Best IT setup for a medical or dental practice in the Hills District
Most small medical and dental practices in the Hills District are running on IT that was never really designed for a healthcare environment. A consumer-grade router from JB Hi-Fi, aging computers that take three minutes to boot, and a practice management system that nobody's properly configured. It works until it doesn't. And in a clinical environment, "until it doesn't" is a serious problem.
Whether you're setting up a new practice in Norwest or trying to figure out why your existing setup keeps causing headaches, this guide covers what a properly built IT environment actually looks like for a small practice and what separates a good setup from one that creates risk.
The non-negotiables: what every practice needs
These are the baseline components every medical or dental practice should have regardless of size.
Business-grade internet with 4G failover
Consumer NBN plans are fine for a home office. They're not fine for a practice where your appointment book, clinical records, Medicare claiming, and patient communications all depend on an internet connection.
The key difference with a business NBN plan isn't just speed, it's priority support and a guaranteed response time if something goes wrong. More importantly, your setup should include a 4G failover router: a secondary connection that kicks in automatically if your primary internet drops. A fifteen-minute internet outage at the wrong time means a waiting room full of patients and no way to access their records.
A proper managed router and switch not the ISP's default box
The modem-router your internet provider sends out is designed to get you online. It's not designed to segment traffic, prioritise clinical systems over general browsing, or give you any visibility into what's happening on your network. A managed business router (from vendors like Cisco Meraki, Ubiquiti, or Fortinet) gives you proper control and security at the network level.
If your practice has more than a handful of devices, you also need a managed network switch to handle the wired connections cleanly, not a consumer plug-in hub from an electronics store.
Separate networks for clinical systems and patient Wi-Fi
Your clinical systems and your patient waiting room Wi-Fi should be on completely separate networks. This is basic network hygiene: a patient connecting to your Wi-Fi should have zero visibility into or pathway toward the devices running your practice management software.
This is also a practical compliance measure. If something goes wrong with a device on the patient network, it can't touch your clinical data.
Microsoft 365 Business for email and communication
Using personal Gmail or Hotmail accounts for clinical correspondence is a compliance problem and a security risk. Microsoft 365 Business gives your practice professional email addresses, proper admin controls, multi-factor authentication and data stored in Australian datacentres.
It also gives you Microsoft Teams for internal communication between reception and consulting rooms which is far cleaner than staff yelling across a hallway or texting on personal phones.
Automatic offsite backups — the 3-2-1 rule
The 3-2-1 backup rule is simple: three copies of your data, on two different types of storage, with one copy offsite. For a practice, this typically means your data lives on your server or workstation, is backed up to a local device (like a NAS), and is also automatically backed up to a secure cloud location.
A Dropbox folder does not count as a backup. Neither does an external hard drive that nobody's checked in six months. Your backups should be automatic, tested regularly, and include your practice management database not just documents.
Endpoint protection on every device
Windows Defender, the built-in antivirus that comes with Windows, is better than nothing. It is not sufficient for a practice handling sensitive patient data. Business-grade endpoint protection (such as Sophos, Crowdstrike, or Microsoft Defender for Business) includes threat monitoring, ransomware protection, and centralised management so you can see the security status of every device from one place.
Practice management software: getting it running properly
This is where most practice IT problems actually live. The software itself is usually fine, it's the environment around it that causes grief.
The most common systems used by practices in the Hills District:
- Best Practice — the dominant choice for GP clinics across Australia
- Medical Director — another common GP platform, particularly in older practices
- Dental4Windows — used by the majority of dental practices in Australia, with over 4,000 practices nationally
- Genie Solutions — popular with specialist clinics
- Cliniko — common in allied health (physio, chiro, psychology)
- Zedmed — used across GP and specialist settings
The critical distinction is whether your system is server-based or cloud-hosted.
Server-based systems (which includes most installations of Best Practice and Dental4Windows) store your data on a physical server — either on your premises or hosted in a data centre. This server needs to be properly specified, maintained, and backed up. An underpowered server, or one running on a consumer PC someone repurposed five years ago, will make your entire practice slow and is a single point of failure.
