GDPR & Data Protection

IT Security at Your Practice - Passwords, Backups, and the Reception Computer

Author:

The minimum IT security measures a physiotherapy practice must implement without an IT specialist: named accounts, passwords, disk encryption, 3-2-1 backups, and separate patient Wi-Fi.

Tomasz has run a one-person physiotherapy practice for three years. The reception computer does everything at once -- keeping patient records, issuing invoices, checking email, and sometimes playing a cartoon for a child who came in with a parent for a visit. The password to the system is the dog's name, additionally written on a yellow sticky note taped to the monitor, "so it's easier not to forget." Nobody has ever made a backup of the data -- "the computer works, so why bother."

Then one day the laptop from the practice disappeared from his car during a coffee break, and Tomasz realized he had lost more than just a piece of hardware. He lost access to the records of several hundred patients, and worse -- he had no idea whether someone else had just gained access to them. Had the disk been encrypted, the thief would have ended up with a useless piece of metal. Without encryption, they potentially had a full database of personal and medical data. This article shows what minimum IT security measures a physiotherapy practice must implement to meet the requirements of GDPR Article 32 -- without hiring an IT specialist and without technical jargon.

Why IT security isn't "something for IT people"

GDPR Article 32 requires the data controller to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing. A physiotherapy practice processes health data -- a special category of data requiring heightened protection. This provision isn't aimed only at large companies with an IT department. It applies to every practice, including a one-person one, where the entire "infrastructure" is a single laptop and a router from the internet provider.

The good news is that most of the measures described in this article require no technical knowledge or extra cost -- just consistency and writing down what you should be doing anyway. We cover what to do once a data leak has actually happened separately, in the article on the 72-hour data breach notification obligation -- here we focus on how to avoid getting into that situation in the first place.

Named accounts instead of one shared login

The most common mistake at small practices is a single shared account in the records system, used by everyone -- the owner, the receptionist, sometimes contracted physiotherapists too. Convenient, but inconsistent with the accountability principle in GDPR Article 5(2), which requires the controller to be able to demonstrate who had access to specific data and when.

With a shared login, if unauthorized access to a patient record occurs, or a record gets accidentally deleted, there's no way to establish who was actually at the computer at that moment. The fix is simple: everyone with access to the EDM system or the reception computer should have their own, named account with a separate password. The operating system (Windows, macOS) supports this for free, with no extra software -- just set up separate user profiles. The same applies to access to the patient records system itself, which we cover in more detail in the article on electronic medical records in physiotherapy.

A password policy that actually works

A password written on a sticky note taped to the monitor has been a textbook example of poor security practice for years -- and it's still one of the most common sights at small practices. It ties directly into the so-called clean desk policy: paper documents containing patient data, and access passwords, should never be left in plain sight, especially at reception, where every patient waiting for their appointment can see them.

A sensible password policy at a practice doesn't need to be complicated -- a few simple rules are enough:

  • At least 12 characters long -- a long password is more secure than a short one, even if it's less "clever."
  • Uniqueness -- a different password for the records system, a different one for email, a different one for business banking. One password for everything means a leak in one place opens access to the rest.
  • No writing it down anywhere visible -- no sticky notes on the monitor, no notes in a visible notepad on the reception desk.
  • Change it after every employee leaves -- if a contracted physiotherapist ends their collaboration, passwords to shared systems should be changed immediately, not "whenever it's convenient."

If remembering several different long passwords is a problem, a password manager is the solution -- free and paid tools of this kind store passwords in encrypted form and require you to remember only one master password.

Disk encryption -- the single most important security measure

If a practice were to implement only one technical measure from this list, it should be encrypting the disk of the computer and laptop where patient records are stored. The reason is simple: hardware can be stolen, lost, left in the wrong place -- it happens even to the most careful people. What matters is what happens to the data afterward.

If the disk is not encrypted, a thief or finder can access all the personal and medical data stored on it with little effort, even without knowing the Windows login password -- simply removing the drive and connecting it to another computer is enough. That constitutes a personal data breach, which in most cases must be reported to the data protection authority within 72 hours.

If the disk is encrypted (e.g. via BitLocker on Windows or FileVault on macOS -- both built into the operating system and free), the data on the stolen device is unreadable to an unauthorized person. The GDPR explicitly treats such data as effectively inaccessible to unauthorized parties, which in many cases means there is no obligation to report the breach to the data protection authority -- losing the physical device is not the same as losing the data if nobody can actually read it anyway. Turning on encryption is usually a few clicks in system settings and takes a few minutes.

Backups following the 3-2-1 rule

Data loss doesn't have to involve theft. A disk failure, a spilled coffee, an accidentally deleted file, a ransomware attack -- any of these can wipe out a practice's entire patient records in seconds if there's no backup copy. A proven and simple method is the 3-2-1 rule:

Rule element What it means in practice
3 copies of the dataThe original on the computer + two backup copies (not counting the original as a "copy")
2 different media typesE.g. an external drive connected to the computer + the cloud, not two external drives of the same type
1 copy off-siteAt least one copy stored physically somewhere other than the practice (e.g. in the cloud) -- so that a fire, flood, or theft at the practice doesn't destroy every copy at once

In practice, for a small clinic this might look like: data on the reception computer, an automatic copy on an external drive connected once a week, and an automatic copy in a cloud service. The key word is "automatic" -- a backup that requires manual attention will sooner or later get skipped. It's also worth periodically checking that the backup can actually be restored -- a backup copy that doesn't work when disaster strikes is only an illusion of security.

