The Server Was Open to the World — and Nobody Knew
The challenge: SY Medical Centre called us because their system kept slowing down. Doctors couldn't access prescribing software, appointments were being disrupted, and the problem had been going on for nearly two weeks. Everyone assumed it was an internet speed issue. It wasn't.
When we looked under the hood, the real problem was serious. Their clinical software server — the one holding patient records — was hosted in the cloud with no restrictions on who could access it. Anyone on the internet could reach it. Hackers had noticed, and were repeatedly trying to break in and flooding the server with junk traffic to slow it down. On top of that, there was no working backup. Just because a server is "in the cloud" doesn't mean it's being backed up — and this one wasn't.
We moved the server out of the open cloud and into a secure, managed environment at their main clinic. All four locations were then connected through a private, encrypted network — so staff at every site could still access what they needed, but no one from the outside could get in. Every login now requires a second verification step (MFA), so even a stolen password alone can't open the door. Security firewalls were installed at each clinic to stop threats before they reach the network, and automatic daily backups were set up and tested so the practice can recover quickly if anything goes wrong.