IT Support

IT Support for Medical Practices in South Africa: Patient Data, Backups and Downtime

IT-Support-SA Team 12 min read
In this article
  1. 01 The Short Answer
  2. 02 Why Practices Are Different
  3. 03 What POPIA Expects of a Practice
  4. 04 The Real Risks
  5. 05 What an Outage Really Costs
  6. 06 A Practical Checklist for Your Practice
  7. 07 Working With Your Practice Software Vendor
  8. 08 Choosing IT Support for a Practice
  9. 09 How IT-Support-SA Can Help
  10. 10 Mistakes That Put Practices at Risk
  11. 11 Conclusion

A medical practice is an unusual kind of business to run IT for. It holds some of the most sensitive information a person has, it cannot easily stop seeing patients while a system is fixed, and the people running it are trained to look after patients, not servers. This guide sets out what good IT support looks like for a GP, dentist, specialist or vet practice in South Africa: what POPIA expects of you, the real risks, how to protect patient records, how to keep working when the power or internet goes down, and a calculator that shows what an outage costs your practice. IT-Support-SA provides IT support from Pietermaritzburg for businesses across KwaZulu-Natal and the rest of South Africa. This article is general information, not legal advice.

The Short Answer

A practice needs five things to be in good IT shape: patient records that are backed up and proven to restore, protection against ransomware and phishing with multi-factor authentication, an individual login for every person so access is traceable, a plan for power and internet failure, and someone who supports your practice software and your staff quickly. POPIA does not prescribe the tools, but it requires reasonable security for the information you hold, and health information gets the strictest treatment.

Why Practices Are Different

Three things make practice IT harder than ordinary office IT:

  • The data is special. Health information is special personal information under POPIA, and a breach affects patients’ dignity and trust, not just your finances.
  • Downtime is immediate. A patient is in the chair or the room. If you cannot open a record, book, bill or send a prescription, the whole schedule slips.
  • The system is specialised. Practice management software, imaging, lab links and medical-aid billing are all connected, and fixing one without breaking another needs care.

What POPIA Expects of a Practice

POPIA applies to every practice as a responsible party. A few points matter most:

  • Health information is special personal information. Section 26 restricts processing it, but Section 32 allows medical professionals and healthcare institutions to process it as needed for the proper treatment and care of the patient. That covers using records for care. It does not relax the duty to secure them.
  • Section 19 requires reasonable security. Appropriate technical and organisational measures to prevent loss, damage and unauthorised access. For a practice that means access control, encryption, backups, patching and endpoint protection.
  • Section 21 covers outsourcing. If a supplier, such as your IT provider, billing service or cloud host, handles patient information for you, you need a written agreement requiring them to secure it.
  • Section 22 covers breaches. If personal information may have been accessed by an unauthorised person, you must notify the Information Regulator and the affected people as soon as reasonably possible.
  • Section 72 covers sending data abroad. Some cloud services store data outside South Africa. Ask where, and on what basis.

Professional rules apply on top. The Health Professions Council’s guidance on confidentiality and record keeping, and the National Health Act’s confidentiality provisions, carry their own expectations, so treat the POPIA checklist as a floor, not the full picture. Our POPIA IT compliance checklist covers the technical measures in more detail.

The Real Risks

Ransomware

Criminals can target practices because the data is valuable and the pressure to pay is high. One click on a fake invoice or a fake delivery email can lock the practice management system and every file with it, and the threat to publish patient records makes it a breach as well as an outage. Our guide to ransomware protection explains the layers that stop it, and our guide to data recovery covers what to do when it is already too late.

Backups that have never been tested

A failed server or disk is not an emergency if you can restore. It is a disaster if the backup stopped working six months ago and nobody noticed. Practices need backups that run automatically, stored off-site, with a restore actually tested every quarter. Our guide to cloud backup explains the 3-2-1 rule. Because records must be retained for years, also confirm that old backups remain readable, not only recent ones.

Shared logins

When the whole practice uses one password, nobody can say who opened a patient’s file, and a departing employee keeps access. Every person needs their own account, with rights matching their role: reception does not need clinical notes, and a locum does not need the billing system. Our IT offboarding checklist covers what to switch off when someone leaves.

