Vai al contenuto

GDPR for medical and dental practices

Health data forms a special category, and that raises the required standard at three specific points.

In breve

In a medical practice the data handled forms a special category, and that changes three concrete things: the security measures have to be proportionate to a high risk, an impact assessment becomes necessary more often than people think, and the threshold for informing patients after a breach is lower. Xion brings together the documentary side and the configurations that support it.

Individual logins, not shared ones

With health data, not being able to say who consulted a record is a serious problem, not a formality.

Diagnostic devices are computers

Scanners, radiology systems and analysers run operating systems the manufacturer does not update. They need isolating, not ignoring.

Documents and configurations together

Adequate measures are not a chapter in a manual: they are permissions, encryption and backups that restore.

Why health data raises the standard

The data a medical or dental practice handles is not ordinary personal data: it forms a special category, and the Regulation asks for it to be treated differently. In practice three things change.

The security measures have to be proportionate to the risk, and with health the risk is high by definition. That means individual rather than shared logins, encrypted devices, a record of who consults what. These are not refinements: they are the proportionate minimum.

An impact assessment becomes necessary more often, because large-scale processing of health data is among the cases identified. Clinics and diagnostic centres fall inside more often than they imagine.

The threshold for informing individuals after a breach is lower. Where health data is involved, the possibility of having to tell patients as well as the authority has to be taken seriously rather than dismissed.

The shared login is the most widespread problem

In almost every practice we visit, the practice system opens with a single login used by everybody. It is convenient, and it is unsustainable with health data.

The reason is not formal. Without individual logins you cannot say who consulted a patient’s record, so you cannot answer a complaint, you cannot restrict access to those with a genuine need to know, and you cannot notice an improper consultation. It is also one of the simplest changes to make, and one of those that shifts the risk most.

The same principle covers revocation: when a member of staff leaves, their access has to be closed. With a shared account there is nothing to close, and the password that person knows stays valid.

Diagnostic devices are the least guarded point

An ultrasound scanner, a radiology system, an analyser each contain a computer running an operating system — and that system is almost always old, because the manufacturer certifies that version and nothing else.

It cannot be updated without losing the certification. It cannot be taken off the network either, because it has to send images to the reporting system. The correct answer is to isolate it: the device stays where it is and carries on working, but in a separate section of the network with precise rules about what it can reach and who can reach it.

It is the measure that reduces risk most in a healthcare setting, it can be done without stopping anything, and in most of the practices we visit it has not been done.

Diagnostic images are the heaviest and most fragile data

They are the kind of archive that grows without stopping, that cannot be recreated, and that often lives on a single disk bought to make room — never inventoried, never included in the backups.

The two checks to make immediately are simple: where every patient’s images actually sit, and when their readability from a copy was last tested. The second question, in our experience, almost always gets the same answer.

Documents and configurations are the same thing

Much of what the Regulation asks of a medical practice is not solved by writing a document: it is solved by configuring. Individual logins, permissions by role, encrypted devices, verified backups, a separate network for the equipment.

That is why treating compliance as the consultant’s paperwork and IT as the technicians’ business produces two pieces of work that do not talk to each other — and why we keep them together, following the same logic as GAPOFF.

The rest

See also GDPR in practice, IT and GDPR for medical and dental practices and IT security for the network separation side.

The first step

A written picture: which data you handle, where it sits, who reaches it, how the networked equipment is protected, and whether the copies genuinely restore. Free and without obligation.

Frequently asked questions

Does a medical practice have to carry out an impact assessment?

One is required where the processing may present a high risk to individuals' rights, and large-scale processing of health data is one of the cases identified. A single surgery may fall outside; a clinic, a diagnostic centre or a practice with many professionals falls inside more often than they think. Where it is unclear, the prudent position is to carry one out in short form - it costs little time and documents that the risk was assessed.

Do we need to appoint a data protection officer?

The obligation applies to anyone processing special categories of data on a large scale, and health data is one. The large-scale threshold is not defined by a precise number and has to be assessed case by case, considering volume, duration and geographical extent. A single dental practice normally falls outside; a multi-professional clinic with a wide catchment deserves serious assessment.

Can we use one shared login to the practice system for the whole practice?

It is the situation we find most often and it is not sustainable with health data. Without individual logins you cannot say who consulted a patient's record, which makes it impossible either to answer a complaint or to restrict access to those with a genuine need to know. It is also the simplest change to make and one of those that most reduces risk.

Are networked diagnostic devices a problem?

They are computers running operating systems the manufacturer certifies in one version only and does not update, so they stay exposed for years. It is not solved by updating them - it is solved by isolating them in a separate section of the network, with precise rules about what they can reach. The device carries on working and sending images where it should, without being an open door to everything else.

A patient asks for their data. How do we respond?

It is a right and it has defined response times, normally one month, extendable in complex cases. The practical difficulty is not responding but knowing where all of that person's data sits - the record in the practice system, diagnostic images, reports, paper consents, correspondence. That is exactly what a record of processing activities is for, kept usefully rather than compiled once and filed away.

Looking for a partner to manage your IT?

Tell us what you need: a Xion consultant will get back to you quickly, and the initial assessment visit is free of charge.