Mon – Fri  9AM – 5PM|Client Portal
ITstuffed

IT SUPPORT FOR HEALTHCARE PRACTICES

Managed IT and cyber security for healthcare practices

Your practice depends on technology across almost every part of the working day, from clinical systems and patient records through to appointments, communication, billing and the systems staff use behind the scenes. When support is slow, responsibility between vendors is unclear, or security and continuity have not been properly managed, that workload tends to fall back on practice managers and senior staff who should not be spending their time coordinating IT.

Good IT support should remove that burden. You should know who is responsible, important issues should be followed through without being repeatedly chased, and the technology, security and recovery arrangements behind the practice should be actively managed rather than dealt with only when something goes wrong.

ITstuffed provides managed IT and cyber security for healthcare and allied health practices across Christchurch and Canterbury. Our team also has direct experience working in clinical and hospital environments, which gives us useful context for the systems, priorities and pressures involved.

Reviewing your current IT arrangements?

If you are considering changing providers, have concerns about cyber security or continuity, or are spending too much time managing IT issues internally, tell us what has prompted the review.

Please complete verification before submitting.

Prefer to choose a time? Book a 15-minute IT Fit Check

4.8/5(84 Google reviews)

IT should make the practice easier to run

A healthcare practice already has enough moving parts without IT becoming another management problem.

Most practices rely on a combination of clinical software, Microsoft 365, internet connectivity, phones, booking systems, printers, backups, security products and third-party platforms. Some are supported by your IT provider, some by specialist vendors and some sit somewhere between the two.

Problems usually become frustrating when nobody takes ownership of that whole environment.

Three people talking around a meeting table in the ITstuffed office

Too much IT ends up with management

A clinical software company may say the problem is with the network. The internet provider may say the connection is fine. A staff member still cannot work, and somebody inside the practice ends up coordinating the investigation.

That is the part we want to take away from you.

We work with the other suppliers involved, provide the technical information they need and remain involved until it is clear where the issue sits and what needs to happen next.

Important systems need a continuity plan

Technology downtime has a different impact in a healthcare environment.

Appointments continue. Patients arrive. Clinicians need access to information. Reception still needs to communicate with people. Staff may need to work around systems that would normally support almost every part of the patient journey.

We work with healthcare clients to understand which systems matter most, what dependencies sit behind them and what practical options exist if something becomes unavailable.

The objective is not to pretend outages can be eliminated entirely. It is to reduce avoidable failures and make sure the practice has a considered response when something important does go wrong.

Patient information needs proper security

Patient information may move through clinical software, email, portals, shared systems, laboratory services, booking platforms and other external providers. Some of those systems are within the practice's direct control and others are not.

The Manage My Health breach was a useful reminder of how much healthcare organisations depend on third-party systems. The lesson for an individual practice is not that every external provider should somehow be audited internally. It is that practices need a clear understanding of where their information goes, what systems they rely on and which controls remain their responsibility.

No individual control removes cyber risk. The value comes from having multiple controls working together and somebody responsible for maintaining them.

MFA is important, but it is not the whole security strategy

Multi-factor authentication is one of the most useful protections available for business accounts, but it should not be treated as the point where identity security stops.

One of the healthcare organisations we support experienced a Microsoft 365 compromise while MFA was already in use. One account was compromised and an email sent from that account subsequently led to a second account being compromised.

The available evidence did not establish the precise technical method used to compromise the accounts, so we do not use that incident to claim a particular MFA-bypass technique.

What it does demonstrate is something much simpler: security needs to be layered.

Email protection, identity monitoring, device security, user awareness, sensible access controls and an organised incident response all matter alongside MFA.

Your IT provider should be managing the whole environment

Managing the environment also means taking responsibility when something needs attention. We prioritise support according to business impact rather than treating every request as though it has the same urgency. A printer issue affecting one workstation is different from a clinical system that nobody can access. A password reset is different from an active account compromise.

Issues should have a clear owner, with the practice kept informed until the work is resolved or responsibility has been handed to the right supplier. You should not need to repeatedly ask what is happening with a problem you have already handed over to your IT provider.

Support & operations

  • Day-to-day IT support
  • Vendor coordination
  • User onboarding and offboarding
  • Incident response

Security & continuity

  • Cyber security
  • Backup and recovery
  • Networks and infrastructure

Planning & management

  • Technology planning
  • Microsoft 365
  • Computers and devices

What our healthcare clients say

Our organisation engaged IT Stuffed a bit over a year ago and we have been very happy with their services to date. We value them being a local small business and appreciate their friendly yet professional interactions. They do not fluster easily and that has a calming effect on people with IT challenges.