Power and internet

South Africa’s power cuts and unreliable connections are an everyday threat, and a practice cannot reschedule a root canal. Our guide to load shedding and business IT backup power explains how to size a UPS and plan for a server, router and card machine.

Out-of-date systems

Unsupported software is a known weakness that attackers look for. If your practice system or its computers run on Windows 10, the end of support is a real deadline: see our Windows 10 end of support guide.

Patient messages in the wrong place

Patients expect to reach you on WhatsApp. Used carefully it works. Use a business number rather than a personal phone, send only the minimum clinical detail, avoid results and diagnoses unless the patient has agreed, and keep the conversation on a device the practice controls. If a staff member leaves with the patient conversations on their phone, those records have left with them.

What an Outage Really Costs

Before you decide what to spend on IT, find out what not spending costs. Set the sliders to match a normal day at your practice.

INTERACTIVE CALCULATOR
What does an outage cost your practice?
Set the sliders to match a normal day. Results update as you move them.
At these numbers your practice sees about 9 patients an hour.
One hour down R4,290
6.8 consultations not billed (R4,050) plus R240 of idle staff time. Usual cause: A router or internet fault, or a power cut with no UPS.
Half a day down R17,160
27 consultations not billed (R16,200) plus R960 of idle staff time. Usual cause: A failed server, disk or practice-software update.
A full day down R34,320
54 consultations not billed (R32,400) plus R1,920 of idle staff time. Usual cause: A hardware failure that needs a part or a restore from backup.
Three working days down R102,960
162 consultations not billed (R97,200) plus R5,760 of idle staff time. Usual cause: A ransomware attack or a restore that has to be rebuilt from scratch.
Illustrative estimates from the numbers you set. Lost billing assumes appointments that cannot continue are not simply rebooked, so your real loss may be lower. It also leaves out medical-aid claim delays, patient goodwill, recovery costs and any regulatory consequences of a data breach.

The first thing most owners notice is how fast an hour adds up, and how little of the cost is the IT itself. The second is the long tail: the three-day scenario, which is what a ransomware attack or a server rebuilt from scratch can look like, costs many times a one-hour fault. The calculator deliberately leaves out medical-aid claim delays, patient goodwill, recovery costs and any consequences of a breach, all of which come on top. Be honest about the “share that could carry on by hand” slider: it only counts appointments you could really keep going with paper notes and a handwritten diary.

A Practical Checklist for Your Practice

  1. Individual logins and multi-factor authentication for email, the practice system and remote access.
  2. Automatic off-site backups, and a restore test every quarter that you or your IT provider records.
  3. Patching and endpoint protection on every computer, including the one in the back office.
  4. A UPS on the router, the computers and the card machine, and a UPS plus clean-shutdown plan for any server.
  5. A mobile data backup so cards and cloud systems keep working when the line drops.
  6. A written incident plan: who to call, what to disconnect, how to notify patients and the Information Regulator, and where the paper fallback forms are kept.
  7. A supplier agreement with anyone who handles patient data for you, covering security and breach notification.
  8. A starter and leaver process so access matches the job on day one and is removed on the last day.
  9. Staff training on phishing, since one person opening one email is how most attacks begin.
  10. A short written IT and AI acceptable-use policy: what staff may put into messaging apps and AI tools, and what they must never paste, which includes patient information.

Working With Your Practice Software Vendor

Practice management systems have their own vendors, support lines and update schedules, and your IT provider should work alongside them, not in place of them. A good arrangement looks like this: the vendor looks after the software and its database, your IT provider looks after the machines, network, backups, security and user accounts around it, and both know who to call for what. Before any update, make sure a backup has been taken. Ask the vendor what hardware and operating-system versions they support, so you are not surprised when an upgrade is required.

Choosing IT Support for a Practice

Ask any provider you consider:

  • How fast will you respond when we cannot open patient records, and how is that measured?
  • Do you test restores, and can we see the last result?
  • How is access controlled, and who at your company can see our data?
  • Where is our data stored, and do you sign an operator agreement?
  • What happens during load shedding and how do you help us plan for it?
  • Who do we call after hours and on a clinic day?
  • Have you supported practices before, and are you comfortable working with our software vendor?

