I scan small healthcare websites across North Texas — chiropractors, dental practices, therapy clinics, home health agencies. A few dozen a week. I look at the public-facing parts only: the parts a patient or a stranger can see. The most common thing I find is not a hacker. It's a calendar problem.
Here's the pattern. A practice registered its domain years ago, on a card that has since been replaced. Auto-renew is off, or it's on but pointed at the dead card. The renewal notice goes to an inbox that belonged to the office manager who left in 2023. Nobody is reading it.
What the domain is actually holding up
The website, obviously. But also every email address on it. The scheduling confirmations. The password reset link for the patient portal. The address your billing company sends remittance to. The domain isn't part of your IT — it's the foundation under all of it.
When a domain lapses, none of that fails gracefully. It fails at once, on a Tuesday, at midnight.
And it doesn't fail politely either. After expiration there's a grace period, then a redemption period where getting it back costs far more than the renewal would have — often a hundred dollars or more in redemption fees on top of the renewal itself. After that it goes to auction. Expired healthcare domains get bought, because the traffic is worth something to whoever wants it. Your patients keep typing your web address. It just isn't yours.
I found one practice recently whose registration expires in about five weeks. Good clinic. Two decades in business. Their site had no idea it was about to go dark.
What to do this week, in fifteen minutes
Look up your own domain. Go to lookup.icann.org and enter it. You'll get the expiration date and the name of your registrar. Write both down.
Log into that registrar. Confirm auto-renew is on, and that the card on file hasn't expired. Those are two separate checks and the second one is where most practices fail.
Change the account's contact email. Point it at an address more than one person reads — not a single employee's mailbox, and not an address on the domain itself. A domain that lapses takes its own warning emails down with it.
Set a calendar reminder for thirty days before renewal, every year, with someone's name on it.
Turn on the registrar lock while you're in there, so the domain can't be transferred out without your approval.
That's the whole fix. No project, no vendor, no budget request.
Why this keeps happening
Nobody owns it. IT vendors own the network. The marketing person owns the website. The biller owns the claims system. The domain sits underneath all three and belongs to none of them, which is exactly how something goes five years without anyone looking at it.
The practices that get this wrong aren't careless. They're busy, and the thing that failed was never on anyone's list.
Most of what actually goes wrong at a small practice looks like this: undramatic, preventable, and invisible until it isn't. The interesting part of this work isn't the sophisticated attack. It's the renewal nobody owns.