Veterinary Clinic IT Guide: Software, Records, Checklist
An IT guide for veterinary clinics: cloud and server practice software, imaging storage, lab links, California record rules, DEA logs, and a checklist.
Veterinary clinic IT centers on the practice management software, because whether it runs in the cloud or on a server in your building decides almost everything else: what you back up, what happens in an internet outage, and what hardware you own. Around it sit imaging storage, lab equipment links, card payments, and records that California requires you to keep for at least three years. HIPAA does not apply to animal patients, but state confidentiality and data security laws do. This guide covers each area and ends with a checklist.
Which Practice Management Software Is Cloud and Which Runs on a Server?
Practice information management software (PIMS) holds the appointment book, medical records, invoices, and inventory. The two hosting models lead to different IT needs.
| Product | Vendor | Hosting model |
|---|---|---|
| ezyVet | IDEXX | Cloud, used through a web browser |
| Neo | IDEXX | Cloud; no server required |
| Shepherd | Shepherd Veterinary Software | Cloud |
| Pulse | Covetrus | Cloud |
| Cornerstone | IDEXX | On-premises server; IDEXX also publishes guidelines for a Cornerstone Cloud version |
| AVImark | Covetrus | On-premises, installed in a client/server setup |
What a Server-Based PIMS Needs
- A dedicated server that meets the vendor’s published specification. IDEXX’s Cornerstone hardware guidelines recommend 16 GB or more of memory for database performance, gigabit wired networking, and extra disk and backup space when the server stores digital images.
- A supported version of Windows on the server and workstations, patched on a schedule that fits the software vendor’s update cycle. The same IDEXX document says Cornerstone does not support Windows versions that have reached Microsoft’s end of support, which matters now that Windows 10 support ended on October 14, 2025.
- Backups that you own and test: a local copy for quick restores and an offsite or cloud copy in case of fire, theft, or ransomware.
- A battery backup (UPS) on the server and network equipment, so a power flicker does not corrupt the database.
- Secure remote access if doctors work from home. Do not expose Remote Desktop directly to the internet. See our guide to secure remote access.
What a Cloud PIMS Needs
- A dependable internet connection, since an outage stops access to records. A second connection with automatic failover (often a 4G or 5G cellular modem on the firewall) is the main safeguard.
- Up-to-date browsers and devices in every exam room.
- Multi-factor authentication (MFA, a second proof of identity such as an app code) on every staff login, because the login page is reachable from anywhere.
- A written plan for working during an outage: paper treatment sheets, and a way to view the day’s appointments.
- A periodic export of your data where the vendor offers one, so the clinic holds its own copy.
Our server vs cloud comparison covers the trade-offs in general terms.
How Should a Clinic Handle Imaging and DICOM Storage?
DICOM (Digital Imaging and Communications in Medicine) is the standard file format and network protocol for medical images. Digital X-ray, dental X-ray, ultrasound, and CT equipment produce DICOM files and send them to a PACS (picture archiving and communication system), which may be a server in the clinic or a cloud service from the imaging vendor.
What this means for IT:
- Imaging is part of the medical record. Under California Code of Regulations, title 16, section 2032.3, records must be kept for a minimum of three years after the animal’s last visit, and radiographs and digital images are the property of the facility that ordered them. The regulation also requires each digital image to carry the clinic, veterinarian, client, patient, and date.
- Images are large and they accumulate. Size storage and backups for several years of growth, not for today’s total.
- Check that images are in the backup. If the PACS is local, confirm the image store is included in both the local and offsite copies. If it is a vendor cloud, ask how long images are kept and how you would export them if you changed vendors.
- Use wired connections for imaging workstations and acquisition PCs. Large transfers over Wi-Fi are slow and prone to failure.
- Treat the acquisition PC carefully. The computer attached to an X-ray system often runs vendor-controlled software. Agree with the imaging vendor before applying operating system upgrades, and keep it on a protected network segment.
What Do Lab Integrations Need from the Network?
In-house analyzers and reference laboratories (IDEXX, Antech, and Zoetis are the large ones) can deliver results directly into the patient record. On the IT side:
- Give analyzers and their control stations reserved IP addresses so the PIMS can always find them.
- Keep them on the clinical network, never on guest Wi-Fi.
- If the vendor needs remote access for support, allow that specific connection and nothing broader.
- Record each integration (what connects to what, and the vendor’s support contact) in one document, so a broken link can be traced quickly.
Which Rules Apply to a California Veterinary Clinic?
This is IT guidance, not legal advice. Confirm obligations with your attorney, the Veterinary Medical Board, or your DEA contact.
HIPAA Does Not Cover Animal Patients
HIPAA protects the health information of people and applies to covered entities: health plans, clearinghouses, and health care providers that bill electronically. Animal medical records are outside it. A vendor describing a product as “HIPAA compliant” is not giving a veterinary clinic anything it is required to have.
Client Data Still Has Legal Protection
- Confidentiality. Business and Professions Code 4857 bars a veterinarian from disclosing information about an animal patient, the client, or the care provided, outside listed exceptions such as client consent or a court order.
- Reasonable security. Civil Code 1798.81.5 requires a business holding personal information about California residents to maintain reasonable security procedures appropriate to that information.
- Breach notification. Civil Code 1798.82 requires notice to affected California residents when unencrypted personal information is acquired by an unauthorized person, within 30 calendar days of discovery, plus a sample notice to the Attorney General when more than 500 residents are affected. Encrypted data is exempt unless the key was taken too, which is a strong argument for encrypting laptops and backups.
