Losing access to patient records stops a practice rather than merely inconveniencing it — and where personal data may have been exposed, a regulatory clock starts at the same moment. We work with practices, clinics and care providers across Cambridgeshire on both halves of that: getting clinical systems back, and preserving the evidence needed to answer the regulator honestly. Handled here, by our own engineers, inside the UK.
Clinical databases, imaging storage and practice servers — recovered under a signed processing agreement, held only as long as you specify, and never sent outside the UK.
Before the technical question, the regulatory one, because the deadline is shorter than most people assume.
If personal data has been lost or become inaccessible and there is a risk to the people it concerns, UK GDPR requires notification to the ICO within 72 hours of becoming aware. Not within 72 hours of the recovery finishing, and not within 72 hours of establishing the scale.
That means the reporting decision and the recovery run in parallel rather than in sequence. We can tell you quickly what was affected and whether it is readable, and that assessment frequently informs the notification — but do not wait for it before starting the clock.
Clinical data carries the additional weight that it may be needed for care rather than for records. Where that applies, say so on the first call and it changes what we prioritise.
Practice management and imaging systems, usually on a single server or a small array, frequently with a backup nobody has verified in some time.
Radiology and imaging archives where the format matters as much as the media. Getting the files back and getting the viewer to mount them are two problems.
Trial and study data under governance frameworks, where chain of custody and audit trail matter as much as recovery.
Diagnostic equipment writing to internal drives or cards, often on legacy interfaces because the device outlived its software.
Everything stays in-house. Nothing is subcontracted, no data leaves the UK, and one named engineer handles the job from diagnostic to delivery so the number of people with access is minimal and recorded.
We are ICO registered, we document chain of custody as standard on this class of work whether or not it is requested, and we will sign your own information governance terms before the media arrives. Where a data processing agreement is required, tell us at the diagnostic and it can be in place before anything is sent.
Ring rather than emailing and say that on the call. Where data is needed for care rather than records, that changes what we prioritise and we will be honest about what is achievable and when.
If personal data is affected and there is risk to the individuals concerned, notification to the ICO is required within 72 hours of becoming aware. Start that clock now rather than after the recovery.
Yes, and before the media arrives. Tell us at the diagnostic and it can be in place in advance rather than retrofitted.
That is the second half of the job and we treat it as part of it. Recovering DICOM or a PACS store and having the viewer mount it are different problems, and we will say which we can solve.
One named engineer, in-house, with custody documented at every step. Nothing is subcontracted and no data leaves the UK.
From £500 +VAT for servers and arrays, £300 +VAT for a single machine, fixed in writing after the free 48-hour diagnostic.