How should I set up IT and networks for my private GP service?
Connection, Wi-Fi, devices, accounts, backups, Cyber Essentials and IT support for a small cloud-based practice.
The short answer
Most private GP systems run in the cloud, so for a small practice the network mostly means reliable business broadband with a backup, secure and separate practice and guest Wi-Fi, encrypted and updated devices, and individual accounts with multi-factor authentication. You rarely need an on-site server, and usually only need an NHS network (HSCN) connection if a system you choose requires it. Use Cyber Essentials as your baseline, and consider a managed IT provider under a written data processing contract.
Key points
- Most small private practices are cloud-based and do not need an on-site server.
- Have business broadband with a tested backup connection, and keep guest Wi-Fi separate from practice devices.
- Encrypt and manage every device, and use individual accounts with multi-factor authentication.
- Microsoft 365 and Google Workspace both work; switch on their security features.
- Cyber Essentials is a good baseline; the DSPT is needed if you connect to NHS systems.
- A managed IT provider can access patient data, so it needs a data processing contract.
Start with where your systems live
Most private GP record systems, booking tools, email and accounts now run in the cloud and are used through a web browser. That changes the job. For a small practice, “the network” mostly means a reliable internet connection, secure Wi-Fi, well-managed devices and properly protected accounts.
Older advice often recommended an on-site server for files and access control. Most small practices no longer need one. A server has to be secured, updated, backed up and eventually replaced, and cloud services with good access controls usually do the same job with less risk.
The exception is if you use a system that needs a connection to the NHS network (HSCN). Ask your record system supplier before you choose premises or a broadband contract. A purely private practice using cloud software usually does not need one.
Internet connection
- Choose business broadband with a service level agreement for repairs.
- Check the upload speed as well as download, especially if you run video consultations.
- Have a backup: a 4G or 5G router or a phone hotspot that you have tested, so a broadband fault does not stop clinics.
- Keep a short “system down” plan: how you will see booked patients, record notes and prescribe until the connection returns.
Wi-Fi and the router
- Change the router’s default admin password and keep its firmware updated.
- Use WPA2 or WPA3 encryption with a strong passphrase.
- Run a separate guest network for patients and visitors, so their devices never share a network with practice computers.
- Keep printers, card terminals and other connected devices on the practice network, not the guest one.
- If you share premises, do not rely on the landlord’s Wi-Fi for clinical work unless you control who else is on it.
Computers, phones and printers
Buy business-grade devices that will receive security updates for several years, rather than chasing a specification. Then set them up securely:
- full-disk encryption on every laptop and phone that touches patient data
- automatic updates for the operating system, browser and apps
- a screen lock after a short idle time
- malware protection (built into modern operating systems)
- a device management tool, so you can wipe a lost laptop or phone remotely.
Scanners and multifunction printers often store copies of documents. Check the settings, and wipe them before they leave the building.
Accounts and passwords
- One account per person. No shared logins, including for the record system.
- Multi-factor authentication on email, the record system, accounts and anything holding patient data.
- A password manager, so people can use long, unique passwords.
- Administrator rights only for those who need them, on separate admin accounts.
- A joiners and leavers checklist, so access is removed the day someone leaves.
Microsoft or Google?
Older advice said to stick to Microsoft for NHS compatibility. In practice either Microsoft 365 or Google Workspace works: documents exchange easily, and NHS England recognises both as routes to meeting its secure email standard. Choose the one you and your staff know, and switch on the security features. Some security features need a higher-tier plan. At the time of review, Google’s client-side encryption for Gmail was only on Enterprise Plus and some Frontline and Education editions, not the Business plans. See secure email.
Backups
Ask your record system supplier how it backs up your data and how quickly it can restore it. Back up anything you hold outside it, such as policies, HR files and accounts, and keep at least one copy separate from your main account so ransomware or a deleted account cannot take both. Test a restore at least once a year.
Cyber Essentials and the DSPT
Cyber Essentials is the government-backed baseline, delivered with the National Cyber Security Centre. It covers five controls: firewalls, secure configuration, security updates, user access control and malware protection. The standard level is a verified self-assessment and Cyber Essentials Plus adds a hands-on technical audit. At the time of review the NCSC listed prices for the standard level from £320 plus VAT, and certificates last 12 months. The NCSC also said organisations with a turnover under £20 million that certify get free cyber liability insurance.
If you use NHS systems such as NHSmail or MESH, you also need the NHS Data Security and Protection Toolkit (DSPT). Even if you do not, it is a useful checklist.
Choosing IT support
Many small practices pay a managed IT provider rather than doing it themselves. A good one will:
- set up devices, accounts, Wi-Fi and backups to a written standard
- manage updates, device management and security alerts
- run a helpdesk with stated response times during clinic hours
- handle new starters and leavers quickly
- help you respond to an incident, such as a lost laptop or a suspicious email.
Look for experience with healthcare clients and its own Cyber Essentials certification. Because it can reach patient data, it is your data processor and needs a written contract. Avoid long contracts until you know the service is good, and make sure you keep the admin passwords for your own accounts.
A setup checklist
- Confirm whether any system you plan to use needs HSCN.
- Business broadband plus a tested backup connection.
- Separate practice and guest Wi-Fi, router secured.
- Encrypted, updated, managed devices.
- Individual accounts with multi-factor authentication and a password manager.
- Backups you have tested.
- Cyber Essentials, and the DSPT if you connect to NHS systems.
- A written “system down” plan and an incident contact.
For the legal side of handling patient data, see UK GDPR for private practice. Cyber Essentials and NCSC guidance apply across the UK; the DSPT is NHS England’s toolkit, so check local NHS requirements in Scotland, Wales and Northern Ireland.
Frequently asked questions
Do I need an HSCN connection?
Only if a system you use requires it. Most cloud-based private GP software works over the ordinary internet, so ask your record system supplier before you sign a broadband contract.
Can I work from home on the practice systems?
Yes, if the device is practice-managed, encrypted and updated, you sign in with multi-factor authentication and you work somewhere others cannot see or hear patient information.
Is Cyber Essentials compulsory?
Not by law for a private practice. Some contracts and insurers ask for it, and it is a low-cost way to check the basics.
Should staff use their own phones?
Avoid it for patient data. If you allow it, use device management to keep practice data in a separate, protected area you can wipe.