Availability Is a Clinical Requirement, Not an SLA Line
A clinic session is booked weeks in advance. Patients travel to it. Clinicians are paid for it. When a clinical system is unreachable at nine in the morning, none of that pauses politely — appointments are cancelled, records are kept on paper, and the reconciliation afterwards costs more than the outage did.
That is the difference between healthcare IT and ordinary business IT. Elsewhere, downtime is inconvenient. Here it has a patient at the end of it.
Nerdster provides managed IT support for private healthcare providers across London that treats clinical availability and data compliance as one job, because in practice they are. The controls that keep records safe are the same controls that let you prove they were safe, and the architecture that keeps a clinic running is the same architecture that survives a ransomware attempt.
Patient Records Deserve a Different Architecture
Patient records are special-category personal data under UK GDPR and the Data Protection Act 2018. That is not a paperwork distinction — it raises the standard of care you owe, and it applies across everywhere the data actually travels: the clinical system, admin and billing, referral correspondence, imaging, and any third party you share with.
So we design for it from the start:
- Role-based access, so staff see what their role needs and no more
- Multi-factor authentication on every account, without exception
- Encryption at rest and in transit
- Audit trails recording who accessed which record, and when
- Governed retention, so deletion is a decision with a record behind it
The Caldicott Principles are a useful discipline here even outside NHS settings: justify the purpose, use the minimum necessary, access on a strict need-to-know basis. Where you have a Caldicott Guardian, we build to support that role. We do not fill it — nor act as your DPO. Those are yours.
Retrofitting these controls onto a live provider is slower, costlier and more disruptive than building them once, correctly.
What Each Regulator Actually Requires
It pays to be precise here, because a lot of healthcare IT marketing blurs these together into a single vague obligation.
CQC registration. Regulated activity in England requires registration, and assessment covers whether information is handled safely and securely as part of safe, well-led care. We provide the technical controls and the records behind them. Registration and inspection remain yours.
NHS DSPT. Mandatory where you access NHS patient data or systems — in practice, an NHS contract or a connection to NHS infrastructure — and submitted annually. If neither applies to you, it is not a legal obligation, and we will tell you that rather than sell you a submission. See our DSPT page for what it involves.
UK GDPR and DPA 2018. These apply to every provider, NHS-facing or not. As a controller of special-category data you need appropriate technical and organisational measures, and a DPIA for high-risk processing. The ICO has been notably more active on health data.
Cyber Essentials. Voluntary, government-backed, and increasingly written into NHS contracts and insurance requirements. Worth having before somebody asks for it rather than during a tender.
Ransomware: Why Healthcare Keeps Getting Hit
Healthcare is targeted disproportionately for an uncomfortable reason — the pressure to restore service quickly is unusually high, and attackers know it.
The defence is not a single product. It is layered security plus a recovery capability you have actually tested: managed and patched endpoints, MFA everywhere, segmented networks so one compromised machine is not the whole estate, monitoring that surfaces the unusual, and backups that are encrypted, isolated and restore-tested.
We are deliberately uncompromising about that last point. A backup nobody has restored is not a recovery plan; it is an assumption. In healthcare it is also a governance failure waiting to be documented.
Clinicians Move. The Data Should Not.
Clinicians work across sites, from home, between organisations, and frequently on their own hardware. Prohibiting that tends to produce workarounds rather than compliance.
The workable approach is to separate access from residency: give clinicians secure, authenticated access to clinical systems without patient records ever landing on an unmanaged device. Managed, encrypted devices where practical; controlled sessions where not. Access tied to identity with MFA, so removing someone is one action rather than a hunt across systems.
One Site or Fifteen — the Same Template
Groups get into trouble when each site is built slightly differently, because compliance posture then drifts and no two clinics fail the same way.
We document site one properly — network build, device baseline, access model, backup, monitoring, and the evidence that supports CQC and UK GDPR — and reuse it. Each new clinic becomes a known deployment: predictable cost, consistent controls, and a group-wide answer when someone asks how patient data is protected.
The Line We Will Not Cross
One thing worth stating plainly, because it comes up.
We do not build software that informs a clinical decision. Triage logic, diagnostic support, risk scoring, dosage calculation — that category of software can meet the legal definition of a medical device and fall under MHRA regulation, bringing conformity assessment, clinical evaluation and post-market surveillance obligations with it.
If a project starts drifting in that direction we will flag it at the point we notice, not after it is built. We support the infrastructure clinical software runs on. We do not write the clinical logic, and we would rather lose that piece of work than hand you a regulatory problem dressed as a web feature.
Sector Pages
This page covers private healthcare providers and clinic groups generally. For sector-specific detail we also maintain pages for dental practices, aesthetics clinics, longevity clinics and pathology and diagnostic laboratories.
If you would like to talk through your clinical systems, patient-record security, or how your IT evidence would read to an inspector, we are glad to discuss it in confidence — at whatever stage you are at.
Need the wider picture? See IT support in London for pricing, response times and compliance posture in one place.
Probably not us if
We would rather say so now than discover it three months in.
- You need clinical decision support, triage logic or anything that influences diagnosis or dosage — that is regulated software and we do not build it.
- You want a provider to act as your Caldicott Guardian or DPO. We supply the technical controls; those roles are yours.
- You are a single-chair dental practice — see our dental page, which is written for you specifically.
- Your organisation sits outside the UK regulatory perimeter — our compliance work is built around CQC, the DSPT and UK GDPR.