When faced with a cyber-attack a year ago we greatly appreciated the immediate and ongoing support we received from IT Stuffed. Happy to recommend this service.

Maggy Tai Rākena

Case study

A real healthcare incident

A healthcare centre we had already started working with was preparing to move onto a managed-service agreement when suppliers began reporting phishing emails being sent from one of its Microsoft 365 accounts.

Our investigation identified an active compromise involving two accounts. We contained it within hours and worked with the organisation's cyber insurer, forensic specialists, legal advisers and internal team while the investigation continued.

It happened just before Christmas, when management was understandably concerned about what it might mean for the organisation and its relationships with other parties.

There was no evidence in the available logs that client information had been exfiltrated, and the forensic assessment concluded that exfiltration was unlikely. The centre continued operating while the investigation was completed.

During the incident, the managed-services agreement that had already been under consideration came back signed.

Read the full healthcare case study

A healthcare background inside the IT team

Healthcare is familiar to several members of our technical team for reasons that pre-date ITstuffed.

Daniel Lechner-Page

Daniel

Before founding ITstuffed, Daniel worked as a registered nurse and paramedic.

That experience gives him a useful understanding of healthcare environments and the difference between a minor inconvenience and something that is genuinely affecting the ability of staff to do their jobs.

David

David

David spent nearly 20 years maintaining radiation therapy systems in major New Zealand hospitals, including Christchurch Hospital.

His background combines technical engineering work with experience inside environments where reliability, documentation and careful change management matter.

John Clarkson

John

John has around 20 years of IT experience, including IT and administration work within a major European hospital.

He also volunteers with Hato Hone St John's Major Incident Support Team.

None of that means healthcare IT needs to be overcomplicated. It simply means that when a client explains why a particular problem matters, there is already some context behind the conversation.

Clinical software should not leave your practice manager acting as IT support

Applications such as Medtech, Best Practice and Gensolve have their own specialist support teams, and we do not try to replace them.

Our role is to manage the wider technology environment and deal with the points where different systems meet.

If a clinical application is having trouble communicating with a workstation, Microsoft 365, the network, a printer or another service, we can work directly with the relevant vendor and provide the technical information required.

That means the practice manager should not need to relay technical messages between several different suppliers while everybody tries to determine whose problem it is.

The same approach applies to other important technology providers used by the practice.

We document key dependencies, understand who supports what and deal directly with suppliers where that is the most effective way to resolve an issue.

ACC, privacy and information security

ACC has reminded providers of their responsibilities around privacy and information security, including the requirements that apply through its contractual arrangements.

For a healthcare provider, that makes good IT management part of a wider governance responsibility rather than something that belongs only to the IT company.

We do not provide legal advice about what a particular incident could mean for an ACC contract.

What we can do is help with the technical side of the equation:

  • security controls;
  • user and device management;
  • documentation;
  • backup and recovery;
  • incident containment;
  • technical investigation;
  • evidence gathering;
  • remediation;
  • coordination with insurers, forensic specialists or legal advisers where required.

Having those arrangements established before an incident is considerably easier than trying to assemble them while one is already underway.

Technology planning should happen before something becomes urgent

Managed IT should cover more than support tickets.

Healthcare practices change. Staff numbers increase, software is introduced, devices age, security expectations move, suppliers change and the practice may open another location or provide services differently.

Those changes should feed into a technology plan.

For our managed clients, we review the environment and discuss what is changing in the business so that upcoming technology requirements can be considered before they become urgent.

That may include:

  • device replacement planning;
  • Microsoft 365 changes;
  • security improvements;
  • software projects;
  • network upgrades;
  • backup and recovery;
  • business continuity;
  • cyber insurance requirements;
  • budgeting for upcoming technology work.

The aim is to give management a clearer view of what needs attention now, what can wait and what should be budgeted for later.

An ITstuffed engineer talking through work with a client

Predictable monthly IT costs

Managed IT works best when the provider is responsible for the environment rather than earning more every time something breaks.

Our managed services are provided for a fixed monthly price based on the agreed service.

That gives the practice more predictable IT costs and removes the hesitation that can come with deciding whether a support issue is important enough to justify another hourly bill.

Projects or work outside the managed-service scope are discussed separately before they proceed.

What we manage for healthcare practices

Day-to-day IT support

Staff have access to an IT team that can deal with the routine issues that otherwise interrupt their work.

Where possible, we work directly with the person experiencing the problem rather than asking management to coordinate support internally.

Microsoft 365

We manage Microsoft 365 environments including user accounts, licensing, security configuration and the services staff use for email, files and collaboration.

