IT and cyber compliance for NZ healthcare and allied-health practices

How a NZ healthcare practice scaled from zero to 100+ staff in under 12 months, and what yours can learn from it.

This is a real case study, with the client's permission, about what good looks like when a clinical service scales fast and the IT has to keep up. Read it first. If you see your own practice in the story, the assessment is one click away.

Get My Cyber Security & Compliance Risk Assessment

Four quick questions, then pick a time. No obligation, no sales pitch. You keep the report either way.

Not ready? Read the case study and see what the assessment covers.

Prefer the phone? Call 0800 242 206.

  • Supporting NZ businesses since 2005
  • 100+ organisations, 20 to 200 staff
  • Support calls answered in under 11 seconds
  • 98% client retention (2022 to 2025)
  • ISO 27001 certifiedISO 27001 + ISO 42001 certified, independently audited annually

Case study: scaling ADHD Simple to 100+ staff in under 12 months

  • Client:ADHD Simple (psychiatry and MedTech)
  • Location:NZ and Australia
  • Sector:Healthcare, allied health, digital health
  • Engagement:2024 to present

The situation.

ADHD Simple is a fast-growing psychiatry and MedTech service supporting patients across New Zealand and Australia. When OxygenIT came on board, the team was small, the device estate was inconsistent, and clinician onboarding was taking days. Clinicians were bringing their own tools, support tickets were going to personal emails, and there was no formal onboarding path.

What we did.

  • Stood up a managed IT environment designed for clinical use, with healthcare-grade security and a zero-tolerance posture for breach
  • Built a one-click clinician onboarding process that takes minutes instead of days
  • Consolidated the device estate to a single standard, with each new clinician's laptop imaged, secured, and shipped before their first shift
  • Stood up a NZ-based helpdesk that the ADHD Simple team reports reaching in 20 to 30 seconds
  • Implemented the cyber security controls healthcare-grade practices are expected to have: MFA, endpoint protection, email security, DNS filtering, tested backups, and patch management as a default

The result.

  • 5 days from signed quote to first laptops delivered to clinicians
  • 20 to 30 second answer time on clinician support calls, as reported by ADHD Simple
  • 1-click clinician onboarding
  • Zero to 100+ staff in under 12 months across NZ and AU
  • Healthcare-grade security posture, with the documentation an insurer or auditor accepts

Case study interview with Cameron Houston, CEO, ADHD Simple.

What this case study is actually about

The headline number is 5 days from signed quote to laptops delivered. The headline number is also the least interesting part.

The interesting part is what made it possible. A clinical service that scales from zero to 100+ staff in a year is not just a tech problem. It is a clinical safety problem, a privacy problem, a clinician experience problem, and a regulator-trust problem, all at once. The IT has to be the thing that makes the rest of that scale safely, not the thing that gets in the way.

If you are running an allied health, specialist, or digital health practice in NZ and any of the following sounds familiar, the rest of this page is for you:

  • Clinicians are bringing their own devices, or onboarding takes longer than a shift
  • Your cyber insurance questionnaire answers are out of date, and you would struggle to prove them
  • Your patient data lives in more places than your privacy policy says it does
  • Support tickets disappear into a black hole, and your team has learned to live with it
  • A clinician quit last week, and you are still not sure their access has been cleanly revoked

These are the problems we solve. The case study is the proof. The audit is the starting point.

The OxygenIT team

If you saw your practice in that case study, here's the next step

Our Cyber Security & Compliance Risk Assessment checks your practice against the controls your insurer, your auditors, and the Health Information Privacy Code expect. It takes one booked call to start, and the report tells you exactly where you stand.

What the Cyber Security & Compliance Risk Assessment covers

This is not a sales call with a checklist stapled to it. We take your actual cyber insurance policy wording and your privacy obligations, and we check your practice against both, control by control.

What gets checked:

  • The security controls your insurance questionnaire says you have, verified against what is actually configured
  • Patient data access and the audit trail that proves it
  • Multi-factor authentication coverage across every staff login, including clinician exceptions
  • Backup status, and whether those backups have actually been tested
  • Patching, email security, DNS filtering and endpoint protection
  • Where patient records and clinical notes live, and who can reach them
  • Whether the Health Information Privacy Code's expectations on storage, access and disclosure are operationally met (optional module - confirm with the practice on the call)

What you get:

  • A plain-English report: compliant, at risk, or non-compliant, control by control
  • A prioritised fix list, so you know what to do first and what can wait
  • Documentation you can put in front of your insurer at renewal and your auditor at review
Assessments start from $1,500. Practices that need the Health Information Privacy Code module can include it; the exact scope and price are confirmed on the call.

What working with OxygenIT looks like

Managed IT and helpdesk.

