solo practitioner are quicker to collect, and blackmail leverage doesn’t need to come from a Fortune 500 breach. Small practices are targeted precisely because they’re vulnerable, and because they rarely detect an intrusion until serious damage is already done.

1. The High Value of Protected Health Information

A stolen credit card number is a problem a bank can fix in under an hour. A stolen mental health record is an entirely different matter. Medical histories, psychological evaluations, and therapy session notes can never be cancelled or reissued, they stay sensitive for life. That permanence is what drives demand. Protected Health Information (PHI) routinely commands far higher prices on dark web markets than payment card data, according to cybersecurity researchers who monitor these exchanges. Criminals use PHI in several ways: committing identity theft with authentic health credentials, building highly convincing targeted phishing schemes using a patient’s own medical history, or going after patients directly with threats of exposure unless they pay extortion fees. The blackmail angle lands especially hard in mental health, patients dealing with stigma around their diagnosis are often far more willing to pay quietly than to risk having that information made public.

2. Smaller Budgets and Limited IT Resources

Most therapy practices, solo offices and small group practices alike, don’t have a dedicated IT department. That’s not a flaw in the business model; it’s simply the reality of running a small clinical operation. But it’s also exactly what cybercriminals count on. A hacker probing a private practice isn’t up against enterprise-grade firewalls, intrusion detection systems, or regular security audits, the layered defenses that make hospital networks comparatively hard targets. They’re often facing a router still running factory-default credentials, software that hasn’t been patched in months, and staff who have never sat through a phishing awareness training. That gap between the value of the data and the quality of the defenses is what makes small practices easy prey.

3. The Shift to Telehealth and Hybrid Care

Telehealth has genuinely improved access to mental health care, fewer no-shows, less geographic friction, reduced stigma around walking into an office. But the rapid adoption of online therapy has also expanded the attack surface for cybercriminals considerably. Personal devices used for sessions, unencrypted video software that isn’t HIPAA-compliant, client communications sent over standard email or unencrypted SMS, and weak home Wi-Fi networks all create security gaps that hackers can exploit to reach your client database. A determined attacker doesn’t need to defeat a sophisticated firewall when a therapist is conducting sessions from a home network still running its factory-default password with no VPN in place.

What Therapy Practices Can Do To Protect Themselves

Relying on basic antivirus software made sense when the main risk was an accidental malware download. That threat model is obsolete. Today’s attackers use phishing emails engineered to clear spam filters, ransomware that encrypts an entire file system before a single alert fires, and social engineering tactics that need no technical vulnerability at all, just a staff member who didn’t recognize a spoofed sender address. Safeguarding patient privacy and your professional reputation now requires layered defenses, not a single tool. Here are the practical steps that will actually move the needle.

Implement Multi-Factor Authentication (MFA)

Multi-factor authentication (MFA) is one of the most effective account defenses available, and on most platforms it costs nothing to enable. A stolen password alone won’t get an attacker in, they also need the second factor, whether that’s a time-based code, or a physical hardware key. Enable MFA on every system that touches patient data: your email, your EHR platform (SimplePractice and TherapyNotes both support it natively), and your billing software. If MFA is available and you haven’t turned it on, a phishing attack on any one of your staff members is all it takes to hand over full access.

Use Dedicated HIPAA-Compliant Systems

Personal Gmail, standard Zoom, and FaceTime weren’t built for healthcare, using them to send or store protected health information (PHI) puts you in direct violation of HIPAA. Purpose-built alternatives exist for every category: email services, EHR platforms, and video platforms all include the safeguards federal law requires. Before you activate any software that will touch patient data, get a signed Business Associate Agreement (BAA) from the vendor. That contract legally obligates them to protect your patients’ information, and without it, you bear the full liability for any breach, regardless of where the failure originated.

Secure Your Networks and Devices

Every device that accesses patient records should be encrypted, BitLocker on Windows machines, FileVault on Macs, and the built-in device encryption on iOS and Android phones and tablets. For remote work, require a VPN: it encrypts the connection between your staff’s home or coffee-shop network and your systems, blocking interception on networks you don’t control. Your office Wi-Fi should run on WPA3 if your router supports it, and your guest network must sit on a completely separate SSID, never the same one your computers use to reach patient records.

Conduct Regular Employee Training

Verizon’s annual Data Breach Investigations Report consistently identifies human error as a leading factor in data breaches across industries, and therapy offices are no exception. Your front desk staff and billing coordinators need to know what a healthcare-targeted phishing email actually looks like: fake insurance verification requests, spoofed EHR login alerts, and “urgent” messages impersonating a state licensing board are all common lures. Platforms like KnowBe4 run simulated phishing campaigns that train staff through realistic drills rather than slides. Schedule these exercises quarterly, attackers retool their tactics constantly, and an employee who breezed through a training in January may still click a convincing fake in October. Security awareness only works if it stays current.

Establish a Reliable Backup Strategy

A ransomware attack is only catastrophic if you have no clean copy of your data to restore from. The standard approach is the 3-2-1 rule: three copies of your data, stored on two different media types, with one copy kept off-site or in the cloud, and that off-site copy must be isolated from your main network so ransomware can’t reach it during an active attack. Tools like Backblaze for Business, Acronis Cyber Protect, and Veeam make automated, encrypted backups straightforward to configure. One step most practices skip: actually restoring from the backup before you need it. Run a test recovery at least once a year to confirm the backup works and to know how long a real restoration would take. Finding out the backup was corrupted after a ransomware attack is not a position you want to be in.

FAQs

Can I use standard email to communicate with therapy clients?

