lutz logo
lutz logo
  • Services
  • Industries
  • News & Insights
  • About
  • Client Portal
Search
  • Services
  • Accounting
  • Tech
  • Financial
  • M&A
  • Talent
  • Accounting Services
Services
  • Audit & Assurance
  • Client Advisory Services
  • Outsourced Accounting
  • Tax
  • Business Valuation
  • Litigation Support & Forensic
View All
Industries
  • Agribusiness
  • Construction
  • Family Office
  • Healthcare
  • Manufacturing & Distribution
  • Nonprofit
View All
News & Insights
Estate Planning Guide
Guide
Estate Planning Guide

Protect what matters. Our Estate Planning Guide provides a thorough overview of the documents and strategies needed to secure your financial legacy.

Read More
  • Tech Services
Services
  • Outsourced IT
  • Data Analytics
  • Digital Transformation
View All
Resources
Microsoft Copilot Explained
Blog
Microsoft 365 Series: Copilot Explained - Your New AI Assistant

For organizations using Microsoft 365, Copilot is quickly becoming one of the most impactful tools for AI in the workplace.

Read More
Business Insights
Untitled design (1)-Mar-08-2024-08-50-35-9527-PM
Video
Pella Client Testimonial
"I've used them for valuation work, stock transfers, hosting all of my technology, and now data analytics. I'd say they lead the pack in terms of anticipating what I'm going to need before I even know I need it."
View Now
  • Financial Services
Services
  • Financial Planning
  • Investment Advisory
  • Retirement Plan Services
  • Pooled Employer 401(k) Plan
View All
Resources
  • Lutz Financial Blog
  • Our Team
  • Client Portal
  • Charles Schwab Login
  • Send Files Securely
Contact Us
NEWS & INSIGHTS
Website Featured Content Images
Market Commentary
Financial Market Updates

Read our latest financial market updates and sign up to receive them straight to your inbox.

Read More
  • M&A Services
Services
  • Transaction Advisory
  • Business Valuation
  • Succession Planning
View All
Resources
Employee Stock Ownership Plan
Blog
Employee Stock Ownership Plan Benefits & Best Practices

Understanding how ESOPs work and whether your organization is a good fit is critical to determining if this exit plan aligns with your goals.

Read More
Business Insights
Red Flags & Deal Accelerators in Financial Due Diligence
Webinar Recording
Red Flags & Deal Accelerators in Financial Due Diligence
When it comes to buying or selling a business, financial due diligence can uncover both warning signs and opportunities that significantly impact value.
Read More
  • Talent Services
Services
  • Search & Staffing
  • Outsourced HR
  • HR Consulting
View All
Candidate Resources
  • Job Seeker Process
  • Current Opportunities
  • Lutz Internships
Contact Us
News & Insights
HR Solutions for Employee Experience
Blog
HR Solutions That Elevate the Employee Experience
For growing businesses, the phrase “employee experience” often gets reduced to surface-level perks, but the true meaning goes much deeper.
Read More
Business Insights
BLOG
Explore Topics

Get the latest news and insights on relevant topics that matter most to you.

View All
Webinars & Events
Events
Register Today

Register for an upcoming event or access our library of on-demand recordings.

View All
Market Updates
COMMENTARY
Stay Informed

Catch up on market moves with our weekly update, featuring in-depth insights and analysis.

View All
Resources
EBOOKS & GUIDES
Download Now

Take a deep dive into challenging business topics with these free educational resources. 

View All
  • News & Insights
  • Business Insights
  • Webinars & Events
  • Market Updates
  • Resources
Business Insights
BLOG
Explore Topics

Get the latest news and insights on relevant topics that matter most to you.

View All
  • Industries
Industries

We have dedicated industry groups to ensure our clients receive tailored advice and strategies to stay ahead of the curve.

Agribusiness
Construction
Family Office
Healthcare
Manufacturing & Distribution
Nonprofit
View All
  • About
About

Lutz is a business solutions firm for people seeking a partner to help energize and heighten economic and organizational success.

Our Company
Our Team
Locations
Careers
Internships
Contact Us
  • Client Portalss
Client Portal

Log in to your relevant client portal to access your account, upload documents, or make a payment.

Make a Payment
Accounting Client Portal
Financial Client Portal
Charles Schwab Login
Send Files Securely
QuickBooks Support
Contact Us
  • Private Practice

Ransomware Readiness: 10 Questions Every Small Practice Should Ask

Luke Schlueter
July 28, 2026
Ransomware Readiness: 10 Questions Every Small Practice Should Ask

Ransomware is one of the most disruptive cyber threats facing healthcare organizations today. Unlike many cyber incidents, ransomware can quickly lock employees out of critical systems, interrupt patient care, delay billing, and create complex compliance and reporting obligations.

