
Here is the uncomfortable truth most consultants won’t say out loud: your IT guy is not your cybersecurity. He hooks up your printers, keeps EagleSoft running, and swaps a hard drive when one dies. That is a completely different skill set from defending a database full of Social Security numbers, insurance IDs, and clinical histories that criminals will pay real money for. And in 2023, when a chain with more than 1,000 locations got its scheduling systems, phones, and business applications shut down by a cyberattack, the excuse “my IT has it handled” officially stopped being a strategy.
On the Bulletproof Dental Practice podcast, Pete Boulden sat down with a former Secret Service officer — a man who was personally caught in a government breach that exposed 22.1 million records — to break down exactly how practices get hit and what actually protects them. This article is built on that conversation. No fear-selling, no product to push. Just the playbook.
Because you are softer, and your data is worth more than you think. A dental record is a stacked hand: name, date of birth, address, Social Security number, insurance credentials, sometimes payment cards — all in one file. A stolen credit card gets cancelled in an hour. A medical identity does not. That is why healthcare climbed onto the list of the most-targeted small-business sectors, landing at roughly number four.
Pete has said it plainly on the show: a dental office is a far richer target than a hair salon or a car dealership. You hold more valuable information, and your business is built on protecting it — which means a criminal knows you will pay to get it back. That combination is catnip for ransomware crews. The industry runs about five years behind mainstream small business on security, and the attackers know that too.
Everyone pictures a hacker as a hoodie behind a keyboard in another country, hammering your firewall for months with no guarantee of getting in. That is the expensive, hard way. The cheap, reliable way is human hacking — social engineering — and estimates in the episode put it on track to represent the overwhelming majority of business breaches.
Here is how the guest described the attack, step by step, and it should chill every owner:
That is it. No firewall was breached because no firewall was involved. Every antivirus subscription and every Norton license in the building is now irrelevant, because the attacker walked straight past the technology and manipulated a human being. And there is no smoking gun — no alert, no crashed computer. The pipeline is open and silently feeding data out, and you may never know it happened.
No — and this is the mental shift that matters. Firewalls leave breadcrumbs: if someone attacks your perimeter and you have real cybersecurity monitoring running alongside IT, you get notified — what country, what actor, what attempt. The human route leaves no breadcrumbs at all. That is precisely why sophisticated actors are moving to it. Software got better at the perimeter, so the attackers stopped attacking the perimeter and started attacking your people.
As Pete admits on the episode, even he — an owner who scrutinizes every “who is this from” field — nearly fell for a near-perfect Google impersonation email where the address and branding were flawless. If it can almost get the tech-forward host of a dental podcast, it will get your busy front desk on a Tuesday morning.
Pete pushed the guest hard for practical, non-paranoid steps. Here is the tactical stack that came out of it — none of it requires a five-figure contract:
HIPAA is the floor, not the ceiling. Remember when HIPAA landed and practices realized a violation could cost six figures? That is the compliance frame most owners still live in — spend the minimum, check the box, move on. Cybersecurity is a different animal because the threat is active and adaptive. There is real movement at the federal level toward a dedicated annual cybersecurity certification for healthcare, distinct from IT and distinct from your current HIPAA training. Owners who treat security as a living protocol instead of a once-a-year checkbox will be the ones still standing when the certification lands.
Here is where Craig Spodak’s side of the house matters. Bulletproof is built on transparency and trust with your team — sharing numbers, building people up, refusing to run a practice on suspicion. Cybersecurity can pull you the other way, into paranoia, into locking everyone out, into treating your own team as the threat. The answer is not fewer trusted people. It is better-trained, better-led people who understand why a USB drive from a stranger is a loaded weapon. You protect the practice by building a culture sharp enough to spot the con — not by turning the office into a bunker.
Dentistry is hard enough. You already carry the clinical load, the team, the equipment, the risk of the building. Now cybersecurity gets bolted on too. You should not carry that alone — and the whole reason Bulletproof exists is that you don’t have to. This is exactly the kind of blindside the best owners in the country war-game together before it ever hits their office.
That is what happens inside our world. At Bulletproof Summit, owners trade the real playbooks — the systems, the vendors, the mistakes — so you learn from someone else’s breach instead of your own. Inside the Bulletproof Mastermind, you get a room full of growth-minded owners who pressure-test your defenses and your decisions, month after month. Dentistry does not have to be a lonely profession, and you do not have to face the next threat by yourself.
The best is yet to come — but only for the owners who lock the doors before someone else finds them open.
The 1% of dentists, who want 100% from life.