Ten questions to ask about your practice IT
Originally published in GP magazine .
Written for GP magazine around 2003. This is the version I submitted - the published article may have been edited.
It can be difficult to know what areas are important when evaluating your practice computer usage. The following questions are a useful checklist to ask yourself or any IT support person you may have to ensure you are not forgetting anything important.
Is your anti-virus software set up correctly and working properly? All servers and client PCs in your practice should have anti-virus software installed and running. It should perform regular checks of your computer and update itself regularly to make sure you are covered against the newest viruses. Check it is installed on every machine as it is easy to forget to put it onto new machines.
Have you removed any temporary staff or old employees from your system? This is good practice as a common cause of security breaches in other industries is disgruntled ex-employees who still have valid passwords and knowledge of the IT system.
Make sure your backups are working properly. Your server and clinical data should be being backed up regularly. It might be worth having your data validated to make sure it is restorable. You may also have collected files on individual PCs that are important. Check you are backing these up as well. It may be better to save them on the server in a shared folder.
Make sure every PC is using the same version of the software you use and that it has been updated. I have come across different computers in an office having different versions of Microsoft Office running. Not all PCs may have the latest security updates, leaving them vulnerable to hackers. Different desktops may have different versions of your drug information or travel data, which can compromise clinical safety or just be embarrassing when you can’t find a new drug.
Check everyone has had a copy of your computer use policy. It is easy to forget temporary staff, students or people from other organisations such as the PCT. By pointing out what can and can’t be done - e.g. not installing unauthorised software - you can avoid problems.
Make sure nobody has installed pirated or unlicensed software on any machines. This is particularly easy if you have a lot of people coming into your practice. Not only could this land you with a large fine but it may conflict with your existing software and in certain circumstances breach your security.
Ensure your password policy is being used. It is very easy, particularly for shared computers, to be left logged in under the first person to log in in the morning, so that any audit trail is compromised. This could land you in medico-legal trouble. If your system allows automatic logging off after a period of inactivity, this should be activated.
Is all your equipment security marked and secured, particularly in areas that are easy for the public to get to? This can be easy to forget for new equipment.
Have an up-to-date list of all the computer equipment in your practice, with detailed specifications, e.g. memory, processor etc. It is useful for insurance purposes, and also if money becomes available for upgrading existing equipment it is easy to see what can be changed or moved around.
Simple upgrades can be very cost effective. Check the speed your network is operating at. There are two speeds available, 10 and 100 Mbps. Newer equipment will almost certainly work at the faster speed. If your network hub is relatively old and is only at the slower speed, replacing it with a faster hub or switch and upgrading any existing network cards to the higher speed can make dramatic differences to the speed at which your network works, and is quite affordable. Adding memory to a computer is the cheapest way of improving its performance.