All insights

Does a general practice need its own IT department?

2 min readBy Brendon Whiting, Founder · 17 June 2026

No. A general practice needs the functions of an IT department, a help desk, patching, security monitoring, someone owning vendor problems, but not the headcount. Hospitals employ IT teams because they run at hospital scale; a practice gets the same functions from a managed provider for a published per-user monthly fee.

The comparison with hospitals is worth making, because it shows what the job actually is. A hospital IT department keeps clinical systems running, secures patient data, manages devices and wrangles vendors, around the clock. A general practice has exactly the same list, Best Practice or MedicalDirector instead of hospital systems, the same Privacy Act obligations, the same dependence on results arriving, just at a scale where a full-time hire is hard to justify and a single hire could never cover the hours.

The economics are blunt. One IT salary buys a practice one person: on leave sometimes, asleep at night, strong in some areas and not others. The same functions delivered as managed support cost a per-user monthly fee and arrive with things no small team can staff, a 24/7 network and security operations centre, depth across the clinical software, cover that does not take annual leave. Our published plans run $79 to $199 per user per month.

The honest caveat is that outsourcing the functions does not outsource the ownership. Someone inside the practice, usually the practice manager, still owns the decisions: what gets bought, who gets access, when to say yes. And the tech-savvy receptionist who reboots the router is a kindness, not a security control. To see what the functions cost against what you have now, our Essential Eight Cyber Security Scorecard is free, or call 1800 456 567.

See what the functions cost, per person.

Every plan is managed IT support with a named Essential Eight maturity level built in, priced per user per month and published openly.

Frequently asked questions

It keeps clinical systems running, secures patient data, manages devices and networks, applies updates and deals with vendors, continuously. The reason the question matters for a practice is that the list is identical at clinic scale: the same functions have to exist somewhere, whether performed by employees, a managed provider, or nobody, which is the risky default.

A managed provider does the work, but the practice still needs one named owner, usually the practice manager, who approves spending, access and changes. The provider should make that job light: plain-English recommendations, a documented environment and regular reporting. If nobody inside the practice owns IT, decisions default to whoever shouts loudest on a bad day.

A middle model: the practice keeps some IT capability in-house, often for day-to-day requests, while a provider supplies the heavier functions, security operations, patching discipline, backup management and escalation depth. It suits larger practices and groups. The boundary needs writing down, otherwise both sides assume the other one tested the backups.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.