Healthcare IT

IT Support for Australian Medical Practices

Privacy Act compliant IT for GPs, specialists, and allied health. My Health Records security, data breach response, and the controls Australian healthcare regulators expect to see.

18 minute read•Updated June 2026
Healthcare Context

Why medical practices need different IT

Medical practices handle sensitive health information under the Privacy Act. A breach affects real people in vulnerable situations. Regulators, insurers, and patients expect higher standards than a typical small business.

Sensitive data types

Mental health notes, sexual health, substance abuse, family violence. Breach consequences extend beyond financial loss to real harm for patients.

Multiple regulatory layers

Privacy Act, My Health Records Act, state health records legislation, RACGP standards, and professional board requirements. Compliance is multi-layered.

Continuous availability

Practice cannot function without access to patient records. Appointments, scripts, referrals all require clinical system access. Downtime directly impacts patient care.

High staff turnover

GPs come and go. Locums rotate. Reception staff change frequently. Access provisioning and removal must be tight and documented.

Compliance

Australian healthcare compliance requirements

Five regulatory frameworks that affect medical practice IT. Document your compliance with each.

RegulationRequirementApplies ToPenalty
Privacy Act 1988 (Cth)Australian Privacy Principles. APP 11 requires reasonable security steps. Health information is sensitive - highest protection required.All medical practices handling patient dataUp to $62.5 million for serious/repeated breaches (2026)
My Health Records Act 2012Secure access to My Health Record system. Audit logging of all access, role-based access controls, staff training documented, security and access policy reviewed annually.All registered healthcare provider organisations (HPOs)Civil penalties up to $50,000 per breach, suspension from My Health Record system
Notifiable Data Breaches SchemeReport eligible breaches to OAIC and affected individualsAll practices with 10+ staff turnover (most medical practices)Reputational damage, patient notification costs, OAIC investigation
State Health Records ActsVaries by state. Victoria Health Records Act 2001, NSW Health Records and Information Privacy Act 2002.State-specific requirementsState-based penalties and complaints mechanisms
RACGP StandardsCriterion 1.3: Information management. Secure systems, backup, access controls.General practices seeking RACGP accreditationAccreditation impact, insurance implications
Security Controls

Eight security controls for medical practices

These controls form the baseline for Privacy Act compliance and cyber insurance renewal in Australian medical practices.

Encrypted devices with remote wipe

Windows 10/11 Pro with BitLocker (XTS-AES 256-bit encryption). macOS with FileVault. iOS/Android devices with device encryption. Microsoft Intune MDM manages compliance: encryption required, PIN/biometric lock, auto-wipe after 10 failed attempts. Remote wipe enabled for lost/stolen devices. Compliance policies block access from non-compliant devices via Conditional Access.

Critical

Role-based access to clinical systems

Azure AD security groups: "Doctors-FullAccess", "Nurses-ClinicalOnly", "Reception-AppointmentsBilling", "Billing-ClaimsOnly". Medical Director/Best Practice/HealthSuite configured with role-based permissions. Unique Azure AD logins, no shared accounts. Access reviews quarterly via Azure AD Access Reviews. Automated offboarding runbook removes access within 24 hours of staff departure.

Critical

Multi-factor authentication everywhere

MFA on email (Exchange Online), clinical systems (Medical Director/Best Practice SSO), My Health Record (PRODA with MFA), remote access (Azure AD Conditional Access). Microsoft enforcing MFA for all admin sign-ins from Feb 2026. Use Microsoft Authenticator (number match) or FIDO2 keys (YubiKey), not SMS. Conditional Access policies: require MFA for all cloud apps, block legacy authentication (POP3, IMAP, SMTP).

Critical

Immutable backup of patient records

Veeam Backup & Replication or Altaro VM Backup for on-prem clinical databases. Cloud clinical systems (Best Practice Cloud, Medical Director Cloud) have native backup but export critical data weekly. Immutable backup with 90-day retention (ACSC ML2). Object lock enabled on Azure Blob/S3. Test restores quarterly - document results. RTO < 4 hours, RPO < 1 hour. Backup stored separate from production network (different VLAN or cloud).

Critical

Endpoint Detection and Response

Microsoft Defender for Endpoint or CrowdStrike Falcon on all devices accessing patient data. Real-time behavioural analysis, ransomware rollback, automated investigation and remediation. Alerts integrated with SIEM (Microsoft Sentinel). EDR logs retained 12 months for forensic analysis. Blocks unauthorised process execution, credential dumping, lateral movement.

High

Email security gateway

Microsoft Defender for Office 365 (Plan 1 or 2) or Check Point Harmony Email. Phishing protection with AI-based detection, malware scanning, attachment sandboxing (Safe Attachments), URL rewriting and time-of-click analysis (Safe Links). Anti-spoofing: SPF, DKIM, DMARC configured with p=reject policy. Most breaches start with email - this is critical infrastructure.

High

Audit logging and monitoring

Microsoft 365 Unified Audit Log enabled. Clinical system audit logs (Medical Director/Best Practice) exported to SIEM (Microsoft Sentinel). Alert rules: after-hours access (outside 7am-7pm), bulk downloads (>50 patient records in 1 hour), access to VIP patients (staff, celebrities), repeated failed logins. Logs retained 7 years. Review alerts weekly, full log review monthly.

High

Staff security training

Annual privacy and security training (OAIC-approved content). Phishing simulations monthly (KnowBe4 or Microsoft Attack Simulation Training). Document attendance in HR files. New starter induction within first week (privacy, security, My Health Record access). Role-specific training: reception (phone scams), doctors (telehealth security), billing (Medicare fraud detection).

High
Common Gaps

Six common IT gaps in Australian medical practices

These gaps appear repeatedly in medical practice assessments. Each one carries Privacy Act, My Health Records, or professional board risk.

Shared logins for clinical systems

Risk: Cannot attribute access to individuals. Breach investigation impossible. Violates My Health Record requirements.

Fix: Unique logins for every staff member. Review access quarterly. Remove leavers within 24 hours.

No MFA on email or clinical systems

Risk: Account takeover via phishing. Attacker gains access to patient records and Medicare provider number.

Fix: Enable MFA immediately. Use app-based authentication where possible. Document exceptions.

Patient records on unencrypted USB drives

Risk: Lost USB = notifiable data breach. No encryption, no access control, no audit trail.

Fix: Ban USB drives for patient data. Use secure cloud sharing or encrypted drives with MDM.

No tested backup of clinical database

Risk: Ransomware or hardware failure locks you out of patient records. Practice cannot operate.

Fix: Daily immutable backup. Test restores quarterly. Document recovery time objectives.

Receptionists accessing full clinical records

Risk: Privacy Act violation. Staff access patient data beyond their role requirements.

Fix: Implement role-based access. Receptionists access appointments and billing only.

No incident response plan

Risk: Panic and mistakes during a breach. Delayed notification to OAIC and patients. Regulatory penalties.

Fix: Document incident response plan. Include OAIC notification timelines. Test annually.

Need help with medical practice IT compliance

We audit medical practices for Privacy Act compliance, My Health Records security, RACGP standards alignment, and cyber insurance readiness. Deliverables include a prioritised remediation plan and evidence documentation for auditors and insurers.