A medical practice is an unusual kind of business to run IT for. It holds some of the most sensitive information a person has, it cannot easily stop seeing patients while a system is fixed, and the people running it are trained to look after patients, not servers. This guide sets out what good IT support looks like for a GP, dentist, specialist or vet practice in South Africa: what POPIA expects of you, the real risks, how to protect patient records, how to keep working when the power or internet goes down, and a calculator that shows what an outage costs your practice. IT-Support-SA provides IT support from Pietermaritzburg for businesses across KwaZulu-Natal and the rest of South Africa. This article is general information, not legal advice.
The Short Answer
A practice needs five things to be in good IT shape: patient records that are backed up and proven to restore, protection against ransomware and phishing with multi-factor authentication, an individual login for every person so access is traceable, a plan for power and internet failure, and someone who supports your practice software and your staff quickly. POPIA does not prescribe the tools, but it requires reasonable security for the information you hold, and health information gets the strictest treatment.
Why Practices Are Different
Three things make practice IT harder than ordinary office IT:
- The data is special. Health information is special personal information under POPIA, and a breach affects patients’ dignity and trust, not just your finances.
- Downtime is immediate. A patient is in the chair or the room. If you cannot open a record, book, bill or send a prescription, the whole schedule slips.
- The system is specialised. Practice management software, imaging, lab links and medical-aid billing are all connected, and fixing one without breaking another needs care.
What POPIA Expects of a Practice
POPIA applies to every practice as a responsible party. A few points matter most:
- Health information is special personal information. Section 26 restricts processing it, but Section 32 allows medical professionals and healthcare institutions to process it as needed for the proper treatment and care of the patient. That covers using records for care. It does not relax the duty to secure them.
- Section 19 requires reasonable security. Appropriate technical and organisational measures to prevent loss, damage and unauthorised access. For a practice that means access control, encryption, backups, patching and endpoint protection.
- Section 21 covers outsourcing. If a supplier, such as your IT provider, billing service or cloud host, handles patient information for you, you need a written agreement requiring them to secure it.
- Section 22 covers breaches. If personal information may have been accessed by an unauthorised person, you must notify the Information Regulator and the affected people as soon as reasonably possible.
- Section 72 covers sending data abroad. Some cloud services store data outside South Africa. Ask where, and on what basis.
Professional rules apply on top. The Health Professions Council’s guidance on confidentiality and record keeping, and the National Health Act’s confidentiality provisions, carry their own expectations, so treat the POPIA checklist as a floor, not the full picture. Our POPIA IT compliance checklist covers the technical measures in more detail.
The Real Risks
Ransomware
Criminals can target practices because the data is valuable and the pressure to pay is high. One click on a fake invoice or a fake delivery email can lock the practice management system and every file with it, and the threat to publish patient records makes it a breach as well as an outage. Our guide to ransomware protection explains the layers that stop it, and our guide to data recovery covers what to do when it is already too late.
Backups that have never been tested
A failed server or disk is not an emergency if you can restore. It is a disaster if the backup stopped working six months ago and nobody noticed. Practices need backups that run automatically, stored off-site, with a restore actually tested every quarter. Our guide to cloud backup explains the 3-2-1 rule. Because records must be retained for years, also confirm that old backups remain readable, not only recent ones.
Shared logins
When the whole practice uses one password, nobody can say who opened a patient’s file, and a departing employee keeps access. Every person needs their own account, with rights matching their role: reception does not need clinical notes, and a locum does not need the billing system. Our IT offboarding checklist covers what to switch off when someone leaves.
Power and internet
South Africa’s power cuts and unreliable connections are an everyday threat, and a practice cannot reschedule a root canal. Our guide to load shedding and business IT backup power explains how to size a UPS and plan for a server, router and card machine.
Out-of-date systems
Unsupported software is a known weakness that attackers look for. If your practice system or its computers run on Windows 10, the end of support is a real deadline: see our Windows 10 end of support guide.
