If you've experienced a cybersecurity failure, or data breach, you've come to the right place.
Experiencing a data breach is unfortunately becoming more common, with veterinary practices of all sizes facing increasingly sophisticated cyber threats in 2025. Here are key recommendations and best practices, informed by recent industry guidance and real-world incidents:
Immediate Steps After a Breach
- Conduct a Post-Incident Review: Analyze how the breach occurred, what data was accessed, and whether any vulnerabilities remain. Engage a cybersecurity professional or managed security service provider if needed.
- Notify Insurance Provider: If you have cyber liability insurance through the AVMA or another insurance company, now is a great time to file a claim.
- Notify Affected Parties: Depending on the data compromised, you may have legal or regulatory obligations to notify clients, partners, or authorities.
- Update Credentials: Immediately reset passwords and review access permissions for all affected systems.
Strengthening Cybersecurity: Best Practices for 2025
1. Implement Strong Access Controls
- Enforce the principle of least privilege: users only get access to what they need.
- Do not use default "Idexx123" passwords
- Use role-based access control (RBAC) and regularly review permissions.
2. Require Multi-Factor Authentication (MFA)
- MFA is one of the most effective defenses against credential theft and unauthorized access.
3. Keep Systems and Software Updated
- Enable automatic updates for operating systems, applications, and security tools to patch vulnerabilities quickly.
4. Use Next-Generation Firewalls and Endpoint Protection
- Deploy advanced firewalls that inspect traffic and block threats at the network perimeter.
- Implement endpoint protection and detection solutions (EDR/XDR) for all devices, especially with remote/hybrid work. We utilize CrowdStrike in our law firm, as it is used by most of the Fortune 500 and has great small business pricing.
5. Encrypt Data at Rest and in Transit
- Use strong encryption standards (like AES-256) for sensitive data stored on servers and transmitted over networks.
6. Regular Data Backups and Disaster Recovery
- Maintain frequent, automated backups stored securely and offsite. Test your disaster recovery plan regularly.
7. Employee Training and Phishing Awareness
- Conduct ongoing cybersecurity training to help staff recognize phishing, social engineering, and suspicious activity.
- Simulate phishing attacks to test and improve awareness.
8. Regular Security Audits and Penetration Testing
- Schedule security assessments to identify vulnerabilities before attackers do.
- Include penetration testing after major system changes or at least annually.
9. Secure Server and Cloud Configurations
- Harden servers by disabling unnecessary services, using strong authentication, and limiting direct internet exposure.
- Review cloud security settings to prevent accidental data exposure and enforce identity and access management (IAM) controls.
10. Adopt a Zero Trust Security Model
- Assume no user or device is trusted by default, regardless of network location. Continuously verify identity and device posture before granting access.
11. Monitor and Respond to Threats
- Use security monitoring tools and maintain logs to detect unusual activity early.
- Have an incident response plan and rehearse it with tabletop exercises.
Additional Considerations
- Physical Security: Restrict access to critical infrastructure and servers.
- Mobile and Remote Work Security: Secure mobile devices with encryption, strong authentication, and mobile device management (MDM).
- Compliance: Ensure your practices align with industry regulations (CCPA, GDPR, state veterinary medical data privacy acts, etc.) to avoid fines and reputational harm.
Final Thoughts
You are not alone-many organizations are facing similar challenges as cyberattacks rise in frequency and sophistication. By implementing these best practices and fostering a culture of security awareness, you can significantly reduce your risk and improve your resilience against future incidents.
If you have not already, consider consulting with a cybersecurity expert or managed security provider to tailor these recommendations to your office's specific needs
About Jeff Schick
Animal health attorney Jeffrey Schick, ESQ, graduated from the University of Pennsylvania Law School. The son of two veterinary dermatologists, Jeff grew up “in the clinic” and now uses his experience to help veterinarians. When not practicing law, you can find Jeff in the Colorado Mountains with his family and dogs.

Share On:
