
01 · Healthcare & clinics
Patient data on a system built for convenience
- The problem
- Records are reachable by more staff than strictly need them, access is not logged in a way anybody could reconstruct afterwards, and several small suppliers touch the data with no agreements in place. The practice is not careless, the systems simply grew around the work.
- What we build
- Patient data is separated and encrypted with access cut to the minimum necessary role by role, every read and write is logged to storage that cannot be edited, retention and deletion are implemented rather than merely described in a policy, and each supplier is brought under a proper data-processing agreement.
- What changes
- A defensible answer to who accessed what and when, a deletion request that actually executes end to end, and documentation the practice's own data-protection officer can work from.