Patient messages in the wrong place
Patients expect to reach you on WhatsApp. Used carefully it works. Use a business number rather than a personal phone, send only the minimum clinical detail, avoid results and diagnoses unless the patient has agreed, and keep the conversation on a device the practice controls. If a staff member leaves with the patient conversations on their phone, those records have left with them.
What an Outage Really Costs
Before you decide what to spend on IT, find out what not spending costs. Set the sliders to match a normal day at your practice.
The first thing most owners notice is how fast an hour adds up, and how little of the cost is the IT itself. The second is the long tail: the three-day scenario, which is what a ransomware attack or a server rebuilt from scratch can look like, costs many times a one-hour fault. The calculator deliberately leaves out medical-aid claim delays, patient goodwill, recovery costs and any consequences of a breach, all of which come on top. Be honest about the “share that could carry on by hand” slider: it only counts appointments you could really keep going with paper notes and a handwritten diary.
A Practical Checklist for Your Practice
- Individual logins and multi-factor authentication for email, the practice system and remote access.
- Automatic off-site backups, and a restore test every quarter that you or your IT provider records.
- Patching and endpoint protection on every computer, including the one in the back office.
- A UPS on the router, the computers and the card machine, and a UPS plus clean-shutdown plan for any server.
- A mobile data backup so cards and cloud systems keep working when the line drops.
- A written incident plan: who to call, what to disconnect, how to notify patients and the Information Regulator, and where the paper fallback forms are kept.
- A supplier agreement with anyone who handles patient data for you, covering security and breach notification.
- A starter and leaver process so access matches the job on day one and is removed on the last day.
- Staff training on phishing, since one person opening one email is how most attacks begin.
- A short written IT and AI acceptable-use policy: what staff may put into messaging apps and AI tools, and what they must never paste, which includes patient information.
Working With Your Practice Software Vendor
Practice management systems have their own vendors, support lines and update schedules, and your IT provider should work alongside them, not in place of them. A good arrangement looks like this: the vendor looks after the software and its database, your IT provider looks after the machines, network, backups, security and user accounts around it, and both know who to call for what. Before any update, make sure a backup has been taken. Ask the vendor what hardware and operating-system versions they support, so you are not surprised when an upgrade is required.
Choosing IT Support for a Practice
Ask any provider you consider:
- How fast will you respond when we cannot open patient records, and how is that measured?
- Do you test restores, and can we see the last result?
- How is access controlled, and who at your company can see our data?
- Where is our data stored, and do you sign an operator agreement?
- What happens during load shedding and how do you help us plan for it?
- Who do we call after hours and on a clinic day?
- Have you supported practices before, and are you comfortable working with our software vendor?
Our guide to what IT support costs in South Africa explains how the main pricing models compare.
How IT-Support-SA Can Help
We support practices with managed IT: proactive monitoring and patching, backups that are tested by restoring, ransomware and phishing protection, multi-factor authentication and user access, help for staff when something breaks, and planning for power and internet failure. We can review how your practice stands against the checklist above and give you a plain list of gaps in order of importance. See our IT support services or get in touch and tell us how your practice runs today. We support practices across Pietermaritzburg, the KZN Midlands, Durban, Ladysmith, Johannesburg, Cape Town and all 9 provinces of South Africa.
Mistakes That Put Practices at Risk
- Never testing a restore until the day it is needed.
- One shared login for the whole front desk.
- No UPS on the router or the card machine, so a power cut stops billing.
- Patient details on a personal phone with no plan for when that person leaves.
- Running unsupported software because it still works.
- No agreement with the suppliers who handle patient data.
- No written incident plan, so the first breach is also the first time anyone decides what to do.
- Treating IT as a cost to minimise rather than the system the whole day runs on.
Conclusion
A practice’s IT does not need to be complicated, but it does need to be dependable. Back up and prove the restore, give every person their own login with multi-factor authentication, keep software patched, plan for power and internet failure, secure the data in line with POPIA, and know who to call when something breaks mid-clinic. Do those things and an outage becomes an inconvenience rather than a crisis.
If you would like a practical review of your practice’s IT, contact IT-Support-SA or WhatsApp us.