Cloud-hosted systems store data remotely and are accessed via a browser or lightweight app. They're simpler to manage from an IT perspective but are entirely dependent on your internet connection which is why the 4G failover mentioned above matters so much.
Regardless of which system you use, it needs to be installed and configured by someone who understands healthcare IT not just general IT. The network configuration, user permissions, and backup settings all need to be set up correctly from the start.
Compliance: what NSW health practices actually need to know
This is the section most IT providers skip and most practice managers don't know enough about. It matters.
The Privacy Act covers every health practice regardless of size
Most small businesses are exempt from the Privacy Act 1988 if their annual turnover is under $3 million. Health practices are explicitly excluded from that exemption. As confirmed by the OAIC, all organisations that provide a health service and hold health information are covered by the Privacy Act regardless of their size or turnover.
That means your two-GP clinic in Castle Hill has the same legal obligations to protect patient data as a major hospital.
The Privacy and Other Legislation Amendment Act 2024
In 2024, the Australian Government passed significant privacy law reforms that directly affect health practices. The key change for practices: individuals can now sue a practice directly for a serious invasion of privacy. This is a new statutory tort that didn't exist before. If a data breach exposes patient records due to inadequate security, your practice faces potential legal action from affected patients not just regulatory penalties.
The practical IT implications of this: you can no longer treat cybersecurity as optional or defer it indefinitely.
My Health Record obligations
If your practice connects to My Health Record (and most GP and specialist clinics do), you have additional security obligations set by the Australian Digital Health Agency. These include ensuring only authorised staff can access the system, maintaining audit logs of who accessed what, and reporting breaches promptly.
Multi-factor authentication on all staff accounts that can access My Health Record is not optional - it's a requirement.
What "reasonable steps" actually means in practice
The Privacy Act requires practices to take "reasonable steps" to protect health information from misuse, loss, and unauthorised access. The OAIC has been clear that reasonable steps include:
- Encrypting devices that store or access patient data (if a laptop is stolen from your car, encryption means the data on it is unreadable)
- Using strong, unique passwords and MFA on all clinical systems
- Restricting access to patient records based on staff role — reception staff don't need access to clinical notes
- Having a documented process for what to do if a breach occurs
None of this requires enterprise-level complexity. It does require intention and proper configuration — which is where a lot of small practices fall short.
What a Hills District practice IT setup typically costs
Most IT articles avoid talking about money. Here's a realistic framework.
Managed IT support (ongoing monthly cost) covers monitoring, maintenance, helpdesk support, and security management. For a small practice of 2–5 staff, expect to pay in the range of $300–$600 per month for a properly managed service. For 6–10 staff with more complex systems, $600–$1,200 per month is typical. These figures vary depending on the number of devices, whether you have an on-premises server, and the level of support included.
Hardware (one-off costs) includes workstations, a server or NAS, managed switches, router, and UPS units. A well-specced setup for a small practice typically runs $5,000–$15,000 depending on the number of workstations and whether you need a new server.
Microsoft 365 licensing runs approximately $15–$30 per user per month depending on the plan, billed directly through Microsoft or a partner.
What drives the cost up: on-premises servers, large numbers of devices, legacy systems that need special handling, and compliance-heavy environments (anything involving radiology, pathology, or specialist records).
What keeps costs down: cloud-based practice management software, a small stable team, and standardised hardware that's easy to maintain.
The most common IT mistakes practices make
These come up repeatedly with practices across the Hills District.
Running practice management software on consumer-grade hardware. Best Practice and Dental4Windows are database-heavy applications. They need a properly specced server or workstation with adequate RAM, SSD storage, and a processor that can handle concurrent users. Putting them on a $600 laptop from Harvey Norman creates performance problems that get blamed on the software — when the real issue is the hardware.
No UPS (uninterruptible power supply). A UPS is a battery backup that keeps your server and key devices running for long enough to save your work and shut down cleanly during a power interruption. A sudden power cut to a server mid-operation can corrupt your database. For a device that costs $200–$400, the risk of not having one is hard to justify.
