Pterion · Privacy · Security
Patient records, confidential and secure.
Under PHIPA a clinic is the custodian of its patients’ information. It decides who may see it, it has to protect it, and it has to say so when something goes wrong. We set up the accounts, devices, networks and paperwork that make that true every day, and write the plan for the day it is tested.
Assess Design Build Operate
What it involves
Who may see it, how it is protected, and what happens on the bad day.
- 01
The obligations, in plain language. Protect patient information; name a privacy contact; publish how the clinic handles it; tell patients when it is stolen, lost, or used or disclosed without authority; report to the Information and Privacy Commissioner where the rules require it; send the Commissioner a yearly count of breaches.
- 02
Confidentiality: who may see what. Access by role, so the front desk sees what the front desk needs and no more. One account per person, never a shared login. A confidentiality agreement signed at hire and renewed every year. Looking at a record without a reason is a breach even when nothing leaves the building, so access is logged and the logs are read.
- 03
Accounts and devices. Two-step sign-in on every account that can reach patient information. Laptops and phones encrypted, so a lost device is not a lost set of readable records. Updates applied on a schedule, not when someone remembers. Email filtered, and staff taught to recognise the message that asks for a password.
- 04
The network. Clinical equipment on its own segment with no route to the internet; guest Wi-Fi kept apart from everything clinical; servers inside the clinic encrypted and kept running through a power loss. The anesthesia charting in our own procedure rooms runs this way.
- 05
Vendors, agents and AI tools. Every service that touches patient information has an agreement that says what it may do with the data and where the data is kept. A tool whose terms let it keep or learn from patient information is not used for patient information, and that includes AI tools.
- 06
Backups and the bad day. Backups kept where ransomware cannot reach them, and restored on a schedule to prove they work. A written plan for seeing patients while the systems are down, and a written breach plan: who decides, who is told, when, and what is recorded.
- 07
The software we build. No patient data in code, test data or repositories, and passwords and keys kept out of code. We audit the software itself for patient information, not only the paperwork; one such audit found real patient records compiled into a front-desk application, and they were removed.
What we have built
- The privacy audit that looked inside the software Real patient records found compiled into a front-desk application, removed, and the history scrubbed so it could not return. Applies to Medical · Dental · Aesthetics
- Automated anesthesia charting Monitor readings are captured straight into the anesthetic record as the case runs, so the chart is written during the case rather than reconstructed after it. Applies to Medical · Dental
- Hundreds of private-pay patient leads, tracked from first enquiry to booking Each enquiry is recorded once and followed up on a schedule rather than forgotten, and what a person was told is on file for the next call. Built on licences the clinic already held, with patient data in the clinic’s own tenant. Applies to Medical · Dental · Aesthetics
- A website that does something Enquiries and bookings land in the clinic’s own records with consent recorded at source; nothing waits in an inbox. Applies to Medical · Dental · Aesthetics
What we will not do
- Promise a clinic cannot be breached. No one can. We make a breach harder, make sure it is noticed, and make sure the clinic knows what to do next.
- Hold patient information on our side. Where the work touches it, it stays inside the clinic or in the clinic’s own systems.
- Put patient information into a consumer AI tool, a free account, or any service whose terms let it keep the data or learn from it.
- Recommend a new product before the ones the clinic already pays for are set up properly.
- Name a client, or describe what we saw in a clinic in a way that identifies it. The case studies on this site are written the way we would want ours written.
Questions clinics ask
- Does a small clinic need all of this?
- The obligations are the same at any size; what counts as reasonable is not. A three-room clinic does not need what a hospital needs, but it does need two-step sign-in, encrypted devices, a named privacy contact, and a breach plan written before the day it is needed. Confirm current requirements with the Commissioner’s office or counsel.
- A laptop was stolen. What now?
- Find out what was on it and whether it was encrypted; that decides most of what follows. Where patient information was stolen or lost, the patients are told at the first reasonable opportunity, and the Commissioner is told where the rules require it; counsel helps with both calls. Record it for the yearly count, then fix what let it happen.
- Can patient information live in cloud email and file storage?
- It can, when the service is set up for it: an agreement with the provider that covers patient information, two-step sign-in, access limited by role, and sharing links that expire. The question is less which service than how it is set up.
- Do you sign a confidentiality agreement?
- Before we see anything. Where the work touches patient information, the agreement also sets out our role under PHIPA and what we may and may not do with what we see.
The first step
Ask for a privacy and security review. We spend a day with the accounts, devices, network and paperwork, reading them the way the Commissioner would and looking at them the way an attacker would, and send a short written note: what is exposed, what PHIPA asks for that is missing, and the order to fix it in. No obligation.
Start with an assessment No obligation · a diagnosis first
What it costs
The review is a fixed fee stated up front. Each fix is quoted as a fixed scope, in writing; keeping accounts, devices, updates and backups in order afterwards is a monthly amount agreed in advance. Nothing is billed that was not quoted.
We have run the front desk we are selling the fix for.
Being a clinician is hard enough. Running the business around it is not taught in professional school, and the field is corporatizing around the owners who learned it the hard way.
We exist to help clinician-owned clinics stay independent and succeed: to make the operation efficient, to teach what we had to learn ourselves, and to give owners back the part of the work they love.
an assessment.
No obligation · a diagnosis of the problem and what can be done about it · every scope quoted on its own