A reception tablet may pass between several people during a clinic day. That makes it worth checking two separate questions: who can unlock the device, and whose account is open inside the clinic software.

A successful sign-in does not tell you whether the right person has the right permissions. This checklist helps clinic owners review the everyday arrangement, including shift changes and temporary cover. It is a practical review method, not a security certification or a claim that every software product offers the same controls.

Start with the work people actually do

Write down the tasks each role needs to perform. Reception may need to manage appointment information; a practitioner may need access to relevant clinical records; an authorised manager may need to administer staff or review reports.

Treat these as questions for your own clinic, rather than a universal permission template. Identify which information each person needs, which actions they should be able to take and whether access should be limited to a particular location.

The NCSC's identity and access management guidance recommends defining access needs, reviewing privileges and changing or removing access as people move roles or leave. It also recommends keeping administrative activity separate from ordinary account use.

In a software demonstration, ask to see those boundaries using a test account. A description such as “staff access included” does not show whether someone can export records, change another person's permissions or see information from every location.

Distinguish the device lock from the clinic account

The device lock protects access to the tablet, phone or computer. The application sign-in identifies the user inside the service. Record how both work on each shared device.

The NCSC's device guidance recommends protecting device access and keeping devices, applications and browsers updated. It covers shared business devices as well as personal devices used for work.

For a clinic handover, check what actually happens when one person finishes and another starts. Is the previous user's name still displayed? Can the next person open a record without identifying themselves? Does the software offer a supported lock or switch-user action?

Do not rely on closing one browser tab as proof that the application session has ended. Test the product's documented process, and ask the supplier to clarify behaviour you cannot verify.

Run a short handover rehearsal

Use a supplier-approved test environment with fictional records. Do not create pretend appointments or patient notes in the live clinic diary just to complete this exercise.

  1. Sign in as the first test staff member and check the displayed identity.
  2. Open a permitted test record and begin a harmless sample task.
  3. Save or deliberately discard that work using the normal controls.
  4. Follow the documented lock, sign-out or switch-user process.
  5. Ask the second test user to continue and check their identity and permissions.
  6. Review the available activity record to see which account performed each action.

Note the result and any gap. If the second user can act as the first, stop using that handover method and agree a supported alternative with the supplier. If a shared device cannot provide an appropriate separation for its intended use, change the arrangement before relying on it.

The aim is a repeatable routine staff can follow between appointments without guessing which session is open.

Check the accounts around the clinic system

Clinic software is only one part of the picture. Email, file storage, payment services and website administration may have their own accounts and recovery routes.

The NCSC's guidance on important online accounts recommends passkeys where available, and strong unique passwords with two-step verification where passwords remain in use. Apply each provider's supported controls. Do not assume a clinic PIN automatically protects a separate email or payment account.

Check who owns recovery details and how an authorised replacement would regain access. A clinic should not discover during an absence that an essential service depends entirely on a former employee's personal phone.

A fictional clinic example

A fictional clinic has two practitioners, one receptionist and a visiting practitioner. The owner initially plans to leave the reception tablet signed in all day for convenience.

During a test rehearsal, the team notices that switching chairs does not switch the account. They agree a documented handover routine and ask the supplier to demonstrate how each person's activity is recorded.

The visiting practitioner's access is given a review date tied to their work at the clinic. The owner also discovers that a former colleague is still listed on a separate file-sharing service, and assigns that service's access review to the relevant administrator.

No breach or patient outcome is implied by this example. It shows how a small review can reveal assumptions that are otherwise easy to miss.

Include joining, role changes and leaving

Keep a short access checklist alongside staff onboarding and offboarding:

  • Joining: approve the role and location access, explain the device routine and confirm the person can complete their required work.
  • Changing role: review existing permissions before adding new ones, including access held in separate services.
  • Leaving or finishing temporary cover: agree when access ends, transfer ownership of unfinished work and ask the relevant administrators to revoke access through each service's process.

Do not delete clinical records or erase account history as a substitute for ending access. Ask the provider how it preserves attribution and how revocation affects sessions that are already signed in.

Record the next action, not just a tick

A useful review record contains the date, reviewer, systems checked, gaps found, person responsible and the agreed completion date. Avoid putting passwords, PINs or recovery codes in the review document.

Repeat the review after a staffing or device change, and set a periodic review that suits the clinic. For several locations, use the same questions but record where the arrangements differ.

Use Rytura's security and privacy information and the clinic software buyer's checklist as starting points for supplier questions. Verify the controls available for your current service and configuration, then include the handover routine in the team's everyday training.

Sources were checked on 14 September 2026. The rehearsal, checklist and fictional example are Rytura editorial recommendations informed by the linked NCSC guidance.