Proactive monitoring, patching and a NZ-based team that answers your support line, 0800 101 095, in under 11 seconds. No call centre, no ticket black hole. After-hours cover is an optional add-on staffed by our United Kingdom team.

Cyber security.

The six controls insurers actually ask about: multi-factor authentication, endpoint detection and response, patch management, email security, DNS filtering, and tested backups.

Microsoft 365 and cloud.

Setup, migration, backup and disaster recovery for the platforms your practice runs on.

Practice management software support.

We support Indici, MedTech and Best Practice, and we work with the other platforms NZ healthcare and allied health practices use day to day.

Strategy when you need it.

Fractional vCIO and vCSO input for practices that need a technology roadmap, not just a helpdesk.

How it works

  1. Answer four questions. Takes about a minute, tells us if we're a fit.
  2. Pick a time. You'll be redirected straight to the booking calendar.
  3. Get your assessment. A clear report on where you stand with your insurer, your privacy obligations, and what to fix.

FAQ

Do you only work with Christchurch firms?
No. We're NZ-wide, with offices in Christchurch and Wellington and an engineer in Auckland. Most of what we do is delivered remotely, with on-site work where it's needed.
Do you support our practice management software?
We actively support Indici, MedTech and Best Practice, and we work with the other platforms NZ healthcare and allied health practices use day to day. If you're not sure, ask on the call.
We already have an IT provider. Is the assessment still useful?
Yes. The assessment is an independent check against your insurance and privacy obligations. If your current provider has everything in order, you'll have documented proof of it. If not, you'll know exactly what to raise with them.
What size practices do you work with?
We support organisations from 20 to 200 staff, and our healthcare clients range from small specialist practices to multi-clinician operations.
What does the assessment cost?
Assessments start from $1,500. Practices that need the Health Information Privacy Code module can include it; the exact price depends on the size of your practice and what your insurance policy and privacy obligations require, and we confirm it on the call before any work starts.
Will you try to sell us managed IT on the call?
The assessment stands on its own. If there are gaps and you want help closing them, we'll tell you what that looks like. If everything checks out, you'll hear that too.
How is OxygenIT different from other IT companies?
We publish our numbers. Support calls answered in under 11 seconds, a 15 minute response guarantee on P1 critical issues, 98% client retention from 2022 to 2025, and ISO 27001 plus ISO 42001 certification audited independently every year. Few NZ providers publish even one of those.
{ "@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "Do you only work with Christchurch firms?", "acceptedAnswer": { "@type": "Answer", "text": "No. We’re NZ-wide, with offices in Christchurch and Wellington and an engineer in Auckland. Most of what we do is delivered remotely, with on-site work where it’s needed." } }, { "@type": "Question", "name": "Do you support our practice management software?", "acceptedAnswer": { "@type": "Answer", "text": "We actively support Indici, MedTech and Best Practice, and we work with the other platforms NZ healthcare and allied health practices use day to day. If you’re not sure, ask on the call." } }, { "@type": "Question", "name": "We already have an IT provider. Is the assessment still useful?", "acceptedAnswer": { "@type": "Answer", "text": "Yes. The assessment is an independent check against your insurance and privacy obligations. If your current provider has everything in order, you’ll have documented proof of it. If not, you’ll know exactly what to raise with them." } }, { "@type": "Question", "name": "What size practices do you work with?", "acceptedAnswer": { "@type": "Answer", "text": "We support organisations from 20 to 200 staff, and our healthcare clients range from small specialist practices to multi-clinician operations." } }, { "@type": "Question", "name": "What does the assessment cost?", "acceptedAnswer": { "@type": "Answer", "text": "Assessments start from $1,500. Practices that need the Health Information Privacy Code module can include it; the exact price depends on the size of your practice and what your insurance policy and privacy obligations require, and we confirm it on the call before any work starts." } }, { "@type": "Question", "name": "Will you try to sell us managed IT on the call?", "acceptedAnswer": { "@type": "Answer", "text": "The assessment stands on its own. If there are gaps and you want help closing them, we’ll tell you what that looks like. If everything checks out, you’ll hear that too." } }, { "@type": "Question", "name": "How is OxygenIT different from other IT companies?", "acceptedAnswer": { "@type": "Answer", "text": "We publish our numbers. Support calls answered in under 11 seconds, a 15 minute response guarantee on P1 critical issues, 98% client retention from 2022 to 2025, and ISO 27001 plus ISO 42001 certification audited independently every year. Few NZ providers publish even one of those." } } ] }

Find out where you stand before your insurer, or your auditor, does.

Four questions. One booked call. A clear answer on whether your practice is actually compliant with its cyber insurance and privacy obligations, and what to fix if it isn't.

Get My Cyber Security & Compliance Risk Assessment

ISO 27001 + ISO 42001 certified, independently audited every year.

Or call 0800 242 206.