Solution · By industry

Healthcare and clinics

Almost every step of a consultation now runs through a screen. The visit is logged in the practice system, e-prescriptions and e-referrals travel to the national P1 platform, NFZ claims are settled electronically and the notes land in the electronic medical record. If any link in that chain stops, the waiting room fills up and reception spends the day apologising. Working remotely, we keep your clinic going from the first appointment to the last and make sure health data gets the protection GDPR demands.

GDPR
treats health data as a special category
100 %
remote care, nobody visits your clinic
72 h
to report a breach to the Polish regulator, UODO
15 min
response time on the Premium plan

Our side of the work

Five areas. Some keep the consulting rooms running, others cover your duties towards patients and the regulator. Everything is done over secure remote access, mostly outside surgery hours.

Agree the scope

Practice software and the P1 link

We look after the server or cloud platform beneath your practice system, its database, patching and monitoring. We also track the certificates and accounts used to talk to P1, so e-prescribing never breaks on a Monday morning because a file quietly expired.

Who can open a patient file

Personal logins in place of one shared “reception1” account, permissions tied to each role, two-factor sign-in, encrypted drives on doctors' laptops and a trail showing who viewed which record.

Backups of medical records

Several database copies a day, one copy held away from the clinic where ransomware cannot reach it, and trial restores at a frequency set out in the contract. Medical records are kept for many years, with periods that vary by record type, so the backup retention policy is drawn up together with your lawyer or DPO.

Email, results and online booking

Encrypted delivery of test results, rules that catch PESEL numbers in ordinary messages (in Microsoft 365, for example, where your licence includes the feature), a booking form that asks only for what it needs, and data processing agreements with your booking and text message providers.

Front desk and consulting rooms

PCs, prescription printers and Wi-Fi with a separate network for patients, all updated and fixed remotely. Medical devices stay with the manufacturer's own service team.

Where we start

First we remove whatever could halt appointments, then we tidy up the paperwork a regulator or an unhappy patient would ask to see.

01

Data map

We find where the EDM sits, where X-ray images and scanned referrals are stored, who can reach them and how data travels to the lab, the NFZ or an insurer.

02

Risks and contracts

A risk analysis for health data, a review of processing agreements with your software, email and booking vendors, and updated entries in the record of processing activities.

03

Safeguards

Named accounts, MFA, encryption, backups proven by a test restore and a fallback connection. We make changes in the evenings and at weekends so the appointment book stays untouched.

04

Ongoing care

A helpdesk during your opening hours, daily backup checks and periodic permissions reviews, useful for instance when contract doctors leave.

A visit from UODO is rare, an outage of the practice system is far more common. An hour without patient files means rescheduled visits, paper prescriptions written in a hurry and a reception desk under siege. That is why we agree the target recovery time with you at the very start, alongside the GDPR requirements, instead of discovering it during the first incident.

Questions and answers

The application, its templates, dictionaries and version upgrades belong to the software vendor. We own everything underneath and around it: the server or cloud, the database, backups, network, accounts and security. When a fault sits on the boundary, we contact the vendor ourselves, so you are not left relaying messages between two companies.

Nobody outside the platform operator can fix P1 itself, but your clinic should have a written plan for that day: who issues paper prescriptions and how records are completed afterwards. Losing your own connection is easier to prevent. We remotely configure a router with a 4G backup line, bought from your usual supplier, and the switchover happens automatically.

Usually yes, provided the provider offers adequate security guarantees, you have signed a data processing agreement with it and your DPO or lawyer has confirmed where the data may be held. Keeping it within the European Economic Area is the simplest route. We help you pick the service, check the contract and describe the set-up in your data protection documents, so moving the server does not open a fresh problem.

That turns mainly on the scale at which you process health data, and the assessment is best made with a lawyer. We prepare the technical material the DPO relies on every day: an inventory of systems, permissions and safeguards.

No. Ultrasound scanners, X-ray units and spirometers have their own authorised service. Our job is the network and the computers they plug into: we place devices in a separate segment, restrict their traffic and make sure the workstation next to a scanner cannot become a back door into everything else. If trouble appears at that boundary, we speak to the equipment service team.

Let us look at IT in your practice

Tell us how many doctors consult, which practice software you use and whether you hold an NFZ contract. We reply within one working day and suggest where to begin.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.