Almost every step of a consultation now runs through a screen. The visit is logged in the practice system, e-prescriptions and e-referrals travel to the national P1 platform, NFZ claims are settled electronically and the notes land in the electronic medical record. If any link in that chain stops, the waiting room fills up and reception spends the day apologising. Working remotely, we keep your clinic going from the first appointment to the last and make sure health data gets the protection GDPR demands.
Five areas. Some keep the consulting rooms running, others cover your duties towards patients and the regulator. Everything is done over secure remote access, mostly outside surgery hours.
We look after the server or cloud platform beneath your practice system, its database, patching and monitoring. We also track the certificates and accounts used to talk to P1, so e-prescribing never breaks on a Monday morning because a file quietly expired.
Who can open a patient file
Personal logins in place of one shared “reception1” account, permissions tied to each role, two-factor sign-in, encrypted drives on doctors' laptops and a trail showing who viewed which record.
Backups of medical records
Several database copies a day, one copy held away from the clinic where ransomware cannot reach it, and trial restores at a frequency set out in the contract. Medical records are kept for many years, with periods that vary by record type, so the backup retention policy is drawn up together with your lawyer or DPO.
Email, results and online booking
Encrypted delivery of test results, rules that catch PESEL numbers in ordinary messages (in Microsoft 365, for example, where your licence includes the feature), a booking form that asks only for what it needs, and data processing agreements with your booking and text message providers.
Front desk and consulting rooms
PCs, prescription printers and Wi-Fi with a separate network for patients, all updated and fixed remotely. Medical devices stay with the manufacturer's own service team.
Where we start
First we remove whatever could halt appointments, then we tidy up the paperwork a regulator or an unhappy patient would ask to see.
01
Data map
We find where the EDM sits, where X-ray images and scanned referrals are stored, who can reach them and how data travels to the lab, the NFZ or an insurer.
02
Risks and contracts
A risk analysis for health data, a review of processing agreements with your software, email and booking vendors, and updated entries in the record of processing activities.
03
Safeguards
Named accounts, MFA, encryption, backups proven by a test restore and a fallback connection. We make changes in the evenings and at weekends so the appointment book stays untouched.
04
Ongoing care
A helpdesk during your opening hours, daily backup checks and periodic permissions reviews, useful for instance when contract doctors leave.
A visit from UODO is rare, an outage of the practice system is far more common. An hour without patient files means rescheduled visits, paper prescriptions written in a hurry and a reception desk under siege. That is why we agree the target recovery time with you at the very start, alongside the GDPR requirements, instead of discovering it during the first incident.
Questions and answers
The application, its templates, dictionaries and version upgrades belong to the software vendor. We own everything underneath and around it: the server or cloud, the database, backups, network, accounts and security. When a fault sits on the boundary, we contact the vendor ourselves, so you are not left relaying messages between two companies.
Nobody outside the platform operator can fix P1 itself, but your clinic should have a written plan for that day: who issues paper prescriptions and how records are completed afterwards. Losing your own connection is easier to prevent. We remotely configure a router with a 4G backup line, bought from your usual supplier, and the switchover happens automatically.
Usually yes, provided the provider offers adequate security guarantees, you have signed a data processing agreement with it and your DPO or lawyer has confirmed where the data may be held. Keeping it within the European Economic Area is the simplest route. We help you pick the service, check the contract and describe the set-up in your data protection documents, so moving the server does not open a fresh problem.
That turns mainly on the scale at which you process health data, and the assessment is best made with a lawyer. We prepare the technical material the DPO relies on every day: an inventory of systems, permissions and safeguards.
No. Ultrasound scanners, X-ray units and spirometers have their own authorised service. Our job is the network and the computers they plug into: we place devices in a separate segment, restrict their traffic and make sure the workstation next to a scanner cannot become a back door into everything else. If trouble appears at that boundary, we speak to the equipment service team.
Tell us how many doctors consult, which practice software you use and whether you hold an NFZ contract. We reply within one working day and suggest where to begin.
Hours Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings Online via Teams or Google Meet
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
We fill in the gaps. If anything is missing for a quote, we ask by email or suggest a quick call on Teams or Google Meet.
We put a proposal together. Scope, a price in PLN and a start date we can actually hit, with no hidden small print.
You decide in your own time. The offer lands in your inbox. Take a look, ask about any line of it, and only then make up your mind.
Where are you based?
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.
We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.