Updates and antivirus -- basic hygiene

This is the most obvious element, yet still often overlooked. The operating system and the records-management software should be updated regularly -- vendors release updates specifically to patch discovered security holes. A computer running an outdated system, where "update available" pop-ups get dismissed for years, is a much easier target for malware.

The same goes for antivirus software -- a computer storing medical data should have one installed and kept up to date. It doesn't have to be an expensive, enterprise-grade solution; even Windows Defender, built into Windows, provides real protection as long as it's active and updated.

Patient Wi-Fi -- a separate network, not one for everyone

This is a surprisingly common mistake: a practice has one router, one Wi-Fi password, and gives that same password to patients waiting for appointments while the reception computer with access to patient records runs on the same network. A guest device connected to the same network as a computer holding medical data is, in theory, in the same "network space" as that computer -- depending on the router's configuration, this can create additional risk of access.

The fix is simple and available on nearly every modern router: a guest network. This is a separate Wi-Fi network, broadcast by the same router, but isolated from the main network -- devices connected to the guest network cannot see devices on the main network, including the reception computer. Setting it up is usually a single option in the router's admin panel, labeled exactly as "guest network" or "guest Wi-Fi."

A personal phone with patient data

Convenient, but risky: sending appointment reminder texts from the owner's or receptionist's personal phone. Once a personal phone has patients' names and phone numbers saved -- in contacts, in the SMS history, sometimes alongside a note about the type of therapy -- that phone becomes a device processing personal data, subject to the same security requirements as the practice computer. And a personal phone rarely has the same safeguards: screen lock, encryption, controlled access for household members.

A safer approach is to use the reminder feature built into the appointment booking system (if it offers one) or a dedicated business phone number, kept separate from personal communication. If that's not possible, it's worth at least regularly clearing the SMS history containing patient data and securing the phone with a strong lock code and encryption.

[SP] Example -- Solo Practice: After losing his laptop, Tomasz enables disk encryption (BitLocker) on the new device, sets up a separate user account for himself and for the physiotherapist who occasionally fills in for him, and configures automatic backups to an external drive and to the cloud. The whole process takes him one afternoon, with no IT specialist involved.

[GR] Example -- Group Practice: At a practice with five physiotherapists and a shared reception, the owner discovers that everyone logs into the records system with the same "reception" account, and the Wi-Fi password given to patients is identical to the password of the network the records computer runs on. She sets up named accounts for every employee and turns on a separate guest network on the router -- both changes at no extra cost.

Why all of this needs to be written down

Implementing all the measures above is only half of the obligation. The accountability principle in GDPR Article 5(2) requires the data controller to be able to demonstrate compliance -- it's not enough for passwords to be long and the disk to be encrypted if, during an inspection by the data protection authority, the practice can't document any of it. An inspector can't "see" that a backup has been running reliably for two years -- but they can see a written procedure and a record of it being followed.

That's why the minimum IT security measures should be described in a simple, internal document: what password rules apply at the practice, who has access to which systems, how often and where backups are made, what to do in case of lost or stolen hardware. It doesn't need to be an elaborate information security policy in the style of a large corporation -- a concise, few-page instruction that the practice can point to during an inspection or when onboarding a new employee is enough.

Frequently asked questions

Does a small, one-person practice really need all of these safeguards?

Yes. GDPR Article 32 doesn't exempt small entities from the obligation to implement appropriate security measures -- instead, it requires the measures to be proportionate to the risk. Because a physiotherapy practice processes health data, the risk is high regardless of the number of people employed, and most of the measures described here (named accounts, encryption, backups, separate Wi-Fi) require no extra cost or specialist knowledge.

Does disk encryption really remove the obligation to report a breach to the data protection authority?

In many cases, yes, though it always requires an individual assessment of the situation. If the data on the stolen or lost device is effectively encrypted and the encryption key wasn't taken along with the hardware, the data remains unreadable to an unauthorized person, which the GDPR treats as a situation where the risk to the rights and freedoms of individuals is negligible. It's still worth documenting the encryption and the circumstances of the incident, in case the data protection authority has questions.

How much does implementing these safeguards cost for a small practice?

In most cases, little to nothing. Disk encryption (BitLocker, FileVault), user accounts, and a guest network on the router are features built into the operating system and networking hardware that just need to be switched on. The only real cost might be an external drive for backups (a one-time expense of a few hundred zloty) or a subscription for cloud storage to keep an off-site copy.

Is a cloud backup safe for patients' medical data?

It can be, provided the cloud provider offers adequate security guarantees and the practice has a data processing agreement with them that complies with GDPR Article 28. It's also worth checking where the provider's servers are physically located -- processing within the European Economic Area is simpler from a compliance standpoint than transferring data outside it.

CTA: Already implemented the technical safeguards but missing the written documentation to show during an inspection? FizjoReady packages include complete GDPR documentation for a physiotherapy practice, ready to implement without an IT specialist. See FizjoReady packages

Related articles:
- Electronic medical records in physiotherapy
- KSeF at a physiotherapy practice 2026
- Data breach -- the 72-hour notification obligation

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.