Personal Gmail and Yahoo Mail don’t provide the level of encryption HIPAA requires for protected health information, and neither service offers a Business Associate Agreement, which means they can’t legally be used to transmit patient data. Purpose-built alternatives are designed for healthcare providers and include BAAs as a standard part of their service agreements. One nuance worth knowing: Google Workspace for Business is a different product from a free Gmail account, and Google does offer a BAA for Workspace, so if your practice already runs on Workspace, it can potentially be configured for HIPAA compliance. But you still need that BAA signed before sending any PHI. Confirm encryption is active end-to-end and the agreement is in place before the first message goes out.

What is ransomware, and how does it affect therapists?

Ransomware is malware that encrypts every file it can reach on your system, patient session notes, intake forms, billing records, appointment histories, and holds the decryption key until you pay. For a therapy practice, that means no access to records before sessions, no ability to submit insurance claims, and no way to reach scheduling data until the situation is resolved. Paying the ransom doesn’t guarantee you’ll recover anything; the FBI’s Internet Crime Complaint Center (IC3) advises against it, and many victims who pay still don’t receive working decryption keys. There’s also a legal dimension that compounds the damage: a ransomware attack that exposes patient data triggers HIPAA’s Breach Notification Rule, requiring you to notify affected patients within 60 days of discovering the breach. If more than 500 patients are affected, you must also notify HHS and local media. OCR fines for HIPAA violations can range from $100 to $50,000 per violation depending on the level of culpability, and those run on top of any ransom you may have already paid.

Are small solo therapy practices really at risk for cyberattacks?

Yes. Automated scanning tools don’t discriminate by practice size, they probe every internet-connected device looking for unpatched software, open remote-access ports, and default credentials. A solo therapist running an outdated laptop with no firewall registers on these scans exactly the same way a large hospital network does. Small practices are actually attractive in a specific way: mental health records carry a premium on criminal markets because they contain diagnoses, medication histories, and patient disclosures that are rarely documented anywhere else, information that’s useful for blackmail and identity fraud. That high-value data sits behind defenses that are typically far thinner than those at larger health systems with dedicated IT and security staff. That gap is the target.

What is the single biggest cybersecurity threat to my therapy practice?

Ransomware and phishing are the two threats that cause the most immediate, hardest-to-reverse damage to therapy practices, and they’re directly connected. Phishing is how most ransomware gets in. A staff member clicks a link in what looks like a scheduling confirmation or an insurance authorization request, and that single click can deploy malware that spreads across your network and encrypts every file it reaches within hours. Mental health records carry a specific premium for criminal groups because they contain diagnoses, medication histories, and patient disclosures that people often haven’t shared with anyone else, details that are uniquely useful for blackmail and identity fraud. That combination of high-value data and typically minimal IT defenses makes therapy practices disproportionately attractive targets for ransomware groups.

I use a well-known telehealth platform. Isn’t that secure enough?

HIPAA-compliant telehealth platforms like Zoom for Healthcare and Doxy.me handle end-to-end encryption on their end, but that only covers data in transit between their servers and your device. It doesn’t protect your own network configuration, your account passwords, or the way the platform is configured on your side. Zoom for Healthcare, for instance, requires waiting rooms to be enabled, local recording to be disabled, and meeting links to be password-protected to align with HIPAA guidance; out-of-the-box defaults don’t cover all of that. Your patient’s home network is also a variable outside your control, if they’re on an unsecured public Wi-Fi or a compromised router, the session can be intercepted before it ever reaches the encrypted channel. The platform is the floor, not the ceiling.

What are the first steps to becoming HIPAA compliant with my IT?

Start with a formal Security Risk Assessment (SRA), and understand that under HIPAA’s Security Rule, this isn’t optional. The SRA identifies every place protected health information (PHI) lives in your practice: your EHR, billing software, email accounts, staff laptops, and any cloud storage you rely on. It then evaluates threats across your administrative, physical, and technical systems and produces a prioritized plan to close the gaps. The HHS Office for Civil Rights consistently identifies failure to complete an SRA as one of the most common findings in HIPAA compliance audits, which means it’s both the logical place to start and the first thing regulators will check.

Can’t I just protect my practice with standard antivirus software?

Antivirus software is a baseline, the equivalent of locking your front door while leaving the windows open. Real protection requires layers. A managed firewall (Fortinet and SonicWall are widely deployed in healthcare settings) controls what traffic enters and leaves your network. Email filtering tools like Proofpoint or Barracuda intercept phishing attempts before they reach your staff’s inbox, critical, since phishing is the leading initial entry point for healthcare breaches. Multi-factor authentication (MFA) through Microsoft Authenticator or Duo Security should be active on every account that touches PHI. Regular security awareness training keeps staff from becoming the weakest link. And a tested backup and disaster recovery plan, one that takes hourly snapshots and can restore systems in hours rather than days (Datto and Veeam are common choices for practices), is what separates a serious incident from a practice-ending one.

Secure Your Practice, Protect Your Patients

The confidentiality you uphold in your office doesn’t stop at the waiting room door, it runs through every system that stores a client’s name, diagnosis, or session notes. A breach isn’t just a regulatory problem; it’s a clinical one. Clients disclose things in therapy they haven’t told anyone else. When that information is exposed through a ransomware attack or a phishing intrusion, the harm is personal, and the trust that took years to build can be gone quickly. That’s why data security belongs in the same ethical frame as informed consent and confidentiality, not siloed off as someone else’s IT problem.

IPM Computers works specifically with mental health practices to handle the ongoing work of HIPAA-compliant IT: security risk assessments, managed firewalls, encrypted backups, staff phishing-awareness training, and 24/7 monitoring. If the compliance and security side of running a modern practice feels like it’s pulling you away from client care, that’s the problem we’re built to solve. Reach out today to talk through where your practice stands and what it would take to close the gaps.