PSS News

Cybersecurity PSA: Is Your Backup Actually Backing Up?

Yesterday, we were called about a ransomware attack involving a medical billing service.

When they logged into the computer running Lytec, they found their files encrypted and a Notepad document with instructions to visit a Tor website and pay to have the files decrypted.

That is exactly the type of situation backups are supposed to protect you from.

And in this case, they did have backup software running.

The problem was that it wasn’t backing up what they thought it was.

A “Successful Backup” Doesn’t Always Mean Your Data Is Safe

Lytec stores its data in a Microsoft SQL database.

Because those database files are actively being used while the server is running, a normal file-backup program generally cannot back up the live SQL files directly.

Instead, a proper backup file first needs to be created from the SQL database.

There are several ways in which a backup file can be created from SQL data:

1. Manual Lytec Backup

Lytec has a built-in backup function under Tools > Backup Data.

It works, but it must be run manually. Unfortunately, we often discover that it has not been run only after a disaster occurs and the backup is suddenly needed.

2. Lytec Automatic Backup

Lytec also has a built-in automatic backup function, but it relies on Windows Task Scheduler, which can be an unreliable link in the process.

3. SQL Server Agent

On Client/Server versions of Microsoft SQL Server that support SQL Server Agent, a technician can configure a reliable automatic backup directly on the server to run every day.

4. Specialized Third-Party Software

There are also third-party backup programs specifically designed to back up SQL databases directly.

For systems that support it, Option 3 is our preferred method for reliably creating current backup files on the server.

Creating the Backup Is Only Half the Job

Even a perfectly configured automatic SQL backup does not help much if the backup remains only on the same server.

If ransomware encrypts the server, the hard drive fails, the computer is stolen, or the building is damaged by fire, the backup may disappear along with the original data.

That means your backup plan needs to take one more step.

There are two common ways to protect those backup files:

1. External Hard Drives

This can work well, but ideally you need at least two external hard drives so one can be disconnected and stored in a fire safe or taken off site.

How often should you rotate them?

That depends on how much data you are willing to re-enter after a disaster.

If you only swap the drive once a month and something happens on the 29th day, you may potentially have a month of data to reconstruct.

The weakness of this method is that it once again depends on someone remembering to swap the drives consistently — and noticing a problem before reconnecting the protected drive.

2. Off-Site Backup Software

A service such as CrashPlan or Carbonite can automatically move backup files off site.

This is our recommended approach.

But even off-site backup software only works if it is configured to protect the correct files and folders.

What Went Wrong in This Case?

Unfortunately, this client’s backup setup failed on multiple fronts.

First, new Lytec/SQL backups were no longer being created.

The newest database backup in the backup folder was from 2025.

Second, although the client was using CrashPlan, CrashPlan was not backing up the database backup folder at all.

It was only backing up the Windows User folder each night.

So even if there had been a current SQL backup sitting in the proper backup folder, CrashPlan was not configured to move that file off site.

Both problems could have been identified before the ransomware attack if the backup configuration had been reviewed.

Backup software cannot protect files that were never created — or folders it was never told to back up.

Why This Can Happen

Windows Task Scheduler can be a fragile link in an automated backup process.

Scheduled tasks can stop running for a variety of reasons, including changes to Windows user credentials or passwords.

At the same time, a separate backup program may continue operating normally and reporting successful jobs.

You see a green checkmark.

You see “Backup Successful.”

Everything appears fine.

But unless someone verifies both that current SQL backups are being created and that those files are actually included in your off-site backup, you may not discover the problem until you need to restore your data.

And by then, it may be too late.

Don’t Assume. Verify.

The obvious advice after a ransomware attack is:

“Make sure you have backups.”

We think there is a better question:

When was the last usable backup of your database actually created — and is that backup safely stored somewhere else?

We don’t expect every medical practice to know how to answer that.

You shouldn’t have to understand SQL backup jobs, Windows Task Scheduler, database logs, folder selections, or backup file timestamps just to know whether your patient and billing data is protected.

That’s our job.

If you aren’t completely sure your Lytec backups are working properly, call Physicians Software Solutions before disaster strikes.

We can review your current backup configuration, verify that new database backups are actually being created, make sure those files are included in your off-site backup, identify weaknesses in the process, and help you build a more reliable backup strategy.

Don’t wait until ransomware is on the screen to find out whether the backup you were counting on actually exists.

This Is Also One of the Problems We’re Building Phoenix to Solve

Situations like this are part of the reason we’ve been developing Phoenix, our next-generation practice management platform.

Phoenix has not launched yet. We’re still a few weeks away from beginning beta testing.

But from the beginning, one of our goals has been to remove many of the fragile processes that practices currently have to piece together themselves.

For local installations, Phoenix includes a service application designed to automate important processes such as backups without depending on Windows Task Scheduler.

Phoenix will also offer a cloud-hosted option.

For practices that choose the hosted version, the idea is simple:

You take care of your patients and your practice. We take care of the infrastructure behind it.

For hosted practices, that means we can manage the hosting environment, backups, updates, and much of the cybersecurity responsibility that practices today often have to manage across multiple computers, programs, and vendors.

No assuming that a scheduled task is still running.

No relying on a green checkmark from a program that doesn’t know whether your database backup is current.

No discovering during an emergency that the backup you trusted is months out of date.


Is Your Backup Actually Working?

If you use Lytec and you aren’t 100% certain that your database is being backed up correctly, give us a call. A small amount of time spent verifying your backup today can prevent an enormous problem later.

Call us and let us make sure the backup you’re counting on is actually there when you need it.