24/7 System Monitoring Active
Security emergency: (916) 740-1407 hipaa@comodotechnology.com
Sign in
Print this plan and keep it on paper
Two pages, with blanks for your security officer, counsel and insurance carrier. During a ransomware event the screens are the first thing you lose.
Reaching Comodo

The fastest way to reach us is already on your computer

Every practice computer we manage has a Comodo icon in the system tray, next to the clock. It raises a ticket or starts a chat without you leaving what you are doing — and it tells us which machine you are on, which is usually the difference between a fix in minutes and three emails asking which PC you meant.

Three clicks, from any practice computer
1
Find the Comodo icon
Bottom-right of your screen, beside the clock. If you cannot see it, click the small arrow to show hidden icons.
2
Click it
A short menu opens with everything below.
3
Pick Submit a Ticket, or Live Chat
If no technician is free, chat takes a message instead and we come back to you.
What the menu looks like
COMODO TECHNOLOGY
Submit a Ticket
Live Chat
916.740.1407
Comodo Technology
Mandated Under 45 CFR § 164.308(a)(6)

Healthcare & Dental Security Incident Response Plan

Standard operating procedure for client practices across California when handling suspected ransomware, unauthorized ePHI exposure, compromised cloud credentials, or lost clinical hardware.

Call Comodo now: (916) 740-1407
SEV-1 Critical

Active Breach / Ransomware

Files encrypted with strange extensions, Open Dental / Dentrix database locked, ransom note on screen, or mass ePHI exfiltration.

• Unplug Ethernet & turn off Wi-Fi
• Leave PC power ON (preserves memory logs)
• Call Comodo immediately on (916) 740-1407
SEV-2 High

Credential Theft / Lost ePHI Device

Staff entered M365 or PMS credentials into a phishing portal; lost or stolen practice iPad, doctor laptop, or unencrypted flash drive.

• Microsoft 365 sessions revoked globally
• Comodo triggers remote wipe via MDM
• Initiate 4-Factor Risk Assessment
SEV-3 Low

Blocked Phish / Misdirected Fax

Suspicious email link clicked but blocked by Comodo DNS filter; single patient record accidentally faxed to wrong specialist.

• Request written destruction confirmation
• Run EDR deep scan on endpoint
• Document in 6-Year HIPAA log

The 6-Phase Containment & Resolution Protocol

Practice workflow executed in coordination with Comodo Technology engineers

1

Immediate Discovery

Staff observes anomalous behavior (locked charts, odd browser popups, suspicious MFA push alerts). Practice Security Officer alerted within 15 minutes.

2

Physical Containment

Disconnect physical network jack and disable Wi-Fi. Do not reboot or power down. Comodo isolates device endpoint via cloud EDR agent remotely.

3

Forensic Eradication

Comodo engineers extract endpoint volatile memory logs, identify infection source, kill malicious background processes, and verify backup repository integrity.

4

Clean State Recovery

Restore clean virtual machine snapshots or database backups from immutable offsite cloud storage. Validate Open Dental / Dentrix integrity before clinical check-in.

5

4-Factor Breach Audit

Practice legal counsel and HIPAA Officer run the statutory 4-factor test under 45 CFR § 164.402 to establish whether a formal notification obligation exists.

6

Regulatory Disclosure

If compromised, issue individual patient notices (≤ 60 days) and file with the HHS OCR breach portal. Retain comprehensive logs for mandatory 6 years.