Solution · By sector

Healthcare and clinics

By the time a patient sits down, reception has already done a fair amount: pulled up the electronic record, confirmed the appointment, checked the insurer's policy and got the e-prescription from last time ready to renew. If any one of those steps fails, patients pile up in the waiting area and the front desk spends the morning apologising. We keep all of it working remotely throughout the clinic day, for GP practices, dental clinics, physiotherapy, psychology and aesthetics centres. And we handle health data for what the GDPR says it is: sensitive information deserving more care than anything else you hold.

Art. 9
of the GDPR places health data in a special category
100 %
remote, with no visits to your premises
72 h
to notify the AEPD of a personal data breach
15 min
for us to react when you are on Premium

What we look after

Five fronts. Some keep today's diary on track, others cover what you owe patients and the Spanish data protection authority. We connect through encrypted remote sessions, ideally once the last patient has gone.

Send an enquiry

Practice software and patient records

A server in the comms cupboard or a cloud-based package, its database, updates and monitoring. We track the digital certificates clinicians use to sign private e-prescriptions and reports, so an expired one does not stop a doctor prescribing at nine on a Monday. When the vendor ships a new release, we prepare the machines beforehand and confirm afterwards that the diary, insurer billing and tablet-signed consent forms still behave.

Who opens which record

One login per person instead of a shared “reception1” used across three shifts, permissions matched to the actual job (the hygienist has no need to see billing), a second authentication factor, encrypted laptops for clinicians and an access log you can consult when a patient asks who has looked at their file.

Backups of clinical records

The database copied several times a day, an off-site copy that ransomware cannot encrypt, and trial restores as often as the contract says. Spain's patient autonomy law (Law 41/2002) sets minimum retention periods for clinical records; you decide the retention policy with your adviser or DPO, and we turn it into technical rules.

Reports, results and appointments

Results and X-rays sent over an encrypted channel instead of as a plain email attachment or through someone's personal WhatsApp, rules that catch an ID number or diagnosis sent by mistake, an online booking form trimmed to the fields you really need, and processor agreements signed with the booking platform and the SMS reminder service.

Everyday front desk

Reception and surgery computers, printers, card terminals, and patient Wi-Fi kept apart from the internal network. We patch and troubleshoot from a distance. Medical equipment such as an ultrasound unit or intraoral scanner stays with its official service provider.

Where we begin

Anything able to stop appointments comes first. After that, the documents a patient using their right of access, or an AEPD inspector, might request.

01

Where the data lives

Where the clinical record lives, where X-rays and scanned consent forms are kept, who gets in, and how information reaches the laboratory, the insurer or a specialist you refer to.

02

Risks and agreements

Assessing the risks around health data, checking the contracts with the software vendor, hosting provider and booking platform, and an updated record of processing activities. Where a DPIA is needed, we write the technical section.

03

Getting it right

Individual accounts, MFA, disk encryption, backups whose restores are proven, plus a secondary internet line. We roll changes out after the last patient of the day or on a Saturday, so the diary is never touched.

04

Continuous follow-up

A helpdesk during opening hours, a daily look at the backups and a periodic permissions review, say when a nurse leaves or a locum dentist joins for the summer.

An AEPD inspection is unlikely; the practice software going down is far less so. Take a dental clinic in Seville with four surgeries: an hour without records means rescheduled appointments, treatment quotes nobody can pull up and a phone that never stops. That is why the recovery time gets agreed at the outset, together with the GDPR measures, and not after the first outage.

Common questions

The application itself, with its treatment lists, report templates, fee schedules and releases, belongs to the vendor. We take responsibility for everything beneath and around it: server or cloud, database, backups, network, user accounts and security. If a problem straddles both, we raise it with the vendor's support team on your behalf, so you never have to act as go-between.

Spain's data protection act, the LOPDGDD, lists healthcare centres that are required to keep clinical records among those that must appoint one, with an exception for practitioners working on their own account. Whether you fall inside that rule is for a legal adviser to confirm. What we can supply is the material a DPO relies on day to day: a systems inventory, a permissions list, a description of security measures and exportable access logs.

Yes, with a provider that signs a processor agreement, encrypts the data and gives clear commitments about where it is stored; keeping it inside the European Economic Area makes things simplest. Apply is not a hosting provider. We can shortlist suitable ones, go through the contract, plan the migration and describe the arrangement in your GDPR documentation.

A wide-scale carrier outage is beyond anyone at the clinic, so write down in advance what the team does then: how patients are seen without the record and how it is filled in later. An outage on your own line, on the other hand, can be kept short. We set up a router that fails over to a 4G or 5G SIM, which you take out with your carrier; the switch then happens by itself.

No. An ultrasound machine, an X-ray unit or an intraoral scanner is maintained by its authorised service engineer. Our job covers the network segment and the PC attached to the device: we isolate it in its own segment, restrict the connections it may make and stop it becoming a way into the rest of the clinic. If a fault spans both sides, we speak to that engineer directly.

No, and we do not offer site visits: all the work is remote. If something physical has to be done, such as plugging in a box or swapping a cable, a member of your team does it with our engineer on a video call, or the installer you already use takes care of it. For example, at a physiotherapy practice with two treatment rooms, replacing the network switch takes around twenty minutes over lunch, with someone from reception following the instructions.

Let us review your clinic's IT

Tell us how many clinicians see patients, which practice software you use and where your data sits today. We will reply within one working day with a first outline.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.