Want to Protect Your Practice From Hackers? Start Here

October 05, 2026

Happy Sunday!

As the owner of a wealth management firm, one of my worst nightmares is a cyber security breach. We have layers (and layers) of defenses in place, including simulated phishing emails to make sure our team can identify potential threats, monthly cybersecurity training, and a (sometimes annoyingly prohibitive) VPN that adds an additional layer of security when our team works remotely to name- just to name a few surface level measures.

But cybersecurity concerns aren’t limited to my own business. I hear far too many stories about breaches and security issues in optometric practices, including the following examples I’ve heard about just this year:

  • Practice emails being incorrectly flagged as spam— we actually had this issue in our company where we couldn’t email any google hosted email address only to learn multiple practices have experienced the same disruption
  • Calling the wrong phone number for support and reaching a scammer instead of the actual provider
  • A cyber breach involving stolen EHR data that took months to recover and required some really not fun disclosures to patients
  • A robbery where cameras were connected to an onsite server—and the server was stolen along with many frames and other equipment
  • Old or unknown users having access to important systems. I recently heard about a patient communication platform that had inadvertently added private-equity users to a private practice’s system because the names were similar

We’re hosting a webinar on October 13th(REGISTER HERE!) covering the basics of what practices should be doing to protect themselves, so you can better understand what your IT service provider should—and shouldn’t—be doing for you.

But there’s one very simple area you can start managing today: your people (including yourself).

It’s worth dedicating a small amount of time during your team meetings each quarter to cybersecurity awareness and requiring simple, ongoing training. A few basic habits can go a long way toward preventing a breach:

(Side note: while I always write my own content including the graphic information, credit to ChatGPT for the image)

In summary, cybersecurity isn’t just an IT issue although it is mission critical to have that set up correctly in your practice. But your staff is one of your practice’s most important lines of defense, and that's something you can start managing today.

Want to learn more about what you should be doing to protect your practice? Join our webinar on October 13th. As always, a replay will also be available if you can’t attend live.

A couple of other small updates:

  • 1- If you haven't filed yet, personal tax returns on extension are due in 11 days on October 15th.

  • 2- A few weeks ago, my colleague Alexis wrote about Trump Accounts. Enrollment has been lacking so auto enrollment has come into effect for 60 million children (presumably including my 9 and 11 year old). It's up to you on whether to claim it, but please know if you have a child eligible for the $1,000 government contribution (children born between January 1, 2025, and December 31, 2028), the parent HAS to claim the account to get the credit.

  • If you haven't heard, rate have spiked and when I last checked a 2 year treasury was sitting around a 4.8% yield. Make sure your extra cash is working for you!

Have a great rest of your Sunday!

Natalie

Owner, Hayes Wealth Advisors