Skip to content
// Industries

Regulated, deadline-bound, and allergic to downtime.

The diary does not move when a server does.

EMR access, referrals and billing are the load-bearing systems. Everything we run in a clinic is arranged around keeping those available during the hours patients are actually in the building.

The record has to be there before the patient sits down. Everything else is negotiable.

Clinical software is unforgiving: it authenticates against a directory, writes to a database, and talks to peripherals that were certified years ago and have not been updated since. That combination fails in predictable ways, and almost all of them are avoidable with a patch ring, a monitored dependency list and a restore that somebody has actually run.

01 · What actually breaks

Five failures we see in every clinic.

None of them exotic. Clinical estates grow by accretion and nobody is paid to look at the whole thing until it stops.

Healthcare IT failures, their cause, and the fix
Failure Why it happens here What we do about it
01EMR unavailable at open Why it happens hereAuthentication depends on one server nobody documented, and it was patched on the vendor’s schedule What we do about itPatch rings, monitored dependencies, and maintenance windows that never touch clinic hours
02Peripherals stop after an update Why it happens hereCertified diagnostic hardware breaks on a driver change pushed without testing What we do about itDevice-specific maintenance ring, drivers pinned and tested before release
03Shared logins at the front desk Why it happens hereTurnover made individual accounts feel like overhead, so one account grew permissions What we do about itNamed accounts with MFA and role-based access — also what an assessment asks you to demonstrate
04Backups exclude the thing that matters Why it happens hereThe EMR database or the imaging store was never in scope; the green tick was believed What we do about itCoverage confirmed against the real data map, with a quarterly restore test
05A laptop leaves the building Why it happens hereUnencrypted device with cached patient data becomes a notifiable breach What we do about itEnforced disk encryption and remote wipe through Intune, applied by policy not by trust

The pattern repeats: the clinic grew faster than anyone wrote down. The first thirty days of an engagement is mostly documentation.

02 · Obligation

PHIPA sits with you. The evidence is ours.

No provider can make a practice compliant — the custodian is the practice. What a provider supplies is safeguards, and the records to prove they were in place.

The security stack
A nurse updating a record at a clinic reception desk while a patient waits calmly nearby.
01

Access control you can demonstrate

Named accounts, MFA everywhere, permissions matching role rather than history. If reception can open clinical notes they do not need, that is a finding waiting to happen.

02

Audit trails that survive

Sign-in and access logging retained long enough to answer a question months later, which is when questions arrive.

03

Encryption enforced, not assumed

Disk encryption on every workstation and laptop, applied through policy. A lost device becomes an inconvenience rather than a notification.

04

A breach process written in advance

Who assesses, who notifies the Information and Privacy Commissioner of Ontario, what patients are told and in what order. Agreed at onboarding, not drafted in a panic.

03 · A clinic day

Where the pressure actually falls.

Support demand in a clinic is not evenly distributed. It spikes at open and almost nothing can wait until tomorrow.

07:30

Open

Workstations wake, EMR authenticates, peripherals initialise. Most clinic tickets land in this half hour.

08:00

First patient

From here the estate is load-bearing. Anything needing a restart has missed its window.

Through the day

Clinical use

Constant read and write against the record, with referrals and results arriving from outside systems.

16:00

Billing

The day’s claims submit. A broken path found now is a cash-flow problem, not an IT one.

After close

Maintenance

Patching, updates, backup verification — all of it here, which is why none of it happens at 07:30.

// Why this matters in the contract

A clinic needs coverage weighted to the open, not a flat service level across the day. That appears in the agreement as a defined start-of-day response and a maintenance window that never touches patient hours — two clauses generic MSP contracts rarely contain.

04 · What we recommend

For a clinic, in this order.

First Backup & recovery. A practice that cannot restore its record system has an existential problem, not a technical one. Also the fastest thing to fix.
Second Managed IT. One owner, with the maintenance window and start-of-day response written into the agreement.
Third Cybersecurity. MFA and named accounts first, then the rest. Most of what an assessment asks about lives here.
Ongoing Microsoft 365. Identity, device compliance, mail security — and a licence review that usually finds seats belonging to staff who left.

If budget only stretches to one this year, take the first. Recoverability cannot be retrofitted after the event. Further reading for clinics: the PHIPA compliance checklist for Ottawa clinics, and what disaster recovery actually involves. The layers behind this list are EDR on every endpoint, Sophos MDR and the email gateway.

05 · Questions

The ones practices actually ask.

If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.

We work alongside whichever EMR you run rather than reselling one. That matters when something breaks: we are on your side of the vendor support call rather than defending a product.

Maintenance runs outside clinic hours by default. Anything that must happen during the day is scheduled around your book, not the other way round.

No provider can make you compliant — PHIPA obligations sit with the custodian. We put the technical safeguards in place, document them, and give you the access logs and restore evidence an assessment will ask for.

Canadian residency by default for anything we control, including backups. If a vendor stores data elsewhere we will tell you where, before you sign rather than after.

Yes, and it is worth planning three months out. Connectivity lead times and clinical software licensing are the two things that consistently delay an opening, and both are avoidable with notice.

The record is there before the patient sits down.

Twenty minutes. Tell us what your clinic runs and what went wrong last — we will tell you what we would fix first.