Medical and allied health practices: securing daily work without slowing down appointments
Health data attracts attackers, and a practice has neither an IT department nor time to spare. Here are the measures that genuinely protect, ranked by effort.
A practice does not need an enterprise setup. It needs five things maintained over time: named sessions rather than a shared account, automatic workstation locking, a tested offline backup, multi-factor authentication on email, and updates applied. Hosting health data, for its part, is a matter for an HDS-certified host (HDS is the French certification for health data hosting), which you can check with your practice software vendor.
A practice stores particularly sensitive data, rarely has anyone dedicated to IT, and works at a pace where nobody has time to think about security between two patients. That combination makes it a convenient target.
The good news is that a small number of measures covers most of the real risk, and none of them slows down appointments once in place.
1. One account per person, never a shared session
A single account shared between practitioners and reception staff is the most widespread practice and the most problematic. It makes it impossible to know who opened which record, which is a regulatory problem as much as a practical one.
A named session for each person, with rights suited to their role, can be set up in a single visit and changes nothing about ease of use once habits have formed.
2. Automatic screen locking
A reception workstation is left unattended for several minutes every hour, in a room patients walk through. Automatic locking after a few minutes of inactivity is the cheapest measure of the lot, and one of the most effective.
3. An offline backup, tested
- A copy that stays connected all the time will be encrypted along with everything else in a ransomware attack.
- A restore you have never tried is no guarantee: run the test once a year, on a real record.
- Check with your vendor exactly what the practice software backup covers, and what it does not.
4. Email, the main way in
Turn on multi-factor authentication for every mailbox, including the reception mailboxes. A stolen password is then no longer enough to read the practice's correspondence.
Be wary of messages that imitate a colleague, a laboratory or an organisation and ask for a change of bank details. This is the most common payment fraud scenario, and it targets organisations of all sizes.
5. Health data hosting: what to check
As soon as personal health data is hosted on behalf of the practice, the regulations require a host that holds HDS certification.
This is not handled on the practice side but on the practice software vendor's side. The question to ask is direct: where is the data hosted, and is the host HDS certified? The answer should be written and verifiable, not verbal.
Frequently asked questions
- Does a medical practice have to host its data with an HDS-certified host?
- Whenever personal health data is hosted on behalf of the practitioner, HDS certification is required of the host. In practice, you check this obligation with the practice software vendor, who should state in writing where the data is hosted.
- Is the shared account at reception really a problem?
- Yes, on two counts. It makes it impossible to trace who opened which record, which is expected in the event of an inspection or an incident. And it prevents you from removing access when someone leaves without changing everyone's password.
- Which measure should I start with on a limited budget?
- Multi-factor authentication on email, and an offline backup that has genuinely been tested. These two measures cover the two most frequent scenarios, account theft and data encryption, at a very low cost.
Next step
Sources
Published 2 September 2026 · Équipe Skill Group, Cybersécurité
Going further
Ransomware: what to do in the first hour
The decisions taken in the first sixty minutes largely determine how long the shutdown lasts. Here is the order of actions, and the three mistakes to avoid.
Microsoft 365: the security settings to check in your company
Microsoft 365 is secure by design, not by default. Here are the settings that matter, and the backup question that many companies discover too late.
Food industry: what really stops when IT goes down
On a production site, an IT failure does more than get in the way: it blocks shipping, traceability and sometimes the line itself. Here is how to prioritise.