- CCPA. The California Consumer Privacy Act applies only to for-profit businesses above thresholds listed by the Attorney General, such as more than $25 million in gross annual revenue or personal information from 100,000 or more residents or households. Most single-location clinics fall below them. Our CCPA guide has more.
- Card payments. Accepting cards brings PCI DSS, the card industry’s security standard. See our PCI DSS guide.
Controlled Substance Records and IT
Clinics that stock controlled substances hold a DEA registration. The record-keeping rules touch IT in several places:
- Retention. 21 CFR 1304.04 requires inventories and records to be kept and available for inspection for at least 2 years. Schedule II records must be kept separately from all other records; Schedule III to V records must be either separate or readily retrievable. The same section allows records on an in-house computer system.
- Inventory. 21 CFR 1304.11 requires a new inventory of all controlled substances at least every two years.
- Storage. 21 CFR 1301.75 requires controlled substances to be kept in a securely locked, substantially constructed cabinet.
- State reporting. Under Health and Safety Code 11165, a veterinarian who dispenses a Schedule II to V controlled substance reports it to CURES, the state prescription database, no more than seven days after dispensing.
What that means in practice: if the drug log is electronic, it belongs in the backup, and old entries must stay readable for the whole retention period even after a software change. Every staff member needs an individual login so that log entries identify a person. Computer clocks should sync automatically so timestamps are trustworthy. A camera covering the drug cabinet, recording to storage that staff cannot erase, supports the physical security requirement. Because California’s three-year medical record rule is longer than the federal two-year minimum, many clinics simply keep everything for the longer period.
How Should the Clinic Network Be Laid Out?
Network segmentation splits one physical network into separate virtual networks (VLANs) that cannot reach each other. A sensible clinic layout:
- Clinical: PIMS workstations, exam room devices, imaging, lab analyzers, and the server if there is one.
- Payments: card terminals, kept apart to limit PCI scope.
- Guest Wi-Fi: internet only, for the lobby.
- Cameras and building devices: cameras, recorder, door controllers, thermostats.
- Staff personal devices: phones, kept off the clinical network.
Our network segmentation guide explains the equipment involved. The American Veterinary Medical Association’s cybersecurity resources for practices recommend offsite backups, regular patching, staff awareness training, MFA, and endpoint protection, which matches the checklist below.
Veterinary Clinic IT Checklist
- You know whether your PIMS is cloud or server based, and who supports it
- Server-based: the server meets the vendor’s current specification and runs a supported Windows version
- Server-based: local and offsite backups run daily, and a test restore was done in the last six months
- Cloud-based: a second internet connection fails over automatically, and an outage procedure is written down
- Imaging files are included in backups, or the imaging vendor has confirmed retention and export terms in writing
- Records, images, and lab data are retained at least three years after each patient’s last visit
- Electronic controlled substance logs are backed up and readable for the full retention period
- Every staff member has an individual login; no shared passwords at the front desk
- MFA is on for the PIMS, email, online pharmacy, payroll, and banking
- Former employees are removed from every system the day they leave
- Clinical, payment, guest, and camera networks are separated
- Laptops and backup drives are encrypted
- Workstations, the server, the firewall, and imaging PCs are patched on an agreed schedule
- Analyzer and imaging integrations are documented with vendor contacts
- Server and network equipment are on battery backup
Questions to Ask Any IT Provider
- Have you read my PIMS and imaging vendors’ system requirements, and will you coordinate changes with them?
- How will imaging data be backed up, and how long would a full restore take?
- What is the plan for an internet outage during appointments?
- How will lab analyzers and imaging equipment be kept reachable but protected?
- Will I receive documentation and all admin passwords?
- How are scope and price agreed before work begins?
When You Do Not Need Much of This
A mobile or single-doctor practice on a cloud PIMS, with vendor-hosted imaging and no server, has a short list: encrypted laptops and tablets, MFA everywhere, a cellular hotspot as backup internet, and a password manager. Servers, segmented networks, and local backup systems become relevant as you add exam rooms, in-house imaging, and staff.
Common Questions
Does HIPAA apply to veterinary clinics?
No. HIPAA covers the health information of people, held by health plans, clearinghouses, and providers that bill electronically. Animal records are outside it. California still requires veterinarians to keep client and patient information confidential, and requires any business to protect personal information with reasonable security and to notify residents after certain breaches.
How long must a California veterinary clinic keep records?
At least three years after the animal’s last visit, under title 16, section 2032.3 of the California Code of Regulations. That includes radiographs and digital images, which belong to the facility that ordered them. Federal controlled substance records have a separate two-year minimum, so many clinics keep everything for the longer period.
Is a cloud PIMS safer than a server?
It moves the work. The vendor handles server security, patching, and backups of its own platform. The clinic remains responsible for strong logins with MFA, secure devices, reliable internet, and an outage plan. A well-run server can be equally sound but needs backups, patching, and hardware refreshes that someone must own.
Do electronic drug logs satisfy DEA record rules?
Federal regulations permit records on an in-house computer system, provided they meet the content, separation, and retrieval requirements and remain available for inspection for at least two years. Confirm the details of your own log with your DEA contact or a compliance adviser, then make sure IT backs it up and keeps it readable.
How Coastal Growth Co. Can Help
We can review your clinic’s servers or cloud setup against vendor requirements, build and test backups that include imaging, separate clinical, payment, and guest networks, and set up internet failover, working alongside your PIMS and imaging vendors. Scope and price are agreed first. See our managed IT service and networks, security, and cameras service, or get in touch through the contact page.
- veterinary clinics
- practice management software
- data backup
- networks
- compliance
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward