Solution · By sector

Medical practices and healthcare

The practice assistant unlocks the door at 7:30 and from that moment everything has to work: insert the e-card, open the patient record, pull the lab result, issue the e-prescription. If the practice software freezes or a workstation loses the server, the waiting room fills up within minutes. We look after the IT of GP surgeries, group practices, dental practices, physiotherapists and psychotherapists, entirely through remote access. And we treat health data the way the GDPR expects: as a special category that deserves more protection than a customer mailing list.

Art. 9
GDPR: health data belongs to the special categories
72 h
deadline for reporting a personal data breach to the DSB
15 min
response time on the Premium plan
0
engineer visits to your practice, as everything is done remotely

What we take care of

Five areas that matter in almost every practice. Some keep the daily surgery running; the rest make sure you are on solid ground with patients, the Medical Chamber and the DSB.

Send an enquiry

Practice software and servers

Whether the records sit on a small server in the storeroom or in the vendor's cloud, the OS, the database engine, patching and alerting are ours to look after. Before a major version change we prepare the workstations; afterwards we check that billing, forms, scanners and the links to ELGA and e-Befund still behave. What the program does internally remains the vendor's responsibility.

Who can open which record

Individual logins in place of one shared “reception” account, permissions matched to each role, screens that lock when someone steps away, encrypted laptops for home visits and a record of every look-up. Should a patient want to know who opened her chart, you have evidence to show her instead of a shrug.

Backing up patient data

Several backups a day, one copy held outside the practice where ransomware cannot reach it, and restore tests at regular intervals. Medical records are subject to long statutory retention periods. Which ones apply to you is best confirmed with the Chamber or a lawyer; we turn the answer into technical retention rules.

Results, appointments and messages

Findings leave the practice encrypted or through the health networks designed for them, never as an ordinary email attachment and certainly not via a personal messenger app. Online booking asks only for what is strictly needed, and both the online booking provider and the text-message reminder tool have signed a processing agreement.

Workstations and network

PCs at reception and in the consulting rooms, printers, card readers plus visitor Wi-Fi in the waiting area that cannot see a single internal device. Updates and faults are dealt with remotely. Clinical devices like ultrasound or X-ray units remains with its manufacturer or their authorised service partner.

Where we begin

First, anything that could bring surgery hours to a halt. Then the paperwork you will need when a patient requests access to her data or the DSB gets in touch.

01

Overview

Where do the records live, where are the scanned consent forms, who reaches them and how, and what data travels to labs, referring doctors or hospitals?

02

Risks and contracts

We assess the risks around the health data, go through the agreements with your software supplier, hosting company and booking service, and bring the register of processing up to date. Where a DPIA is needed, we contribute the IT chapter.

03

Hardening

Personal accounts, multi-factor sign-in, encryption, tested backups and a fallback line. We deploy in time slots agreed with you in advance, so no appointment has to move.

04

Ongoing care

Helpdesk cover Monday to Friday, 8:00-17:00 Austrian time, backups verified every morning and permissions revisited whenever staff change, say an assistant starting parental leave or a locum covering the holidays.

An inspection by the DSB is rare; a dead patient database is not. Take a general practice in Linz with two health insurance contracts and a packed waiting room on a Monday. Sixty minutes without the database leaves the team shuffling bookings, unable to prescribe and apologising at the desk. That is why we agree at the outset how quickly the records must be back after an outage, and size the backup and fallback line to match.

Frequently asked questions

Content such as service catalogues, forms, text templates and billing rules is maintained by the vendor or its reseller. Our remit is the platform it runs on and everything surrounding it, from hosting and database to backup, networking, accounts and protection. If a problem straddles both sides, we contact the vendor directly and spare you the role of go-between.

That depends mostly on how much data you process. A single-doctor surgery is often assessed differently from a large outpatient clinic or a group practice spread over several sites. Whether the duty applies to you should be confirmed by the Chamber or a lawyer. Whatever the outcome, we hand over the material a DPO relies on: an inventory of systems, who can access what, a summary of protective measures and access logs that can be exported.

As a rule it is, on condition that the provider enters into a processing agreement, encrypts everything and can demonstrate that storage stays in Austrian or other EU data centres. The Health Telematics Act (GTelG) adds its own rules for electronic exchange; check the details with the Chamber or a lawyer. Apply does not host patient records itself. We help you pick a provider, read the contract with you, plan the move and document the set-up for your data protection records.

Nobody in a practice can prevent a regional outage at the provider, so a written fallback procedure is part of the package: how do you treat patients without the records, and how do you catch up afterwards? A fault on your own line, by contrast, can be bridged quickly. We configure a router with an LTE or 5G backup connection, you order the SIM card from your provider, and the switch-over happens automatically.

No. Servicing and testing ultrasound, X-ray, ECG or intraoral scanners stays with the manufacturer or its service partner. Our part is the network and the PC the device is plugged into: a separate network segment, only the connections it needs and no open remote access for third parties. An old PC attached to a scanner therefore cannot become the route attackers use to reach everything else.

No, and it is not something we offer: all our work is remote. Hands-on tasks, like re-plugging a cable or exchanging a router, are carried out by one of your staff with our engineer guiding on video, or by an electrician you already know. For a physio practice with a pair of treatment rooms, swapping a network switch like this fits comfortably into a lunch break.

Let us take a look at your practice IT

Tell us how many doctors and therapists work with you, which practice software you use and where your data is kept today. We will reply within one working day with an initial proposal.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.