Security & compliance

HIPAA doesn't cover vets. The risk still does.

Veterinary practices sit outside HIPAA, but they hold client identities, payment cards and controlled-substance records, and they depend on systems that ransomware can stop in an instant.

What actually applies

The rules and risks that matter for a veterinary practice

This is a plain-English overview, not legal advice. Requirements vary by state, so confirm specifics with your state veterinary board and your attorney.

HIPAA Generally not applicable

HIPAA governs human-health covered entities and their business associates. Animal medical records aren't protected health information. Many owners hear "HIPAA" and assume either that it applies, or that nothing does. Neither is right.

PCI DSS Applies if you take cards

Any business that accepts payment cards must follow the Payment Card Industry Data Security Standard. That means secure, current card terminals, segmented networks, no stored card numbers, and an annual self-assessment through your processor.

Client data & breach laws Applies

Client names, addresses, phone numbers, emails and payment details are personal information. Every US state has a data-breach notification law, and many state veterinary practice acts also require medical records to be kept confidential.

DEA recordkeeping Applies to registrants

Practices registered with the DEA must keep complete, accurate controlled-substance records, including inventories and dispensing logs, and keep them available for inspection for at least two years. Electronic logs need access controls, an audit trail and reliable backups.

The protection stack

Layered security sized for a clinic

Multi-factor sign-in

On email, PIMS, remote access and admin accounts. This one control blocks most account takeovers.

Endpoint detection & response

EDR on every workstation and server, watched around the clock, with suspicious machines isolated quickly.

Email security

Filtering for phishing and fake invoices, plus SPF, DKIM and DMARC so nobody can convincingly impersonate your clinic.

Immutable backups

Copies that ransomware can't encrypt or delete, with restore tests on a schedule.

Network segmentation

Guest Wi-Fi, card terminals, imaging and staff devices on separate networks.

Staff awareness

Short, practical training for front-desk and medical staff, who are the people attackers actually target.

We also help with cyber-insurance questionnaires: carriers increasingly ask about MFA, EDR, backups and training before they quote or renew. We document what's in place so you can answer accurately.

Publicly reported incidents

It has happened to veterinary practices

Two publicly reported cases, summarized from news coverage, with the lessons any practice can apply. We weren't involved in either.

October 2019 · Large veterinary group

Ransomware reaches hundreds of hospitals

National Veterinary Associates, a group of roughly 700 animal-care facilities, discovered a Ryuk ransomware attack on a Sunday morning. About 400 locations were affected. Reporting described core Microsoft servers being hit and many practices losing access to their patient-management systems.

Lesson: attackers strike on weekends and holidays, and shared central systems can spread one incident across every clinic. Monitoring has to be 24/7, and multi-site networks need segmentation.

Source: KrebsOnSecurity, "Ransomware Bites 400 Veterinary Hospitals" (Nov. 2019)

July 2021 · Independent animal hospital

A small clinic loses years of records

York Animal Hospital in Maine was hit over the Fourth of July weekend. Local news reported a ransom demand of about $80,000 in bitcoin. The server and backup data were wiped, and the practice rebuilt from a years-old copy and paper records, asking clients to help restore their pets' history.

Lesson: backups attached to the same network can be destroyed along with everything else. Keep an offline or immutable copy, and test restoring it.

Sources: WGME (July 2021); Sun Journal (July 2021)

Want to know where you stand?

We'll review your backups, sign-in security and network setup and give you a short, honest list of what to fix first.