Medical and allied health

Healthcare IT Support for New Zealand Practices

IT built around clinical workflows and the Privacy Act, for practices in Christchurch, Dunedin and throughout New Zealand.

Supporting New Zealand businesses since 1989.

A protected patient record at the centre of the clinical systems that read and write to it

What it is

What is healthcare IT support?

Healthcare IT support is the work of keeping a practice’s clinical software, infrastructure and security controls running and inside the law. The practice management system holding the record, the secure messaging carrying referrals, the National Health Index and ACC connections behind them, the network and logins underneath, and the controls that keep all of it compliant with the Privacy Act.

In a clinic an IT failure is never only an IT failure. It is a patient safety event, a privacy issue and a compliance issue at the same time. That is why healthcare gets treated differently from general business IT, and why managed IT services for a practice include obligations that most businesses never have to think about.

The risk

Why do clinics get targeted?

A full medical record carries identity, contact, financial and health data in one bundle, which makes it worth more to a criminal than a stolen card.

Attackers also know that a practice which loses access to its records will often pay quickly, because the alternative is cancelling a week of appointments and explaining why to every patient in the book.

Almost none of it is exotic. It is a phishing email that captures a clinician’s password, a laptop without disk encryption, a shared login on a shared workstation, or a backup that turned out to be online and writable when the ransomware ran.

The gap is rarely knowledge. It is that nobody in the practice owns the job of closing it.

A captured clinician password opening the door to the patient record system

What you get

What does Exodesk cover for a practice?

  • The clinical stack. Practice management software such as Medtech, Indici or MyPractice, secure messaging through HealthLink, telehealth, and the payment and ACC claiming running alongside it. Behind those sit the national connections a practice depends on daily: the National Health Index, immunisation reporting to Te Whatu Ora, and the referral and results traffic moving between providers.
  • Identity and access. Individual logins, role based access so reception sees what reception needs, multi-factor authentication, and same-day removal when someone leaves.
  • Backup that has been restored. Three copies, two media, one offline. Tested by actually restoring, not by checking a green tick.
  • Network separation. Guest wifi that cannot reach clinical systems, and printers, EFTPOS and connected devices on their own segments.
  • Endpoints. Disk encryption, patching, endpoint protection and remote wipe on every machine that touches patient data, including the ones that leave the building.
  • The paperwork. Access reviews, an incident response plan in plain language, and the evidence you need if the Privacy Commissioner ever asks for it.

Deeper security work sits outside the support plan and is quoted on its own. Cyber security services covers audits, penetration testing and certification support.

Compliance

What does the Privacy Act require of a practice?

The Privacy Act 2020 sets the baseline for handling personal information. The Health Information Privacy Code 2020 layers thirteen stricter rules on top for any health agency, covering collection, use, disclosure, accuracy, retention and the patient’s right to see and correct their own record.

Two obligations follow that practices routinely underestimate.

Breach notification. Any breach likely to cause serious harm must be reported to the Office of the Privacy Commissioner and to the affected patients as soon as practicable. Exposure of patient records will almost always meet that threshold.

Retention. The Health (Retention of Health Information) Regulations 1996 generally require records to be kept for at least ten years after the patient last received services. That has to survive system replacements, vendor changes and staff turnover, which makes it a design decision rather than an afterthought.

The Ministry of Health publishes HISO 10029, the Health Information Security Framework, as the reference standard. A small practice is not expected to match a hospital control for control, but it sets the direction of travel and it is what we scope against. Where you want the gaps ranked before anything is committed, a cybersecurity risk assessment does that.

Support in practice

What happens when you log a job

Work is triaged by what it is blocking, not by the order it arrived in. A printer that nobody needs until Thursday does not sit in front of a site that cannot trade.

  • A site down or a security incident goes straight to the top and is picked up immediately, including outside business hours.
  • One person unable to work is treated as urgent, because from where they are sitting it is total.
  • Requests that are not blocking anyone, new starters, software installs, changes, are scheduled rather than dropped in front of something more serious.
  • Anything the monitoring raises is worked without a ticket from you at all, which over a year is where most of the volume goes.

Response times are set out in a service level agreement, or SLA, agreed with you rather than advertised here. What is reasonable for a five person office and a fifty person one are not the same number, and we would rather commit to an SLA that fits your business than publish a figure that flatters us.

Cost

What does healthcare IT support cost?

Managed IT

A fixed monthly fee per user, with unlimited helpdesk support included rather than metered. You know what next month costs before it starts.

Projects and compliance work

A migration, a security audit or certification support are quoted separately on their own merits, so you can see what each one costs.

