The before-and-after photo just landed in someone's personal camera roll.

We configure the managed devices used for clinical photography and test where your app actually saves images, including the copies outside the patient record.

When three vendors say it is somebody else's problem, we get on the phone with them.

Ask one IT question

It can start with a slow app, not a hacker

A med spa treatment room between appointments: a clean empty treatment chair, a device cart with a handpiece in its cradle and a small screen showing indistinct shapes, and a tablet on a stand on the counter behind.

The clinical app is slow, so somebody reaches for the ordinary Camera app instead. That photo is now outside the clinical record, and here is where it can land:

  • The camera roll
  • An iCloud or Google Photos library
  • A messaging app
  • A device backup

If that phone or account is personal and unmanaged, the copy sits outside the practice's control entirely.

A treatment consent is not a marketing authorization, and a face photo tied to a body area or a service can be protected health information with no name attached at all.

We set up the managed devices and account controls used for clinical photography. Where the clinical application supports direct capture without leaving a camera-roll copy, we test and configure that workflow so the approved method is also the practical one for staff.

We work for you.

Our managed IT has no long-term contract. There is no separate onboarding fee either.

We resell nothing and take no vendor commissions. Nobody pays us to recommend their product.

Within our scope, we document what your business controls. That means the domains and the administrative accounts. The documentation is yours whenever you want a copy, including when you leave.

One person can end up administrator of everything

It happens gradually. One capable person ends up holding the keys to all of it:

The practice system

Aesthetic Record, Nextech, PatientNow, Zenoti, AestheticsPro, Boulevard or Envision

The payment processor

Check who can change the payout settings.

Email and the website

Check who controls the recovery addresses on file.

Before-and-after photos and consents

TouchMD, RxPhoto, or wherever the clinical images actually live.

Manufacturer reward portals

Each one keeps its own patient records, separate from the chart.

Patient financing

RepeatMD and whatever membership or rewards platform sits beside it.

The device clouds

Each manufacturer runs its own, with a separate login.

PatientNow's own account of itself says Crystal Clear Digital Marketing, RxPhoto and Envision joined it to make a single platform. So two of the practice systems above and one of the two photo products come from the same company. Ask who answers when the photo product and the chart disagree.

If they leave and nobody else has admin, recovering the accounts becomes a hunt through personal inboxes and forgotten recovery codes.

For the systems we manage, we can set up individual logins and a second administrator wherever the vendor allows it, and plan for same-day access removal when you tell us somebody has left.

Where electronic health records live can matter under Texas law

If your attorney determines that Texas Health and Safety Code Chapter 183 applies to your practice and to a particular system, the law requires a covered entity to ensure electronic health records containing patient information are physically maintained in the United States or a U.S. territory.

That includes records held through third-party data centers and cloud providers, which is where most practices actually keep them.

Which means somebody has to actually check where the data sits:

  • The production database
  • Photo storage
  • Backups
  • Disaster-recovery copies

A vendor's "HIPAA compliant" badge does not answer the question of which country the records are in.

Your attorney decides whether and how Chapter 183 applies to your practice. Within an agreed IT scope, we can help obtain and document written vendor statements about those storage locations and configure the technical systems accordingly. We do not provide legal interpretation or a compliance determination.

A connected laser is a device on your network, not just an appliance

The rear panel of a clinical device on a cart, with a blue network cable plugged into it and running to a faceplate on the wall alongside its power lead and a coiled service hose.

Treatment devices connect to Wi-Fi now, for usage tracking, remote support and automatic updates. Put one on an unrestricted network alongside staff laptops, guest Wi-Fi and payment terminals, and a problem on any of them can become a problem for all of them.

Isolating a treatment device has to be tested with the vendor first. A change that blocks calibration or a required update becomes a treatment-day problem.

Where the device and payment vendors support it, we design and test separate segments for:

  • Clinical workstations
  • Payment terminals
  • Connected treatment devices
  • Guest Wi-Fi

The device vendor confirms the design preserves calibration, updates, consumable authentication and remote support. Within our written scope we can document the connected devices the practice identifies for its equipment records.

A vendor's disaster recovery protects the vendor, not necessarily your one deleted patient

A record gets deleted by mistake, or a staff account is compromised. The SaaS vendor's own backup may not give the practice a way to recover one patient's file, and may not guarantee your data stays readable once the contract ends.

Ask now whether they can restore one patient's record, and whether you can take readable records with you when the contract ends.

We can document what the vendor's recovery process does and does not cover. Where backup is in our written scope and the system offers a usable export path, we keep the practice-controlled copy isolated and test the restores available to us.

If we set up or take over a system, we document the practice-controlled domain, administrative accounts, and records within our scope so the practice is not dependent on our continued involvement.

Ask one IT question

Pick the thing about your practice's IT that has been nagging at you and send it over. You will get a straight answer, at no charge, with nothing to sit through afterward. If the honest answer is that somebody has to look at it, we will say so.

Send one question

Email it or pick up the phone. No form to fill in first and no meeting to sit through.

Get a straight answer

At no charge. If it can be answered honestly from the outside, we answer it. If it cannot, we say that instead.

Decide what happens next

Nothing follows automatically. If a closer look would help, we will tell you, and it is still your call.

Before you send it

We already have somebody doing our IT

Ask anyway. If your person has it handled, that is what you will hear, and it will have cost you one email. We are not trying to talk you out of somebody who is doing the job.

What is this going to cost

The answer to a question costs nothing. Anything past that is scoped and priced in writing first, and you approve it before anyone touches a system.

We are in the middle of a contract with someone

Nothing here asks you to break an agreement. A straight answer to one question is not a switch, and plenty of people ask us something years before anything changes.

The free answer, and any separate review

  • An answer to a question, not troubleshooting, system access or ongoing support.
  • Some questions cannot be answered honestly from the outside.
  • If a closer look would help, we may offer a read-only review as a separate engagement, with a written summary of what we found and what we would do about it.
  • Before anyone touches a system, both sides confirm in writing the scope, the sample, who authorizes the access, the date and any fee.
  • Asking does not book a review, and printed material does not reserve an appointment.
  • Reviews are subject to availability. One per practice.

A review is a point-in-time sample of the systems named in the written scope. Items outside that scope are not evaluated and have not passed. It is not a HIPAA or Texas-law audit, legal opinion, compliance determination, certification, or guarantee that protected health information cannot be exposed.

Ask before the next photo ends up in the wrong place

Can your staff take a treatment photo without leaving a copy in somebody's camera roll? Start there.

Call (817) 265-5000 or email [email protected].

Ask one IT question