Our guide to what IT support costs in South Africa explains how the main pricing models compare.

How IT-Support-SA Can Help

We support practices with managed IT: proactive monitoring and patching, backups that are tested by restoring, ransomware and phishing protection, multi-factor authentication and user access, help for staff when something breaks, and planning for power and internet failure. We can review how your practice stands against the checklist above and give you a plain list of gaps in order of importance. See our IT support services or get in touch and tell us how your practice runs today. We support practices across Pietermaritzburg, the KZN Midlands, Durban, Ladysmith, Johannesburg, Cape Town and all 9 provinces of South Africa.

Mistakes That Put Practices at Risk

  • Never testing a restore until the day it is needed.
  • One shared login for the whole front desk.
  • No UPS on the router or the card machine, so a power cut stops billing.
  • Patient details on a personal phone with no plan for when that person leaves.
  • Running unsupported software because it still works.
  • No agreement with the suppliers who handle patient data.
  • No written incident plan, so the first breach is also the first time anyone decides what to do.
  • Treating IT as a cost to minimise rather than the system the whole day runs on.

Conclusion

A practice’s IT does not need to be complicated, but it does need to be dependable. Back up and prove the restore, give every person their own login with multi-factor authentication, keep software patched, plan for power and internet failure, secure the data in line with POPIA, and know who to call when something breaks mid-clinic. Do those things and an outage becomes an inconvenience rather than a crisis.

If you would like a practical review of your practice’s IT, contact IT-Support-SA or WhatsApp us.

Frequently Asked Questions

Does POPIA apply to a medical practice?
Yes. A practice is a responsible party and must secure the personal information it holds. Health information is special personal information, which POPIA treats more strictly, although Section 32 allows medical professionals and healthcare institutions to process it as needed for the proper treatment and care of the patient. That permission covers using the information for care. It does not remove the duty to keep it secure, which is where IT comes in. This is general information, not legal advice.
What are the biggest IT risks for a doctor's or dentist's practice?
Ransomware that locks patient records and the practice management system, a failed server or disk with no tested backup, a power cut during a clinic day, shared logins that mean nobody can say who opened a record, and patient information sent over personal WhatsApp or email. Most can be prevented with ordinary measures: tested backups, a UPS, individual logins, multi-factor authentication and patched software.
How long must a practice keep patient records, and how does that affect backups?
Professional guidance from the Health Professions Council of South Africa has generally required records to be kept for a minimum period, commonly stated as at least six years, and longer for minors and some other cases. Check the current guidance for your profession, because it can change. For IT, this means backups and archives must retain records for that long and remain readable, which is a different requirement from keeping last week's backup.
Is it safe to use WhatsApp to communicate with patients?
It is convenient and widely used, but it needs care. Use a business number, not a personal phone, send the minimum clinical detail, avoid sending results or diagnoses unless the patient has agreed and understands the risk, and keep conversations on a device the practice controls so they stay with the practice when a staff member leaves. Marketing messages need opt-in consent under Section 69 of POPIA.
What should I do if patient records are lost or accessed by someone they should not be?
Contain it first: disconnect affected devices, change passwords and preserve logs. Then establish what was affected. If personal information may have been accessed or acquired by an unauthorised person, Section 22 of POPIA requires you to notify the Information Regulator and the affected people as soon as reasonably possible. Involve your IT provider and, for anything serious, a legal adviser. Having a written response plan beforehand makes this far easier.
Can a practice run on cloud systems during load shedding and outages?
Cloud systems depend on internet and power at the practice, so they do not remove the problem, but they change it: patient data is safe off-site and you can work from anywhere with a connection. Pair a cloud practice system with a UPS for the router, computers and card machine, plus a mobile data backup connection. A local server needs its own UPS and a clean shutdown plan.
What does good IT support for a medical practice include?
Proactive monitoring and patching, backups that are tested by restoring, protection against ransomware and phishing, multi-factor authentication, individual user accounts and a record of who can see what, support for the practice management software and its vendor, help for staff when things break, a plan for power and internet failure, and someone to call who understands that a practice cannot wait until tomorrow.

Need help with your IT?

Get a free IT audit from South Africa's trusted IT partner — no obligation, no jargon, just straight answers.

Related Articles