The comparison worth making is against a day of cancelled appointments, which most practices can price accurately, and against the cost of a notifiable breach, which they usually cannot. An IT assessment gives you the figure. No charge and no obligation.

Switching

How does switching providers work for a practice?

The clinical system cannot be down while it happens. That is the objection that stops most practices moving even when they want to, and it does not need to be true.

We document what you are running before anything changes, take over monitoring and access in a planned order, and run alongside your existing provider until the handover is complete. Nothing is switched off until the thing replacing it is working.

The part that needs you is usually one conversation about administrator accounts and passwords, and a decision about timing. Most practices pick a quiet week rather than a quiet day, and nothing that could interrupt a consult happens during clinic hours.

The risk in a handover is almost never technical. It is undocumented access that nobody wrote down, which is why the documentation comes first rather than last.

Confidentiality

Who will have access to patient data?

A practice should know who can reach its record system, and it is a fair question to put to any provider before the contract rather than after.

Supporting the systems a clinic runs on does not usually require reading clinical records, and the distinction is worth drawing early. Where access to a clinical system is needed for a particular piece of work, it should be scoped to what that job requires and agreed with you rather than assumed.

We are happy to work through the detail before anything starts: how our people are identified in your systems, what they are able to reach, and how often that is reviewed.

Getting started

Where should a practice start?

1

Audit access to the clinical system

Who has an account, when each was last used, and whether multi-factor authentication is enforced. Closing dormant accounts and turning on MFA removes the biggest single risk within a fortnight.

2

Restore from the backup

Not check it. Restore, and time how long it takes. If recovery is slower than the practice can tolerate, that changes before anything else does.

3

Write the incident response down

Who is called first, who notifies the Privacy Commissioner, what patients are told, and which systems get isolated. A practice that has thought this through handles an incident in hours rather than days.

Who it is for

Who does Exodesk support?

Medical practices, allied health providers and specialist clinics across Christchurch, Dunedin and the wider South Island, and elsewhere in New Zealand.

Veterinary clinics carry a different mix of imaging volume, retention rules and after-hours access, so those are covered separately in IT for veterinary practices. Community pharmacies sit outside that again, running a dispensary and a retail counter over one network, so the dispensary, the drug register and the vaccine fridge are covered on their own.

Questions

Healthcare IT FAQs

What laws apply to healthcare IT in New Zealand?

The Privacy Act 2020 and the Health Information Privacy Code 2020, supported by the Health (Retention of Health Information) Regulations 1996. The Ministry of Health also publishes HISO 10029, the Health Information Security Framework, as the recognised standard for protecting health information.

What does the Health Information Privacy Code add?

It sets thirteen rules that adapt the Privacy Act principles to health settings, covering collection, use and disclosure, accuracy, retention and the patient’s right to access and correct their record. It applies in addition to the Privacy Act rather than instead of it.

How long must patient records be kept?

Generally at least ten years from the date the patient last received services, under the Health (Retention of Health Information) Regulations 1996. Some records need to be kept longer for clinical or legal reasons, so a retention plan should be confirmed with the practice’s legal advisor.

What is the biggest cyber threat to a clinic?

Phishing leading to ransomware. A stolen clinician password gives access to the patient record system, after which ransomware can encrypt clinical data and any online backups together. Multi-factor authentication and an offline backup copy stop most of that chain.

Do small clinics need the same controls as large practices?

Yes for the core ones. Multi-factor authentication, encryption, tested backups, role-based access and an incident response plan apply regardless of size, because the Privacy Act applies equally to a solo practitioner and a large medical centre. The scale of the work changes. The obligations do not.

Can patient data be stored in the cloud?

Yes, provided the service meets the security and privacy requirements of the Privacy Act and the Health Information Privacy Code. Confirm where the data sits, who can reach it, how it is encrypted and what the contract commits the provider to before signing.

How often should a practice audit its IT?

A full review annually, with shorter checks on access, backups and patching each quarter. After any major change, such as new clinical software, a merger or a security incident, an additional review confirms the controls still work as intended.

Can you work alongside our existing IT person?

Yes. That is a co-managed arrangement and it is common in practices large enough to have someone internal. We supply the tooling, the after-hours cover and the specialist depth a single hire cannot span, and your person keeps the relationships and the clinical knowledge.

Next step

Request an IT assessment for your practice

We look at the clinical stack, access, backups and where the compliance gaps are, then come back with what to fix first and what it costs. No charge and no obligation.

Contact

Send us a message

Tell us what your practice runs on and where the concerns are.

Contact

Start typing and press Enter to search

Call Us Now