The fastest way to reach us is already on your computer
Every practice computer we manage has a Comodo icon in the system tray, next to the clock. It raises a ticket or starts a chat without you leaving what you are doing — and it tells us which machine you are on, which is usually the difference between a fix in minutes and three emails asking which PC you meant.
On a phone, a personal device, or a computer we do not manage, use one of these instead.
Healthcare & Dental Security Incident Response Plan
Standard operating procedure for client practices across California when handling suspected ransomware, unauthorized ePHI exposure, compromised cloud credentials, or lost clinical hardware.
Active Breach / Ransomware
Files encrypted with strange extensions, Open Dental / Dentrix database locked, ransom note on screen, or mass ePHI exfiltration.
Credential Theft / Lost ePHI Device
Staff entered M365 or PMS credentials into a phishing portal; lost or stolen practice iPad, doctor laptop, or unencrypted flash drive.
Blocked Phish / Misdirected Fax
Suspicious email link clicked but blocked by Comodo DNS filter; single patient record accidentally faxed to wrong specialist.
The 6-Phase Containment & Resolution Protocol
Practice workflow executed in coordination with Comodo Technology engineers
Immediate Discovery
Staff observes anomalous behavior (locked charts, odd browser popups, suspicious MFA push alerts). Practice Security Officer alerted within 15 minutes.
Physical Containment
Disconnect physical network jack and disable Wi-Fi. Do not reboot or power down. Comodo isolates device endpoint via cloud EDR agent remotely.
Forensic Eradication
Comodo engineers extract endpoint volatile memory logs, identify infection source, kill malicious background processes, and verify backup repository integrity.
Clean State Recovery
Restore clean virtual machine snapshots or database backups from immutable offsite cloud storage. Validate Open Dental / Dentrix integrity before clinical check-in.
4-Factor Breach Audit
Practice legal counsel and HIPAA Officer run the statutory 4-factor test under 45 CFR § 164.402 to establish whether a formal notification obligation exists.
Regulatory Disclosure
If compromised, issue individual patient notices (≤ 60 days) and file with the HHS OCR breach portal. Retain comprehensive logs for mandatory 6 years.