IT Support for Australian Medical Practices
Privacy Act compliant IT for GPs, specialists, and allied health. My Health Records security, data breach response, and the controls Australian healthcare regulators expect to see.
Why medical practices need different IT
Medical practices handle sensitive health information under the Privacy Act. A breach affects real people in vulnerable situations. Regulators, insurers, and patients expect higher standards than a typical small business.
Sensitive data types
Mental health notes, sexual health, substance abuse, family violence. Breach consequences extend beyond financial loss to real harm for patients.
Multiple regulatory layers
Privacy Act, My Health Records Act, state health records legislation, RACGP standards, and professional board requirements. Compliance is multi-layered.
Continuous availability
Practice cannot function without access to patient records. Appointments, scripts, referrals all require clinical system access. Downtime directly impacts patient care.
High staff turnover
GPs come and go. Locums rotate. Reception staff change frequently. Access provisioning and removal must be tight and documented.
Australian healthcare compliance requirements
Five regulatory frameworks that affect medical practice IT. Document your compliance with each.
| Regulation | Requirement | Applies To | Penalty |
|---|---|---|---|
| Privacy Act 1988 (Cth) | Australian Privacy Principles. APP 11 requires reasonable security steps. Health information is sensitive - highest protection required. | All medical practices handling patient data | Up to $62.5 million for serious/repeated breaches (2026) |
| My Health Records Act 2012 | Secure access to My Health Record system. Audit logging of all access, role-based access controls, staff training documented, security and access policy reviewed annually. | All registered healthcare provider organisations (HPOs) | Civil penalties up to $50,000 per breach, suspension from My Health Record system |
| Notifiable Data Breaches Scheme | Report eligible breaches to OAIC and affected individuals | All practices with 10+ staff turnover (most medical practices) | Reputational damage, patient notification costs, OAIC investigation |
| State Health Records Acts | Varies by state. Victoria Health Records Act 2001, NSW Health Records and Information Privacy Act 2002. | State-specific requirements | State-based penalties and complaints mechanisms |
| RACGP Standards | Criterion 1.3: Information management. Secure systems, backup, access controls. | General practices seeking RACGP accreditation | Accreditation impact, insurance implications |
Eight security controls for medical practices
These controls form the baseline for Privacy Act compliance and cyber insurance renewal in Australian medical practices.
Encrypted devices with remote wipe
Windows 10/11 Pro with BitLocker (XTS-AES 256-bit encryption). macOS with FileVault. iOS/Android devices with device encryption. Microsoft Intune MDM manages compliance: encryption required, PIN/biometric lock, auto-wipe after 10 failed attempts. Remote wipe enabled for lost/stolen devices. Compliance policies block access from non-compliant devices via Conditional Access.
Role-based access to clinical systems
Azure AD security groups: "Doctors-FullAccess", "Nurses-ClinicalOnly", "Reception-AppointmentsBilling", "Billing-ClaimsOnly". Medical Director/Best Practice/HealthSuite configured with role-based permissions. Unique Azure AD logins, no shared accounts. Access reviews quarterly via Azure AD Access Reviews. Automated offboarding runbook removes access within 24 hours of staff departure.
Multi-factor authentication everywhere
MFA on email (Exchange Online), clinical systems (Medical Director/Best Practice SSO), My Health Record (PRODA with MFA), remote access (Azure AD Conditional Access). Microsoft enforcing MFA for all admin sign-ins from Feb 2026. Use Microsoft Authenticator (number match) or FIDO2 keys (YubiKey), not SMS. Conditional Access policies: require MFA for all cloud apps, block legacy authentication (POP3, IMAP, SMTP).
Immutable backup of patient records
Veeam Backup & Replication or Altaro VM Backup for on-prem clinical databases. Cloud clinical systems (Best Practice Cloud, Medical Director Cloud) have native backup but export critical data weekly. Immutable backup with 90-day retention (ACSC ML2). Object lock enabled on Azure Blob/S3. Test restores quarterly - document results. RTO < 4 hours, RPO < 1 hour. Backup stored separate from production network (different VLAN or cloud).
Endpoint Detection and Response
Microsoft Defender for Endpoint or CrowdStrike Falcon on all devices accessing patient data. Real-time behavioural analysis, ransomware rollback, automated investigation and remediation. Alerts integrated with SIEM (Microsoft Sentinel). EDR logs retained 12 months for forensic analysis. Blocks unauthorised process execution, credential dumping, lateral movement.
Email security gateway
Microsoft Defender for Office 365 (Plan 1 or 2) or Check Point Harmony Email. Phishing protection with AI-based detection, malware scanning, attachment sandboxing (Safe Attachments), URL rewriting and time-of-click analysis (Safe Links). Anti-spoofing: SPF, DKIM, DMARC configured with p=reject policy. Most breaches start with email - this is critical infrastructure.
Audit logging and monitoring
Microsoft 365 Unified Audit Log enabled. Clinical system audit logs (Medical Director/Best Practice) exported to SIEM (Microsoft Sentinel). Alert rules: after-hours access (outside 7am-7pm), bulk downloads (>50 patient records in 1 hour), access to VIP patients (staff, celebrities), repeated failed logins. Logs retained 7 years. Review alerts weekly, full log review monthly.
Staff security training
Annual privacy and security training (OAIC-approved content). Phishing simulations monthly (KnowBe4 or Microsoft Attack Simulation Training). Document attendance in HR files. New starter induction within first week (privacy, security, My Health Record access). Role-specific training: reception (phone scams), doctors (telehealth security), billing (Medicare fraud detection).
Six common IT gaps in Australian medical practices
These gaps appear repeatedly in medical practice assessments. Each one carries Privacy Act, My Health Records, or professional board risk.
Shared logins for clinical systems
Risk: Cannot attribute access to individuals. Breach investigation impossible. Violates My Health Record requirements.
Fix: Unique logins for every staff member. Review access quarterly. Remove leavers within 24 hours.
No MFA on email or clinical systems
Risk: Account takeover via phishing. Attacker gains access to patient records and Medicare provider number.
Fix: Enable MFA immediately. Use app-based authentication where possible. Document exceptions.
Patient records on unencrypted USB drives
Risk: Lost USB = notifiable data breach. No encryption, no access control, no audit trail.
Fix: Ban USB drives for patient data. Use secure cloud sharing or encrypted drives with MDM.
No tested backup of clinical database
Risk: Ransomware or hardware failure locks you out of patient records. Practice cannot operate.
Fix: Daily immutable backup. Test restores quarterly. Document recovery time objectives.
Receptionists accessing full clinical records
Risk: Privacy Act violation. Staff access patient data beyond their role requirements.
Fix: Implement role-based access. Receptionists access appointments and billing only.
No incident response plan
Risk: Panic and mistakes during a breach. Delayed notification to OAIC and patients. Regulatory penalties.
Fix: Document incident response plan. Include OAIC notification timelines. Test annually.

Remote Support