Skip to content

Clinics and healthcare

A nightly copy, a current certificate and no odd warnings.

A healthcare website flagged as not secure loses patients before anyone reads it. And what gets lost does not come back on its own.

The clinic website is copied whole every night away from the server that serves it, the restore is tested and the security certificate renews itself, which are the measures article 32 of the GDPR requires you to be able to demonstrate.

Last reviewed:

The padlock does get looked at in healthcare

Anybody about to leave their name and phone number on a clinic’s form will notice whether the browser says the site is secure. If it says otherwise, they do not leave them. The certificate is there from day one and renews itself, precisely so that doubt never arises.

Being able to restore is not optional: it is in article 32

The GDPR lists the required security measures and two of them describe exactly this: being able to restore the availability and access to personal data in a timely manner after an incident, and regularly verifying that the ability works. A clinic handles special category data, so that bar is looked at more closely than in other sectors.

What gets kept from a healthcare website

The page for each treatment, which took time to write and review; the photos of the centre and the team; the legal texts with their date; and the appointment requests received. It is not the medical record — that lives in your management software and has its own backups — but it is everything else.

And testing it before needing it

A copy nobody has ever restored is an assumption. The test happens cold, on a quiet day, so that nobody discovers at eight on a Monday morning that the file was incomplete.

The same thing, explained in general: Daily backups

What we do about it

Part of the maintenance: you never have to ask, and it is never billed apart.

  • A full copy every night Pages, photos, legal texts and the requests received.
  • Kept off the server If the machine is the problem, the copy does not go with it.
  • The restore tested Tested cold, with a record that it works.
  • Security certificate Renewed on its own, with no warnings to scare anyone off.
  • Security updates The server kept current with nothing for you to approve.
  • Restore on request You tell us, we pick the point and leave it as it was.

And this you change with one sentence

You write what you want changed and we publish it.

I have deleted a treatment page

Recovered exactly as it was yesterday, with its text and its photos.

A «not secure» warning is showing

We look at it the same day: nearly always something loaded without encryption.

I want a copy for our own archive

Prepared and handed over whenever you ask.

Frequently asked questions

Are medical records included in this copy?

No. Medical records live in your management software, not on the website, and they have their own backups and their own requirements. This is about the website.

Does this make me GDPR compliant?

It covers the part of article 32 that depends on the website. The rest is your data protection officer’s work.

How long does a restore take?

For one page, minutes. For everything, longer, and we give you the estimate at the start.

What if somebody tries to break into the site?

The server is kept updated and watched. If something happens, we tell you what we know, not once it is already resolved.

Where all this comes from

Every figure and every rule quoted above, linked to the official text.

When was your website backup last tested?

If nobody knows, there is no tested backup. We will set it up and show you the restore working.

Write to us