Skip to content

Case Study: How an Ordinary Medical Practice Discovered the Hidden Risks in Their IT Setup

Many medical practices in South Africa still rely on basic email hosting and personal software. Here’s how one practice discovered the hidden risks of an unmanaged IT setup — and why compliance and data protection matter more than ever.

Introduction

At Just Plain IT, we were introduced to a small medical practice that believed their IT setup was “good enough.” They were paying around R200 per month for basic email hosting and assumed everything was under control. What we discovered is a story that repeats across many healthcare environments — systems that seem fine day-to-day but quietly put the entire practice at risk.

The Reality We Found

  • Emails running on basic IMAP or POP hosting with no encryption.
  • PCs using consumer-grade operating systems that cannot be centrally managed or encrypted.
  • Personal or Family versions of Microsoft Office being used for business — a clear licensing violation.
  • No backups, no MFA (multi-factor authentication), no monitoring, and no password policies.
  • Patient files stored locally on unprotected laptops and desktops.

Everything appeared to “work,” but there was no security, no compliance, and no resilience behind it.

The Hidden Risks

  1. Compliance Exposure: The setup violated the POPI Act and HPCSA requirements, which mandate encryption and secure storage of patient information.
  2. Data Loss: Without backups, a single hardware failure or ransomware attack could destroy years of patient history.
  3. Legal & Licensing Issues: Personal software licenses cannot be used commercially — putting the practice at legal risk.
  4. No Accountability: With no MFA or audit logs, there was no visibility into who accessed what data — or when.
  5. False Sense of Security: Paying R200 per month for basic email created the illusion of protection, when in reality there was none.

The Assessment

We performed a detailed review of the environment and presented clear findings:

  • Data handling risks under POPIA.
  • Operational risks from unmonitored devices.
  • Reputational risks if patient information were to leak.

It became evident that the practice didn’t need “more IT” — it needed the right IT.

The Transformation

With proper management in place, the practice now operates securely and compliantly:

  • Patient information is encrypted and backed up.
  • Devices are centrally monitored and protected.
  • Communication and storage meet healthcare data standards.
  • IT issues are handled proactively, not reactively.

Their monthly cost increased from R200 to R2,500, but that investment now protects their entire business — patient records, reputation, and peace of mind.

Before vs After

  Before (R200/month) After (Managed IT)
Email Basic inbox Secure, encrypted system
Devices Windows Home Business-grade, managed environment
Backups None Regular automated backups
Compliance None POPIA & HPCSA aligned
Support Basic Ad-hoc Proactive monitoring & helpdesk

Conclusion

The difference between R200 and R2,500 isn’t about paying more for an email address — it’s about protecting your patients, your data, and your reputation.

For medical professionals, IT isn’t about convenience. It’s about safeguarding patient trust and ensuring your practice can function securely every single day.

Ready to Review Your IT Setup?

If you’re unsure whether your current environment meets compliance standards, book a quick IT review with our healthcare IT team.

Contact Us

Like this article?

Share on Facebook
Share on Twitter
Share on Linkdin
Share on Pinterest

Leave a comment