Kosmos IT
Menu

IT support for allied health practices

Allied health practices cannot have practice management software down during clinic hours. We support the systems reception and practitioners rely on, protect patient records to privacy standards, and do every disruptive change outside consulting times — without exception.

What breaks most

  • Practice management software unavailable with a waiting room full of patients
  • Reception unable to print a referral or process a claim
  • Patient records accessible to more staff than actually need them
  • Backups that miss the practice software's own database
  • Devices left signed in at a shared reception desk

What we do about it

  • Practice management and clinical software support, including the database behind it
  • Encrypted backups with access logging, tested on a schedule
  • Role-based access so records are only reachable by the people who need them
  • Secure messaging and referral workflows that clinicians will actually use
  • All changes scheduled outside consulting hours

Software we see and support: Cliniko, Nookal, Best Practice, Medical Director, Coreplus, HealthLink and Medicare Online, plus the imaging and device software attached to them.

The part most providers skip

Privacy is a design decision. Health records fall under the Privacy Act and the Australian Privacy Principles, which means access control and logging matter as much as backup. We build both in rather than adding them after a request.

What working with us looks like

Every engagement starts the same way — an audit, then the fixes that carry the most risk, then a rhythm you stop having to think about.

Week one — audit, outside clinic hours

We walk the practice before opening or after close. Reception machines, the practice management database and where it actually lives, backup coverage of that database, who can reach patient records, and the devices left signed in at the front desk.

Weeks two to four — access and backup

Role-based access so records reach only the people who need them, multi-factor authentication on every account, and a backup that genuinely includes the practice software's own database rather than the folder next to it.

Before go-live — a tested restore

We restore the practice database to a separate location and open it. Until that has happened once, a backup is an assumption. You get the result in writing, dated, which is also what an insurer will ask for.

Ongoing — access reviews

Every quarter we check who still has access after staff changes, confirm logging is intact, and re-test the restore. Practices drift here faster than anywhere else, and the drift is invisible until it matters.

A job like yours

A three-practitioner clinic at Victoria Point had backups running nightly for two years. When a drive failed, the backup turned out to be copying the practice software's folder while the database was open — every copy was unusable. We rebuilt from a two-week-old export and lost a fortnight of notes. The fix took an afternoon; the lesson was that nobody had ever tried a restore. We now test theirs quarterly and send the result in writing.

Questions from allied health

Can you work outside clinic hours?

Yes. Anything that interrupts reception or a practitioner happens before opening, after closing, or on a day the practice is closed. We treat consulting hours as unavailable time, and that's part of the arrangement rather than a favour.

How do you protect patient records?

Encrypted backups, access limited by role, multi-factor authentication on every account, and logging so it's possible to see who opened what. We also review who still has access when staff change, which is where most practices quietly drift.

Do you support practice management systems directly?

We support the environment they run in and work with the vendor on the application itself. In practice we resolve most issues — performance, printing, database and connection faults — without you needing to sit on hold with the software company.

Does our backup meet Privacy Act obligations?

Backup alone does not. The Australian Privacy Principles are about who can reach patient records and whether you can show it, so encryption, access limited by role and logging matter as much as having a copy. We set all three up together and can produce a short written summary of the controls for an insurer or a patient complaint.

Can you help when we add a practitioner or a room?

Yes, and it is quicker if we know early. A new practitioner needs an account, a device, access to the right records and a licence — and often a network point in a room that never had one. Given a week's notice it is done before their first patient rather than during it.

The services this usually involves

Cybersecurity

The practical controls that stop small businesses being robbed: MFA, patching, managed antivirus and staff who know the signs.

Data backup and recovery

Backups that are monitored, tested and off-site — plus recovery when someone else's backup turns out to be empty.

Microsoft 365

Email, Teams, SharePoint and OneDrive set up properly, licensed correctly, and secured against the obvious attacks.

Where we see this most

Start with the audit and see what's actually wrong

Call 07 3824 6117Book a callout