Protecting your practice's health information — a free guide
The real list. No email wall, no lead capture. What to actually do, what it costs you in time, and what it costs you if you skip it.
1. Two-factor everywhere — email first
Turn on two-factor authentication (2FA) for every account that holds client information. Start with your email — it's the master key to every account recovery in your practice. Takes about 10 minutes per account, done once.
2. Password manager — stop reusing passwords
One password manager (1Password and Bitwarden are both solid) and a unique password on every account. The initial setup takes an afternoon; after that it's faster than trying to remember which variation you used.
3. Spot the fake email — never enter a password from a link
The tell is urgency: "your account will be suspended," "verify immediately," "unusual activity detected." Go directly to the site in a new tab instead of clicking the link — phishing emails can't survive that one habit.
4. Encrypt every device — let it update
FileVault on Mac, BitLocker on Windows — turn it on, write the recovery key somewhere safe (not on the same machine). Set updates to run automatically overnight. A lost encrypted laptop is just a lost laptop.
5. Back up for real — automatic, offsite, tested
Backups that only live on your own machine aren't backups — they're copies. Automatic, encrypted, stored somewhere outside your office. Run a restore drill at least once a year. A backup you've never tested is a guess.
6. Keep client data in Canada
Files you hold for Ontario clients should live on Canadian servers. Check where your tools actually store data — not just what the privacy policy claims. If you can't find a straight answer, that's the answer.
7. Separate work from personal accounts
Work email and file storage separate from personal use. Family members, personal photos, and personal files don't belong on the same drive as clinical records — and your work accounts should have no reason to touch a family member's device.
8. The email question
Email is the riskiest channel for health information: minimum necessary content, no bare attachments with identifying information, a secure portal for anything sensitive. Document client consent when you do use email for clinical purposes — the consent protects you, not just them.
9. Know who can touch what — individual logins, same-day offboarding
Every staff member gets their own login; nothing shared. When someone leaves the practice, access ends that day — not next week, not when you remember. A shared password is an access record you can never audit.
10. Keep an access story and a bad-day plan
Know who has access to what, written down somewhere you can find it. Write a one-page plan for what your practice does if you're suddenly unreachable. It doesn't have to be long — it has to exist before you need it.
11. Delete deliberately
In Ontario, a child's clinical record is typically kept until roughly age 28 — that's a long time, so know when the clock ends. Everything outside retention requirements should have a scheduled purge. Old files you can't account for are a liability that compounds quietly.
This list covers what you can do yourself. If you want someone to look at your actual setup and tell you what's covered and what isn't — no sales pitch, just a walk through your stack — that's the walkthrough.
Book the free 45-minute walkthrough
No charge, no obligation. You keep the findings either way.