Availability as a clinical requirement, not an SLA line
A clinic session is booked weeks in advance. Patients travel to it. Clinicians are paid for it. When a clinical system is unreachable at nine in the morning, none of that pauses politely — appointments are cancelled, records are kept on paper, and the reconciliation afterwards costs more than the outage did.
That is the difference between healthcare IT and ordinary business IT. Elsewhere, downtime is inconvenient. Here it has a patient at the end of it.
We provide managed IT support for private healthcare providers across London, and we treat clinical availability and data compliance as one job. In practice they are. The controls that keep records safe are the controls that let you prove they were safe. The architecture that keeps a clinic running is the architecture that survives a ransomware attempt.
The architecture patient records actually need
Patient records are special-category personal data under UK GDPR and the Data Protection Act 2018. That is not a paperwork distinction — it raises the standard of care you owe, and it applies across everywhere the data actually travels: the clinical system, admin and billing, referral correspondence, imaging, and any third party you share with.
So we design for it from the start:
- Role-based access, so staff see what their role needs and no more
- Multi-factor authentication on every account, without exception
- Encryption at rest and in transit
- Audit trails recording who accessed which record, and when
- Governed retention, so deletion is a decision with a record behind it
The Caldicott Principles are a useful discipline here even outside NHS settings: justify the purpose, use the minimum necessary, access on a strict need-to-know basis. Where you have a Caldicott Guardian, we build to support that role rather than fill it, and the same applies to your DPO. Both remain your appointments.
Retrofitting these controls onto a live provider is slower, costlier and more disruptive than building them once, correctly.
What each healthcare regulator actually requires
It pays to be precise here, because these four are easily bundled together into a single vague obligation.
CQC registration. Regulated activity in England requires registration, and assessment covers whether information is handled safely and securely as part of safe, well-led care. We provide the technical controls and the records behind them. Registration and inspection remain yours.
NHS DSPT. Mandatory where you access NHS patient data or systems — in practice, an NHS contract or a connection to NHS infrastructure — and submitted annually. If neither applies to you, it is not a legal obligation, and we will say so before you spend anything on it. See our DSPT page for what it involves.
UK GDPR and DPA 2018. These apply to every provider, NHS-facing or not. As a controller of special-category data you need appropriate technical and organisational measures, and a DPIA for high-risk processing. The ICO has been notably more active on health data.
Cyber Essentials. Voluntary, government-backed, and increasingly written into NHS contracts and insurance requirements. Worth having before somebody asks for it rather than during a tender.
Why ransomware keeps finding healthcare
Healthcare is targeted disproportionately for an uncomfortable reason — the pressure to restore service quickly is unusually high, and attackers know it.
The defence is not a single product. It is layered security plus a recovery capability you have actually tested: managed and patched endpoints, MFA everywhere, segmented networks so one compromised machine is not the whole estate, monitoring that surfaces the unusual, and backups that are encrypted, isolated and restore-tested.
We are deliberately uncompromising about that last point. A backup nobody has restored is not a recovery plan; it is an assumption. In healthcare it is also a governance failure waiting to be documented.
Clinician mobility without the data moving with them
Clinicians work across sites, from home, between organisations, and frequently on their own hardware. Prohibiting that tends to produce workarounds rather than compliance.
The workable approach is to separate access from residency: give clinicians secure, authenticated access to clinical systems without patient records ever landing on an unmanaged device. Managed, encrypted devices where practical; controlled sessions where not. Access tied to identity with MFA, so removing someone is one action rather than a hunt across systems.
Site fifteen opened the same way as site one
Groups get into trouble when each site is built slightly differently, because compliance posture then drifts and no two clinics fail the same way.
We document site one properly — network build, device baseline, access model, backup, monitoring, and the evidence that supports CQC and UK GDPR — and reuse it. Each new clinic becomes a known deployment: predictable cost, consistent controls, and a group-wide answer when someone asks how patient data is protected.
Where regulated medical software begins
This comes up often enough to be worth setting out clearly.
We do not build software that informs a clinical decision. Triage logic, diagnostic support, risk scoring, dosage calculation — that category of software can meet the legal definition of a medical device and fall under MHRA regulation, bringing conformity assessment, clinical evaluation and post-market surveillance obligations with it.
If a project starts drifting in that direction we will flag it at the point we notice, not after it is built — early enough for you to plan a proper regulatory route or take a different approach. We support the infrastructure clinical software runs on. The clinical logic itself belongs with a developer set up to carry conformity assessment and post-market surveillance, and we are glad to help you work out who that should be.
IT support by healthcare sector
This page covers private healthcare providers and clinic groups generally. For sector-specific detail we also maintain pages for dental practices, aesthetics clinics, longevity clinics and pathology and diagnostic laboratories.
If you would like to talk through your clinical systems, patient-record security, or how your IT evidence would read to an inspector, we are glad to discuss it in confidence — at whatever stage you are at.
Need the wider picture? See IT support in London for pricing, response times and compliance posture in one place.
When another approach fits better
If any of these describe you, we are glad to point you somewhere better suited.
- You need clinical decision support, triage logic or anything that influences diagnosis or dosage — that is regulated software and we do not build it.
- You want a provider to act as your Caldicott Guardian or DPO. We supply the technical controls; those roles are yours.
- You are a single-chair dental practice — our dental page covers that setup in more detail.
- Your organisation sits outside the UK regulatory perimeter — our compliance work is built around CQC, the DSPT and UK GDPR.