Many healthcare practices have invested in cybersecurity tools, but ransomware readiness goes beyond prevention. The real question is whether your organization could detect an attack, limit the damage, recover critical systems, and continue serving patients if ransomware made it through your defenses.

The questions below address the specific controls, processes, and recovery capabilities that often determine the severity of a ransomware incident’s impact on an organization. Use this assessment to identify potential gaps, evaluate your preparedness, and better understand how your practice would respond if ransomware disrupted operations tomorrow.

 

1. Could one stolen password expose your entire environment?

Compromised credentials are a common starting point for ransomware attacks, making access controls one of the most important defenses.

Multi-factor authentication is required for email, VPN, and administrator accounts.
Former employee accounts are removed promptly.
Administrative privileges are limited to those who need them.
Remote access tools are restricted and secure.

Warning Signs

  • Shared administrator accounts are still in use.
  • MFA is optional rather than required.
  • Former employee accounts remain active.
  • Administrative privileges are not governed.

 

2. Are known vulnerabilities being addressed before attackers find them?

Cybercriminals often look for known vulnerabilities. Keeping systems updated helps close those gaps before attackers can exploit them.

A process exists to regularly review missing patches.
Critical patches are applied within a defined timeframe.
Internet-facing systems are prioritized.
Operating systems and applications are kept up to date.

Warning Signs

  • Software updates are delayed until someone has time.
  • Unsupported operating systems are still in use.
  • Patch status is not regularly reviewed.
  • Internet-facing systems are updated on the same schedule as everything else.

 

3. Could your team spot a phishing attempt?

Phishing emails remain one of the most common ransomware entry points because they rely on human error rather than technical vulnerabilities.

Risky file types and macros are restricted.
Email authentication protocols (SPF, DKIM, and DMARC) are configured.
Employees can easily report suspicious emails.
Staff receive ongoing phishing awareness training.

Warning Signs

  • Employees receive training only during onboarding.
  • Suspicious emails often go unreported.
  • Email Authentication is not properly configured.
  • Staff are unsure how to verify unexpected requests or attachments.

4. Are your employees part of the security strategy?

Technology plays a critical role in preventing ransomware, but employees also need to understand how their actions affect security. A strong security culture encourages people to report concerns quickly, ask questions, and treat cybersecurity as part of daily operations.

Security awareness training occurs regularly.
Phishing simulations are conducted.
Employees know how to report suspicious activity.
Participation and improvement are tracked.

Warning Signs

  • Training is viewed as a compliance exercise rather than a business priority.
  • Employees are hesitant to report mistakes.
  • Security topics are discussed only after incidents occur.
  • Leadership is not actively involved in reinforcing cybersecurity practices.

 

5. Would you know if ransomware was spreading through your network?

The sooner unusual activity is detected, the more likely your organization is to contain an attack before it reaches critical systems.

Endpoint detection and response (EDR) or advanced security tools are deployed.
Employees understand when to report an incident
Alerts are regularly reviewed.
Critical systems are segmented to limit lateral movement.

Warning Signs

  • Devices have inconsistent security protections.
  • Security alerts are rarely reviewed.
  • All systems share the same network with few restrictions.
  • You would rely on an employee reporting a problem before an incident is discovered.

 

6. Does everyone know their role during an incident?

When ransomware strikes, uncertainty can slow response efforts and increase damage.

A ransomware response plan is documented.
Key responsibilities are clearly assigned.
Contact information is available offline.
Response procedures are reviewed regularly.

Warning Signs

  • Employees do not know who to contact during an incident.
  • Response procedures exist but have never been tested.
  • Critical contact information is stored only on affected systems.

 

7. Could your team contain an attack quickly?

The actions taken during the first few minutes of a ransomware incident often determine how far the attack spreads.

Employees understand how to isolate affected devices.
Procedures exist for preserving evidence.
Leadership knows when to activate the response team.
Initial containment steps have been documented and discussed.

Warning Signs

  • Employees would immediately reboot infected devices.
  • Staff is uncertain whether systems should be disconnected from the network.
  • There is no clear process for escalating incidents.
  • The organization has never practiced an incident response scenario.

 

8. Could you restore your data without paying a ransom?

If ransomware encrypts your systems, recovery depends on whether you can restore clean, accessible data.