Computers and devices

Devices are monitored, maintained and patched, with lifecycle planning used to identify equipment approaching replacement rather than waiting until it becomes unreliable.

Cyber security

Security is managed across devices, accounts, email, web access, identity and user awareness rather than relying on a single product.

Backup and recovery

Backups are monitored and recovery arrangements form part of the wider continuity discussion.

A successful backup is useful only if the information can actually be recovered when it is required.

Networks and infrastructure

We manage and monitor the wider environment supporting the practice, including network equipment and internet-related infrastructure where it forms part of the managed service.

Vendor coordination

Where an issue involves another technology provider, we work directly with them rather than sending the problem back to the practice to coordinate.

User onboarding and offboarding

When staff join or leave, accounts and access can be handled through a defined process so important access is provided or removed consistently.

Incident response

If a security incident occurs, we can assist with containment, investigation and remediation and coordinate with other parties involved in the response.

Technology planning

For clients on the appropriate managed service, regular Business Technology Reviews provide a structured opportunity to look ahead, discuss changes in the practice and maintain a technology roadmap and budget.

SMB1001 Gold Certified

SMB1001 Gold

ITstuffed holds SMB1001 Gold certification and uses the framework as part of the way we manage our own cyber security.

MicrosoftHuntressHPCiscoSynology
4.8/5(84 Google reviews)

Frequently asked questions

Do you support Medtech, Best Practice and other clinical software?

Yes, although those applications have their own specialist support teams and we do not try to replace them.

Our role is to manage the wider IT environment and work with the software vendor when an issue crosses between systems.

For example, if a clinical application is having trouble with a workstation, network connection, Microsoft 365 service or another part of the environment, we can investigate our side of the issue and deal directly with the vendor where appropriate.

The objective is to avoid leaving the practice manager in the middle of several technical support teams.

What does working with ACC mean for our IT and cyber security?

ACC providers have privacy and information-security responsibilities, including requirements contained in ACC's contractual arrangements.

We do not provide legal advice about how a particular incident would affect a provider agreement.

We help clients manage the underlying technical controls, documentation, backups, incident response and remediation that form part of a well-managed environment.

Where an incident requires specialist legal, insurance or forensic advice, we can also work with those parties on the technical response.

We already have MFA. Isn't that enough?

MFA remains an important security control, but it is one part of a wider identity and security strategy.

Email protection, identity monitoring, access control, endpoint security, patching, web protection, backups and staff awareness all address different parts of the risk.

The healthcare incident described on this page involved two compromised Microsoft 365 accounts while MFA was already in use. The available evidence did not establish exactly how the first account was compromised, so we do not claim that a particular MFA-bypass technique was responsible.

What does the Privacy Act require if we have a breach?

Under the Privacy Act 2020, an organisation must notify the Privacy Commissioner and affected people when a privacy breach has caused, or is likely to cause, serious harm, subject to the requirements and exceptions in the Act.

Healthcare organisations also need to consider the Health Information Privacy Code when dealing with health information.

ITstuffed can assist with containment, technical investigation, evidence gathering and remediation. Where there is uncertainty about notification or other legal obligations, the organisation should obtain appropriate privacy or legal advice.

Can you work with our existing software and suppliers?

Yes.

In most healthcare environments, no single technology provider controls everything.

We regularly work alongside software vendors, internet providers and other suppliers and will deal with them directly when the issue requires it.

Do you provide onsite support?

Yes, where onsite work is required and included within the relevant service arrangement.

A significant amount of modern IT support can be completed remotely, but there are still situations where being physically onsite is the most appropriate option.

How quickly do you respond?

Support is prioritised according to impact and urgency.

Critical outages and active security incidents are treated differently from routine support requests.

Do you only work with large healthcare organisations?

No.

Our healthcare clients include small and medium-sized practices and allied health organisations.

The more important question is whether the organisation wants its technology actively managed rather than relying on reactive support when something breaks.

What happens if we already have an IT provider?

That is common.

Changing IT providers involves access, documentation, licensing, security, backups, vendor relationships and communication with the outgoing provider.

A well-managed transition should deal with those areas methodically without expecting the client to coordinate the technical handover themselves.

We can discuss the current arrangement first and explain what a transition would involve before you make a decision.

Reviewing your practice's IT support?

You may be considering changing providers, dealing with recurring support problems, reviewing cyber security or simply questioning whether the current arrangement is still suitable for the practice.

Tell us what has prompted the review and we will get in touch.

You do not need to diagnose the problem or prepare a technical summary before contacting us.

Start the conversation

* Required

Please complete verification before submitting.

Prefer to choose a time? Book a 15-minute IT Fit Check

Based in Christchurch and working with healthcare and allied health practices across Canterbury.