In a medical practice, IT touches the most sensitive thing there is: patients
Appointment books, records, reports, billing, recalls: it all runs through the systems — and it all concerns health data, the category the GDPR protects most closely. Xion IT Group works with medical and dental practices and clinics with an approach that brings together continuity, security and privacy compliance.
What we do for medical practices
- GDPR for health data — privacy notices, record of processing, appointments, supplier management and training (the service);
- Backup and disaster recovery — records and appointment books protected with encrypted off-site copies (XRB);
- Email and access security — multi-factor authentication, anti-phishing and permissions by role;
- Managing workstations, servers and network — with preventive maintenance and monitoring (XION MSP);
- Operational continuity — because a frozen appointment book means a full waiting room;
- Administrative automation — communications, reminders and document handling;
- Fast support, remotely and on site.
Where to start
A combined privacy and security review: we check GDPR documentation, backups, access and email in a single assessment, producing a clear list of priorities. The first visit is free.
Health data: the most sensitive category under the GDPR
The data a medical or dental practice handles is not ordinary data: it forms a special category under the GDPR, with strengthened obligations. That means adequate technical measures — encryption, access set by role, a record of who consults what — but also correct documentation: specific privacy notices, a record of processing activities, appointments for staff, and management of suppliers, from the practice software vendor to the external laboratory. Xion handles both planes, technical and documentary, with the GAPOFF platform keeping track of obligations and deadlines. In healthcare, an inspection or a complaint is not a remote hypothesis.
When the appointment book stops, the practice stops
In a medical practice, continuity has a very concrete face: a full waiting room and an appointment book nobody can reach. Practice software, appointment scheduling, patient records, sometimes the diagnostic equipment: everything runs through the systems, and a stoppage translates immediately into patients waiting and appointments to reschedule. That is why we design a practice’s infrastructure with resilience in mind — continuous monitoring, backups that allow a fast restart, quick support both remotely and on site. The aim is simple: the technology should never come between the clinician and the patient.
Health data: the category that changes the rules
The data a medical practice handles is not ordinary personal data: it forms a special category, and that raises the required standard at three specific points.
Security measures have to be proportionate to the risk, and with health data the risk is high by definition. In practice that means individual rather than shared logins, encrypted devices, and a record of who consults what.
A data protection impact assessment becomes necessary where processing is large-scale or systematic — a threshold that clinics and diagnostic centres reach more often than they think.
Breach notification has lower thresholds: where health data is involved, the possibility of having to inform patients as well has to be taken seriously rather than dismissed.
These are not theoretical obligations: they are the reason a medical practice’s infrastructure has to be designed a certain way from the start, rather than brought into line afterwards.
Diagnostic devices are computers, and nobody treats them as such
This is the most underestimated point. An ultrasound scanner, a radiology system, an analyser each contain a computer running an operating system, and that operating system is almost always old, because the manufacturer certifies that version and nothing else.
It cannot be updated. It cannot be taken off the network either, because it has to send images to the reporting system. The correct answer is to isolate it: the device stays where it is and carries on working, but in a separate section of the network with precise rules about what it can reach and who can reach it. It is the single measure that reduces risk most in a healthcare setting, and in most of the practices we visit it has not been done.
What we find in medical and dental practices
- One shared login for the practice system, used by everybody. With health data, not being able to say who consulted a record is a serious problem.
- Diagnostic images on a single disk, with no copy. They are the heaviest data and the hardest to reproduce.
- The reception computer with the same privileges as everything else, despite being the most exposed, because everyone’s memory sticks and emails pass through it.
- Backups that do not capture the practice database properly, and therefore will not restore.
- No procedure for when a patient asks for their own data, which is a right with a defined response time.
Where we work
Xion IT Group has its head office in Milan and offices in Lecco and Bergamo, and works with practices and clinics across Lombardy, combining the technical side with the privacy work that healthcare data demands.