Backups follow the 3-2-1 rule: three copies, two storage locations, one offsite or offline copy.
At least one backup is isolated from our network.
We regularly test backup restoration.
Backup access is protected with separate credentials.

Warning Signs

  • Backups have never been tested.
  • All backups remain connected to the production network.
  • Multiple employees have unrestricted access to backup systems.

 

9. How quickly could your practice return to normal operations?

Recovery involves much more than turning systems back on. It requires knowing which applications are most critical, how quickly they need to be restored, and how staff and patients will be kept informed.

Critical systems have been prioritized.
Acceptable downtime has been defined.
Full recovery testing has been performed.
Communication plans exist for staff and patients.

Warning Signs

  • No formal recovery priorities exist.
  • Backup restores have never been tested at scale.
  • Business operations depend heavily on a single application.
  • Communication plans would need to be created during the incident.

 

10. Are you prepared for compliance and reporting requirements?

For healthcare organizations, ransomware often extends beyond downtime and becomes a potential compliance issue. Determining whether protected health information was accessed or exfiltrated is often just as important as restoring systems.

Security risk assessments are performed and documented.
Procedures exist for determining whether data was accessed or exfiltrated.
Breach notification requirements are understood.
Compliance responsibilities are assigned before an incident occurs.

Warning Signs

  • Regulatory obligations have not been reviewed recently.
  • Leadership is unclear about reporting requirements.
  • Risk assessments are outdated or incomplete.
  • Compliance decisions would be made only after an incident occurs.

 

What do your results mean?

Mostly Checked

Your practice has many foundational safeguards in place to reduce ransomware risk. Continue reviewing controls, testing recovery plans, and updating procedures as systems, staffing, and threats change.

Some Checked

Your practice has made progress, but remaining gaps could slow response or increase downtime during a ransomware event. Prioritize the areas that would have the greatest impact on patient care, data access, and recovery.

Few Checked

Your practice may have meaningful exposure to ransomware and related cybersecurity threats. Addressing these foundational controls can help protect systems, patient data, and daily operations.

 

Keep Your Practice Safe with Lutz

Every question in this checklist is designed to identify a potential gap in your ransomware readiness. Whether it's access controls, backup testing, employee training, or incident response planning, the goal isn't perfection. It's understanding where your practice may be vulnerable and addressing those weak spots.

If you found areas where the answer was "not yet" or "I'm not sure," you're not alone. Many healthcare practices know cybersecurity matters but struggle to determine which risks to focus on first. That's where an outside assessment can help.

Lutz’s Outsourced IT team helps healthcare organizations evaluate their current environment, identify gaps, and prioritize practical improvements that strengthen security and support business continuity. As part of Lutz's Healthcare industry specialty, our team understands the unique challenges medical practices face and can help you build a roadmap to better protect your systems and patient data. To start a conversation, contact us.

Recent News & Insights

Private Practice
Ransomware Readiness: 10 Questions Every Small Practice Should Ask
Ransomware is one of the most disruptive cyber threats facing healthcare organizations today. ...
Read More
Market Commentary
The Market & The Midterms
As November approaches, investors will hear increasingly confident predictions about what a ...
Read More
Recent News
Lutz Announces 2026 Senior through Manager Promotions
Lutz, a Nebraska-based business solutions firm, recently announced multiple promotions to ...
Read More
Recent News
Lutz Announces 2026 Shareholder & Director Promotions
Lutz, a Nebraska-based business solutions firm, is proud to announce the promotion of 10 team ...
Read More
module-bg-desktop module-bg-mobile

Let’s get you where you want to go.

We work to simplify complexities, help make critical business decisions, and confidently focus on the things that are truly important to you. We embrace your business as our own to spark the right solutions and help you thrive.
Contact Us
Lutz-Logo-white

HEADQUARTERS
13616 California St, Suite 300 | Omaha, NE | 68154

  • Services
    • Accounting
    • Consulting
    • Financial
    • M&A
    • Talent
    • Tech
  • About
    • Our Company
    • Our Team
    • Offices
    • Careers
    • Internships
    • Current Opportunities
  • Client Portal
    • Make a Payment
    • Accounting Client Portal
    • Financial Client Portal
    • Send Files Securely
    Submit RFP
TOLL-FREE: 866.577.0780 | © Lutz & company, PC 2026 | Privacy Policy
Follow us on LinkedIn Twitter - X Logo Follow us on Instagram Follow us on Facebook