Using personal email accounts for clinical correspondence. Sending patient referrals, results, or clinical notes from a personal Gmail or Hotmail account is a privacy compliance issue. It also means there's no organisational record of that correspondence, no admin control over the account, and no way to recover it if the staff member leaves.
Shared logins across multiple staff. When two or three staff members share a single login to your practice management software, you lose your audit trail. If something goes wrong with a patient record, there's no way to know who made the change. Most accreditation standards and the Privacy Act expect you to be able to demonstrate who accessed what and when.
No tested offsite backup. Many practices have backups running — but have never tested whether they actually restore correctly. A backup that's never been tested is a theory, not a safety net. Backups should be tested at least quarterly.
Relying on a generalist IT person who doesn't understand healthcare. General IT support is fine for many businesses. Healthcare practices have specific compliance obligations, specialised software environments, and consequences for downtime that most other small businesses don't face. Your IT provider should understand the Australian Privacy Act, have experience with practice management software, and know what My Health Record access requirements look like.
What to look for in an IT provider for your practice
Not all IT providers are equal, and the Hills District has a mix of options ranging from large national companies to individual freelancers. Here's what matters:
Experience with Australian practice management software. Have they actually configured Best Practice, Dental4Windows, or Medical Director before? Can they speak to the difference between a server-based and cloud-hosted deployment?
Understanding of healthcare privacy obligations. Do they know what the OAIC requires? Can they explain what "reasonable steps" means in the context of your specific setup?
Local enough to come on-site. Remote support handles most things. But there are situations — a server failure, a new workstation setup, a network reconfiguration — where you need someone who can physically be there. An IT provider based in the Hills District can be on-site the same day.
Proactive monitoring, not just break-fix. A good IT provider is watching your systems before things go wrong. They should be able to tell you when a disk is close to failure, when a device hasn't backed up recently, or when there's unusual activity on the network — rather than waiting for you to call because something's broken.
Clear response time commitments. Ask specifically: if my practice management software goes down in the middle of a patient day, what is your guaranteed response time? Get the answer in writing.
Frequently asked questions
Does the Privacy Act apply to my small practice?
Yes — unconditionally. Unlike most small businesses, health service providers are covered by the Privacy Act regardless of their annual turnover. This applies to GP clinics, dental practices, specialists, and allied health providers.
What internet speed does a medical practice need?
For a practice with 3–5 simultaneous users accessing cloud-based systems and Medicare, a minimum of 50 Mbps download / 20 Mbps upload is a reasonable baseline. If you use cloud-based imaging or large file transfers, faster is better. More important than raw speed is reliability and a 4G failover for when the primary connection drops.
How much does IT support cost for a small clinic?
For a small practice of 2–5 staff with a managed IT service, expect $300–$600 per month. This typically covers monitoring, maintenance, security management, and helpdesk support. Hardware costs are separate.
What is the best practice management software for a GP clinic in Australia?
Best Practice and Medical Director are the two dominant platforms for GP clinics in Australia. Both are capable systems — the right choice depends on your workflows, your clinical preferences, and what other clinics in your referral network use. An IT provider can help with the technical setup of either, but the clinical decision is best made in consultation with your GPs.
What happens if there's a data breach at my practice?
Under the Notifiable Data Breaches scheme, health practices are required to notify both the OAIC and affected individuals if a breach is likely to result in serious harm. The 2024 privacy law reforms also introduced a new right for individuals to sue directly for serious invasions of privacy. Having proper security measures in place — encryption, MFA, access controls, and backups is your best defence both legally and practically.
Ready to get your practice IT sorted?
CF IT Solutions works with medical and dental practices across the Hills District — Castle Hill, Norwest, Baulkham Hills, and surrounding areas. We understand the specific compliance obligations that health practices face, and we have hands-on experience with the practice management software your team relies on every day.
If your current setup is causing headaches, or you're not sure whether you're meeting your Privacy Act obligations, we're happy to have a no-obligation conversation about where you stand and what a properly built environment would look like for your practice.