Why health data raises the standard
The data a medical or dental practice handles is not ordinary personal data: it forms a special category, and the Regulation asks for it to be treated differently. In practice three things change.
The security measures have to be proportionate to the risk, and with health the risk is high by definition. That means individual rather than shared logins, encrypted devices, a record of who consults what. These are not refinements: they are the proportionate minimum.
An impact assessment becomes necessary more often, because large-scale processing of health data is among the cases identified. Clinics and diagnostic centres fall inside more often than they imagine.
The threshold for informing individuals after a breach is lower. Where health data is involved, the possibility of having to tell patients as well as the authority has to be taken seriously rather than dismissed.
The shared login is the most widespread problem
In almost every practice we visit, the practice system opens with a single login used by everybody. It is convenient, and it is unsustainable with health data.
The reason is not formal. Without individual logins you cannot say who consulted a patient’s record, so you cannot answer a complaint, you cannot restrict access to those with a genuine need to know, and you cannot notice an improper consultation. It is also one of the simplest changes to make, and one of those that shifts the risk most.
The same principle covers revocation: when a member of staff leaves, their access has to be closed. With a shared account there is nothing to close, and the password that person knows stays valid.
Diagnostic devices are the least guarded point
An ultrasound scanner, a radiology system, an analyser each contain a computer running an operating system — and that system is almost always old, because the manufacturer certifies that version and nothing else.
It cannot be updated without losing the certification. It cannot be taken off the network either, because it has to send images to the reporting system. The correct answer is to isolate it: the device stays where it is and carries on working, but in a separate section of the network with precise rules about what it can reach and who can reach it.
It is the measure that reduces risk most in a healthcare setting, it can be done without stopping anything, and in most of the practices we visit it has not been done.
Diagnostic images are the heaviest and most fragile data
They are the kind of archive that grows without stopping, that cannot be recreated, and that often lives on a single disk bought to make room — never inventoried, never included in the backups.
The two checks to make immediately are simple: where every patient’s images actually sit, and when their readability from a copy was last tested. The second question, in our experience, almost always gets the same answer.
Documents and configurations are the same thing
Much of what the Regulation asks of a medical practice is not solved by writing a document: it is solved by configuring. Individual logins, permissions by role, encrypted devices, verified backups, a separate network for the equipment.
That is why treating compliance as the consultant’s paperwork and IT as the technicians’ business produces two pieces of work that do not talk to each other — and why we keep them together, following the same logic as GAPOFF.
The rest
See also GDPR in practice, IT and GDPR for medical and dental practices and IT security for the network separation side.
The first step
A written picture: which data you handle, where it sits, who reaches it, how the networked equipment is protected, and whether the copies genuinely restore. Free and without obligation.